Privacy education, consultancy & implementation, in 50+ jurisdictions.enquiry@vedhacon.com
Guidance and examples adapt to your selection.↑↓ to browse, ↵ to apply
Not sure where to start?Check your readiness in 10 minutes

Eighteen questions, eight domains, a prioritised list of gaps. Nothing leaves your browser.

Begin the assessment
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
Retention · Practical guide

Retention schedules: the control everyone writes and no one runs

A schedule is policy. The control is data being deleted, anonymised or defensibly retained at the right time across production, copies, vendors and backups—with evidence.

Vedhacon Privacy Operations practice10 min read

Most organisations have a retention schedule. Far fewer can produce a record showing that a rule ran, which records were affected, which copies were excluded and why. The gap appears because legal and records teams write by record type while technology stores by table, object, tenant, mailbox, archive and backup.

A retention period that no system enforces is a promise, not a control.

Start with purpose and legal need

GDPR Article 5(1)(e) requires personal data to be kept in identifiable form no longer than necessary for the purposes for which it is processed, subject to conditions for longer storage for archiving, research or statistical purposes. Article 17 includes erasure rights and exceptions; neither provision creates one universal period.

India’s DPDP Act links erasure to withdrawal of consent or a reasonable conclusion that the specified purpose is no longer being served, unless retention is necessary for compliance with law. Final Rules add particular requirements for specified classes and purposes, subject to scope and commencement.

Do not start with a round number

“Seven years” is not a retention rationale. Identify the purpose, trigger, applicable legal minimum, defensible operational maximum, relevant limitation periods and documented exception. Apply longer minimums only to the records and purpose they actually cover.

Write an executable retention rule

Fields behind an operational rule
FieldQuestionExample output
Record scopeWhich data, people, purpose and business process?Unsuccessful applicant file for recruitment decisions
TriggerWhich event starts the clock?Candidate receives final rejection notice
MinimumMust any records be retained for a legal or contractual period?Defined evidence subset retained for the applicable claim period
MaximumWhen must identifiable data be deleted or anonymised?End of approved period after trigger
Systems and copiesWhere does the data exist?ATS, mailbox, shared drive, analytics export and vendor tenant
MechanismHow will deletion or anonymisation happen?Automated lifecycle rule plus monthly exception queue
OwnerWho operates and who approves the rule?HR operations owner; privacy approves exceptions
EvidenceHow is execution demonstrated?Job log, count, sample test and exception record

Map policy to the data estate

Use the RoPA and system inventory to translate each schedule row into implementable rules. One record category may exist in several systems with different technical capabilities. One system may require several rules because purposes and triggers differ.

From schedule row to running control
StepActionEvidence
1. ReconcileMatch record categories to activities, systems, vendors, exports and physical copies.Coverage matrix and unresolved gaps
2. TranslateConvert the period into a machine- or operator-readable trigger and action.Rule specification and test cases
3. ConfigureBuild lifecycle, deletion, anonymisation or archive jobs with access controls.Configuration record and approval
4. Handle exceptionsApply scoped holds or statutory minimums without suspending unrelated deletion.Exception register and expiry review
5. TestUse dated records around the boundary to verify selection and outcome.Pre/post samples and results
6. OperateRun automatically or through a controlled manual queue.Execution logs, counts and failures
7. MonitorReview exceptions, failures, growth and samples.Metrics, alerts and remediation tickets

Where deletion silently stops

Common failure points and required controls
Failure pointWhat goes wrongControl
Legal holdsBroad holds are applied without defined scope or release.Record matter, custodian, data scope, owner, start, review and release date.
BackupsProduction deletion is followed by restoration of expired data.Document backup expiry, restrict use and reapply deletion after restore.
Exports and spreadsheetsCopies leave the governed system and receive no trigger.Limit export, label purpose, expire storage and scan known repositories.
Data warehousesSource deletion does not remove transformed or joined copies.Propagate identifiers and deletion events through pipelines.
VendorsCustomer deletion does not reach processors or sub-processors.Contract duties, API or ticket workflow, confirmation and testing.
Test environmentsProduction data is copied and retained indefinitely.Use synthetic data, minimise copies and enforce environment expiry.
Paper and devicesPhysical files, local downloads and retired devices sit outside jobs.Controlled collections, destruction records and disposal chain of custody.

Apply DPDP Rule 8 carefully

The final DPDP Rules include class-specific treatment for certain large e-commerce entities, online gaming intermediaries and social media intermediaries, using inactivity periods and advance notice before erasure. Rule 8 also provides minimum retention for specified logs and related personal data for particular purposes. These provisions are not a universal retention schedule for every organisation or dataset.

Before implementing a rule, confirm whether the organisation and processing fall within the relevant class, which data and purpose are covered, the applicable period, notice requirement and commencement date. Where Rule 8 applies to erasure after inactivity, the notice must be given at least 48 hours before erasure. Keep the notification and resulting action as evidence.

Control holds and exceptions

A hold suspends a defined disposal action; it should not freeze every record in a system. Record the legal or investigative basis, affected custodians and data, approving authority, start date, review frequency and release criteria. Apply the hold technically where possible and verify it does not capture unrelated records.

Exception register
  • Rule and systems affected.
  • Records, custodians and date range in scope.
  • Reason and authority for the exception.
  • Owner, start date and next review date.
  • Technical implementation and validation.
  • Release decision and resumed deletion evidence.

Design for backup and restore

Immediate record-level deletion from immutable backup media may not be feasible. Define the backup retention period, access restrictions, segregation and restoration process. If a backup is restored, ensure expired records are not returned to normal use and that relevant deletion rules are reapplied before the environment becomes operational.

Do not describe backup data as deleted if it remains recoverable. Explain the actual lifecycle and safeguards accurately in internal records and, where relevant, external notices.

Prove that deletion operates

Evidence for retention and deletion controls
EvidenceWhat it demonstrates
Approved schedule and rationalePurpose, trigger, legal basis, minimum and maximum were considered.
System mappingRules cover production, copies, vendors, archives and physical records.
Configuration and change recordThe approved rule was implemented and controlled.
Execution logWhen the job ran, scope, counts, outcome and failures.
Exception and hold registerSuspensions are justified, scoped and reviewed.
Vendor confirmationDeletion propagated to processors and relevant sub-processors.
Sample testExpired records are absent and retained records are not deleted early.
Failure remediationErrors produce tickets, owners, dates and closure evidence.

Monitor the control

  • Percentage of schedule rules mapped to systems and owners.
  • Deletion jobs completed, failed and overdue.
  • Records deleted or anonymised by rule and system.
  • Exceptions and holds past their review date.
  • Vendors awaiting deletion confirmation.
  • Repositories containing expired or unmapped data.
  • Sample-test failures and time to remediation.

References and scope

  • Regulation (EU) 2016/679 (GDPR), Articles 5(1)(e) and 17.
  • Digital Personal Data Protection Act, 2023 (India), including section 8 duties relevant to erasure and legal retention.
  • Digital Personal Data Protection Rules, 2025 (India), Rule 8 and applicable schedules and commencement notifications.

General information for practitioners, not legal advice. Retention periods depend on purpose, jurisdiction, sector, contracts, litigation and commencement. Confirm current official texts and obtain qualified advice for the records concerned.