Retention, erasure and legal holds
Section 8(7)–(8) and Rule 8 are scheduled for 13 May 2027.
The operating question is not “keep or delete?” It is “for this record and purpose, which trigger, duration, authority, hold and disposition apply in each system and backup?”
DPDP rule
Section titled “DPDP rule”The Data Fiduciary must erase personal data, and cause its processor to erase it, when the Data Principal withdraws consent or when it is reasonable to assume the specified purpose is no longer being served, whichever is earlier, unless retention is necessary for compliance with law.
Rule 8 and the Third Schedule add inactivity-based deeming periods for specified classes and purposes, advance notice before erasure, and a one-year retention requirement for certain logs/data connected with security and disclosure. Apply the exact class and Schedule entry; do not make its period a universal default.
Decision order
Section titled “Decision order”- Identify record, personal-data fields, system and processing purpose.
- Calculate the purpose/consent trigger.
- identify every binding retention or preservation source and its entity scope;
- apply a scoped legal hold where facts require preservation;
- choose field deletion, record deletion, irreversible anonymisation, suppression or archive;
- propagate to processors and derived indexes;
- handle backup expiry and restore-time re-deletion;
- issue a certificate only for destinations with verified completion.
Retention-rule fields
Section titled “Retention-rule fields”rule_id, tenant_id, entity_id, record_class, system_idpurpose_id, data_categories[], principal_categories[]trigger_type, trigger_event, duration, dispositionauthority_source_id, provision, status, effective_periodjurisdiction, sector_profile, precedence_rationalebackup_policy, processor_propagation, verification_querymaker_id, checker_id, approved_at, next_review_atConflicts are surfaced, never silently “resolved” by the longest period. A legal reviewer records why a more specific sector or litigation duty requires retention and which uses remain suppressed.
Legal holds
Section titled “Legal holds”A hold has a matter, legal authority/rationale, scope, custodians, systems, data, start, review cadence, release condition and two-person approval. A hold blocks only matching disposal actions. It does not permit new marketing, analytics or disclosure.
Backups
Section titled “Backups”Backups are not an infinite erasure exception. The design:
- uses bounded immutable-backup retention;
- prevents ordinary application access;
- records deletion tombstones outside the backup;
- reapplies deletion after a restore before business access;
- tests restoration and re-deletion;
- records when every backup generation containing the record expires.
Certificate semantics
Section titled “Certificate semantics”A deletion certificate names the instruction, subject pseudonym, systems, records/categories,
method, completion time, verification result, lawful exceptions, backup expiry, processor
acknowledgements and signer. It must say partial when any destination is pending, unreachable or
held.
Acceptance tests
Section titled “Acceptance tests”- Given withdrawal and a seven-year sector record duty, when disposal is evaluated, then consent-only marketing use stops and the retained regulated record is purpose-restricted.
- Given a backup restore, when tombstones are replayed, then affected records are re-deleted before the restored service is released.
- Given one processor supplies no proof, then the certificate is partial and escalated.
- Given a hold is released, then disposal is recalculated from the original trigger; the timer does not restart at release.