DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

When a Data Principal exercises their right to erasure under the DPDP Act 2023, you do not always have to delete. Erasure can be refused where retaining the personal data is necessary to comply with a legal obligation — for example tax, company-law, KYC, or sector-specific record-keeping requirements. In that case the correct answer is retain the specific data the law requires, delete the rest, and tell the Data Principal why. This checker helps you decide, for a given erasure request, whether a statutory retention requirement overrides it and to what extent.

Statutory Retention vs Erasure Request — Delete or Retain?

When a law requires you to keep data but a Data Principal asks you to erase it, which wins? Work through the DPDP erasure-vs-retention conflict in under 3 minutes.

Delete or retain? Work through the request

Handling an erasure request that collides with a retention law

When does a statutory retention requirement override the right to erasure?

The right to erasure under the DPDP Act 2023 is real but not absolute. The Act allows a data fiduciary to retain personal data — and therefore to decline an erasure request for that data — where retention is necessary to comply with a legal obligation. Indian businesses sit under many such obligations: income-tax and GST record-keeping, Companies Act and statutory-audit retention, RBI and KYC rules for regulated entities, and sector-specific requirements in insurance, healthcare and telecom. Where one of these requires you to keep a specific record for a set period, that requirement overrides an erasure request for that specific record until the period ends.

The key discipline is scope. A retention law justifies keeping only the data it actually covers, for only the period it mandates. It does not license keeping an entire customer profile forever because one invoice must be retained for tax purposes. The correct response to a colliding erasure request is almost always partial: retain the legally mandated record, erase or de-identify everything else, and explain the split to the Data Principal.

What is the right way to respond when retention and erasure conflict?

A defensible response has four parts. First, pin down exactly which data the request covers and which data a law requires you to keep — these are often not the same set. Second, retain only the overlap, for only the mandated period, and restrict its use to the compliance purpose. Third, erase or de-identify everything outside that overlap rather than keeping it out of habit. Fourth, reply to the Data Principal within a reasonable timeline, explaining what you are keeping, on what legal basis, and for how long, then log the whole decision.

Getting this wrong in either direction creates risk: erase data a law required you to keep and you breach the retention obligation; refuse erasure without a genuine legal basis and you breach the DPDP Act. Niti Bharat helps Indian companies build a retention-schedule-linked erasure workflow so that front-line teams can answer delete-or-retain correctly and consistently, with a documented basis every time — exactly the kind of process the Data Protection Board will expect to see as enforcement ramps toward May 2027.

Get the erasure-vs-retention decision kit (free)

A PDF decision tree plus a mapping of common Indian statutory retention periods (tax, company law, KYC, sector rules) against the DPDP right to erasure, with a response-letter template.

Frequently Asked Questions

Can I refuse an erasure request because I need the data?+
Not simply because you want to keep it. You can retain data — and decline erasure for that data — where retention is necessary to comply with a legal obligation or another genuine lawful basis. A general business preference to keep data is not a valid reason to refuse a DPDP erasure request.
If one record must be kept, can I refuse to erase the whole account?+
No. A retention law justifies keeping only the specific data it covers, for only the period it mandates. You should retain that record and erase or de-identify everything outside its scope, then explain the split to the Data Principal.
What happens once the statutory retention period expires?+
Once the mandated period ends, the legal obligation no longer justifies keeping the data, and continuing to hold it conflicts with the DPDP storage-limitation principle. Unless a separate live lawful basis applies, the data should be erased or de-identified at that point.
Do I need to tell the Data Principal why I am retaining their data?+
Yes. Good practice — and the spirit of the DPDP Act's transparency principles — is to respond within a reasonable timeline explaining what you are retaining, on what legal basis, and for how long, while erasing whatever is not lawfully required to be kept.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
Telecom Subscriber Consent CheckerTelemedicine Consent Adequacy CheckerVendor Review Due-Date CheckerE-Commerce DPDP Compliance PackSee all Calculators tools →📝 DPDP Compliance Cost India📝 DPDP Compliance Pricing India