Video 07Erasure and breach

Retention and Erasure

Erase personal data when its purpose ends, across every system, with proof, shown through a telecom operator.

Duration 0:412 videos in this series

Videos in this series

View all
  1. Video 07Now playingRetention and ErasureDuration 0:41
  2. Video 08Personal Data Breach ResponseDuration 0:42

Description

Erase personal data when its purpose ends, across every system, with proof, shown through a telecom operator.

A customer closed her mobile connection years ago, and her data may still sit in several systems. The DPDP Act requires erasure once the purpose is served or consent is withdrawn, including by processors. The DPDP Rules add a 48 hour notice before erasure in specified cases and require logs to be kept for at least one year.

In TrustOS you define retention rules and review expiry conditions. Approved jobs erase or suppress data across connected systems, with exceptions and retries tracked, and each job records when and where it ran so completion is verified.

In this video

  • When erasure is required
  • 48 hour notice and one year log retention
  • Erasure jobs across connected systems
  • Exceptions, retries and verified completion

Put the DPDP Act into practice with TrustOS.

A scoped gap assessment shows where your organisation stands today and which controls to put in place first.