The DPDP Act doesn't ask you to keep everything. It asks you to prove you didn't.
The Digital Personal Data Protection Act, 2023 is an erasure law as much as a privacy law. Data Fiduciaries must delete personal data once its purpose is served or consent is withdrawn, whichever comes first — and then be able to show, on demand, that the deletion happened, when, and why any exception applied. Most organisations can delete. Few can prove it.
Deletion is easy. Defensible deletion is the archive's job.
What the Act actually requires
Four obligations that show up in an audit, not just in the statute text.
Erase on purpose, not on convenience
Section 8(7) requires a Data Fiduciary to erase personal data when the purpose it was collected for is no longer being served, or the individual withdraws consent — whichever happens first — unless another law requires the data to be kept longer. "We might need it later" is not in the statute.
You stay liable through your processors
Section 8(1) makes the Data Fiduciary responsible for compliance in respect of any processing done on its behalf by a Data Processor. Outsourcing the storage doesn't outsource the obligation — you need visibility into what a processor holds and when it's due for erasure, not just a contract that says they'll handle it.
Significant Data Fiduciaries carry extra weight
Entities the government designates as Significant Data Fiduciaries face additional duties under Section 10 of the Act — including appointing a Data Protection Officer and undergoing independent audits of their processing. An archive that can produce its own audit trail on request turns that duty into a formality instead of a project.
The clock is phased, not simultaneous
Core operational provisions — notice and consent mechanics, security safeguards, breach intimation, and the Significant Data Fiduciary obligations above — come into force on a phased timetable rather than all at once. Building the erasure and logging discipline into your archive now means the compliance date is a non-event.
Source: Digital Personal Data Protection Act, 2023 (meity.gov.in), Sections 8 and 10.
Why an archive, not a policy document, satisfies this
Erasure you can show, not just claim
When a regulator or a data principal asks whether a record was deleted, "our policy says 30 days" isn't an answer. A logged, timestamped erasure event is.
Exceptions recorded at the moment they happen
Some erasure requests get rejected — another law requires the record to be kept. That decision needs to be captured with its reason, next to the record, not reconstructed from memory six months later.
One system of record across processors
If your data moves through more than one processor, your erasure story is only as strong as your weakest link's logging. A single archive of record removes that gap.
Building CUSTOS with design partners now. Selling from Q1 2027.
If DPDP erasure and audit trails are a live problem for your organisation, and you want a say in what ships, talk to us.