Your loyalty database may be holding data you should have deleted long ago.
Imagine this. You ran a loyalty card scheme three years ago. Those customer phone numbers and purchase records are still sitting in your system. You forgot about them. But the law has not. Under the new data protection law, keeping old customer information without a reason is a problem. If something goes wrong, you could face a big fine. Does this sound like your shop or chain?
Say your store collected phone numbers for a Diwali sale two years ago. You never deleted them. That is a risk now. Or your support team saved return requests with Aadhaar copies. Those files are still on someone's laptop. That is also a risk. If a hacker steals this old data, you must report it fast. But who calls whom — your store manager or your head office? Decide this now. Write it down. Train your team before something goes wrong.
Find all old customer lists, loyalty records, and return logs in your system.
Write down who calls whom if customer data is ever leaked or stolen.
Check if your business is ready. Takes 3 minutes. Visit saralprivacy.com/assessment
“A retail database ages faster than most retailers think.”
Free — takes 3 minutes
Answer a few simple questions. Get your free Readiness Score — sent to your email or WhatsApp.
Check My Readiness →Take our free 3–5 minute industry assessment to find out your compliance risk level.
Take Free Assessment →Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Download the Guide →5 Ready-to-Use Templates
Start complying — not just reading
Privacy Notice, Consent Language, Data Inventory, DSR SOP, Vendor Register. Delivered free to your email.
2-min reads, plain English, every morning. Free forever.