What the DPDP Act 2023 Actually Requires When You Retire a Laptop

The Digital Personal Data Protection Act, 2023 requires organisations to erase personal data once the purpose for holding it is over. That obligation does not stop at your servers. It follows the personal data sitting on the laptops, desktops and drives you retire — which means disposal is now a data-protection activity, not a facilities one.
Practically: you need to be able to show that personal data on retired devices was destroyed, and that the person who destroyed it was under a written obligation to you.
Most Indian companies have spent the last two years working through DPDP compliance for their live systems — consent notices, privacy policies, breach reporting, data principal rights. Almost none have applied the same thinking to the equipment leaving the building.
That gap is not a technicality. Retired equipment is where personal data sits longest, gets watched least, and leaves your control most completely.
What actually changed in 2023
Before the DPDP Act, India's data protection regime for most private companies rested on Section 43A of the Information Technology Act, 2000 and the 2011 SPDI Rules. That framework was narrow. It applied to a defined list of “sensitive personal data” — passwords, financial information, health data, biometrics — and its enforcement mechanism was compensation to an affected person who could show wrongful loss.
The Digital Personal Data Protection Act, 2023 is a different structure. It applies to all digital personal data, not a sensitive subset. It creates a named accountable role — the Data Fiduciary, meaning the organisation that decides why and how personal data is processed. And it establishes a regulator, the Data Protection Board, with the power to impose financial penalties directly rather than waiting for an individual to bring a claim.
Three shifts matter for anyone responsible for IT assets:
- Scope widened. An employee's name and phone number on a retired laptop is personal data. Under the old rules, arguably not covered. Under DPDP, covered.
- Accountability became named. The Data Fiduciary is answerable for what happens to personal data, including data it no longer actively uses.
- Processors became your responsibility to bind. If a third party handles personal data on your behalf, the Act expects that relationship to sit under a contract.
The erasure obligation, in plain terms
The Act contains an erasure principle: once the purpose for which personal data was collected is no longer being served, and retention is not required by law, the data should be erased.
Read that against a laptop being retired from your finance team. The purpose it was collected for — running that person's work — is over. There is usually no legal retention requirement attached to the local copy specifically. So the personal data on that machine falls squarely inside the erasure principle.
Now the practical question: what does “erased” mean when the data lives on a physical drive that is leaving your building?
It cannot mean deleting files, because deleted files remain recoverable. It cannot mean reformatting, for the same reason. It has to mean either overwriting the media so the original content cannot be reconstructed, or destroying the media physically. Anything short of that leaves personal data intact on a device you no longer control — which is the definition of the risk the erasure principle exists to close.
| Action | What happens to the data | Defensible under an erasure obligation? |
|---|---|---|
| Delete files, empty recycle bin | File index entry removed. Data intact on disk. | No |
| Quick format / reinstall OS | Partition table rewritten. Most data recoverable. | No |
| Certified overwrite (software erasure) | Every addressable sector overwritten. Original content not reconstructable. | Yes, with a record |
| Degaussing (magnetic media only) | Magnetic domains destroyed. Drive permanently unusable. | Yes, for HDDs and tape |
| Physical shredding | Media reduced to fragments. | Yes, any media type |
| Sell to a scrap dealer as-is | Data leaves the building intact, in someone else's hands. | No |
The international reference vocabulary for this is NIST Special Publication 800-88, which separates outcomes into Clear, Purge and Destroy. It is worth knowing that language when you are comparing what different disposal vendors claim to do — a vendor who says “we wipe drives” without specifying which of those outcomes they achieve is telling you very little.
Why retired devices are the blind spot
Live systems get attention because they are visible. Someone owns the CRM. Someone owns the HR system. Access reviews happen. Backups get tested.
A retired laptop has no owner. It came off a desk, went into a cupboard, and stopped appearing in anyone's weekly workload. In most Indian offices that cupboard has been filling for years.
Three specific patterns produce the most exposure:
The storeroom accumulation. Equipment retired over five or eight years, sitting in a locked room, with no record of what is in there. Every one of those machines was retired under whatever the practice was at the time, which usually means no wipe and no documentation.
The loose drive drawer. Drives pulled out of decommissioned machines and set aside “just in case”. These have usually left every asset register, which means nobody is tracking them and nobody would notice one going missing.
The informal sale. A scrap buyer collects a batch, pays cash, and leaves. No wipe, no list, no record of where the equipment went. This is still the most common disposal route in India, and it produces a complete break in the chain at exactly the point where the data is most exposed.
What counts as evidence
Here is the part most organisations miss. Under an accountability-based regime, doing the right thing is only half of it. You also have to be able to show that you did.
If your disposal process is sound but leaves no paper, then in an audit, a client security review, or a regulatory query, your position is a verbal assurance. That is not a strong position.
What a defensible file looks like:
- A record of what left the premises — when, and to whom. In India this is also a statutory requirement under the E-Waste (Management) Rules, 2022, which expect bulk consumers to channel end-of-life electronics to an authorized recycler.
- A Certificate of Destruction stating what was destroyed, by which method, and on what date — issued after destruction, not at collection.
- A written agreement with the vendor covering data handling. Under DPDP, a party processing personal data on your behalf should be under contract, not under a handshake.
- Evidence the vendor is authorized — a current pollution control board authorization, and, where data destruction is in scope, an information security certification such as ISO/IEC 27001.
We wrote a separate guide on what a Certificate of Destruction should actually contain, because most of the ones we see would not survive a serious question.
A practical checklist
If you want to close this gap without turning it into a six-month project, work through these in order:
- Find out what you are holding. Walk the storerooms. Count roughly — laptops, desktops, servers, loose drives, tapes. Precision is not required at this stage.
- Stop the informal channel. Whatever route retired equipment currently takes out of the building, if it does not produce documentation, close it today. New exposure is cheaper to prevent than old exposure is to fix.
- Pick one authorized channel and put it in writing. One vendor, one contract, one document set.
- Clear the backlog in a single documented batch. This turns an open-ended risk into a dated event with paperwork attached.
- Write it into your data-retention policy. Most retention policies describe databases and say nothing about hardware. Add a line covering end-of-life devices, so the process survives the person who set it up.
- File the documents where an auditor can find them — alongside your other data protection records, not in the facilities folder.
None of this is expensive. The backlog clearance is usually free, because retired equipment carries recoverable value that covers the cost of collection. What it costs is a decision and an afternoon.
This guide is general information about Indian data protection and e-waste regulation, not legal advice. For how the DPDP Act applies to your specific organisation, consult a qualified advisor.


