India's DPDP Act gives users a right to erasure, but RBI, PMLA and CERT-In mandate multi-year retention. Here's how to delete what you can, defer what the law holds, and keep audit-proof evidence either way.
A practical, build-it-yourself checklist for the Digital Personal Data Protection Act, organised the way engineers actually ship: consent, data rights, retention, deletion, security, and breach response.
When a regulator asks you to prove a user's data was deleted, a Certificate of Erasure is the answer. What it is, what goes in it, and why a counter-signed one is proof you can't fabricate.
What the DPDP right to erasure actually requires, when you can lawfully refuse it, and how to implement deletion across your database, analytics, CRM and backups - with proof.
Notice in 22 languages, itemised purpose-level consent, withdrawal as easy as giving it, and immutable consent receipts. What the DPDP Act requires of consent - and how to build it.