Time period for specified purpose to be deemed as no longer being served
8. (1) A Data Fiduciary, who is of such class and is processing personal data for such corresponding purposes as are specified in Third Schedule, shall erase such personal data, unless its retention is necessary for compliance with any law for the time being in force, or, for the corresponding time period specified in the Third Schedule, if the Data Principal neither approaches such Data Fiduciary for the performance of the specified purpose nor exercises her rights in relation to such processing.
(2) At least forty-eight hours before completion of the time period for erasure of personal data under this rule, the Data Fiduciary shall inform the Data Principal that such personal data shall be erased upon completion of such period, unless she logs into her user account or otherwise initiates contact with the Data Fiduciary...
Note: The Third Schedule specifies a 3-year inactivity timeout for E-commerce, Gaming, and Social Media companies.
What this means: Companies cannot hoard data forever.
If a user abandons an app (e-commerce, gaming, or social media) and does not log in for 3 years, the company must permanently delete their account and personal data. They must send a warning email 48 hours before the deletion happens.
Key Practical Takeaways for Compliance Teams
-
•
Delegated Specificity: This rule provides concrete operational criteria that must be reflected in technical architectures and compliance records.
-
•
Audit Readiness: Ensure written SOPs, consent logs, and security controls correspond directly to the statutory wording of Rule 8.
-
•
Statutory Traceability: In any legal interpretation, the exact Gazette text above takes precedence over internal summaries.