The direct answer

A legal hold should identify the matter, relevant records, custodians and reason preservation is required. Assess any deletion request against that defined scope and applicable law. Preserve only what the hold justifies, restrict other use, review the hold periodically and resume the normal retention process when it ends.

The business situation

An illustrative scenario

A former employee requests deletion of personal records while an employment dispute is anticipated. HR freezes the entire employee database indefinitely. The concern about evidence is legitimate; the uncontrolled scope and absence of review create a separate governance problem.

A privacy review begins with the processing activity: whose data is involved, who decides the purpose and means, and what each participant actually does. A Data Fiduciary and a Processor have different roles; the contract label is evidence, not the final answer. GDPR terminology should not be imported into an Indian assessment without checking the applicable statutory ground.

What needs examining

01. Write the reason for preservation

Identify the dispute, inquiry or legal requirement and explain the connection between it and each category of records. Separate a mandatory retention period from a litigation-preservation assessment. An undifferentiated instruction to keep everything is difficult to implement and harder to defend. The hold should have an owner and a clear route for clarification.

02. Control access and secondary use

Preservation does not authorise unrestricted reuse. Restrict the held data to the relevant matter and people, subject to applicable requirements. Consider segregation or controlled copies where that enables ordinary deletion elsewhere without damaging evidence. Record integrity, original metadata and chain of custody where these may matter to admissibility or reliability.

03. Make release part of the original design

A hold is incomplete without a review and release procedure. Reassess the matter's status, related proceedings and other applicable retention duties. Notify custodians and Processors of a release, then apply the proper retention schedule. Record the reasoning if part of the material remains subject to a separate duty.

Law, contract and recommended practice

DPDP Act, 2023: sections 4–8, 11–13 and 16, as relevant. The substantive duties discussed here form part of the phased commencement programme; distinguish readiness work from duties already in force. Existing IT, cybersecurity and sector-specific requirements need their own assessment.

Connect the control to the evidence

Use this table to scope the review. The legal basis and the practical control are identified separately.

Obligation or objectivePractical controlEvidence to retain
Law, where applicable
Preserve records required by law or proceedings
Scoped legal hold and deletion assessmentMatter rationale and covered-record inventory
Recommended practice
Prevent unrelated reuse
Restricted access and segregated handlingAccess approvals and activity logs
Recommended practice
Avoid indefinite retention
Periodic review and documented releaseReview dates and deletion completion record

Records to prepare

Bring the complete, current record to the review. Preserve earlier versions where a change or disputed event makes them relevant.

Retention schedule and statutory basis
Matter scope and custodian list
Deletion request and relevant correspondence
Hold notices, reviews and release record

Common questions

Does any threatened claim justify retaining all data?

No. Assess the credibility and scope of the issue, the records likely to be relevant and applicable preservation duties. The retention decision should be proportionate and reasoned, with periodic review.

Can ordinary deletion continue during a hold?

It may continue for records outside a properly defined hold, subject to other retention duties. The systems and custodians must be able to distinguish the populations reliably before deletion proceeds.

The next practical step

Connect every hold to a reason, a bounded record set and a release decision. That gives privacy, legal and IT teams a common basis for handling the request.

Legislation & official resources

These references identify the governing frameworks. Confirm the current text, relevant amendments and applicable judicial position for the matter.

This note is general information. The scenario is hypothetical and does not describe a client matter. The legal result depends on the facts, documents, jurisdiction and operative law. No individual lawyer review is represented by the preparation date.

Explore the AMLEGALS data privacy practice