This document outlines Privra's policy for the retention and erasure of personal data, in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025.
---
# Privra Data Retention and Erasure Policy
*Effective Date: [Insert Current Date, e.g., 14 November 2025]* *Version: 1.0*
## 1. Introduction and Purpose
Privra is committed to protecting the personal data of its Data Principals. This Data Retention and Erasure Policy establishes clear guidelines for how long personal data is retained and when and how it is securely erased. This policy ensures compliance with Section 8(7) of the DPDP Act, 2023, which mandates the erasure of personal data once the purpose for which it was collected is no longer served, or upon withdrawal of consent, subject to legal retention requirements.
The purpose of this policy is to: * Ensure that personal data is only retained for as long as necessary to fulfill the stated processing purposes (purpose limitation, Section 5). * Define the criteria for determining appropriate retention periods. * Outline the procedures for secure erasure of personal data. * Address exceptions to erasure, such as legal or regulatory obligations. * Support Data Principal rights, including the right to erasure (Sections 11-14).
## 2. Scope
This policy applies to all personal data collected, processed, and stored by Privra, regardless of the format (digital or physical) or the location of storage. It covers all employees, contractors, and third-party processors acting on behalf of Privra.
## 3. Key Principles of Data Retention and Erasure
Privra adheres to the following principles regarding data retention and erasure:
* **Purpose Limitation (Section 5):** Personal data is collected and processed only for specific, lawful, and clearly defined purposes. Data will not be retained for longer than is necessary for these purposes. * **Necessity and Proportionality:** Data retention periods are determined based on the necessity of the data for the stated purpose, considering the nature of the data, the risks involved, and the rights of Data Principals. * **Erasure on Purpose No Longer Served or Consent Withdrawal (Section 8(7)):** Personal data will be erased as soon as the purpose for which it was collected is no longer served. This includes situations where a Data Principal withdraws their consent, provided there is no other legal basis for retention. * **Legal and Regulatory Obligations (Section 8(7) exception):** Notwithstanding the above, personal data may be retained for longer periods if required by any applicable law for the time being in force (e.g., tax laws, anti-money laundering regulations, contractual obligations, or for the establishment, exercise, or defence of legal claims). * **Security Safeguards (Section 8(5)):** During the retention period, Privra implements reasonable security safeguards to protect personal data from breaches, unauthorized access, or loss. * **Transparency:** Privra strives to be transparent about its data retention practices, as outlined in its privacy notice.
## 4. Data Retention Periods
Privra determines retention periods based on the specific purpose of processing, legal obligations, and contractual requirements. The following table outlines general retention periods for common data categories:
| Data Category | Processing Purpose(s) | Retention Period