That 2-year-old customer list in your laptop? It may be breaking the law.

You took 500 orders last Diwali. You still have every customer's name, phone number, and address saved. The food is gone. But their information is still sitting in your system. Under the new data law, keeping old customer information without a reason is not allowed. If someone hacks your system and steals that old data, you could face a fine of up to ₹50 crore. Does this apply to you? Yes — if you run a restaurant, cloud kitchen, or tiffin service.
Say you run a cloud kitchen on Swiggy or Zomato. You also take direct WhatsApp orders. You have saved customer names, phone numbers, and addresses in an Excel sheet. Some entries are two years old. Those customers never ordered again. Under the new law, you must delete that old data. Also, if your phone or laptop is stolen, you must have a plan ready. Who will you call first? What will you tell customers? You need to decide this before something goes wrong — not after.
Open your order list and delete contacts older than 12 months.
Write a simple plan: what to do if customer data is stolen.
Check if your business is ready. Takes 3 minutes. Visit saralprivacy.com/assessment
“Old order data is not harmless just because dinner is over.”
Free — takes 3 minutes
Answer a few simple questions. Get your free Readiness Score — sent to your email or WhatsApp.
Check My Readiness →Take our free 3–5 minute industry assessment to find out your compliance risk level.
Take Free Assessment →Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Download the Guide →5 Ready-to-Use Templates
Start complying — not just reading
Privacy Notice, Consent Language, Data Inventory, DSR SOP, Vendor Register. Delivered free to your email.
2-min reads, plain English, every morning. Free forever.