Retention & erasure · DPDP s.8(7), Rule 8

Erasure that happens.

Section 8(7) says erase when the purpose is served or consent is withdrawn. Nyvika turns the retention period you set on each purpose into a schedule, warns the person first, and then erases, including at your processors.

s.8(7) ErasureRule 8 Time periods48-hour warning
The retention queue: people whose purposes have expired, with what will be erased and when
The challenge

Keeping data is the default; the Act reverses it.

Every system you run keeps data forever unless something deletes it. The Act requires the opposite, and it requires you to warn people before inactivity erasure.

s.8(7)
Served or withdrawn means erase
Not archive, not anonymise later, not keep for analytics. Erase, unless a law requires retention, and tell your processors to do the same.
Rule 8
Inactivity has a clock too
For the classes of fiduciary the Rules name, a person who has not used the service within the period must be erased, after a warning 48 hours ahead.
Processors
Your copy is not the only copy
The CRM, the engagement tool and the support desk all hold the person. Erasure that stops at your database is incomplete.
What Nyvika does

Retention as a schedule, not a policy.

Set the period on the purpose. Nyvika does the rest on a nightly run and shows you what it is about to do.

Per-purpose periods

Each purpose carries its retention in days; consent for that purpose expires when it runs out.

  • Shown on the notice, so people know
  • Legal-obligation purposes keep their own period
  • Changing it changes the schedule

Inactivity erasure

People who have not been seen within the period are warned 48 hours ahead and then erased.

  • Warning by email and SMS or WhatsApp
  • Cancelled automatically if they return
  • Last-seen updated by sign-in and widget activity

Review or automatic

Start in review mode and approve each night's queue; switch to automatic when you trust it.

  • Queue shows every person and purpose
  • One-click approve, or hold with a reason
  • Everything audited

Processors instructed

Erasure is only sent to a processor when every purpose it serves for that person has expired.

  • Instruction through the connector
  • Delivery log and retry
  • Contact vault shredded after delivery
One ledger

How it connects.

Every module writes to the same registers and the same hash-chained evidence, so nothing is re-keyed and nothing is lost between teams.

Questions

Asked about retention.

What if a law requires us to keep records longer?

Model that as a legal-obligation purpose with its own retention, for example tax records for eight years. Consent-based purposes expire on their own clock; the legal one keeps what the law requires and nothing more.

How can the ledger stay verifiable after erasure?

Erasure redacts the personal content of the entries and records a redaction entry; the hashes that chain the records are preserved, so verification still succeeds and shows that an erasure happened, when, and why.

Can we try it without deleting anything?

Yes. Review mode shows the nightly queue and does nothing until an officer approves it. Most customers run review mode for the first month.

Still have a question? Write to us.

Stop keeping what you promised to erase.

Bring your purposes and their periods; we will show you tomorrow's queue before you decide.