24. STEP 7 - Data Retention
ISSUE #107Published: 10/2/2026

24. STEP 7 - Data Retention

Ankur Srivastava

Ankur Srivastava

Deputy-CISO / CISSP

Cyber Security & Business Continuity Expert with over 15 years of experience orchestrating InfoSec Governance, risk mitigation frameworks, and disaster recovery architectures. CISSP | M.S. in Cyber Laws & Information Security (IIIT).

Access Price

₹40
Preview

Description

Step 7 of DPDPA compliance is defining your data retention policy—retain data only as long as needed for the approved purpose or legal compliance (tax, audit), then securely erase it, because the more data you keep, the more accountability you carry.

The Third Schedule mandates a three-year auto-eraser rule for three classes: very large e-commerce entities (2 crore+ users), online gaming platforms (50 lakh+ users), and social media platforms (2 crore+ users)—with 48-hour pre-erasure notification and mandatory processing logs retained for at least one year.

Ankur Technology documented retention periods: student/course records for 7–10 years, financial info for 8 years, support tickets for 2–3 years, and CCTV/call recordings for 90 days—reviewed annually.

Best practice: never keep data longer than necessary, and create a single retention policy documenting data types, retention periods, and erasure notification procedures.