Data retentionDPDPIT ActCompliance

Data Retention Policy Template (IT Act Compliant)

workro desk team·6 min read·18 June 2025

Why Data Retention Matters

Keeping data forever is not safer — it is riskier. The DPDP Act 2023 requires you to define retention periods and delete data when it is no longer needed. The IT Act requires certain records to be kept for 8 years. A data retention policy balances these competing requirements.

Retention Periods by Data Type

Data TypeMinimum RetentionMaximum RetentionLegal Basis
Financial records8 years8 yearsIT Act 2000, Companies Act
Employee records8 years post-exit10 yearsLabour laws, PF/ESI
Audit logs3 years5 yearsISO 27001, IT Act
Customer dataAs per contract3 years post-contractDPDP Act
Email communications1 year3 yearsBusiness need
Ticket records1 year3 yearsService quality

Download the Template

Download the Data Retention Policy Template

FAQ

What happens if I keep data longer than the retention period?

Under the DPDP Act, keeping data longer than necessary without justification is a violation. You could face penalties up to ₹250 crore for repeated violations.