Right to Erasure vs Right to Retention: What Happens When the Regulator Says Keep the Data?

    A customer requests erasure. Your regulator requires you to keep the data. Two legal obligations pull in opposite directions. This is one of DPDPA's most common compliance dilemmas.

    OneConsentBlog
    5 min read
    Monday, 3 August 2026
    Illustration contrasting a trash bin labeled with a personal data document being deleted on the left with a locked safe securing a personal data document on the right, connected by arrows and icons representing legal compliance, security, and audit checklist, symbolising the conflict between a customer's right to erasure and a regulator's mandate to retain data under DPDPA.

    A customer files an erasure request. Somewhere in the same building, your compliance team is holding onto the exact same data because RBI or SEBI says they have to for another five to eight years. Two legal obligations, pulling in opposite directions, and someone on your team has to decide what happens next. This is one of the more common headaches under DPDPA, and honestly, it's the kind of dilemma that trips up teams who assume erasure is a simple "delete on request" button.

    The Erasure Right Isn't Absolute

    Under DPDPA Section 12, a Data Principal can ask you to erase their personal data once it's no longer needed for the purpose consent was originally given for, or once they've withdrawn that consent. Straightforward enough on paper. But the Act itself builds in an exception: where another law requires you to keep that data, the erasure request doesn't automatically win. This carve out is what creates the entire tension this post is about.

    Where Regulatory Retention Wins

    Several Indian regulatory frameworks require you to hold onto data well past the point a customer might want it gone. RBI requires KYC records to be kept for five years after an account closes. SEBI mandates eight years of investor records after a transaction. IRDAI requires insurance data for the policy duration plus a defined additional period. Income tax rules call for six to eight years of financial records, and the Companies Act pushes certain company data retention out to eight or ten years. In every one of these cases, the regulator's requirement gives you a legitimate legal basis to refuse or delay erasure, but only for the specific data those rules actually cover.

    Related Reads: How to Handle a DSAR in 72 Hours: A Step-by-Step Playbook for Indian Businesses - linked

    The Part Most Teams Get Wrong

    Here's where the real principle sits, and it's easy to miss. A regulatory retention obligation only justifies keeping data for that regulatory purpose. It doesn't give you a free pass to keep using the same data for anything else. Say a bank customer withdraws consent and asks for erasure. The bank can legitimately hold onto their KYC and transaction records because RBI says so. What it cannot do is keep feeding that same data into marketing analytics, AI model training pipelines, or cross-sell scoring. Once a customer withdraws consent, that retained data needs to be quarantined, sitting there for the regulator and nothing else. I've seen organisations treat "we're required to retain this" as blanket permission to keep using it however they like, and that's exactly the gap a Board complaint would expose.

    A Practical Response Sequence

    When an erasure request lands and part of that data falls under a retention mandate, here's the sequence that actually holds up:

    1. Acknowledge the request within 48 hours, same as any DSAR.

    2. Identify precisely which data is subject to regulatory retention, and write down the exact regulatory provision behind it. Not "we think we need this," but the specific RBI circular or SEBI regulation.

    3. Erase everything that isn't covered by a legal retention obligation. Don't hold onto more than the rule requires just because it's easier.

    4. Tell the Data Principal in writing exactly what's been retained, under which law, for how long, and what it will be used for during that window. Silence here is what turns a manageable situation into an escalation.

    5. Schedule the eventual deletion. Set a calendar trigger for when the retention period expires, so the data doesn't just sit there indefinitely because nobody remembered to follow up.

    Why the Paper Trail Matters More Than the Decision Itself

    Every time you partially honour or defer an erasure request, document the reasoning behind it. Which law required retention, what data specifically, and for how long. This is the single most important thing in this whole process, because if the customer isn't satisfied and takes it to the Data Protection Board, your documentation is the entire defence. A verbal explanation won't hold up. A dated record with the regulatory citation attached will.

    Managing the Tension Long Term

    This tension between erasure and retention isn't going away, and honestly it shouldn't surprise anyone once you sit with it for a minute. Regulators built these retention rules for good reasons (fraud investigation, audit trails, systemic risk), and DPDPA was never going to override all of them. The organisations that handle this well aren't the ones with clever legal arguments. They're the ones who actually know, at a granular level, what data they hold, why they hold it, and under which specific basis. Without that mapping, every erasure request becomes a scramble. With it, you can honour the erasure right to the fullest extent the law actually allows, instead of either over-retaining out of caution or under-retaining out of carelessness.

    Easyrewardz helps organisations manage exactly this kind of complexity, giving compliance teams a clear, auditable trail across consent withdrawal and regulatory retention scenarios so nothing falls through the cracks. If your team is still tracking these decisions in spreadsheets and email threads, OneConsent's data mapping and consent lifecycle tools can give you that same visibility built directly into your compliance workflow.

    Backlink: OneConsent (https://oneconsent.ai)

    Frequently Asked Questions

    Have more questions?

    Search our full DPDP knowledge base for more answers.

    See it live

    See OneConsent in action

    Get a personalised walkthrough of how OneConsent helps your teams stay DPDPA compliant.

    • 30-minute walkthrough
    • DPDPA-ready by design
    • Tailored to your stack