Skip to content

Retention, erasure and legal holds

DPDP — not yet effective

Section 8(7)–(8) and Rule 8 are scheduled for 13 May 2027.

The operating question is not “keep or delete?” It is “for this record and purpose, which trigger, duration, authority, hold and disposition apply in each system and backup?”

The Data Fiduciary must erase personal data, and cause its processor to erase it, when the Data Principal withdraws consent or when it is reasonable to assume the specified purpose is no longer being served, whichever is earlier, unless retention is necessary for compliance with law.

Rule 8 and the Third Schedule add inactivity-based deeming periods for specified classes and purposes, advance notice before erasure, and a one-year retention requirement for certain logs/data connected with security and disclosure. Apply the exact class and Schedule entry; do not make its period a universal default.

  1. Identify record, personal-data fields, system and processing purpose.
  2. Calculate the purpose/consent trigger.
  3. identify every binding retention or preservation source and its entity scope;
  4. apply a scoped legal hold where facts require preservation;
  5. choose field deletion, record deletion, irreversible anonymisation, suppression or archive;
  6. propagate to processors and derived indexes;
  7. handle backup expiry and restore-time re-deletion;
  8. issue a certificate only for destinations with verified completion.
rule_id, tenant_id, entity_id, record_class, system_id
purpose_id, data_categories[], principal_categories[]
trigger_type, trigger_event, duration, disposition
authority_source_id, provision, status, effective_period
jurisdiction, sector_profile, precedence_rationale
backup_policy, processor_propagation, verification_query
maker_id, checker_id, approved_at, next_review_at

Conflicts are surfaced, never silently “resolved” by the longest period. A legal reviewer records why a more specific sector or litigation duty requires retention and which uses remain suppressed.

A hold has a matter, legal authority/rationale, scope, custodians, systems, data, start, review cadence, release condition and two-person approval. A hold blocks only matching disposal actions. It does not permit new marketing, analytics or disclosure.

Backups are not an infinite erasure exception. The design:

  • uses bounded immutable-backup retention;
  • prevents ordinary application access;
  • records deletion tombstones outside the backup;
  • reapplies deletion after a restore before business access;
  • tests restoration and re-deletion;
  • records when every backup generation containing the record expires.

A deletion certificate names the instruction, subject pseudonym, systems, records/categories, method, completion time, verification result, lawful exceptions, backup expiry, processor acknowledgements and signer. It must say partial when any destination is pending, unreachable or held.

  • Given withdrawal and a seven-year sector record duty, when disposal is evaluated, then consent-only marketing use stops and the retained regulated record is purpose-restricted.
  • Given a backup restore, when tombstones are replayed, then affected records are re-deleted before the restored service is released.
  • Given one processor supplies no proof, then the certificate is partial and escalated.
  • Given a hold is released, then disposal is recalculated from the original trigger; the timer does not restart at release.