DPDP Roles, explained simply

India's Digital Personal Data Protection Act. Who is who.

‹ Sector wise readiness

Sector wise readiness

Telecom and ISPs: retention pulls both ways

Does licence retention satisfy DPDP retention?
No, it is the opposite problem. DPDP does not ask you to retain; it asks you to erase when the purpose ends, while your licence and lawful interception duties ask you to keep. The reconciliation between them is what an auditor will want to see on paper.
Who this affects
Telecom operators and ISPs.
What to do about it
Document why you hold what you hold from day one, rather than waiting for a notification to start.

A misconception I keep seeing when telecom and ISP teams read DPDP checklists: "we already retain everything the licence requires, so DPDP retention is handled."

It is the opposite problem. DPDP does not ask you to retain. It asks you to erase when the purpose ends. Your licence and lawful interception duties ask you to keep. Those two pull in opposite directions, and the reconciliation between them is exactly what an auditor will want to see on paper.

What applies from the start, whatever your size

What telecom carries because of the data it holds

What may not apply yet, and stays separate

The better question

The better question is not "does telecom have to retain this?"

It is "for each dataset I keep, can I point to the specific law that requires it, and erase the rest?"

Law creates obligations. Scale and risk influence implementation. But the retention reconciliation is a day one discipline. You cannot wait for a notification to start documenting why you hold what you hold.

If you work in telecom, how clean is your dataset by dataset retention basis?

#DPDP #DataProtection #Telecom #ISP #Privacy #DataRetention

Get DPDP ready in hours, not weeks

Take the readiness assessment and generate your compliance documents from your answers.

Assess My Readiness