DPDP Wiki Talk to us

/The Rules · Schedules

Third Schedule: Time periods after which specified Data Fiduciaries must erase personal data

[See rule 8(1)] The Gazette prints no descriptive heading for this Schedule; the title above is editorial. Printed headings: Class of Data Fiduciaries, Purposes, Time period.

Official text
Part of
The Digital Personal Data Protection Rules, 2025
Referred to by
Rule 8
Source
Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF

THIRD SCHEDULE [See rule 8(1)]

Verbatim from the Gazette of India
S. no.Class of Data FiduciariesPurposesTime period
1.Data Fiduciary who is an e-commerce entity having not less than two crore registered users in India.For all purposes, except for the following: (a) Enabling the Data Principal to access her user account; and (b) Enabling the Data Principal to access any virtual token that is issued by or on behalf of the Data Fiduciary, is stored on the digital facility or platform of such Data Fiduciary, and may be used to get money, goods or services.Three years from the date on which the Data Principal last approached the Data Fiduciary for the performance of the specified purpose or exercise of her rights, or the commencement of the Digital Personal Data Protection Rules, 2025, whichever is latest.
2.Data Fiduciary who is an online gaming intermediary having not less than fifty lakh registered users in India.For all purposes, except for the following: (a) Enabling the Data Principal to access her user account; and (b) Enabling the Data Principal to access any virtual token that is issued by or on behalf of the Data Fiduciary, is stored on the digital facility or platform of such Data Fiduciary, and may be used to get money, goods or services.Three years from the date on which the Data Principal last approached the Data Fiduciary for the performance of the specified purpose or exercise of her rights, or the commencement of the Digital Personal Data Protection Rules, 2025, whichever is latest.
3.Data Fiduciary who is a social media intermediary having not less than two crore registered users in India.For all purposes, except for the following: (a) Enabling the Data Principal to access her user account; and (b) Enabling the Data Principal to access any virtual token that is issued by or on behalf of the Data Fiduciary, is stored on the digital facility or platform of such Data Fiduciary, and may be used to get money, goods or services.Three years from the date on which the Data Principal last approached the Data Fiduciary for the performance of the specified purpose or exercise of her rights, or the commencement of the Digital Personal Data Protection Rules, 2025, whichever is latest.

In this Schedule, —

(a)

“e-commerce entity” means any person who owns, operates or manages a digital facility or platform for e-commerce as defined in the Consumer Protection Act, 2019 (35 of 2019), but does not include a seller offering her goods or services for sale on a marketplace e-commerce entity as defined in the said Act;

(b)

“online gaming intermediary” means any intermediary who enables the users of its computer resource to access one or more online games;

(c)

“social media intermediary” means an intermediary as defined in clause (w) of sub-rule (1) of rule 2 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021; and

(d)

“user”, in relation to—

(i)

an e-commerce entity, means any person who accesses or avails any computer resource of an e-commerce entity; and

(ii)

an online gaming intermediary or a social media intermediary, means any person who accesses or avails of any computer resource of an intermediary for the purpose of hosting, publishing, sharing, transacting, viewing, displaying, downloading or uploading information.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data FiduciaryData Principal

Schedule III of the DPDP Rules, 2025 sets specific time limits for certain large Data Fiduciaries (entities determining the purpose and means of processing personal data) to retain personal data. It applies to three classes of Data Fiduciaries based on their registered users in India: e-commerce entities with at least two crore users, online gaming intermediaries with at least fifty lakh users, and social media intermediaries with at least two crore users. For these specific entities, the standard time period to retain personal data is three years. This three-year clock starts from the date the Data Principal (the individual to whom the data relates) last approached the Data Fiduciary for the specified purpose or to exercise their rights, or from the commencement of the Digital Personal Data Protection Rules, 2025, whichever is latest. There are two exceptions to this three-year time limit. The limit does not apply to data needed to enable the Data Principal to access their user account. It also does not apply to data needed to access virtual tokens issued by the Data Fiduciary that are stored on their platform and can be used to get money, goods, or services. The Schedule also defines these entities. An e-commerce entity operates a digital platform for e-commerce but does not include individual sellers on a marketplace. An online gaming intermediary enables access to online games, and a social media intermediary is defined under the Information Technology Rules, 2021. A user is anyone who accesses or avails the computer resources of these entities.

Key points

  • E-commerce entities and social media intermediaries with at least two crore registered users in India are subject to a three-year data retention limit [Items 1 & 3].
  • Online gaming intermediaries with at least fifty lakh registered users in India are subject to the same three-year limit [Item 2].
  • The three-year period begins from the Data Principal's last approach or the commencement of the DPDP Rules, 2025, whichever is latest [Items 1, 2, & 3].
  • The time limit applies to all purposes except enabling access to a user account or accessing virtual tokens used for money, goods, or services [Items 1, 2, & 3].
  • Individual sellers offering goods on a marketplace are excluded from the definition of an e-commerce entity [Note (a)].

Common misreadings

  • People might think the three-year limit applies to all data held by these entities, but it explicitly excludes data needed to access user accounts or virtual tokens.
  • People might assume individual sellers on an e-commerce platform are bound by the two-crore user threshold, but the text specifically excludes sellers on a marketplace e-commerce entity.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.