Section 8 · Rule 8
Rule 8: Retention and Erasure
Retention under DPDP is purpose-linked. Section 8 requires erasure when personal data is no longer necessary for the specified purpose unless law requires retention. Rule 8 adds deemed time periods for certain Fiduciary classes in the Third Schedule, advance intimation before erasure, and a one-year processing-log retention note tied to the Seventh Schedule.
What Section 8 and Rule 8 say
Under Section 8, a Data Fiduciary must erase personal data that is no longer necessary for the specified purpose, unless retention is necessary for compliance with any law for the time being in force. Data Principal requests for erasure under Section 12 interact with those retention rules. Purpose therefore drives both how long data may be kept and when erasure is required.
Rule 8 is titled around the time period for a specified purpose to be deemed no longer being served. Rule 8(1) applies to Data Fiduciaries of classes processing personal data for corresponding purposes specified in the Third Schedule. Those Fiduciaries must erase such personal data unless retention is required by law, or for the corresponding Third Schedule time period, if the Data Principal neither approaches the Fiduciary for performance of the specified purpose nor exercises rights in relation to such processing. The Third Schedule currently addresses certain large e-commerce entities, online gaming intermediaries and social media intermediaries, with a three-year period measured from last approach or rights exercise (or Rules commencement, whichever is latest), subject to stated exceptions for account access and certain virtual tokens.
Rule 8(2) requires at least forty-eight hours’ advance information to the Data Principal before erasure under that Rule, unless the Principal logs in, initiates contact for the purpose, or exercises rights. Rule 8(3), without prejudice to sub-rules (1) and (2), requires retention of personal data, associated traffic data and other logs of processing — for processing by the Fiduciary or on its behalf by a Processor — for a minimum of one year from the date of such processing, for purposes specified in the Seventh Schedule, after which erasure follows unless another law or government notification requires further retention. This Rule 8(3) one-year note is distinct from Rule 6’s one-year security log retention for investigation and remediation.
What it means in practice
Map each processing purpose to a retention rationale: still necessary for the purpose; required by another law; or, if you fall within a Third Schedule class and purpose, the deemed period and reset events (approach for purpose or exercise of rights). Do not apply Third Schedule timelines to every organisation by default — check class thresholds and purpose carve-outs in the Schedule.
Operationalise erasure across systems of record and processors, with legal-hold exceptions documented. Where Rule 8(2) applies, build the forty-eight-hour pre-erasure notice. Separately implement Rule 8(3) retention of processing logs and associated data for the minimum one-year period for Seventh Schedule purposes, then erase unless a longer legal requirement applies.
Consent records and purpose registers help show why data is still held. Erasure of personal data in product databases is broader than updating a consent flag; plan system-by-system deletion or anonymisation where appropriate under advice.
Common mistakes
- Applying Third Schedule three-year rules to entities or purposes outside that Schedule.
- Collapsing Rule 6 security log retention with Rule 8(3) Seventh Schedule processing-log retention.
- Treating “delete account” in one app as full organisational erasure without processor and backup follow-through.
- Skipping the forty-eight-hour pre-erasure intimation where Rule 8(2) applies.
Official source
ConsentifyAI’s explanation is educational. Authoritative text is published by the Government of India / MeitY.
Information on this page is provided for general educational and implementation-planning purposes. It is not legal advice. Organizations should assess their specific obligations with qualified legal or privacy professionals.