Stop processing and erase on time, with proof.
"Stop using it" and "delete it" are two different duties under the Act. Promiz keeps them in two queues, starts the clock, warns you before deadlines, and closes a task only when your system confirms the work.
- 2
- separate queues: stop processing and erase
- 3
- levels of legal hold: organisation, purpose, consent
- 48 h
- minimum notice before erasure, recorded as delivered or failed
What does the DPDP Act ask after consent ends?
The duty does not end when a person withdraws or when a purpose is served. The Act and Rule 8 set what you must stop, what you must erase, and what you must keep.
Sources: Digital Personal Data Protection Act, 2023, sections 6(6), 8(7) and 8(8); DPDP Rules, 2025, Rule 8 and the Third Schedule. The 48-hour rule in law applies to Third Schedule erasures; Promiz applies it to all erasures.
How does an obligation move through Promiz?
Each obligation has an owner, a deadline and a proof of closure.
- Step 1 A trigger opens the task
A withdrawal opens a stop-processing task. The end of a retention period opens an erasure task.
- Step 2 The clock starts
Promiz sets the deadline. Legal holds and legal-obligation bases pause or exclude it.
- Step 3 Promiz warns you
At least 48 hours before erasure, Promiz sends notice and records whether it was delivered.
- Step 4 Your systems are told
Signed webhooks tell your CRM and data systems what to stop or delete.
- Step 5 Your system confirms
A machine-to-machine acknowledgement closes the task. A nightly job flags anything overdue.
What does the Obligations module give you?
Two queues, kept apart
Withdrawals and erasures carry different deadlines and different proof. Data you must keep by law stops being used without being deleted.
Per-purpose retention
Set how long data for each purpose may be kept. The clock starts when the purpose is served or consent is withdrawn.
Legal holds at three levels
Freeze the clock for the organisation, a purpose or one consent while a dispute or investigation is open.
Notice you can prove
Promiz records the notice actually delivered. A failed notice is recorded as a failure, never as notice given.
Machine-confirmed closure
Your system confirms deletion back to Promiz. Promiz cannot assert a deletion that did not happen.
Overdue escalation
A nightly job flags every task past its deadline. The menu badge counts overdue items only.
Re-consent cancels erasure
If the person consents again before deletion, the erasure task ends and a "Retention cancelled" event is sent.
Full audit trail
Every step, from trigger to closure, is logged end to end.
Why not track this in a spreadsheet?
What is the difference between withdrawal and erasure under the DPDP Act?
Withdrawal means you must stop processing within a reasonable time (section 6(6)). Erasure means you must delete data when the purpose is served or consent is withdrawn, unless another law requires you to keep it (section 8(7)).
Does the 48-hour notice apply to every business?
In law, Rule 8(2) applies to the large platforms in the Third Schedule before an inactivity erasure. Promiz sends notice at least 48 hours before every erasure as good practice.
Can we keep data that RBI or tax law requires?
Yes, where another law requires it. In Promiz, a legal-obligation basis raises a stop-processing task, never an erasure task. You can also place a legal hold.
How does Promiz know data was deleted?
Your system sends a machine-to-machine acknowledgement to Promiz. Only that closes the erasure task.
Does Promiz handle the 3-year inactivity rule?
Not yet. Retention from customer inactivity is still being completed. Ask your Promiz contact what is live for your account.
Watch a withdrawal close with proof.
In 30 minutes we withdraw a consent, send the webhook and close the task with a machine confirmation.
This page explains the law in plain words. It is not legal advice. Your legal team decides how the Act applies to you. Last reviewed 21 September 2026.