Stop processing vs erase: two duties teams keep confusing
"Stop using it" and "delete it" are different duties under the DPDP Act, with different triggers, deadlines and exceptions. Mixing them up erases data the law says you must keep.
By Promiz · Published · 4 min read · Based on the DPDP Act, 2023 and DPDP Rules, 2025 · Not legal advice
What does “stop processing” mean?
Section 6(6) requires a Data Fiduciary to cease processing personal data within a reasonable time once consent is withdrawn, unless processing is required by law. The trigger is the withdrawal; the duty is to stop using the data for that purpose and to make your processors stop too.
Stopping does not mean deleting. A borrower who withdraws marketing consent still has a loan, and the loan file still has to exist.
What does “erase” mean?
Section 8(7) and Rule 8 require erasure once the purpose is served, or once consent is withdrawn and no legal obligation requires retention. The trigger is the end of the purpose or the end of a retention period; the duty is to delete, and to have processors delete, with a notice before the erasure happens.
Erasure is the irreversible one. That is why it needs a countdown, a warning and a confirmation - not a nightly script.
Where do the two collide?
Legal-obligation purposes. RBI record-keeping, IRDAI claims history, tax records: a withdrawal on these must stop non-essential use and must not trigger deletion. A dispute or an investigation adds a legal hold on top, freezing any erasure clock until it is lifted.
A tool that treats every withdrawal as a delete request will erase data the law says you must keep. A tool that never erases will fail Section 8(7). The queues have to be separate.
What does a correct setup look like?
Two queues. A withdrawal opens a stop-processing task with a confirmation deadline, delivered to every connected system. A purpose ending opens an erasure task with a 48-hour notice, a legal-hold check, and closure only when your system confirms the deletion. Legal-obligation purposes are marked as such at setup, so a withdrawal on them stops use and nothing more.
Both tasks write to the same record as the original consent, so the whole story - given, withdrawn, stopped, erased - sits in one chain.