DPDP Insights › All sectors › SaaS and digital platforms
Consumer platforms and SaaS products hold user accounts, behaviour data and content. Large social media and gaming platforms fall under the Third Schedule erasure rule.
Open the interactive tool for this sectorThis sector is in its core view. The law, guides and seat notes apply in full; the sector pack with role briefs and worked examples is being written.
| Rule | What it says | What it means alongside DPDP | Source |
|---|---|---|---|
| DPDP Rules, Third Schedule | Large e-commerce entities and social media platforms (2 crore or more registered users in India) and online gaming platforms (50 lakh or more) must erase data of users inactive for three years, with 48 hours' notice before erasure. | If you cross these thresholds, build the inactivity clock and the warning message. | MeitY |
| CERT-In Directions, 2022 | Report specified cyber incidents within six hours; keep ICT logs 180 days within India. | Applies alongside the DPDP breach steps. | CERT-In |