Authorised Indian Partner for Proton Data Security, USA
Tel: +91 80 26539077•Mob: +91 9243049222•mail@quridge.net

Digital Personal Data Protection Act, 2023

DPDP Act 2023 & Data Destruction in India

The Digital Personal Data Protection Act 2023 and its Rules do not prescribe a destruction technology. They do require erasure, and they hold you accountable for it. This is what a defensible media-destruction process looks like in practice.

Short version: the DPDP Act 2023 requires you to honour erasure and to delete personal data when its purpose is met. It does not name a degausser. It does, however, make you accountable — so your defence is a documented process with a register, and a degausser is the most defensible way to show a hard drive was genuinely sanitised.

1. What the Act actually requires about data deletion

The Digital Personal Data Protection Act, 2023 operates on two principles that create deletion duties.

First, the purpose limitation principle: personal data may be processed only for the lawful purpose for which it was collected. Once that purpose is exhausted, the data must be deleted unless a law requires it to be retained. Second, the erasure with intent principle: a data principal can require the data fiduciary to erase personal data about them, and the fiduciary must put the system in place to honour that. The Rules formalise this through a Data Protection Officer who is responsible for ensuring erasure requests are actioned.

Two consequences matter for IT and facilities teams:

  • Retention has an end. Personal data cannot be held indefinitely "just in case". When the retention period expires, the obligation to delete is live and the obligation to keep the data is gone.
  • Deletion must be provable. "We delete it" is not a defence. If the data ended up on a retired drive in a warehouse, the breach traces back to a control that did not work. You need evidence.

2. Where the real risk sits: retired media, not live databases

Almost every DPDP exposure that has actually caused trouble in India came from hardware, not software:

  • A decommissioned server drive sold or donated "without thought", still containing customer or employee records.
  • A laptop replaced under a buy-back scheme, handed to a second owner, still holding email and saved credentials.
  • A failed drive thrown into the e-waste bin, later recovered by a scrap handler who pulls readable sectors from a single surviving platter surface.
  • An e-waste recycler whose downstream chain is not documented, so nobody can prove where the media ended up.
  • Backup tapes stored off-site whose contents nobody has revisited, holding a complete copy of production data.
The under-appreciated point: a single undegaussed fragment can yield data. This is why Proton's own documentation, and NSA/DoD practice, insist a degausser is used before physical destruction. Crushing alone does not close the risk.

3. What a defensible DPDP destruction process looks like

  • A written media disposal policy that says, per media class, which method is used and who is authorised to perform it.
  • An asset register of every medium in scope — serial number, asset tag, data classification, custodian, location.
  • A destruction register capturing: date, asset tag, serial, media type, machine and model used, cycle verification result, operator signature, custodian signature.
  • Per-cycle verification — so the register says "field strength verified on this cycle" rather than "machine present".
  • Retention rule for the register itself, aligned to your longest personal-data retention period.
  • Authorised recycler documentation under the E-Waste (Management) Rules, with the downstream chain traceable.
  • Periodic audit of the process, and of the disposal bins — a drive in a general waste bin is a finding waiting to happen.

4. Choosing the method by media type

MediaRecommended method in IndiaProton equipmentWhy
Hard drive (2.5"/3.5"/server)Degauss, then crushT-1.5 / T-5 + PDS-100Purge plus physical destruction; works on dead drives
Failed or clicking hard driveDegauss (crusher may struggle)T-1.5 / T-4 / T-5Degaussing does not care whether the drive works
LTO / DLT / DAT tapeDegauss, then crushT-1.5 / T-5 + PDS-75 / PDS-100Off-site tape is the most overlooked exposure
SSD / M.2 / NVMeShred or destroy — degauss has no effectPDS-88 or PDS-30 with SSD kitFlash is not magnetic; only destruction works
Pen drive / memory cardShredPDS-88Small, easy to lose, frequently carried out
Smartphone / tabletShred (remove battery first)PDS-88Holds credentials, location history, cloud tokens
SIM / credit cardShredPDS-88High volume, high value, easy to mishandle
CD / DVDShredPDS-88Confidential printouts and hand-outs

5. The DPDP record set: what to keep

When a regulator, customer or internal auditor asks "how do you dispose of media?", the answer is a record, not a promise. Keep:

  • The destruction register — one row per asset, with the cycle verification value.
  • Machine identification — model, serial number, and the periodic field verification record for that machine.
  • Operator authorisation — who is trained and permitted to operate the degausser.
  • Recycler documentation — e-waste recycler authorisation, weighment or receipt, and the downstream chain.
  • Policy version history — which policy version applied at the time of each destruction batch.
Practical warning. A degausser with no verification output and no register is worse than useless from a compliance point of view, because it produces a false assurance. This is why the T-1.2, T-1.5, T-4 and T-5 report field strength per cycle, and why we supply a test certificate with every machine.

6. Roles: who does what

RoleResponsibility in the destruction chain
Data owner / business ownerDefines the retention period and the classification of data on the media
IT / infrastructureIdentifies media at end of life, moves it to the destruction queue, applies the correct method
Compliance / DPOOwns the policy, samples the destruction register, reports on exceptions
Security / facilityControls access to the destruction room, ensures scrap is not diverted before destruction
Finance / adminEnsures scrap disposal follows the E-Waste Rules and that documentation is retained
Vendor / ITADPerforms the run under your register format and signs it

7. What this means for equipment selection

When you write the media disposal policy, the equipment decision follows from it. The questions to answer are: which media classes are in scope, what proof does the policy require, who operates the machine, and where does the machine live. The degausser buying guide works through the equipment side; the compliance checklist is a one-page version you can take to your auditor.

Frequently asked questions

Straight answers to the questions Indian buyers ask most often. Cannot find yours? Call us — we answer technical questions on the phone.

Does the DPDP Act 2023 say a degausser is mandatory?
No. The Act and the DPDP Rules do not name any specific technology. What they require is that a data fiduciary take reasonable steps to honour erasure requests, and to delete personal data once its lawful purpose is met. In practice that means you need a documented, repeatable and demonstrable deletion process — a degausser is one of the strongest ways to demonstrate purge for magnetic media.
What should a DPDP-compliant destruction process look like?
Four things: a written media disposal policy, a register of every medium destroyed, proof that the destruction method was appropriate to the media type, and a retention rule for the records themselves. The register is what proves compliance later.
How long do I need to keep destruction records?
There is no single prescribed retention period. Good practice, and what most Indian audit frameworks expect, is to keep the register for at least as long as the underlying retention period of the data that was on the media, and commonly 3 to 7 years. Align the register's retention to your longest data retention period.
Does deleting personal data from a live system count?
Yes, for personal data sitting in databases. It does not cover retired hardware, which is where the risk concentrates — an old server drive in a storeroom is a far more likely breach route than a live database.
Who is liable if an old drive leaks?
The data fiduciary — the organisation that determined the purpose and means of processing the personal data. That liability survives the drive leaving the rack, the employee leaving, and the vendor contract ending. Media destruction is a legal risk-control measure, not a housekeeping task.

Need a destruction process that will survive an audit?

Send us your current media disposal policy or a blank destruction register. We will tell you what is missing and specify the equipment to close the gaps.

Request a quote Call +91 9243049222