Version 1.0 • CURRENT
DPDP Rules 2025 Time Period for Deletion & Child Data
RULE 8

Time period for specified purpose to be deemed as no longer being served

Official Statutory Text MeitY Gazette Notified Section 40 Delegated Authority
Plain-Language Compliance Breakdown (Editorial Analysis)

What this means: Companies cannot hoard data forever.

If a user abandons an app (e-commerce, gaming, or social media) and does not log in for 3 years, the company must permanently delete their account and personal data. They must send a warning email 48 hours before the deletion happens.

Key Practical Takeaways for Compliance Teams

  • Delegated Specificity: This rule provides concrete operational criteria that must be reflected in technical architectures and compliance records.
  • Audit Readiness: Ensure written SOPs, consent logs, and security controls correspond directly to the statutory wording of Rule 8.
  • Statutory Traceability: In any legal interpretation, the exact Gazette text above takes precedence over internal summaries.
← PREVIOUS RULE Rule 7: Intimation of personal data breach NEXT RULE → Rule 10: Verifiable consent for processing of personal data of child
Statutory text reproduced under open access public domain principles. This reader is designed for educational and compliance decision support.