Back to DPDP Rules

Data Retention Thresholds (R.8)

Rule 8 data retention - 3-year inactivity threshold for platforms, 48-hour erasure notice, 1-year minimum State data retention under Rule 8(3), and practical implementation.

6 min read

Platform-Specific Retention Limits

Rule 8 prescribes specific retention thresholds for certain categories of Data Fiduciaries, based on user count thresholds: • E-commerce platforms with 2 crore or more registered users • Online gaming intermediaries with 50 lakh or more registered users • Social media platforms with 2 crore or more registered users For these qualifying platforms, personal data must be erased after 3 years from the last interaction with the Data Principal or from the commencement of the Rules, whichever is later. The Data Fiduciary must provide 48-hour advance notice to the Data Principal before erasure. This threshold operationalises Section 8(7) of the Act, which requires Data Fiduciaries to erase personal data when it is no longer necessary for the purpose for which it was processed.

State Data Retention

For personal data processed by or on behalf of the State: • Rule 8(3) requires such data, along with associated traffic data and processing logs, to be retained for a minimum of 1 year after the purpose is fulfilled, for the three purposes specified in the Seventh Schedule, unless another law requires longer retention • The 1-year period is a floor, not a ceiling: it does not authorise erasure at the 1-year mark, and longer retention may still be required under another legal basis The Seventh Schedule specifies three purposes: 1. Use by the State or its instrumentalities of personal data in the interest of the sovereignty and integrity of India or the security of the State, by an authorised person designated under section 17(2)(a) 2. Use by the State or its instrumentalities for performing a function under any law, or for disclosing information to fulfil an obligation under any law, by an authorised person as per the applicable law 3. Carrying out the assessment for notifying a Data Fiduciary or class of Data Fiduciaries as a Significant Data Fiduciary, by an authorised officer in MeitY designated by the Secretary This provision balances the State's administrative needs with Data Principal rights, providing a clear minimum retention period for government data lifecycle management.

Practical Implementation

Organisations should implement the following to comply with Rule 8: • Build automated data lifecycle management systems that track last access dates • Implement 48-hour notification workflows triggered when the 3-year inactivity threshold approaches • Allow Data Principals to 'reset' the inactivity clock by accessing their data • Define 'access' clearly - does logging in count? Viewing a specific record? Making a transaction? • Establish erasure procedures that remove data across all systems, backups, and processor environments • Maintain erasure logs for compliance documentation • Coordinate with data processors to ensure downstream erasure • Consider data archival strategies that comply with the spirit of Rule 8

Frequently Asked Questions

Was this useful?

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.