Can you always delete personal data when someone requests erasure under the DPDP Act? No — the right to erasure under the DPDP Act is real but not absolute. When a data principal asks you to delete their personal data, you must erase it unless retention is required for a specified purpose or to comply with any law in force. This is why a valid erasure response is rarely a simple 'yes, done': you have to identify what can be deleted, what must be retained (tax records, statutory registers, an ongoing legal claim, regulatory retention mandates), and how to handle the harder edges — data sitting in backups, and copies you have shared with processors or third parties. Handling a data erasure request in DPDP India correctly means running a defensible decision process, not a blanket delete. This kit gives you the decision workflow, the response letters for full, partial and refused erasure, the backup-handling protocol and the third-party propagation notice.
Erasure is a right, not an automatic delete. A complete kit to decide what you must delete, what you may lawfully retain, and how to handle backups and shared copies — defensibly.
A defensible erasure response follows a fixed sequence rather than a snap decision. Step one: verify the requester's identity so you are not deleting the wrong person's data or acting on an impostor. Step two: locate every copy of the person's data across your systems — the live database, backups, logs, support tickets, marketing tools and any processor or third party you have shared it with (the checklist you completed maps these). Step three: for each location, ask whether a lawful ground to retain applies. Step four: delete everything not caught by a retention ground, document what was retained and why, and issue the appropriate response letter. Skipping the 'locate everywhere' step is the classic failure — deleting from the CRM while the same data lingers in backups and a vendor's system means the erasure is incomplete and the organisation is still exposed.
The workflow treats erasure as a decision to be recorded, not just an action to be taken. For every request you should be able to show, later, what you deleted, what you kept, and the ground you kept it on. That record is your defence if the data principal escalates the refusal or if the Data Protection Board asks how you handle the right — which is why the kit pairs the workflow with an audit log rather than leaving it to memory.
The DPDP Act lets you retain data despite an erasure request where retention is necessary for the specified purpose for which it was collected, or to comply with any law in force. In practice the recurring grounds are: statutory and regulatory retention (financial records, tax documents, KYC data, employee records, sector-specific mandates that can run several years); an ongoing or reasonably-anticipated legal claim where the data is evidence; and, narrowly, completing a transaction the person themselves initiated. Anything not caught by one of these grounds must be deleted — you cannot retain data simply because it is convenient, might be useful later, or is expensive to purge.
The kit gives you a ground-by-ground reference so you can classify each data category quickly: a payment record may be retained under financial-retention rules while the same customer's marketing profile and behavioural analytics must be deleted, even though both sit in your systems for the same person. This granularity is what turns a blanket 'we can't delete because we have retention obligations' — a common and legally weak response — into a precise, defensible position that deletes what must be deleted and retains only what the law actually requires.
Locations to search on every erasure request:
Handling a data erasure request in DPDP India correctly starts with understanding that the right to erasure has boundaries. When a data principal asks you to delete their data, the DPDP Act requires you to do so unless you need to retain it for the specified purpose it was collected for, or to comply with a law in force. That single exception carries a lot of weight in practice: financial, tax, KYC, employment and sector-specific retention rules routinely require you to keep certain records for years, which means many erasure requests are correctly answered with partial deletion rather than complete erasure.
The failure mode organisations fall into is at both extremes — either deleting nothing because 'we have retention obligations' (over-retention, which breaches the erasure right for the data that is not actually caught) or deleting everything on request (under-retention, which can breach statutory record-keeping duties). The correct answer is granular: classify each category of the person's data, delete what has no retention ground, keep only what the law requires, and document the decision.
Two things make erasure genuinely difficult in real systems. First, backups: personal data persists in backup snapshots and archives long after it is deleted from live systems, and you cannot practically surgically remove one person from an immutable backup. The workable, defensible approach is to put the backed-up record beyond use, confirm it will be purged on the next backup rotation cycle, and document that — rather than either pretending backups do not exist or promising an impossible instant deletion. Second, shared copies: once you have shared a person's data with processors or third parties, an erasure obligation does not stop at your own database — you must instruct those parties to delete their copies too and confirm they have.
These edges are exactly where a generic 'delete on request' policy falls apart and where a documented protocol earns its keep. Niti Bharat's fixed-price DPDP compliance engagements (₹75,000–₹3.2 lakh) build the full data-map and erasure workflow — including backup and processor propagation — for organisations that need to handle the right to erasure reliably at scale; this kit gives your team the decision process and response letters to handle it correctly from the next request onward.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.