Skip to main content

SaaS data retention and deletion in India: a practical checklist

Map SaaS personal data, set purpose-based retention and deletion workflows, handle backups and legal holds, and prepare for India's phased DPDP Act and Rules.

In this guide

How should a SaaS team set a data-retention period?

A retention schedule says what data the service keeps, why it needs it, who owns the decision and how deletion is verified. Avoid both indefinite storage and a single expiry rule that erases records still needed for a valid legal or service purpose. This India-focused guide was checked on 27 September 2026; the DPDP Act and Rules have phased commencement dates, so confirm the provisions effective on the date and facts that apply to your service.

Inventory data by purpose, system and recipient

List personal data and important business records across the live database, search index, file store, analytics, support tools, processors, exports and backups. For each category, name its purpose, collection source, business owner, recipients and deletion mechanism. A data map makes it possible to answer which systems must change when a purpose ends or a valid request arrives.

Check processor and backup behaviour

Document which vendors hold customer data and how deletion instructions flow to them. Define how long encrypted backups remain before normal expiry, how deleted records are prevented from returning during restore, and how legal holds pause deletion. Test the process on a sample record and keep evidence of completion.

Retention and deletion inventory
Data and purposeSystem / processorRetention trigger and periodDeletion or exception pathOwner and evidence
Account profile
Billing or tax record
Security and audit event

What does India's DPDP framework say about erasure and retention?

Check the notified commencement timeline, not just the Act title

The DPDP Act was notified with a staged commencement schedule in G.S.R. 843(E), dated 13 November 2025. As checked on 27 September 2026, sections 3–17, including section 12 on correction and erasure, are scheduled to commence eighteen months after publication, on 13 May 2027. The Rule 8 retention provisions are in the same eighteen-month group. Confirm Gazette notices or amendments before relying on these dates.

Prepare for purpose-linked erasure with a legal-retention exception

Once the relevant DPDP provisions apply, section 12 provides for erasure on a Data Principal's request unless retaining the data is necessary for the specified purpose or to comply with a law in force. Section 8(7) also addresses erasure when the purpose is no longer served, subject to lawful retention. Build a request and exception workflow, but have Indian counsel check the exact scope, commencement and other applicable duties.

Keep the three different DPDP retention rules separate

When the scheduled provisions commence, Rule 6(1)(e) requires specified logs and personal data to be retained for one year to support detection, investigation and remediation of unauthorised access and continued processing after compromise. Rule 8(3) separately sets one year for processing for Seventh Schedule purposes; Rule 8(1) sets inactivity-based erasure periods for listed large e-commerce, gaming and social-media fiduciaries. These are limited rules, not one blanket period for all SaaS data.

How do you implement deletion without losing required records?

Separate deletion, de-identification and restricted retention

Delete data when there is no remaining basis to keep it; de-identify only when the result can no longer reasonably be linked to a person; and restrict access when a valid legal hold or other obligation requires temporary retention. Record the authority and end date for an exception, and do not use an exception to preserve unrelated profile data.

Verify propagation to indexes, files and restored backups

After a request, check derived copies, exports, caches and connected processors, not just the primary table. For backups, document the expiry window and make deletion tombstones or an equivalent control replay after a restore. Keep an audit record of systems checked and results without retaining a duplicate of the erased personal data.

India SaaS data-retention questions

Is the DPDP Act's erasure right already fully in force?

No. The commencement notification phases the Act. As checked on 27 September 2026, section 12 is scheduled for 13 May 2027, eighteen months after the 13 November 2025 Gazette publication. Check the latest official Gazette and legal advice before acting on a live request or making a compliance claim.

Does deleting an account mean every record must disappear instantly?

Not necessarily. The applicable law, purpose, request, contract and record type may allow or require limited retention. Document the specific basis and period, restrict access where appropriate, and delete data that has no continuing valid purpose. Get advice for a disputed or regulated record.

Do backups have to be edited one by one?

A team may use a defined backup-expiry window if it prevents normal access and ensures deleted records are not restored into active use. Test restore procedures and reapply deletion records after a restore. Confirm the design against current legal and contractual duties.

How often should a retention schedule be reviewed?

Review it when the product adds a data purpose, processor, customer segment or regulated workflow, and on a regular schedule. Recheck dates after legal changes, contract renewals and security incidents; assign an owner so the schedule stays operational.