A legal hold should identify the matter, relevant records, custodians and reason preservation is required. Assess any deletion request against that defined scope and applicable law. Preserve only what the hold justifies, restrict other use, review the hold periodically and resume the normal retention process when it ends.
The business situation
A former employee requests deletion of personal records while an employment dispute is anticipated. HR freezes the entire employee database indefinitely. The concern about evidence is legitimate; the uncontrolled scope and absence of review create a separate governance problem.
A privacy review begins with the processing activity: whose data is involved, who decides the purpose and means, and what each participant actually does. A Data Fiduciary and a Processor have different roles; the contract label is evidence, not the final answer. GDPR terminology should not be imported into an Indian assessment without checking the applicable statutory ground.
What needs examining
01. Write the reason for preservation
Identify the dispute, inquiry or legal requirement and explain the connection between it and each category of records. Separate a mandatory retention period from a litigation-preservation assessment. An undifferentiated instruction to keep everything is difficult to implement and harder to defend. The hold should have an owner and a clear route for clarification.
02. Control access and secondary use
Preservation does not authorise unrestricted reuse. Restrict the held data to the relevant matter and people, subject to applicable requirements. Consider segregation or controlled copies where that enables ordinary deletion elsewhere without damaging evidence. Record integrity, original metadata and chain of custody where these may matter to admissibility or reliability.
03. Make release part of the original design
A hold is incomplete without a review and release procedure. Reassess the matter's status, related proceedings and other applicable retention duties. Notify custodians and Processors of a release, then apply the proper retention schedule. Record the reasoning if part of the material remains subject to a separate duty.
Law, contract and recommended practice
DPDP Act, 2023: sections 4–8, 11–13 and 16, as relevant. The substantive duties discussed here form part of the phased commencement programme; distinguish readiness work from duties already in force. Existing IT, cybersecurity and sector-specific requirements need their own assessment.
Connect the control to the evidence
Use this table to scope the review. The legal basis and the practical control are identified separately.
| Obligation or objective | Practical control | Evidence to retain |
|---|---|---|
| Law, where applicable Preserve records required by law or proceedings | Scoped legal hold and deletion assessment | Matter rationale and covered-record inventory |
| Recommended practice Prevent unrelated reuse | Restricted access and segregated handling | Access approvals and activity logs |
| Recommended practice Avoid indefinite retention | Periodic review and documented release | Review dates and deletion completion record |
Records to prepare
Bring the complete, current record to the review. Preserve earlier versions where a change or disputed event makes them relevant.
Common questions
Does any threatened claim justify retaining all data?
No. Assess the credibility and scope of the issue, the records likely to be relevant and applicable preservation duties. The retention decision should be proportionate and reasoned, with periodic review.
Can ordinary deletion continue during a hold?
It may continue for records outside a properly defined hold, subject to other retention duties. The systems and custodians must be able to distinguish the populations reliably before deletion proceeds.
Connect every hold to a reason, a bounded record set and a release decision. That gives privacy, legal and IT teams a common basis for handling the request.
Legislation & official resources
These references identify the governing frameworks. Confirm the current text, relevant amendments and applicable judicial position for the matter.
- Digital Personal Data Protection frameworkMinistry of Electronics and Information Technology · Official framework resource. Apply the relevant Act, Rules and commencement notifications together.
- DPDP Act commencement notification: G.S.R. 843(E)MeitY · Gazette of India · Notification dated 13 November 2025. Different provisions commence in different phases.
This note is general information. The scenario is hypothetical and does not describe a client matter. The legal result depends on the facts, documents, jurisdiction and operative law. No individual lawyer review is represented by the preparation date.
Explore the AMLEGALS data privacy practice