Your Data Was Collected 5 Years Ago - Is It Still Legal for That Company to Hold It?

Think about every service you signed up for five years ago. The food delivery app you used twice. The e-commerce account you created for one purchase. The job portal you registered on and never returned to. The loyalty programme you joined to get a discount and promptly forgot about. Every one of these services collected your personal data. And in most cases, they still have it.

India’s Digital Personal Data Protection Act, 2023 has a clear position on this. Personal data must not be retained beyond the period necessary for the purpose for which it was collected. For the millions of dormant accounts, inactive registrations, and forgotten sign-ups sitting in databases across Indian businesses, the DPDPA has created a legal problem that most of those businesses have not yet begun to address.

The DPDPA's Retention Obligation Explained Simply

Section 8(7) of the DPDPA states that a Data Fiduciary must erase personal data as soon as it is reasonable to assume that the purpose for which it was collected is no longer being served, and retention is no longer necessary for legal or business purposes.

In plain language, this means that if you signed up for a service five years ago, used it a few times, and have not interacted with it since, the company needs to ask itself whether there is still a legitimate reason to keep your data. If you are no longer an active customer, if there is no ongoing contract between you and the company, and if there is no legal requirement that compels the company to keep your records, the DPDPA requires that your data be deleted.

The company cannot keep your data indefinitely on the basis that you might come back someday. That is not a purpose. That is a hope. And the DPDPA does not recognise hope as a lawful basis for data retention.

What Constitutes a Legitimate Reason to Keep Old Data

Understanding whether a company’s continued retention of your five-year-old data is lawful requires understanding what the DPDPA accepts as a legitimate basis for retention.

Legal obligations are the strongest basis. If a company is required by law to retain certain records for a specified period, that legal requirement overrides the DPDPA’s erasure obligation for the duration specified. Financial institutions must retain transaction records for regulatory purposes. Employers must retain certain employee records under labour law. Healthcare providers must retain patient records under medical regulations. These statutory requirements create lawful retention even after the original purpose has been served.

Ongoing contractual relationships are another legitimate basis. If you are still an active customer with an existing contract, the company needs your data to fulfil that contract. But when the contract ends, the retention basis changes. Data held beyond the period needed to wind down the contractual relationship requires another lawful basis.

Pending legal proceedings are a legitimate basis in specific circumstances. If a company is involved in litigation or regulatory proceedings that require it to preserve certain records, it may legitimately retain data beyond its standard retention period for the duration of those proceedings.

Commercial interest, without more, is not a legitimate basis. “We keep your data because it is valuable to us” is not a reason that the DPDPA accepts. Nor is “we keep it in case you come back.” The purpose for which data can be retained must be specific and must have a clear legal or contractual foundation.

The Five-Year Dormant Account Problem

The dormant account scenario is one of the most common and least addressed data retention problems in Indian businesses. A user signs up, uses the service a few times, and then stops engaging. The account sits dormant. The company continues to hold the user’s name, email address, phone number, and behavioural data from their period of activity.

Under the DPDPA, continuing to hold this data without a legitimate retention basis is unlawful processing. The purpose for which the data was collected, to provide the service to an active user, is no longer being served. There is no ongoing contract. And unless there is a specific legal requirement to retain the data, the DPDPA requires that it be erased.

For Indian companies with large user bases, this creates a significant operational challenge. Identifying dormant accounts, determining whether any lawful retention basis exists for each, and implementing deletion processes across multiple data systems is not a small project. But it is a necessary one, and organisations that have not started it are accumulating compliance debt with every day that dormant data remains in their systems.

Your Right to Request Deletion

The DPDPA gives you, as a data principal, the right to request erasure of your personal data. This right is sometimes called the right to be forgotten, though the DPDPA’s version is more limited than its equivalent in some international frameworks.

You can exercise this right by contacting any Data Fiduciary that holds your personal data and requesting that they erase it. The organisation must consider your request and erase data that it no longer has a lawful basis to retain. If the organisation has a legal obligation to retain certain data, it can refuse the erasure request to the extent of that legal obligation. But it cannot refuse to erase data that it has no legitimate reason to hold.

If the organisation refuses your erasure request without a satisfactory explanation, you have the right to raise a complaint with the Data Protection Board of India, which can investigate and, if it finds a violation, impose penalties on the organisation.

How to Find Out Who Still Has Your Old Data

One of the practical challenges of exercising your rights under the DPDPA is knowing who has your data. For data you knowingly provided, such as app registrations and service sign-ups, you should be able to identify the organisations. For data that may have been shared with third parties without your full awareness, the picture is less clear.

You can exercise your right of access under the DPDPA to ask any organisation you believe holds your data to confirm what they hold and explain the basis for holding it. This is a practical starting point for understanding your data exposure across the services you have used over the years.

For data held by financial institutions, your bank statements, annual information statements, and credit bureau reports can give you a picture of what data has been linked to your financial identity and which institutions are holding records about you.

How ComplyPlanet Helps

ComplyPlanet works with Indian organisations to conduct data retention audits that identify what historical data is being held, assess the legal basis for continued retention of each data category, and build deletion processes that bring the organisation into compliance with the DPDPA’s retention obligations.

We also help organisations build the data principal rights response processes that allow them to handle erasure requests, access requests, and correction requests effectively and within the timeframes the DPDPA requires.

Our approach is practical. We understand that years of accumulated data cannot be addressed overnight, and we help organisations prioritise their retention compliance work based on risk, starting with the data categories that create the greatest exposure.

Conclusion

Five years is a long time to hold data that serves no purpose. The DPDPA has made it a legal problem. If a company has your data and no good reason to keep it, the law says it should be gone. As a user, you now have the right to ask. As an organisation, you now have the obligation to answer honestly and act accordingly.

ComplyPlanet – Your Compliance Backbone