Tool
Retention and erasure under Rule 8
Identify the retention triggers on file, compute the 1 year floor and the 48 hour warning deadline deterministically, and see exactly where another law takes over. The framework carries 2 separate 1 year minimum floors, not 1.
Commencement note: Rules 3, 5 to 16, 22 and 23 are not yet in force. The computed date is 13 May 2027, which is interpretation until officially confirmed. Basis of the computation: Publication date 13 November 2025 printed on Gazette issue No. 760, plus eighteen months. The eGazette portal lists this document with a code embedding 14112025 and the Government's own PIB release states 14 November 2025, which would move the computed date by 1 day; the printed masthead date is used, and the interpretation label carries that uncertainty. The corrigendum wording change does not affect this computation. Building ahead of the duty is the practical move. See Rule 8, official text.
Logs and data for the Seventh Schedule purposes must be kept at least 1 year from this date.
The Data Principal must be informed at least 48 hours before the erasure period completes.
The retention duties on file
Timed erasure for the 3 Third Schedule classes
Rule 8(1) deems the specified purpose no longer served, so the section 8(7) erasure duty bites, after a period of inactivity fixed by the Third Schedule. It binds only 3 classes: an ecommerce entity with not less than 2 crore registered users in India, an online gaming intermediary with not less than 50 lakh, and a social media intermediary with not less than 2 crore. The period is 3 years, and it runs from the latest of the Data Principal's last approach for the specified purpose or exercise of rights and the commencement of the Rules, so the clock restarts at commencement for dormant accounts. Every row excepts the data needed to let her access her user account and any stored virtual token usable to get money, goods or services, so this is not account deletion. Retention necessary for compliance with any law in force is carved out. Outside these 3 classes there is no deemed date, and the section 8(7) reasonable assumption test applies instead.
48 hour warning before timed erasure
At least 48 hours before the erasure period completes, the Data Principal must be informed that the data will be erased unless she logs into her user account, otherwise initiates contact for the performance of the specified purpose, or exercises her rights. The warning is defined by reference to each person's own erasure date, so it cannot be satisfied by a fixed batch schedule. Rule 2(1)(c) defines user account to include profiles, pages, handles, email address and mobile number, so the channels that count are wider than a login page. The 48 hours is a floor and not a maximum, so warning earlier is compliant.
1 year floor: Rule 8(3), for the Seventh Schedule purposes
Personal data, associated traffic data and other logs of the processing must be retained for a minimum of 1 year from the date of processing, for the purposes specified in the Seventh Schedule, and then erased, unless further retention is required for compliance with any other law in force or notified by the Government. This is a minimum and not a maximum: it requires keeping data, not deleting it. The Illustration to the sub rule states that the year runs even if the Data Principal deletes her account, and requires the Data Fiduciary to ensure its Data Processor also retains for the year.
1 year floor: Rule 6(1)(e), for security investigation
A second and separate 1 year floor sits in the reasonable security safeguards. Logs and personal data must be retained for 1 year to enable detection of unauthorised access, its investigation, remediation to prevent recurrence and continued processing after a compromise, unless compliance with any law in force requires otherwise. It reaches different material from the Rule 8(3) floor, which also covers associated traffic data, and its saving clause is drafted differently: this one yields where another law "requires otherwise", while Rule 8(3) yields only where "further retention is required". What that difference does is this site's reading of the 2 phrasings and not a statement either sub rule makes. Rule 8(3) also dates its year "from the date of such processing" while this clause fixes no start point at all. Both commence with the same group.
These are the duties on a Data Fiduciary. The Rules carry 1 more duty to keep, at least 7 years for a Consent Manager’s record of consents, notices and sharing under First Schedule Part B item 4(c), which is set out in DPDP data retention and erasure.
Where another law controls: Where retention is necessary for compliance with any other law, that law controls and can require keeping data longer. This tool does not guess what other laws require of you; sectoral retention questions belong with your counsel.
Dates entered here stay on this page. Calculations are deterministic and shown with their assumptions.
The provisions this tool rests on
The provisions below are the sources for the legal statements on this page. Each links to the official document it was verified against, and to the provision on this site wherever this site publishes that provision. The label says whether the site is reporting a requirement, explaining it, reading it, recommending something, or pointing at a text it does not restate.
DPDP Rules 2025, r. 8, (1)
Official requirement · Verified 26 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(1) A Data Fiduciary, who is of such class and is processing personal data for such corresponding purposes as are specified in Third Schedule, shall erase such personal data, unless its retention is necessary for compliance with any law for the time being in force, or, for the corresponding time period specified in the Third Schedule, if the Data Principal neither approaches such Data Fiduciary for the performance of the specified purpose nor exercises her rights in relation to such processing.
Rule 8 on this site Official source ↗ Also on MeitY (byte identical) ↗
DPDP Rules 2025, Third Schedule
Official requirement · Verified 26 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
Three years from the date on which the Data Principal last approached the Data Fiduciary for the performance of the specified purpose or exercise of her rights, or the commencement of the Digital Personal Data Protection Rules, 2025, whichever is latest.
Third Schedule on this site Official source ↗ Also on MeitY (byte identical) ↗
The Third Schedule begins on Gazette page 35 and concludes on page 36. Whether a given business falls inside a class is a legal question about borrowed definitions: the Note to the Schedule defines e-commerce entity itself, borrowing e-commerce and marketplace e-commerce entity from the Consumer Protection Act, 2019, and defines social media intermediary wholly by reference to clause (w) of sub-rule (1) of rule 2 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. The text quoted here is the time period cell, column (4), which is printed identically in all 3 rows; the class and purpose cells differ by row and are described above.
DPDP Act 2023, s. 8, (8)
Official requirement · Verified 26 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(8) The purpose referred to in clause (a) of sub-section (7) shall be deemed to no longer be served, if the Data Principal does not–– (a) approach the Data Fiduciary for the performance of the specified purpose; and (b) exercise any of her rights in relation to such processing, for such time period as may be prescribed, and different time periods may be prescribed for different classes of Data Fiduciaries and for different purposes.
Section 8 on this site Official source ↗
The deeming power Rule 8(1) exercises. Section 8(11), on the same page, clarifies that a Data Principal has not approached the Data Fiduciary in any period during which she has not initiated contact for the performance of the specified purpose.
DPDP Rules 2025, r. 8, (2)
Official requirement · Verified 26 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(2) At least forty-eight hours before completion of the time period for erasure of personal data under this rule, the Data Fiduciary shall inform the Data Principal that such personal data shall be erased upon completion of such period, unless she logs into her user account or otherwise initiates contact with the Data Fiduciary for the performance of the specified purpose or exercises her rights in relation to the processing of such personal data.
Rule 8 on this site Official source ↗ Also on MeitY (byte identical) ↗
DPDP Rules 2025, r. 8, (3)
Official requirement · Verified 26 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(3) Without prejudice to sub-rules (1) and (2), a Data Fiduciary shall retain, in respect of any processing of personal data undertaken by it or on its behalf by a Data Processor, such personal data, associated traffic data and other logs of the processing for a minimum period of one year from the date of such processing, for the purposes as specified in the Seventh Schedule, after which the Data Fiduciary shall cause such personal data and logs to be erased, unless further retention is required for compliance with any other law for the time being in force or notified by the Government.
Rule 8 on this site Official source ↗ Also on MeitY (byte identical) ↗
DPDP Rules 2025, Seventh Schedule
Official requirement · Verified 26 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
Use, by the State or any of its instrumentalities, of personal data of a Data Principal in the interest of sovereignty and integrity of India or security of the State. … Such officer of the State or of any of its instrumentalities notified under clause (a) of sub-section (2) of section 17 of the Act, as the Central Government or the head of such instrumentality, as the case may be, may designate in this behalf.
Seventh Schedule on this site Official source ↗ Also on MeitY (byte identical) ↗
The Seventh Schedule is headed "[ See rule 23(1) and 8(3)]" and runs from Gazette page 40 to page 41. Its 3 purposes are use by the State or its instrumentalities in the interest of sovereignty and integrity of India or security of the State; use by the State or its instrumentalities for performing a function or fulfilling an obligation under law; and carrying out assessment for notifying any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary. Its third column is headed "Authorised person" and names, for each purpose, the person through whom the Central Government exercises the Rule 23(1) power to call for information. The Schedule is a table, so no contiguous run of it reproduces the whole: the text quoted here is row 1, both cells, and rows 2 and 3 are described in this note rather than quoted.
DPDP Rules 2025, r. 6, (1)(e)
Official requirement · Verified 26 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(e) for enabling the detection of unauthorised access, its investigation, remediation to prevent recurrence and continued processing in the event of such a compromise, retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise
Rule 6 on this site Official source ↗ Also on MeitY (byte identical) ↗
DPDP Act 2023, s. 8, (7) Illustrations
Official requirement · Verified 26 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
Illustrations. (I) X, an individual, registers herself on an online marketplace operated by Y, an e-commerce service provider. X gives her consent to Y for the processing of her personal data for selling her used car. The online marketplace helps conclude the sale. Y shall no longer retain her personal data. (II) X, an individual, decides to close her savings account with Y, a bank. Y is required by law applicable to banks to maintain the record of the identity of its clients for a period of ten years beyond closing of accounts. Since retention is necessary for compliance with law, Y shall retain X’s personal data for the said period.
Section 8 on this site Official source ↗
Illustration II to section 8(7) is the framework's own worked example of another law controlling: a bank required to keep client identity records for ten years beyond account closing retains them for that period.
Sources cited on this page
- [1]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 8, (1), p. 27. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 26 August 2026
- [2]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), Third Schedule, p. 35. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 26 August 2026The Third Schedule begins on Gazette page 35 and concludes on page 36. Whether a given business falls inside a class is a legal question about borrowed definitions: the Note to the Schedule defines e-commerce entity itself, borrowing e-commerce and marketplace e-commerce entity from the Consumer Protection Act, 2019, and defines social media intermediary wholly by reference to clause (w) of sub-rule (1) of rule 2 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. The text quoted here is the time period cell, column (4), which is printed identically in all 3 rows; the class and purpose cells differ by row and are described above.
- [3]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, (8), p. 8. Published 11 August 2023. Official source ↗ · Official requirement · Verified 26 August 2026The deeming power Rule 8(1) exercises. Section 8(11), on the same page, clarifies that a Data Principal has not approached the Data Fiduciary in any period during which she has not initiated contact for the performance of the specified purpose.
- [4]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 8, (2), p. 27. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 26 August 2026
- [5]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 8, (3), p. 27. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 26 August 2026
- [6]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), Seventh Schedule, p. 40. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 26 August 2026The Seventh Schedule is headed "[ See rule 23(1) and 8(3)]" and runs from Gazette page 40 to page 41. Its 3 purposes are use by the State or its instrumentalities in the interest of sovereignty and integrity of India or security of the State; use by the State or its instrumentalities for performing a function or fulfilling an obligation under law; and carrying out assessment for notifying any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary. Its third column is headed "Authorised person" and names, for each purpose, the person through whom the Central Government exercises the Rule 23(1) power to call for information. The Schedule is a table, so no contiguous run of it reproduces the whole: the text quoted here is row 1, both cells, and rows 2 and 3 are described in this note rather than quoted.
- [7]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 6, (1)(e), p. 26. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 26 August 2026
- [8]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, (7) Illustrations, p. 8. Published 11 August 2023. Official source ↗ · Official requirement · Verified 26 August 2026Illustration II to section 8(7) is the framework's own worked example of another law controlling: a bank required to keep client identity records for ten years beyond account closing retains them for that period.
Read the guide
DPDP data retention under Rule 8 The section 8(7) purpose test, the Rule 8 deeming mechanics and both 1 year floors, with the Third Schedule classes.