From the blog · 5 October 2026

"Erase on request"
has an asterisk.

A lot of people read the DPDP Act as giving an unconditional right to deletion. It doesn't. Section 8(7)(a) puts a specific, lawful brake on that right — and the brake matters more than the pedal.

A dense held mass behind a gated line, with a smaller released point dispersing freely on the other side.
What's held behind a legal gate doesn't dissolve — what's free to go does.

01 · What the Act actually balances

Section 8(7)(a) says a data fiduciary must erase personal data once its purpose is served and retention is no longer necessary for a legal purpose — unless retention is required by law. That last clause isn't a loophole. It's the Act acknowledging something true: plenty of other Indian laws already require certain records to be kept for fixed periods, for reasons that have nothing to do with the DPDP Act and everything to do with audit trails, financial regulation, or dispute resolution.

02 · Where this actually bites

A bank, an NBFC, an insurer, or an e-commerce platform all sit under sector rules that mandate keeping specific records for years — sometimes well past when a customer would reasonably expect them gone. When an erasure request arrives for data that's also under one of those statutory holds, the two obligations collide, and the Act's own text resolves it: the statutory retention duty wins, for as long as it runs.

03 · The wrong way to resolve the collision

The tempting shortcut is cryptographic — "shred the encryption key and call the data gone." That's exactly backwards when the data is under a legal retention duty: shredding the key destroys the very record the law required you to keep, which turns a compliance measure into a new compliance failure. Crypto-erasure is a real and useful technique, but only for data you're actually permitted to erase and simply don't want to delete byte-for-byte.

04 · What a correct refusal looks like

The honest answer to "please delete my data" under a retention hold isn't silence, and it isn't a vague "we can't do that." It names the specific law or regulation requiring the hold, states how long it runs, and says so to the person who asked — a reasoned, evidenced refusal rather than a shrug. That's the standard we hold Consent Tree's retention decisions to: every category of data either gets erased, or gets a named legal reason it can't be yet, and the two are never confused with each other.

What the Act actually says — S.8(7)(a): erase when the purpose ends — unless another law requires the data be kept, in which case that law's retention period governs.