← All field notes
DPDP · 7 minute read

By Securelay Research

A soft delete is not an erasure workflow.

A deleted_at flag changes what an application displays. It does not, by itself, address copies in processors, replicas, exports, logs, backups, or vector stores. DPDP erasure therefore has to be run as an end-to-end operating workflow.

System map showing why soft deletion is not a complete DPDP erasure workflow.
Original Securelay editorial system map based on sections 8(7) and 12 of the Digital Personal Data Protection Act, 2023.
Primary source Digital Personal Data Protection Act, 2023 — official Gazette textPrimary source Digital Personal Data Protection Rules, 2025 — MeitY

Start with the correct provisions

Section 8(7) of the Digital Personal Data Protection Act, 2023 addresses erasure when consent is withdrawn or the specified purpose is no longer being served, subject to retention required by law. It also requires the Data Fiduciary to cause its Data Processor to erase personal data made available for processing. Section 12 covers a Data Principal’s right to correction and erasure. Section 8(5), by contrast, is the reasonable-security-safeguards obligation.

Map every copy before choosing the control

Build a field-level inventory across the primary application, replicas, analytics, support tools, AI retrieval stores, exports, processor systems, and recovery media. Record the purpose, owner, retention rule, legal hold, and deletion mechanism for each copy. An erasure ticket is not complete until every in-scope system has an accountable outcome.

Where tokenization and cryptographic erasure help

When an application stores opaque references while protected values remain inside a separate vault, fewer operational systems need plaintext. Erasing a subject’s protected records and destroying the associated cryptographic material can make the governed copy unreadable. This reduces the erasure surface, but only for values and routes that were actually integrated; derived data, unmanaged exports, processor copies, and lawful-retention exceptions still need explicit handling.

Keep evidence without turning it into a certification

A completed workflow should retain value-free evidence: request identity, affected scopes, responsible systems, outcomes, timestamps, hashes, and exceptions. Securelay receipts can show that configured erasure operations ran and entered the audit chain. They do not prove that every copy everywhere was deleted, and they do not replace legal review of retention obligations.

Put the control on the data path.Discuss an architecture review