Legacy Data: The DPDP Bottleneck Nobody Budgeted For
Data collected before the DPDP Act isn't grandfathered in. Why legacy data is the compliance bottleneck of 2026–27 — and how to clean it up.

Sanchay Retail is a mid-sized Indian fashion-and-lifestyle chain — the kind with a flagship store in every metro mall, a loyalty card half the neighbourhood still carries, and a website that's been quietly taking orders since the early days of Indian e-commerce. It's been operating since 2014, has accumulated roughly 60 million customer profiles across three platform generations, two acquired loyalty programs, and a mobile app sunset in 2020 whose database was never formally decommissioned. Marketing still pulls from parts of this data for win-back campaigns. Nobody currently at the company can say with certainty which of those 60 million records were collected on explicit consent, which came from an old partner integration, or which belong to users who unsubscribed years ago but were never actually deleted.
This is the real DPDP problem for 2026–27. Everyone's been racing to fix the front door with consent banners, plain-language notices and cookie preferences. Meanwhile, years of unmapped data sit quietly in the CRM, the warehouse, and backups nobody's opened.
Why "old data" isn't a free pass
There's a comforting myth going around compliance circles: that data collected before the DPDP Act existed is somehow grandfathered in as safe, exempt, someone else's problem. It isn't.
The DPDP Act's obligations attach to personal data that is processed digitally, regardless of when it was originally collected. If your organisation is still using that data today — to send a marketing email, score a credit risk, personalise a recommendation — it falls squarely inside the law's reach right now, not from some future date.
What the law does offer is a bridge, not an exemption. Under Section 5(2) of the Act, any organisation that collected personal data before the Act came into force, and is still processing it, must send a one-time retrospective notice to those individuals. That notice has to tell people what data is held, why it was collected, and how they can withdraw consent or ask for deletion. Helpfully, if the original collection was on a valid consent basis, you don't need to go back and re-collect consent from scratch — but you do need to be transparent, in the newly mandated plain-language, multi-lingual format, about data you've been sitting on for years.
That single requirement — sending a notice for everything you've ever collected and still use — is where the scale of the problem starts to show.
The numbers that matter
- Retention limits are now the default. The Third Schedule sets default retention limits: e-commerce and social media platforms with 2 crore-plus users, and gaming platforms with 50 lakh-plus users, must erase data three years after a user's last login or transaction. For companies that have never systematically deleted anything, that's a full engineering project.
- Erasure has a deadline. Under Rule 14, erasure requests must be actioned within 90 days across every processor holding a copy, not just the primary database.
- The penalties are steep. Security-safeguard failures can draw penalties up to ₹250 crore; breach-notification or children's-data failures up to ₹200 crore, potentially per instance.
- The clock is already running. November 2025 marked the Rules' notification; November 2026 is expected to end the Board's "soft enforcement" phase. The first enforcement actions already happened in Q1 2026, against apps with inadequate consent and retention practices.
For Sanchay, that means: mapping every record across live systems, backups, and that old app database; identifying which data still has a legitimate purpose; sending retrospective notices; building deletion pipelines that actually reach three-year-old dormant accounts; and being ready to erase any record within 90 days — including from systems nobody currently owns.

Legacy clean-up keeps losing internal budget fights because it has no natural owner — it sits between IT, legal, and whoever inherited the old system. But regulators investigate the data you actually hold, not just what's collected under the new consent flow. And ungoverned legacy data is statistically the most likely source of the next breach, not the least.
Getting DPDP-ready?
Our compliance specialists can walk you through consent, cookies, and audit readiness for your stack.
.png)