DPDPA Rule 8: Data Erasure Timelines and One-Year Log Retention

DPDPA Rule 8: Data Erasure Timelines and One-Year Log Retention

Ensure your business meets DPDP Act compliance requirements. Discover key obligations for data fiduciaries, penalty risks, and steps to protect user privacy.

Sahil Pugalia

Written by

Sahil Pugalia

Date

Read time

6 min

For decades, the default setting for enterprise data was simple: keep it forever. Storage was cheap, and deletion was risky. DPDPA Rule 8 changes the default.

It replaces indefinite hoarding with a strict, purpose-based lifecycle. You must delete data when its time is up, but you must also retain specific logs for exactly one year. It is a delicate balancing act between erasing too late and erasing too early. The result is a structured operational reality: retain only as long as needed, notify before deletion, and keep a defined audit trail.

Scope and Applicability

This is not a blanket mandate to purge your entire database. As a DPDPA obligation for data fiduciaries, Rule 8 is highly scoped.

The erasure triggers apply only to the specific classes of Data Fiduciaries and processing purposes listed in the Third Schedule. If your processing isn’t on that list, the deeming rule in 8(1) may not apply to you,though separate obligations may still arise under other parts of the law.

Meanwhile, the one-year retention requirement in 8(3) applies to any processing undertaken by you, or on your behalf by a Data Processor, for the purposes specified in the Seventh Schedule.

When Data Must Be Erased

Under Rule 8(1), DPDP data erasure requirements kick in when three conditions are met:

  • The Data Principal has not approached you for the performance of the specified purpose within the time period stated in the Third Schedule.
  • The Data Principal has not exercised her rights in relation to that processing during that time.
  • Retention is not otherwise required for compliance with any law in force.

In plain terms: if the user ghosts you, hasn’t exercised their data rights, and no other law requires you to hold the record, the data has to go.

But this is entirely dependent on the Third Schedule. You have to map your processing purposes to those specific timelines to evaluate when a purpose is legally deemed “no longer served.”

48-Hour Pre-Erasure Notification

You cannot just quietly drop the tables. Rule 8(2) mandates a DPDP 48 hour notice to the Data Principal before the scheduled erasure.

Think of it as a digital last call. The notice must inform the user that erasure will occur unless they:

  • Log into their user account, or
  • Initiate contact with you for the performance of the specified purpose, or
  • Exercise their rights in relation to the processing of the personal data.

This is a last-mile safeguard. If the user takes any of these actions, the automatic erasure condition is paused.

The term “user account” should be read broadly. It includes any digital presence or identifier registered with you,a traditional profile, an email address, or a phone number. Your notification paths must be built to reach users across whatever identifiers you hold.

Illustration of a user account profile with a pause symbol, representing the pause of automatic erasure.

Mandatory One-Year Retention of Data and Logs

Here is where the pendulum swings the other way. Rule 8(3) establishes a strict one-year minimum retention period for:

  • Personal data,
  • Associated traffic data, and
  • Other logs of the processing.

The clock starts on the date of processing, specifically for the purposes listed in the Seventh Schedule. After exactly one year, you must cause this data and logs to be erased, unless further retention is required by another law or notified by the Government.

Crucially, this applies to data processed by you and by any Data Processor acting on your behalf. It operates without prejudice to the erasure rules above. Even if a purpose is served immediately, the one-year minimum acts as a hard floor. You cannot delete these logs early.

How These Timelines Interact

Compliance means managing the collision between these two timelines.

The Third Schedule dictates when data should no longer be kept. If the user is inactive and the clock runs out, erasure is due under 8(1), preceded by the 48-hour notice under 8(2).

The Seventh Schedule dictates when data must be kept. It acts as a floor. Even if the purpose ends earlier, you still retain the data and logs for at least one year before erasing them, unless a different law requires more.

The rule provides concrete illustrations to make this tangible:

  • The E-book Purchase: A completed e-book purchase requires retaining order details, personal data, and processing logs for at least one year from the transaction date,even if the user deletes their account immediately after buying the book.
  • The Cloud Provider: If a company engages a cloud service provider as a Processor, the Data Fiduciary must ensure the Processor also retains data and logs for at least one year before erasure, unless a longer period is mandated elsewhere.
Illustration of a cloud provider and an e-book purchase, demonstrating DPDPA Rule 8 data retention.

Practical Steps for Compliance

1) Map purposes and classes

Identify which processing activities and entity classes fall under the Third Schedule. Record the corresponding inactivity or purpose timelines tied to each activity.

2) Instrument inactivity and rights monitoring

Track whether the Data Principal approaches you for the specified purpose within the relevant period. Track whether they exercise rights related to that processing. Any such action means the 8(1) deeming condition does not apply at that time.

3) Build the 48-hour notification flow

Detect when data is approaching the erasure threshold and trigger notices at least 48 hours in advance. Send them to the user account and any other registered identifiers, providing clear actions to log in, contact you, or exercise data rights.

4) Enforce the one-year mandatory retention

Retain personal data, traffic data, and processing logs for at least one year from each processing event for the Seventh Schedule purposes. Implement a deletion workflow to erase after one year unless a longer legal retention applies.

5) Manage exceptions and other legal holds

Keep a register of applicable laws that require retention beyond one year or beyond the Third Schedule timelines. Apply legal holds that override deletion where required, and release them once the legal need ends.

6) Flow down to Data Processors

Update contracts and technical controls to ensure Processors retain and erase in sync with Rule 8, including the one-year minimum and any longer legal periods. Require audit-ready logs that confirm retention and deletion events.

7) Separate data stores and logs

Distinguish operational data from traffic data and processing logs. Ensure each category is covered by the one-year rule where applicable, and prevent accidental early deletion of logs needed under the Seventh Schedule.

8) Align account deletion with retention duties

When users delete accounts, deactivate access but retain the required personal data and logs for the one-year period and other applicable legal holds. Communicate this clearly in privacy notices and account deletion flows.

Interpretation Boundaries and Risks

  • The 8(1) deeming trigger is limited to the classes and purposes listed in the Third Schedule. Do not apply it generically to all data.
  • The 48-hour notice must precede erasure under this rule. Treat it as a mandatory, not optional, step.
  • The one-year floor in 8(3) is a minimum. If other laws set longer retention, follow the longer period. If none do, erase after one year.
  • A Data Principal’s action, such as logging in or exercising rights, interrupts the automatic erasure condition. Reassess the timeline rather than assuming an indefinite reset.
  • Maintain proof of notifications, interactions, retention, and erasure. In an audit, policies are fiction. Records speak louder.

Closing

Executing Rule 8 is not about writing a better privacy policy. It is about clockwork: accurate mapping to the Third Schedule, reliable inactivity detection, timely user notices, strict one-year retention for the Seventh Schedule purposes, and controlled deletion. Done right, it reduces risk, contains data sprawl, and keeps you audit-ready.

This is where many teams trip. Fragmented systems, unclear purpose mapping, and weak processor oversight create massive gaps.

At Regodit, we provide a structured way to operationalize these exact requirements. We align your purpose catalogs, retention controls, notification workflows, and processor governance in one place. If you need to map Rule 8 timelines, automate 48-hour notices, and enforce the one-year retention floor with clean evidence, schedule a call to discuss your current posture.

Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.

Keep reading

All blogs →