City
Epaper

E-commerce, social media firms must erase inactive user data after 3 years: DPDP Act

By IANS | Updated: November 14, 2025 14:20 IST

New Delhi, Nov 14 The government has notified detailed norms under the Digital Personal Data Protection (DPDP) Act, ...

Open in App

New Delhi, Nov 14 The government has notified detailed norms under the Digital Personal Data Protection (DPDP) Act, introducing stringent data-retention rules for e-commerce platforms, social media intermediaries and online gaming companies.

Under the new guidelines, platforms will be required to delete the personal data of any user who has not logged in or used the service for three consecutive years. The regulation applies to online gaming companies with more than 50 lakh users, as well as social media and e-commerce platforms with more than two crore registered users in India.

Companies must give the inactive user 48 hours' notice before deleting such data, warning them that their data will be deleted if they don't use the platform within that time frame.

For digital platforms with more than 50 lakh users, known as significant data fiduciaries, the Act also establishes a higher compliance threshold.

To make sure that their systems, algorithms, and procedures do not endanger user rights, these organisations are required to perform an annual audit and a Data Protection Impact Assessment. They must additionally verify each year that their technical measures remain safe and compliant.

Although the DPDP Act permits cross-border transfers of personal data, the government has made it clear that these transfers must follow rules that may be communicated regularly. This is especially true if user data is transferred to a foreign state or any organisation under the control of a foreign government.

To strengthen data governance and improve user protection throughout the quickly growing digital ecosystem, the new regulations are a part of the larger operationalisation of India's first digital privacy law.

The government notified the rules for the Digital Personal Data Protection (DPDP) Act, formally operationalising India’s first digital privacy law and setting the compliance clock ticking for companies handling user data.

Social media sites, online gateways, and any other organisations handling personal data are required by the new framework to give users a detailed explanation of the information being gathered and to make it apparent how it will be used.

“With the DPDP Rules now notified, Indian enterprises have a clear roadmap on how they collect, process, secure and govern personal data. The phased rollout is crucial, it gives organisations the space to operationalise privacy, recalibrate their data architecture and embed accountable fiduciary practices seamlessly," said Murali Rao, Partner and Leader, Cybersecurity Consulting, EY India.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

Other SportsIPL 2026 retentions: Maxwell likely to be released, Mayank could be retained as deadline day nears

CricketDiscipline, patience, consistency: Jasprit Bumrah's mantra for success in Test cricket

Entertainment"I love that man...": Salman Khan calls Dharmendra father figure, hopes for his swift recovery

AurangabadCSMC-Police seize 450 kg of banned carry bags

NationalOn Bihar poll results day, Trinamool Congress releases social media video in a probable BJP-ruled Bengal

Technology Realted Stories

TechnologyYouth must stay united and focused for nation-building: FM Sitharaman in Nagaland

TechnologyDRDO develops new-gen man-portable autonomous underwater vehicles for mine countermeasure missions

TechnologyDLC campaign generates over 1 crore certificates: Ministry

TechnologyIndia emerges as the world’s 6th largest patent filer with over 64,000 patents: Jitendra Singh

TechnologyArmy engineers build indigenous Mono Rail System at 16,000 ft to keep Kameng frontier supplied