Call us on:   9289301161/+91 11 49074103   or   email us on   contact@pietos.com

BGV Data Retention Under DPDP in India: Keep, Delete, Prove

Pietos infographic explaining BGV data retention under the DPDP framework in India, featuring data protection, consent management, secure data erasure, and compliant background verification.

BGV data retention under DPDP in India is the question most HR teams skip. You collect consent, run the checks and file the report. Then the report sits in a shared drive for years. Nobody decides when it should go. That gap is now a legal risk.

India’s Digital Personal Data Protection Act, 2023 (DPDP Act) tells you to erase personal data once its purpose ends. So how long can you keep a background verification report? In short, this guide answers that for two groups: rejected candidates and ex-employees. As a result, you will get a retention schedule, an erasure workflow and an audit checklist. Use them to build a defensible BGV data retention policy before the main obligations start in May 2027.

Key Takeaways on BGV Data Retention Under DPDP

  • The DPDP Act does not set one fixed number of years for BGV reports. It sets a test: keep data only while the purpose lasts or a law requires it.
  • The three-year cap in the Third Schedule covers large e-commerce, gaming and social media platforms. It does not cover employers or BGV vendors.
  • BGV data retention for rejected candidates needs a short window. Ex-employees need a longer, law-backed one.
  • You must be able to show why you kept each record. A written schedule is your best proof.
  • Your BGV vendor is a data processor. Your contract must cover deletion, not only collection.

Not sure your current BGV data would pass a DPDP audit? Talk to Pietos about a retention and erasure review and get a plain-language gap list in one call.


What BGV Data Retention Means Under DPDP in India

BGV data retention is the rule set that decides how long you hold background verification data. It covers the candidate’s consent record, identity documents, education and employment proofs, court or address findings, and the final report.

Each item counts as personal data. Therefore, the DPDP Act treats all of it the same way. First, your company is the data fiduciary. Second, the candidate or employee is the data principal. Third, your BGV vendor is the data processor.

This split matters for retention. Because you act as the fiduciary, you decide the purpose and the period. Meanwhile, the vendor follows your instructions. However, the law still holds you accountable for what the vendor does. Pietos explains this fiduciary-processor structure in its guide on how the DPDP Act and AI are rewriting Indian background verification.

BGV Data Retention Versus Storage

BGV data retention is also different from storage. For example, storage asks where the data sits. In contrast, BGV data retention asks how long it sits there and why. A locked, encrypted file that you should have deleted last year is still a violation.

Three questions define every BGV record:

  1. What purpose did we collect this for?
  2. Has that purpose ended?
  3. Does another law force us to keep it?

If you cannot answer all three, you cannot defend the record. Therefore, the rest of this guide helps you answer them.


Why Consent Alone Cannot Cover BGV Data Retention

Most BGV content stops at consent. That is understandable. Consent is the visible front door of the DPDP Act. First, you need a clear, standalone notice. Next, state which checks you will run. Finally, offer a way for the person to withdraw.

Still, consent is only the start of the data life cycle. Once the check ends, three risks appear.

  • Stale data. The candidate you rejected in 2024 still has an Aadhaar copy in your inbox.
  • Silent copies. Recruiters forward reports on email and WhatsApp. Those copies escape every policy.
  • Vendor drift. Your BGV vendor keeps the raw files “for quality purposes” with no end date.

Clearly, each risk breaks the storage limitation principle. In fact, the law expects you to hold data only as long as you need it. Moreover, a data breach makes the problem worse. As a result, a leak of old data you had no reason to keep looks like negligence, not bad luck.

A Real-World Example of Old BGV Data Piling Up

Consider a common case. A firm screens 400 candidates a month and hires 120. Meanwhile, the other 280 people never join. After two years, the firm still holds documents for roughly 6,700 people who have no relationship with the company. As a result, that is a large liability with no business value.

The DPDP Act also lets people ask for erasure. Also, rejected candidates are more likely to ask than employees. After all, they have no ongoing tie to you. They also know their rights better each year. So without a retention schedule, you cannot answer that request fast.


What the Law Says About BGV Report Retention

Three parts of the DPDP framework shape BGV data retention in practice. They are Section 8(7) of the Act, Rule 8 of the DPDP Rules, 2025, and the Third Schedule.

Section 8(7): The Core Erasure Duty for BGV Data Retention

Section 8(7) is the backbone. It says a data fiduciary must erase personal data in two situations. The first is when the person withdraws consent. Second, erasure applies when it is reasonable to assume the purpose no longer applies. Whichever comes first triggers erasure.

However, there is one exception. You may keep the data if a law requires you to. Still, that exception is narrow. “We might need it someday” does not qualify.

The fiduciary must also make sure its processors erase the data. Therefore, your vendor contract needs a deletion clause.

Rule 8: Time Periods for BGV Data Retention

Rule 8 of the DPDP Rules, 2025 turns the principle into time limits for certain classes of fiduciaries. According to ILF’s summary of Rule 8 and the Third Schedule, the fiduciary must erase data when the purpose no longer applies or consent is withdrawn, unless a law requires retention.

In addition, the same summary notes a 48-hour warning. The fiduciary must tell the person at least 48 hours before it erases their data.

The Third Schedule: Who It Actually Covers

The Third Schedule sets a three-year cap. It counts from the date the person last approached the fiduciary for the specified purpose, or from the date the Rules start, whichever is later. It applies to large e-commerce entities, online gaming intermediaries and social media intermediaries that meet set user thresholds.

However, employers and BGV firms do not appear on that list. Read the next section carefully, because many blogs get this wrong.


Does the Three-Year Cap Apply to BGV Data Retention?

No. The three-year cap in the Third Schedule does not apply to a typical employer or BGV vendor. So do not treat “three years” as a safe harbour for background check data.

This creates a real problem. No rule says “keep BGV reports for X years.” Instead, the general test applies. Keep the data while the purpose continues. Then delete it when the purpose ends. Hold it longer only if another law says so.

That test is flexible. However, flexibility puts the burden on you. Instead, you must decide the period, write it down and defend it. In effect, the DPDP Act asks for a reasoned retention schedule, not a magic number.

How to Set Your Own BGV Data Retention Period

Here is a simple way to think about it:

SituationWhat decides the period
Candidate rejected, no disputePurpose ended at the hiring decision
Candidate hiredPurpose continues through employment
Employee exitsPurpose ends, but labour, tax and limitation rules may extend it
Dispute or legal claim pendingLegal hold overrides normal deletion
Vendor holds a copyYour instructions decide, not the vendor’s habits

Note the last row. Therefore, your vendor cannot set its own retention rule for your candidates’ data. You set it. Then the vendor executes it.

Security Logs Differ From Candidate Documents

One more point. Data breach and security rules sit alongside this. The Rules also ask for certain processing logs and related data to stay for a minimum period, so you can investigate security incidents. So treat those logs differently from the candidate’s documents. For example, you can erase the identity documents and still keep a minimal, secure audit log. Read the final Rules text on the MeitY website to confirm the exact log requirements for your case.


The DPDP Timeline for BGV Data Retention: Now and in 2027

Timing affects how fast you must act on BGV data retention. First, the government notified the DPDP Rules in November 2025. According to the PIB press release on the DPDP Rules, the Rules give organisations an eighteen-month period for phased compliance. The PIB explainer PDF repeats this phased approach.

In practice, three stages matter:

  1. November 2025. The Data Protection Board framework began.
  2. November 2026. The consent manager framework starts.
  3. Mid-May 2027. Most substantive duties apply, including retention and erasure.

Some sources quote 13 May 2027 and others quote 14 May 2027. Therefore, plan for the earlier date. Also watch for news of a shorter timeline.

Why Starting Your BGV Data Retention Project Early Pays Off

This gives you a window of about seven months from today. Still, that is not long. In practice, a proper retention project needs data mapping, policy drafting, vendor renegotiation and system changes. In fact, most teams need three to six months.

Start now for a second reason. Also, cleaning up old data takes time. If you hold years of BGV files, you will need a deletion sprint. Moreover, doing that in a rush, right before a deadline, invites mistakes.

Penalties add urgency. The DPDP framework allows fines up to ₹250 crore for failing to maintain reasonable security safeguards. In addition, unnecessary old data expands the damage of any breach. Therefore, deletion is a security control as well as a privacy duty.

Pietos tracks this phased timeline in its DigiLocker background verification 2026 HR guide, which covers the roll-out through May 2027. Read it if your identity checks rely on DigiLocker.


BGV Data Retention for Rejected Candidates

Rejected candidates are the largest and riskiest group in BGV data retention. First, they have no contract with you. Also, they are not employees. In many cases, they may never think about you again. Yet you may hold their most sensitive documents.

When the Purpose Ends for a Rejected Candidate

The purpose of a pre-employment check is to help you decide on a hire. Once you decide not to hire, the purpose has ended. In fact, that is the plainest reading of Section 8(7).

However, real hiring is messy. You may want to keep a rejected candidate for another role. Or you may face a complaint about an unfair rejection. Sometimes you may need to explain the decision to a client.

So the clean answer is short but not zero. Most firms should keep the full documents for a brief, defined window after the decision. Then they should delete them.

A Practical Window for Rejected Candidate Data

The law gives no exact number. However, many compliance teams use a window of 30 to 90 days. It covers three needs:

  • Dispute time. The candidate may challenge an adverse finding.
  • Correction time. The candidate may ask you to fix an error in the report.
  • Audit time. A client may ask why you rejected someone.

After the window, delete the raw documents and the full report. Then keep a thin record. For example, that record can include the candidate ID, the date, the check types run and the decision. However, it should not include Aadhaar copies, address proofs or court details.

Treat this as a starting point. Finally, your legal counsel should confirm it against your sector rules.

What About Candidates Who Withdraw?

Some candidates pull out mid-process. They may also withdraw consent. In that case, Section 8(7) points to erasure as soon as consent ends, unless a law requires otherwise.

Therefore, stop pending checks at once. Also tell your vendor to stop. Then delete the collected data on a short timeline. A window of about 30 days is common.

Do Not Reuse Rejected Data Without Fresh Consent

Talent pools are tempting. However, recruiters like to re-open old candidates. However, the original consent covered one hiring decision. Therefore, reusing the data for a new role is a new purpose. Therefore, that needs new consent.

If you want a talent pool, ask for separate, opt-in consent. Also, keep it apart from the BGV file. Finally, do not use background documents to fill it.


BGV Data Retention for Ex-Employees

Ex-employees sit in a different category for BGV data retention. They worked for you. Many laws touch their records. Therefore, you cannot apply the same short window.

Why Ex-Employee Records Last Longer

Employment creates legal duties that outlive the job. For instance, payroll, provident fund, gratuity, tax and labour records all follow their own retention rules. Also, disputes over dues, conduct or non-compete terms can arrive years later.

Meanwhile, the DPDP Act respects other laws. Section 8(7) lets you keep data when another law requires it. So the BGV report may stay in the personnel file for a period that other rules justify.

The DPDP Act also recognises employment as a lawful ground for processing in some cases. Section 7 lists certain legitimate uses, including purposes related to employment and safeguarding the employer from loss or liability. That helps for current staff. However, it does not give you a blank cheque. You still need a purpose, and the purpose still ends.

Limit What You Keep After Exit: BGV Data Retention Layers

Long retention does not mean full retention. Instead, split the file into layers.

  1. Core record. Keep the verification outcome, dates, the vendor name and the clearance status. These support audits and disputes.
  2. Supporting proof. Keep education and employment proofs only as long as your policy and any law justify.
  3. Sensitive originals. Delete identity document copies early. Aadhaar numbers and photos carry the highest risk and the lowest ongoing value.

Pietos explains why you should avoid storing raw Aadhaar in its guide to Aadhaar verification for employment. Instead, the safer model is authentication, not storage. HR gets a match or no-match result and never holds the number.

A Typical Post-Exit Window

Many firms keep the core record and key proofs for about three years after exit. They pick that number because civil claims commonly follow a three-year limitation period in India. However, some sectors and some records need longer. For example, banks, NBFCs, insurers and regulated staffing firms often face extra rules.

Again, treat three years as a discussion point, not legal advice. Ask your counsel to confirm the right period for each record type.

Alumni and Re-Hire Data in BGV Data Retention

Some firms rehire former staff. Keeping the full old BGV report “in case” is tempting. Resist that. Instead, run a fresh check at re-hire. Old data goes stale, while fresh checks are more accurate and better justified.


Want a retention schedule built for your sector? Ask Pietos for a DPDP-ready retention template covering candidates, employees and vendors.


A Sample BGV Data Retention Schedule You Can Adapt

Use this table as a draft. So your counsel must confirm each period. The figures below are suggested starting points, not statutory limits.

Record typeSuggested retentionWhy
Consent record and notice versionLife of the record plus the audit windowProves lawful collection
Rejected candidate: identity documentsDelete 30–90 days after decisionPurpose ended
Rejected candidate: full reportDelete 30–90 days after decisionPurpose ended, dispute window closed
Rejected candidate: thin audit record1–3 yearsDefends the decision
Withdrawn candidate: all dataDelete within about 30 daysConsent withdrawn
Employee: verification reportThrough employmentPurpose continues
Ex-employee: core recordAbout 3 years after exit, or longer if a law requiresLimitation and labour rules
Ex-employee: identity copiesDelete soon after onboarding or exitHighest risk, lowest value
Records under legal holdUntil the matter closesLegal duty
Security and access logsMinimum period the Rules setBreach investigation

Two Rules That Make the Retention Schedule Work

Two rules make this table work.

First, every row needs an owner. HR, legal or IT must own each deletion. Second, every row needs a trigger. A trigger is an event like “decision date” or “exit date.” Systems can then calculate deletion dates on their own.


How to Handle an Erasure Request From a Candidate or Ex-Employee

The DPDP Act gives data principals the right to ask for erasure. Your process must be quick, clear and provable. Follow these six steps.

  1. Log the request. Record the date, the person and the scope. Use one intake channel, such as a dedicated email or portal.
  2. Verify identity. Confirm the requester is the data principal. Do this before you share or delete anything.
  3. Check for a legal reason to keep the data. Look at labour, tax, audit and dispute needs. If a law requires retention, keep only what it requires.
  4. Check for a legal hold. If a claim is live, pause deletion and tell the person why.
  5. Delete across all systems. Cover the HRMS, ATS, email, shared drives, backups and the BGV vendor.
  6. Confirm in writing. Tell the person what you erased and what you kept. Give the legal reason for anything you kept.

Speed matters. In fact, the DPDP framework expects grievance handling within a defined time. Sources on the Rules mention a maximum of 90 days for grievance resolution. So aim to finish well inside that limit.

Backups and Email: The Two Hardest Systems

Backups deserve a special note. Deleting live data while old backups keep it is a common gap. Instead, set a backup rotation that expires old copies on a fixed cycle. Then document that cycle.

Email is the hardest system. For example, recruiters forward reports, and inboxes hold attachments for years. So ban email as a storage channel for BGV reports. Give recruiters a secure portal link instead. Links expire, but attachments do not.


Legal Holds and Conflicting Laws in BGV Data Retention

Deletion has one big exception: a legal duty to keep. In fact, this is where many firms freeze. They fear deleting anything. As a result, they keep everything. However, that is the wrong answer.

A legal hold is specific. Instead, it applies to named people, a named matter and a named period. It does not apply to your whole database. When a hold starts, the legal team should issue a written notice. When the matter closes, the hold should end in writing. Then normal deletion resumes.

When Two Laws Conflict on BGV Data Retention

You may face conflicts between laws. For example, a labour rule may ask you to keep a record while an ex-employee asks for erasure. In that case, the DPDP Act itself points to the other law. You keep what the law requires. Then you delete the rest.

Document each conflict. Then write down three things:

  • The record you kept
  • Which law required it
  • Your planned deletion date

That note is your proof if a regulator asks.

Sector Rules to Map First

In addition, sector rules add layers. For example, NBFCs answer to RBI expectations. Insurers answer to IRDAI. Security agencies answer to PSARA. Contract labour firms answer to labour codes. If you work in a regulated sector, map those rules first. Pietos covers several of these angles in its gig worker background verification guide, which notes that a compliant process applies a defined retention window rather than holding worker data forever.


Vendor Duties in BGV Data Retention and Erasure

Your vendor holds a copy of your candidates’ data. Therefore, your BGV data retention policy is only as strong as the vendor’s deletion. However, many contracts say a lot about collection and almost nothing about deletion.

Review your vendor agreement for these clauses:

  • Processing only on your instruction. The vendor may not reuse your candidate data for its own products.
  • Retention period. The contract names the exact period, or it links deletion to your instruction.
  • Deletion on request. Deletion follows within a set number of days after you ask.
  • Deletion certificate. You receive written confirmation of deletion.
  • Sub-processor control. The vendor tells you which sub-processors hold data and applies the same rules to them.
  • Breach notice. You get an alert fast when something goes wrong.
  • Return or destroy at exit. The vendor returns or destroys all data when the contract ends.

Five Questions to Ask Your Vendor About BGV Data Retention

Ask your vendor these five direct questions:

  1. Can your platform run automatic purge cycles by client rule?
  2. Can you delete one candidate’s data on a single instruction?
  3. Do you keep any copy after deletion, including backups?
  4. Do you give a deletion certificate or log?
  5. Where does the data sit, and who can access it?

Pietos describes purge cycles and consent controls in its overview of instant verification capabilities. Its platform also lets HR teams set automated purge cycles and redact sensitive data after the hiring decision is logged.

Bias also enters here. Also, collecting too much data raises fairness risk. Pietos discusses this link between purpose limitation and fair screening in its post on bias-free background verification under the DPDP Act. In short, retention discipline and DEI goals support each other.


The Cost of Ignoring BGV Data Retention

Inaction feels cheap, but it is not. Poor BGV data retention costs money in four ways.

Higher breach impact. Old data enlarges a breach. In fact, every extra record adds to the notification list, the legal bill and the reputational damage. For example, a firm that deleted rejected candidates’ files after 90 days has a much smaller breach.

Regulatory exposure. The DPDP framework allows penalties up to ₹250 crore for security safeguard failures. Also, fines apply per violation and can stack. Excess data also weakens your defence.

Client and audit friction. Enterprise clients now ask vendors for DPDP evidence. As a result, a firm with no retention schedule loses deals or faces long questionnaires. In fact, BGV audits often fail on missing evidence, not missing checks.

Operational drag. Large stores of old data slow searches, raise storage costs and confuse teams. As a result, nobody knows which file is the truth.

Benefits of Fixing BGV Data Retention

Now consider the benefits of fixing this:

  • Lower breach and fine exposure
  • Faster response to erasure requests
  • Cleaner audits and client reviews
  • Stronger candidate trust
  • Lower storage and admin cost

Trust is the quiet gain. Candidates notice when you handle their data with care. A visible, plain-language retention promise sets you apart from rivals who say nothing.


Common Objections to BGV Data Retention Limits

Teams raise the same worries again and again. Here are honest answers.

“What if we need the report later?” Keep a thin record, because it proves you ran the check and shows the outcome. Also, you rarely need the full identity documents again.

“Deleting data will hurt our defence in a dispute.” Retention for a live or likely dispute is lawful, but a blanket hold on everything is not. Use targeted holds instead.

“Our vendor already stores it securely.” Security does not replace retention. Secure but unnecessary data still breaks the storage limitation principle. Also, you stay accountable for the vendor.

“The rules are not in force yet.” The main duties start in mid-May 2027. Cleanup, vendor changes and system work take months, so waiting leaves you exposed.

“We do not know what the final Rules require.” The Rules are already notified. Read the final text on the MeitY website. Instead, build your policy on the purpose test, which is stable, and adjust the details as guidance arrives.

“This is too costly for a small team.” Start small, since a one-page schedule, a quarterly deletion run and a vendor clause cost far less than a breach.


A 90-Day Plan to Fix BGV Data Retention

You do not need a giant project. Use three sprints.

Days 1–30: Map and Decide

  • List every place BGV data lives. Include the HRMS, ATS, email, drives, phones and vendor portals.
  • List every data type you collect for each check.
  • Decide the purpose for each data type.
  • Draft the retention schedule with legal counsel.
  • Name an owner for each row.

Days 31–60: Build and Contract

  • Turn the schedule into rules in your systems.
  • Add expiry to portal links.
  • Amend vendor contracts with deletion and certificate clauses.
  • Write an erasure request procedure.
  • Train recruiters to stop emailing reports.

Days 61–90: Clean and Prove

  • Run a first deletion sprint on old rejected candidate data.
  • Test one erasure request end to end.
  • Ask your vendor for a deletion certificate.
  • Record all actions in a compliance log.
  • Schedule a quarterly review.

By day 90, you have a written policy, working controls and evidence. In short, that is what auditors and regulators want to see.


BGV Data Retention Audit Checklist

Use this list every quarter. Answer yes or no.

  1. Do we have a written BGV retention schedule?
  2. Does each record type have an owner and a trigger?
  3. Do we delete rejected candidate data within our set window?
  4. Is only a thin record left after deletion?
  5. Do we avoid storing raw Aadhaar copies?
  6. Can we process an erasure request within the limit?
  7. Do we cover backups and email in deletion?
  8. Does our vendor contract cover deletion and certificates?
  9. Do we log every legal hold and every release?
  10. Can we show proof of each deletion run?

Score yourself. If you give fewer than seven yes answers, you have real gaps. Then fix the items you missed first.


Work With a BGV Partner That Builds BGV Data Retention Into the Process

BGV data retention works best when the platform enforces it. Manual reminders fail. In contrast, automated purge cycles, consent dashboards and candidate portals make compliance routine.

Pietos runs background verification for NBFCs, startups and GCC setups across India. Its hybrid model combines digital checks with physical field verification in tier 2 and tier 3 cities. It builds consent, retention and erasure controls into the workflow, so your HR team does not carry the burden alone.

Ready to close the retention gap? Book a DPDP-compliant BGV review with Pietos. Also, you will get a clear map of your data, a draft retention schedule and a vendor checklist. No obligation.

Frequently Asked Questions

How long can you keep a BGV report under DPDP?

The DPDP Act sets no single period for BGV reports. You may keep a report while its purpose lasts, or longer if another law requires it. For rejected candidates, that often means a short window after the decision. For ex-employees, it can extend through the limitation and labour-record period.

Does the three-year retention cap apply to background verification?


No. The Third Schedule cap applies to large e-commerce, online gaming and social media entities that meet set user thresholds. Employers and BGV vendors need their own reasoned schedule.

When must you delete a rejected candidate’s data?

Delete it once the hiring purpose ends and any dispute window closes. Many firms use a window of 30 to 90 days. Withdrawn candidates should see faster deletion. Ask your counsel to confirm the period for your sector.

Can a candidate ask you to delete their BGV data?

Yes. The DPDP Act gives data principals the right to seek erasure. You must delete unless a law requires you to keep the data. Tell the person what you erased and what you kept.

Do ex-employees have the right to erasure of BGV records?

They can ask. However, labour, tax and limitation rules may require you to keep some records. Keep only what the law needs and delete the rest.

Is the BGV vendor responsible for deleting data?

The vendor processes data on your instruction. You stay accountable as the data fiduciary. Your contract should require deletion on request and a written confirmation.

Should you store Aadhaar copies after verification?

No. Use authentication or masked tokens where you can. If you must hold a copy, delete it as early as possible. Read Pietos’ guide to Aadhaar verification for employment for the safer model.

When do the main DPDP retention rules start?

Most substantive duties start in mid-May 2027, after the eighteen-month phase-in. The Data Protection Board framework is already in place. Start your retention project now.

What is a legal hold?

A legal hold pauses deletion for records tied to a live or likely dispute. It applies to named records and a named matter. Lift it in writing when the matter ends.

What should a BGV retention policy include?

Include the record types, the purpose, the retention period, the trigger, the owner and the deletion method. Add rules for holds, erasure requests, backups and vendors.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top