All guides
GuidesJul 21, 2026 - 8 min read

How long can you keep customer data? DPDP retention, the Third Schedule, and the RBI conflict

DPDP says erase when the purpose is served. RBI says keep KYC for years. The Companies Act wants invoices for eight. Here is how retention actually works when the laws point in opposite directions.

Who this is for
Anyone who has ever wondered if they can delete that old spreadsheet
What you leave with
A defensible retention position - what to keep, how long, under which law, and why

Retention is the duty everyone gets wrong in both directions at once. Half of Indian businesses keep everything forever because storage is cheap and deleting feels risky. The other half will panic-delete things the law required them to keep. The DPDP Act punishes the first habit; the Income-tax Act punishes the second. This guide is the map between them.

The DPDP baseline: purpose served, data gone

Section 8(7) is short and sharp: erase personal data when the specified purpose is no longer being served and retention is not required by law. There is no general "keep it seven years just in case" under DPDP - the default is the opposite. A customer who has not bought from you in years, a rejected job applicant's resume, a lead list from a 2023 expo: for each, the question is "what purpose is this still serving?" and if the honest answer is none, the erasure duty has already begun.

The Third Schedule: hard clocks for big platforms

The 2025 Rules added something concrete for scale: e-commerce and social media platforms with 2 crore or more registered Indian users, and online gaming platforms with 50 lakh or more, must erase a user's data three years after the user last engaged - unless the user returns or another law requires keeping it. And at least 48 hours before that erasure, the platform must tell the user their data is about to go, giving them one last chance to log in. If you are anywhere near those thresholds, this is an engineering project with a legal deadline, not a policy paragraph.

The conflict: when RBI says keep and DPDP says erase

Now the part that confuses everyone. An NBFC customer closes their loan account and asks for erasure under Section 12. DPDP says the purpose is served. But RBI's KYC directions require identity records to be kept for years after the relationship ends; PMLA wants transaction records too. Which law wins? The sectoral one, for the mandated period - Section 8(7) itself carves out retention required by law. The discipline that keeps this defensible is documentation: for every record you hold past its DPDP purpose, you should be able to name the law that requires it and the period it mandates. "RBI makes us" is a complete answer only when you can show which direction, which record type, and until when.

The same pattern repeats across sectors:

  1. Finance: KYC and transaction records under RBI directions and PMLA - years after exit.
  2. Insurance: policy and claim records under IRDAI norms - tied to policy life and disputes.
  3. Healthcare: clinical records under medical-records norms - commonly three-plus years, longer for inpatient and medico-legal cases.
  4. Every company: books of account and invoices - eight years under the Companies Act and tax law. The invoice survives; the marketing profile built from it must not ride along.
  5. Employment: payroll, PF, and ESI records under labour and tax law - while rejected candidates' resumes have no such shelter.

One rule DPDP sets as a floor, not a ceiling

Rule 6(1) requires security logs to be kept for at least one year - one of the few places the Act says "keep longer", because logs are how breaches get investigated. Deleting logs aggressively in the name of minimisation is the over-correction to avoid.

What a defensible position looks like

A written retention schedule: each data category, its holding period, the source of that period (DPDP purpose, or the named sectoral law), and what happens at expiry - erase, anonymise, or restricted retention with a documented reason. Not a policy PDF nobody follows: a schedule someone owns. PrivacyReady's retention plannergenerates exactly this per industry - the DPDP baseline, your sector's overlays, and the Third Schedule check - as a printable schedule, and puts the duty on your data map so it actually gets done. And if you sit in the genuinely contested cases - an NBFC arbitrating erasure requests against RBI holds - that is judgement territory, which is what the checklist will honestly tell you. As always: orientation, not legal advice; the section references are there so your counsel can verify fast.

This guide, done for you

Everything above becomes a scored report on your live website in about a minute - each gap named, mapped to its section, with the fix. Free, no card, no signup, no code.

Free. No card, no signup, about a minute.

A PrivacyReady readiness report: score, executive summary, and gaps mapped to sections of the DPDP Act