Privacy & Governance

“RBI Says Keep the Data, DPDP Says Delete It. Who Wins?”

Retention and deletion requirements can collide in regulated industries. The answer is to model the conflict explicitly instead of treating it as a simple delete-or-keep decision.

04

Regulated organisations can have legitimate reasons to retain information for defined periods. At the same time, privacy governance introduces expectations around purpose, retention and deletion.

The governance problem

A single "delete everything after X days" rule is rarely enough. Retention should be mapped to purpose, data category, legal or regulatory obligations and documented exceptions.

A practical model

  • Create a data inventory and purpose map.
  • Define retention rules by category and obligation.
  • Document lawful retention exceptions.
  • Separate active data from restricted or legally retained data.
  • Maintain evidence for why retention continued.

The goal

The goal is a defensible governance model where retention and privacy decisions are intentional, documented and auditable.

← Back to all articles