What the DPDP Act says about erasure
The Digital Personal Data Protection Act, 2023 gives a Data Fiduciary three erasure duties:
- Section 8(7)(a): erase personal data when the person withdraws consent, or when the purpose is clearly over, whichever comes first. The exception is data another law requires you to keep.
- Section 8(7)(b): make sure any Data Processor you shared the data with erases it too.
- Section 12: erase a person’s data when they ask you to.
Section 8(5) also requires reasonable security safeguards. Failing this duty carries the highest penalty in the Act: up to ₹250 crore. Personal data left on a laptop sold to a refurbisher is the kind of failure this covers.
What the DPDP Rules 2025 add, and when
The government published the DPDP Rules on 13 November 2025. They come into force in three phases. Most duties, including retention and erasure, apply 18 months after publication, in May 2027.
| Phase | When | What applies |
|---|---|---|
| 1 | November 2025 | Definitions and setting up the Data Protection Board |
| 2 | November 2026 | Rules for Consent Managers |
| 3 | May 2027 | Main duties for Data Fiduciaries, including notices, security, breach reporting, retention and erasure |
The Rules also set time limits for erasing the data of inactive users on some large platforms, such as big e-commerce, gaming and social media services. Users must be told before their data is erased.
The Rules also require you to keep processing logs for a minimum period. So you can’t simply erase everything. You need a retention schedule that says what to keep, for how long, and when to erase it.
This is a practical guide, not legal advice. Check the retention periods for your sector against the official Gazette notification with your legal team.
Don't forget old devices
DPDP projects usually list the applications that hold personal data, such as the CRM, the HR system and the data warehouse. Old devices are often left off the list, but they hold personal data too:
- Laptops hold downloaded customer lists, HR spreadsheets and saved email.
- Phones used for sales or support hold customer contacts, chats and photos of KYC documents.
- Servers and storage being shut down hold full copies of databases.
- Leased equipment goes back to the leasing company, often with data still on it.
Deleting a customer from the CRM doesn’t delete the export saved on an old laptop. If that laptop goes to a recycler with the file still on it, you’re still responsible.
What proof of erasure looks like
You need to be able to show that you erased the data. For devices, keep four things:
- A retention schedule. It says when each type of personal data must be erased, and which law, if any, says to keep it longer.
- An erasure record for each device that held personal data. It shows the asset tag, the drive serial, the method and the standard.
- Verification. Proof that the erasure was checked, not just started.
- Records from your vendors. If an ITAD partner or refurbisher erases devices for you, get a certificate for each device, not one letter for the whole batch.
A certificate that follows NIST SP 800-88 and IEEE 2883 covers points 2 and 3. Our compliance page shows how VaultRazer records map to Section 8(7), GDPR, HIPAA and ISO 27001.
Checklist for the next six months
- Add devices and storage to your DPDP data inventory, alongside your applications.
- Write your retention schedule. For each type of data, note the purpose, how long you keep it, any law that requires you to keep it, and what triggers erasure.
- Make device erasure a required step when staff leave, when hardware is replaced and before leased equipment is returned.
- Require a certificate for each device in every ITAD, recycling and leasing contract. Keep all certificates in one place.
- For live systems where you can’t wipe the whole device, use file erasure to complete and log Section 12 requests.
- Test your process. Pick a laptop retired last quarter and see how long it takes to find its certificate.
Frequently asked questions
When does the DPDP Act's erasure duty start?
The DPDP Rules were published on 13 November 2025 and come into force in phases. The main duties, including retention and erasure, apply from May 2027.
Does the DPDP Act cover data on old laptops and phones?
Yes. The Act covers digital personal data wherever it's stored. If an old device holds personal data, you still have to erase it and keep it secure until you do.
Is a factory reset enough for DPDP compliance?
The Act doesn't name a method, but you must be able to show the data was erased and can't be recovered. A factory reset on a laptop usually can't be verified and leaves no record. A standards-based erasure with a certificate for each device gives you proof.
What is the maximum penalty under the DPDP Act?
Failing to take reasonable security safeguards to prevent a personal data breach can lead to a penalty of up to ₹250 crore. Other breaches have lower limits, set out in the Act's schedule.