1. What the Act actually requires about data deletion
The Digital Personal Data Protection Act, 2023 operates on two principles that create deletion duties.
First, the purpose limitation principle: personal data may be processed only for the lawful purpose for which it was collected. Once that purpose is exhausted, the data must be deleted unless a law requires it to be retained. Second, the erasure with intent principle: a data principal can require the data fiduciary to erase personal data about them, and the fiduciary must put the system in place to honour that. The Rules formalise this through a Data Protection Officer who is responsible for ensuring erasure requests are actioned.
Two consequences matter for IT and facilities teams:
- Retention has an end. Personal data cannot be held indefinitely "just in case". When the retention period expires, the obligation to delete is live and the obligation to keep the data is gone.
- Deletion must be provable. "We delete it" is not a defence. If the data ended up on a retired drive in a warehouse, the breach traces back to a control that did not work. You need evidence.
2. Where the real risk sits: retired media, not live databases
Almost every DPDP exposure that has actually caused trouble in India came from hardware, not software:
- A decommissioned server drive sold or donated "without thought", still containing customer or employee records.
- A laptop replaced under a buy-back scheme, handed to a second owner, still holding email and saved credentials.
- A failed drive thrown into the e-waste bin, later recovered by a scrap handler who pulls readable sectors from a single surviving platter surface.
- An e-waste recycler whose downstream chain is not documented, so nobody can prove where the media ended up.
- Backup tapes stored off-site whose contents nobody has revisited, holding a complete copy of production data.
3. What a defensible DPDP destruction process looks like
- A written media disposal policy that says, per media class, which method is used and who is authorised to perform it.
- An asset register of every medium in scope — serial number, asset tag, data classification, custodian, location.
- A destruction register capturing: date, asset tag, serial, media type, machine and model used, cycle verification result, operator signature, custodian signature.
- Per-cycle verification — so the register says "field strength verified on this cycle" rather than "machine present".
- Retention rule for the register itself, aligned to your longest personal-data retention period.
- Authorised recycler documentation under the E-Waste (Management) Rules, with the downstream chain traceable.
- Periodic audit of the process, and of the disposal bins — a drive in a general waste bin is a finding waiting to happen.
4. Choosing the method by media type
| Media | Recommended method in India | Proton equipment | Why |
|---|---|---|---|
| Hard drive (2.5"/3.5"/server) | Degauss, then crush | T-1.5 / T-5 + PDS-100 | Purge plus physical destruction; works on dead drives |
| Failed or clicking hard drive | Degauss (crusher may struggle) | T-1.5 / T-4 / T-5 | Degaussing does not care whether the drive works |
| LTO / DLT / DAT tape | Degauss, then crush | T-1.5 / T-5 + PDS-75 / PDS-100 | Off-site tape is the most overlooked exposure |
| SSD / M.2 / NVMe | Shred or destroy — degauss has no effect | PDS-88 or PDS-30 with SSD kit | Flash is not magnetic; only destruction works |
| Pen drive / memory card | Shred | PDS-88 | Small, easy to lose, frequently carried out |
| Smartphone / tablet | Shred (remove battery first) | PDS-88 | Holds credentials, location history, cloud tokens |
| SIM / credit card | Shred | PDS-88 | High volume, high value, easy to mishandle |
| CD / DVD | Shred | PDS-88 | Confidential printouts and hand-outs |
5. The DPDP record set: what to keep
When a regulator, customer or internal auditor asks "how do you dispose of media?", the answer is a record, not a promise. Keep:
- The destruction register — one row per asset, with the cycle verification value.
- Machine identification — model, serial number, and the periodic field verification record for that machine.
- Operator authorisation — who is trained and permitted to operate the degausser.
- Recycler documentation — e-waste recycler authorisation, weighment or receipt, and the downstream chain.
- Policy version history — which policy version applied at the time of each destruction batch.
6. Roles: who does what
| Role | Responsibility in the destruction chain |
|---|---|
| Data owner / business owner | Defines the retention period and the classification of data on the media |
| IT / infrastructure | Identifies media at end of life, moves it to the destruction queue, applies the correct method |
| Compliance / DPO | Owns the policy, samples the destruction register, reports on exceptions |
| Security / facility | Controls access to the destruction room, ensures scrap is not diverted before destruction |
| Finance / admin | Ensures scrap disposal follows the E-Waste Rules and that documentation is retained |
| Vendor / ITAD | Performs the run under your register format and signs it |
7. What this means for equipment selection
When you write the media disposal policy, the equipment decision follows from it. The questions to answer are: which media classes are in scope, what proof does the policy require, who operates the machine, and where does the machine live. The degausser buying guide works through the equipment side; the compliance checklist is a one-page version you can take to your auditor.