When a Data Principal exercises their right to erasure under the DPDP Act 2023, you do not always have to delete. Erasure can be refused where retaining the personal data is necessary to comply with a legal obligation — for example tax, company-law, KYC, or sector-specific record-keeping requirements. In that case the correct answer is retain the specific data the law requires, delete the rest, and tell the Data Principal why. This checker helps you decide, for a given erasure request, whether a statutory retention requirement overrides it and to what extent.
When a law requires you to keep data but a Data Principal asks you to erase it, which wins? Work through the DPDP erasure-vs-retention conflict in under 3 minutes.
The right to erasure under the DPDP Act 2023 is real but not absolute. The Act allows a data fiduciary to retain personal data — and therefore to decline an erasure request for that data — where retention is necessary to comply with a legal obligation. Indian businesses sit under many such obligations: income-tax and GST record-keeping, Companies Act and statutory-audit retention, RBI and KYC rules for regulated entities, and sector-specific requirements in insurance, healthcare and telecom. Where one of these requires you to keep a specific record for a set period, that requirement overrides an erasure request for that specific record until the period ends.
The key discipline is scope. A retention law justifies keeping only the data it actually covers, for only the period it mandates. It does not license keeping an entire customer profile forever because one invoice must be retained for tax purposes. The correct response to a colliding erasure request is almost always partial: retain the legally mandated record, erase or de-identify everything else, and explain the split to the Data Principal.
A defensible response has four parts. First, pin down exactly which data the request covers and which data a law requires you to keep — these are often not the same set. Second, retain only the overlap, for only the mandated period, and restrict its use to the compliance purpose. Third, erase or de-identify everything outside that overlap rather than keeping it out of habit. Fourth, reply to the Data Principal within a reasonable timeline, explaining what you are keeping, on what legal basis, and for how long, then log the whole decision.
Getting this wrong in either direction creates risk: erase data a law required you to keep and you breach the retention obligation; refuse erasure without a genuine legal basis and you breach the DPDP Act. Niti Bharat helps Indian companies build a retention-schedule-linked erasure workflow so that front-line teams can answer delete-or-retain correctly and consistently, with a documented basis every time — exactly the kind of process the Data Protection Board will expect to see as enforcement ramps toward May 2027.
A PDF decision tree plus a mapping of common Indian statutory retention periods (tax, company law, KYC, sector rules) against the DPDP right to erasure, with a response-letter template.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.