DPDP right to erasure: the deletion request a Pune insurer got wrong
A 260-person corporate insurance agency in Pune deleted a former customer’s records in forty minutes. Their auditor spent the next nine weeks explaining why those were the wrong forty minutes.

A DPDP right to erasure request is not an instruction to delete everything. Section 12 gives a data principal the right to have personal data erased, and that right steps back wherever another law requires you to hold the record. In BFSI the carve-out is wide. RBI’s KYC Master Direction read with the PMLA holds identity and transaction records for five years past the end of the relationship. IRDAI’s records regulations run to ten years on policy and claim records, and insurance brokers hold their books for seven years from the end of the year concerned.
So the failure mode is rarely a refusal. It is deleting records your regulator required you to keep, while the copies you were actually obliged to erase sit untouched in six other places nobody mapped.
11:20 AM on a Tuesday in June. The subject line was three words. Delete my data.
The sender had held a motor policy through a 260-person corporate insurance agency in Pune, had not renewed since 2023, and had recently read something about the new law. His email was polite and one line long. It reached the grievance address on the website, which was working, which already put them ahead of most.
Nikhil runs IT there and wears the compliance hat on Thursdays. He did what a careful person does. Found the customer in the CRM, confirmed there was no live policy, no open claim, no unpaid premium, and pressed delete. Forty minutes including the tea. He sent a confirmation the same afternoon.
I read that closure note in week one of a readiness review and signed it off. Clean request, clean response, well inside the timeline. I want to be honest about that, because the mistake is the lesson and it was mine before it was his.
The forty minutes that felt like compliance
Delete is the most satisfying button in this profession. It produces a number that goes down. Nothing else in compliance does that.
The CRM held a name, two phone numbers, an email address, a vehicle registration, a policy number, three years of renewal reminders, and a marketing flag set to yes in 2019 and never touched again. All of it went.
Now read that list again. The marketing flag and the reminder history had no legal reason to survive, so deleting them was correct and overdue. The policy number and the identity record were a different animal sitting in the same row, and the delete did not distinguish between them.
The core policy administration system was untouched, because Nikhil had never thought of it as a place a customer lives. It is the place a customer lives. It held the proposal form, the KYC scans, the premium trail and one claim from 2021.
Achha, so far this is a filing problem, not a breach. That is usually where these start.
Where the data actually was
We spent three weeks on one question. If this customer wrote again next month and asked us to prove what we hold, could we produce the list.
Seven places. Not seven systems. Seven places.
The policy administration system, holding what the regulator requires. A third-party administrator’s claims platform, still holding the 2021 file, because the deletion instruction that went to the CRM never went to the processor. Two years of mailbox backups, holding renewal correspondence as attachments. A shared drive folder called Renewals 2023, holding an export of 4,112 lapsed customers with phone numbers, built for one campaign and never cleared.
Then the three that make an auditor slow down. Scanned KYC pages on a former agent’s personal WhatsApp, forwarded in 2022 because the branch scanner was down. A physical file in a steel cupboard at the branch, legitimate and recorded nowhere. And a returned laptop in the storeroom, collected from a sales manager who left in 2024, never wiped, still carrying a local copy of the renewals folder.
Here is my confession, and it is small and it cost nine weeks. In week one I saw a line in the CRM export log reading bulk export, 4,112 rows, marketing, dated 2023. I read it as a campaign artefact, the sort of thing you note and move past. It was the spreadsheet. It was also why the customer’s phone number survived a deletion he had been told was complete. Yaar, I read an amber signal as background noise, and it was the whole finding.
We have seen this shape in most BFSI estates we walk into. The regulated systems are governed. The copies are not, and the copies are where an erasure request actually lands.
The retention floor nobody had written down
Only now does the table earn its place. This is the sheet we built for them, and it is the one document that decides how you answer a DPDP right to erasure request in BFSI.
| Record class | What holds it in place | Minimum you must keep | Can erasure delete it |
|---|---|---|---|
| Customer identity and KYC records | RBI KYC Master Direction, read with the PMLA | Five years from the end of the business relationship | No, while that clock runs |
| Transaction records | PMLA record-keeping obligations | Five years from the transaction date | No |
| Insurance policy and claim records | IRDAI Maintenance of Insurance Records Regulations, 2015 | Ten years on policy records, settled claims to the specified timeline | No |
| Broker and intermediary books | IRDAI Insurance Brokers Regulations, 2018 | Seven years from the end of the year concerned | No |
| Marketing flags and campaign lists | Nothing sectoral | Only while the stated purpose lasts | Yes, and quickly |
| CRM activity tied to a named person | Nothing sectoral | Purpose-bound only | Yes |
| Copies on personal phones and unwiped laptops | No lawful basis at all | These should not exist | Yes, and this is where the finding lands |
Read the first four rows against the last three. The regulator is not fighting the Act; the Act already yields to it. The DPDP Act as tracked by PRS India makes the erasure right conditional, and it steps aside where retention is required by law. The Act text and notified Rules sit with MeitY; the KYC obligations that override you are in RBI’s Master Direction on KYC.
One page, four columns, every record class you hold. Sneha, their legal head, built theirs in two afternoons from the policy manual. Every erasure answer after that took twenty minutes instead of nine weeks.
One more thing catches BFSI teams out. The notified Rules put a hard three-year erasure clock on certain large platforms, the big e-commerce, social media and online gaming fiduciaries above stated user thresholds. Insurers, banks, NBFCs and intermediaries are not on that list. If somebody told you to auto-delete customer data at three years, they read a schedule that is not about you.
What the letter should have said
Nikhil’s confirmation said the data had been deleted. It was not true, and it was the kind of untrue a regulator reads as misrepresentation rather than error.
The reply we use now has four parts and fits on one screen. What has actually been erased, named by category. What is retained and under which specific law, with the period. The date those records become erasable, a real date and not in due course. And the grievance route if the person disagrees, including escalation to the Data Protection Board.
It takes twenty minutes when the retention matrix exists and is unanswerable when it does not. Theek hai, it also beats a deletion confirmation that quietly is not one. On timing, the Rules cap grievance redressal at ninety days and expect you to publish your own timeline inside that. Ninety is an outer wall, not a target.
Then the objection I hear in most of these rooms, usually from the CFO rather than the compliance head. Enforcement is not live yet, we will deal with it later. Enforcement timing is a gamble, and even before a single fine your clients’ RFPs are already starting to ask about it. Later is more expensive and more panicked, which is the only reliable thing about later. The ₹250 crore ceiling is the tail risk, and the tail is not what gets most firms. The working-paper finding is.
Answering a DPDP right to erasure request yourself
Five steps, and the order matters more than the tooling.
Write the retention matrix first. Four columns, every record class, the law pinning each one. Until it exists you cannot answer an erasure request correctly, and no product will do it for you.
Then map where each class physically lives, including the places that are not systems. Processors, mailbox backups, shared drives, branch cupboards, returned devices. Same exercise as a data mapping day at an NBFC, and the step most firms skip.
Fix the processor chain next. Your erasure instruction has to travel to every processor and your contract has to say so. A TPA holding a claim file after you erased yours is your finding, not theirs.
Close the informal copies, bluntly. Scanned KYC on a personal phone is not a grey area, and a laptop that leaves an employee unwiped is the cheapest breach anybody buys. That side we cover in IT asset disposal under DPDP and the device lifecycle management practice.
Only then tune the tooling. Discovery and monitoring belong in Secure Data Guard, and the regulator-overlap side, the IRDAI and RBI mapping and the breach clocks, we set out separately in what IRDAI and RBI expect on DPDP. Bas. The first two steps cost nothing but attention.
Where our pitch loses, and I would rather say it here. If you already run a staffed privacy function with a live RoPA and retention schedule, you do not need us for this part. Ask us for the device and endpoint layer instead, or do not ask us at all.
What to take away
- Erasure yields to retention, not the other way round. Section 12 lets you decline where another law requires the record. In BFSI that covers KYC, transaction, policy and claim files. Say so in writing, with the law named.
- The finding is in the copies, not the core system. Seven places held this customer and only one was governed. Mailbox backups, a processor’s platform, a shared drive export, a personal phone and an unwiped laptop held the rest.
- Never confirm a deletion you have not verified. A confirmation email that is not true reads as misrepresentation, which is a worse conversation than a partial refusal with reasons.
- The three-year auto-erase rule is not yours. It applies to the large e-commerce, social media and online gaming fiduciaries above the stated thresholds. Banks, insurers, NBFCs and intermediaries are not on that list.
- Build the retention matrix before you buy anything. Four columns, two afternoons. It turns a nine-week scramble into a twenty-minute letter.
Questions Nikhil wishes he had asked in week one
Does a DPDP erasure request mean we must delete a customer’s KYC records?
No, not while a retention obligation is running. The Section 12 erasure right steps back where another law requires the record. For banks and NBFCs, RBI’s KYC Master Direction read with the PMLA holds identity and transaction records for five years past the end of the relationship or the transaction date. For insurers, IRDAI’s records regulations run to ten years on policy records. Decline that part, name the law and the period in your reply, and erase everything outside it.
How long do we have to respond to a DPDP erasure request?
The notified Rules cap grievance redressal at ninety days and expect you to publish your own timeline within that bound. Treat ninety as the wall, not the target. Most BFSI firms we work with publish fifteen or thirty days and hit it, because the retention matrix already holds the answer. Miss your own published timeline and the data principal can escalate straight to the Data Protection Board.
Does the three-year erasure rule in the DPDP Rules apply to banks and insurers?
No. That clock sits in a schedule aimed at specified large e-commerce platforms, social media intermediaries and online gaming intermediaries above stated user thresholds, and it carries a pre-erasure notice to the user. Banks, insurers, NBFCs and insurance intermediaries are not in that class. Anyone telling you to auto-delete customer data at three years has applied a schedule that is not about your sector.
What do we do about customer data on an agent’s personal phone?
Treat it as the finding it is. There is no retention basis for a scanned KYC page on a personal WhatsApp, so it is squarely erasable and should never have been there. Fix why it happened, usually a broken scanner or a process that quietly assumes a personal device. Then close the device return path, because a laptop that leaves an employee unwiped carries the same problem in a bigger box.
Still deciding? These are the pages we send BFSI clients next.
The steel cupboard at the branch turned out to be the best-run thing in the estate. The clerk who keeps it had a register, in pen, with a date against every file that went in and every file that came out. She could answer in four minutes what four systems could not answer in nine weeks. Nikhil photographed two pages of that register and used it as the template for the retention matrix. Sometimes the compliance programme is already in the building, and it is written by hand.
We map where one customer’s data actually lives across your systems, processors, backups and returned devices, and hand you the four-column retention matrix to answer the next request in twenty minutes.
Get my free DPDP erasure readiness check
Retention periods above are published minimums under the RBI KYC Master Direction read with the PMLA, the IRDAI Maintenance of Insurance Records Regulations, 2015, and the IRDAI Insurance Brokers Regulations, 2018, as they stood at the time of writing. Confirm the current text and any amendments with your own regulator before relying on a date. The Pune engagement is one anonymised client review, not a published benchmark. This is a practitioner note on operating practice, not legal advice.






