/The Rules · 2025
Rule 8: Time period for specified purpose to be deemed as no longer being served
DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.
- Provision
- Rule 8 of The Digital Personal Data Protection Rules, 2025
- Status
- Comes into force on 13 May 2027 (phase 3)
- Made under
- s. 8 General obligations of Data Fiduciary
- Schedules referenced
- Third ScheduleSeventh Schedule
- Source
- Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF
A Data Fiduciary, who is of such class and is processing personal data for such corresponding purposes as are specified in Third Schedule, shall erase such personal data, unless its retention is necessary for compliance with any law for the time being in force, or, for the corresponding time period specified in the Third Schedule, if the Data Principal neither approaches such Data Fiduciary for the performance of the specified purpose nor exercises her rights in relation to such processing.
At least forty-eight hours before completion of the time period for erasure of personal data under this rule, the Data Fiduciary shall inform the Data Principal that such personal data shall be erased upon completion of such period, unless she logs into her user account or otherwise initiates contact with the Data Fiduciary for the performance of the specified purpose or exercises her rights in relation to the processing of such personal data.
Without prejudice to sub-rules (1) and (2), a Data Fiduciary shall retain, in respect of any processing of personal data undertaken by it or on its behalf by a Data Processor, such personal data, associated traffic data and other logs of the processing for a minimum period of one year from the date of such processing, for the purposes as specified in the Seventh Schedule, after which the Data Fiduciary shall cause such personal data and logs to be erased, unless further retention is required for compliance with any other law for the time being in force or notified by the Government.
A Data Fiduciary (an entity that decides how and why data is processed) must erase personal data if the Data Principal (the individual the data is about) stops interacting with them for a set time. This rule applies to specific classes of Data Fiduciaries and purposes listed in the Third Schedule. If the Data Principal does not contact the Data Fiduciary or exercise their rights for the time period specified in that schedule, the data must be erased, unless another law requires keeping it.
Before erasing this data, the Data Fiduciary must give the Data Principal advance notice. At least forty-eight hours before the time limit expires, the Data Fiduciary must inform the individual that their data will be erased. The erasure is stopped if the individual logs into their account, contacts the Data Fiduciary for the original purpose, or exercises their rights regarding the data before the period ends.
Despite the rules above, there is a mandatory minimum retention period for certain records. A Data Fiduciary must keep personal data, associated traffic data, and processing logs for at least one year from the date of processing for purposes listed in the Seventh Schedule. This one-year rule applies whether the processing is done by the Data Fiduciary or by a Data Processor (an entity processing data on its behalf). After one year, the data and logs must be erased unless another law or government notification requires keeping them longer.
Key points
- Data Fiduciaries listed in the Third Schedule must erase personal data if the Data Principal does not interact with them for the time period specified in that schedule. [(1)]
- The Data Fiduciary must notify the Data Principal at least forty-eight hours before this time period ends and the data is erased. [(2)]
- The erasure is paused if the Data Principal logs in, initiates contact, or exercises their rights before the deadline. [(2)]
- Data Fiduciaries and their Data Processors must retain personal data, traffic data, and processing logs for a minimum of one year for purposes in the Seventh Schedule. [(3)]
- After the one-year minimum, the data and logs must be erased unless another law requires longer retention. [(3)]
Common misreadings
- A Data Fiduciary can erase data the moment the time period in the Third Schedule ends without telling the Data Principal. (Correction: The Data Fiduciary must inform the Data Principal at least forty-eight hours before the time period is completed.)
- If a Data Principal deletes their account, the Data Fiduciary must immediately erase all records of their past transactions. (Correction: The Data Fiduciary must still retain personal data and processing logs for a minimum of one year from the date of processing for purposes in the Seventh Schedule.)
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.