All templates
PoliciesSection 8
Data Retention Policy Template
An internal policy defining retention periods, review cycles, and erasure procedures for categories of personal data.
Template
DATA RETENTION AND ERASURE POLICY [Organization Name] Effective Date: [Effective Date] | Policy Owner: [DPO / Role] 1. PURPOSE This Policy establishes how long [Organization Name] retains personal data and the process for erasure, in fulfilment of our obligation under Section 8(7) of the DPDP Act, 2023 to erase personal data when the specified purpose is no longer being served, consent is withdrawn, or retention is no longer necessary for legal purposes, subject to the operational triggers set out under the DPDP Rules, 2025. 2. SCOPE This Policy applies to all personal data processed by [Organization Name] as a Data Fiduciary, across all business functions: [Customer, HR, Vendor, Marketing, etc.], and to all systems, databases, and physical records holding such data. 3. RETENTION PRINCIPLES a. Purpose limitation: data is retained only as long as necessary to fulfil the purpose for which it was collected. b. Legal minimums: where a law mandates a minimum retention period (e.g., tax, labour, corporate records), that period overrides shorter operational timelines. c. Consent withdrawal trigger: where processing is consent-based and consent is withdrawn, retention ceases unless a legitimate use or legal obligation independently applies. d. Inactivity trigger: where the DPDP Rules specify erasure upon a defined period of Data Principal inactivity (e.g., account dormancy), that trigger is honoured unless a longer legal retention applies, and a reminder notice is sent before erasure where required. 4. RETENTION SCHEDULE (illustrative — customise per category) | Data Category | Retention Period | Basis | |---------------------------------|----------------------------------|----------------------------------| | Customer account & transaction data | [X years] after account closure | [Tax/consumer law reference] | | Marketing consent & preference data | Until withdrawal + [X months] | Consent (Section 6) | | Employee HR records | [X years] post-employment | [Labour law reference] | | Recruitment/candidate data (unsuccessful) | [X months] | Legitimate interest / equal opportunity audit | | CCTV / access-control logs | [X days/months] | Security (Section 7) | | Security/access logs (systems) | Minimum [1 year] or as prescribed | DPDP Rules, 2025 baseline | | Payment/financial transaction records | [X years] | [Financial regulation reference]| 5. ERASURE PROCEDURE a. Automated flagging: systems shall flag records reaching their retention limit for review [quarterly/monthly]. b. Verification: the Data Protection Officer or designated owner verifies no overriding legal hold or active legitimate use applies. c. Erasure method: data is securely deleted or irreversibly anonymised using [method, e.g., cryptographic erasure, secure wipe] such that it cannot be reconstructed. d. Backup handling: retained backups are purged of erased records within [X days] of the live-system erasure, or are subject to documented backup-cycle erasure. e. Third-party instruction: where data was shared with processors/partners, we instruct them to erase or return corresponding copies per the applicable Data Processing Agreement. 6. EXCEPTIONS TO ERASURE Retention beyond the schedule above may continue where necessary for: compliance with a legal obligation (Section 7(b)), ongoing legal proceedings, exercise or defence of legal claims, or archiving/research/statistical purposes permitted under Section 17. 7. RECORD-KEEPING A retention and erasure log shall be maintained recording: data category, erasure date, method used, and approving authority, retained for audit purposes for [X years]. 8. ROLES AND RESPONSIBILITIES The Data Protection Officer is responsible for policy oversight; Business/Function Heads are responsible for implementing retention schedules within their systems; IT/Engineering is responsible for building erasure and anonymisation tooling. 9. REVIEW This Policy shall be reviewed [annually] or upon material change in applicable law, and updates approved by [designated approver, e.g., Head of Compliance]. Approved by: [Name, Designation] Date: [Date]
This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.