Therapist & Co.
← All guidesLogin
Guide · Records

How long to keep client records in India

Last updated 1 September 2026
For guidance only. Take a retention decision with a lawyer, and the financial-records part with a chartered accountant. This is a research summary of published law, not legal advice. What is right for your practice depends on your registration, your State, who you see and what has been alleged, none of which we can see. Nothing here creates a professional relationship.

The short answer

No Indian law tells a psychotherapist how long to keep a clinical record. The three-year figure that circulates is a rule binding registered medical practitioners in respect of indoor patients. It does not reach a psychologist or a counsellor, and it is not about outpatient therapy.

Nor does the DPDP Act impose one. It requires you to erase when the purpose is served or consent is withdrawn, unless retention is necessary to comply with a law. So the real question is not “what is the required period”, it is “what period can I justify, and have I written down why”. Defensibility comes from having reasoned and disclosed, not from picking a number someone else used.

Guidance only. Retention sits at the intersection of data-protection law, limitation periods and professional duty. Set your schedule with a lawyer who can see your own practice rather than adopting the example below unexamined.

What actually applies to you, and what does not

InstrumentRetention dutyDoes it bind a therapist?
Medical council conduct regulationsThree years, indoor patients, from commencement of treatmentNo, unless you are a registered medical practitioner, so a psychiatrist rather than a psychologist. And it is written about indoor patients, not outpatient therapy. This is the source of almost every wrong answer on this question.
Telemedicine Practice Guidelines 2020Records kept for “such period as prescribed from time to time”Binds registered medical practitioners, and the period is left indeterminate in any case.
Mental Healthcare Act 2017No express retention periodIts confidentiality duties reach mental health professionals. But a “mental health establishment” is defined around people being admitted to and residing at it, so an outpatient-only practice most likely sits outside that registration regime.
EHR Standards for IndiaPreserve for the lifetime of the person, with records of the deceased made inactive after three yearsA standard, in recommendatory language, not a statute. It also points in the opposite direction to data-protection minimisation, and nothing resolves that conflict. Relevant mainly if you join a national digital health programme.
Income-tax rules on books of accountSix years from the end of the relevant assessment yearThe one clearly binding retention rule most practitioners have never connected to this question. It covers invoices, receipts and ledgers, which contain personal data. Whether psychotherapy counts as a profession for the stricter book-keeping rules is itself open, so confirm it with a chartered accountant.
Guidance only. Which of these reaches you depends on your registration and your State. A psychiatrist, an RCI-registered clinical psychologist and an unregistered counsellor are in three different positions here.

What the DPDP Act actually requires

The erasure duty, in the Act’s own words. Note the opening clause, because it is the one that does the work for a clinician:

(7) A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force, (a) erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier; and (b) cause its Data Processor to erase any personal data that was made available by the Data Fiduciary for processing to such Data Processor.

Digital Personal Data Protection Act 2023, section 8(7). Extracted from the Act as published by the Ministry of Electronics and Information Technology.

The Act then illustrates that very exception with a bank, and the illustration is worth reading because it is the shape of the argument a clinician makes too:

X, an individual, decides to close her savings account with Y, a bank. Y is required by law applicable to banks to maintain the record of the identity of its clients for a period of ten years beyond closing of accounts. Since retention is necessary for compliance with law, Y shall retain X’s personal data for the said period.

Illustration (II) to section 8(7) of the same Act

The difficulty for a therapist is immediate. The bank has a statute naming ten years. You do not have one. So the compliance-with-law limb helps you for your financial records and very little else, and you have to look elsewhere for the clinical file.

Guidance only. Do not read the bank illustration as permission to keep a clinical record indefinitely. It works because a specific law names a specific period.

There is no automatic delete clock for your practice

This is widely misreported, so it is worth being precise. The Act says a purpose is deemed no longer served if the person does not come back to you or exercise their rights for such time period as may be prescribed. That prescription happened in the DPDP Rules 2025, and it is narrow:

(1) A Data Fiduciary, who is of such class and is processing personal data for such corresponding purposes as are specified in Third Schedule, shall erase such personal data, unless its retention is necessary for compliance with any law for the time being in force, or, for the corresponding time period specified in the Third Schedule, if the Data Principal neither approaches such Data Fiduciary for the performance of the specified purpose nor exercises her rights in relation to such processing.

DPDP Rules 2025, rule 8(1)

The Third Schedule names exactly three classes: an e-commerce entity with at least two crore registered users, an online gaming intermediary with at least fifty lakh, and a social media intermediary at a similar scale. A therapy practice is not any of them. So no period has been prescribed for you, and the three-year auto-erasure clock people cite does not apply to your records.

One correction worth making, because the wrong version is circulating. Rule 8(3) is often quoted as imposing a one-year minimum retention of personal data and processing logs on every Data Fiduciary. The actual gazette text ties that duty to “the purposes as specified in the Seventh Schedule”, and the Seventh Schedule is about State access to data. It is not a general one-year retention duty on a private practice, and you should not rely on it as a reason to keep anything.

Guidance only. These rules commence eighteen months after the Rules were published in the Gazette, which falls in mid-May 2027. Confirm the exact date, and the current text, on the Ministry website before you act on timing.

When a client asks you to erase everything

The right to ask is real, and the answer is not a simple yes or no. The Act gives you two grounds to keep, and the second is wider than most summaries admit:

(3) A Data Principal shall make a request in such manner as may be prescribed to the Data Fiduciary for erasure of her personal data, and upon receipt of such a request, the Data Fiduciary shall erase her personal data unless retention of the same is necessary for the specified purpose or for compliance with any law for the time being in force.

Digital Personal Data Protection Act 2023, section 12(3)

Read that carefully. You may decline where retention is necessary for compliance with a law, or where it is necessary for the specified purpose. The specified purpose is the one you wrote in your own consent notice.

That gives you the single most useful drafting move available: put the retention period inside the specified purpose. A notice that says the purpose is “providing psychotherapy to you, including maintaining a clinical record for the period during which a claim relating to your care could be brought” makes the retention part of the purpose the client agreed to, rather than an exception you invoke against them afterwards.

There is a second, narrower ground:

17. (1) The provisions of Chapter II, except sub-sections (1) and (5) of section 8, and those of Chapter III and section 16 shall not apply where, (a) the processing of personal data is necessary for enforcing any legal right or claim;

Digital Personal Data Protection Act 2023, section 17(1)(a)

The shape of this is exactly right for a clinician: it switches off the erasure duty while leaving intact the obligation to keep the data secure. You may hold it, but you must guard it.

The honest caveat, and it is a real one: the Indian text says “enforcing” a legal right or claim, where the European equivalent says establishment, exercise or defence of legal claims. Whether keeping a record in order to defenda future complaint falls inside “enforcing” has not been decided by anyone. The better view is that it must, because the alternative requires a practitioner to destroy the only evidence of their own competence. But that is a reasoned prediction, not settled law, and you should treat it as such.

Guidance only. Whether a specific erasure request can be partly declined is a legal judgement about your facts. Take the first one you receive to a lawyer, and reuse the reasoning afterwards.

The clock that actually matters: how long can you be sued

Since no statute sets your retention period, the practical anchor is how long a claim can still be brought against you.

  • Consumer protection: a complaint must generally be filed within two years of the cause of action, and that period can be extended for sufficient cause. This is the most commonly used route for claims against practitioners in India.
  • Ordinary civil claims: a residuary limitation period of three years, running from when the right to sue accrues, which in a case of harm discovered late can be later than the last session.
  • Clients you saw as minors, and this is the one people miss: where the person was a minor when the right accrued, time runs from when they reach majority. In practice a client seen at fifteen can bring a claim well into their early twenties.
  • Professional council complaints generally carry no fixed limitation at all.

A retention schedule you could defend

This is an example with its reasoning shown, not a required period. Adopt it, adapt it or reject it, but be able to say why you chose what you chose.

RecordExample periodThe reason you would give
Clinical record, adult clientThree years from last contactTracks the ordinary civil limitation period, and comfortably covers the shorter consumer one.
Clinical record, client seen as a minorUntil the client reaches about twenty-oneBecause limitation runs from majority, not from the last session. A uniform three-year rule silently fails here.
Anything touched by a live or threatened complaint, claim or proceedingUntil final resolution, then three yearsDestroying records after notice of a claim is far worse for you than any retention question. This overrides everything else in the table.
Invoices, receipts, ledgersSix years from the end of the relevant assessment yearIncome-tax books of account. Keep these physically separate from clinical notes, so a tax rule never becomes a reason to hold a clinical file.
The signed consent and the version of the notice it refers toAs long as the record it authorised, plus a yearThe Act puts the burden of proving notice and consent on you, so the proof must outlive the processing.
Session recordingsThe shortest period you can justifySeparate opt-in consent, and disproportionate risk relative to their clinical value once the specific use has passed.
Marketing list, testimonials, newsletterDelete on withdrawal, immediatelyPure consent processing with no retention justification at all.
Guidance only. Periods in this table are illustrative and were chosen to track limitation risk. They are not a professional recommendation for your practice, and a lawyer may well set them differently for you.

What to actually do when the request arrives

  • Acknowledge in writing, quickly. Publish a response period and meet it. The Rules set a long stop, not a target.
  • Delete immediately everything with no retention reason: marketing lists, newsletter subscriptions, testimonials, recordings, reminder integrations, anything not part of the clinical or financial record.
  • Do not reflexively delete the clinical record. Move it to a closed archive: out of active use, access restricted, encrypted, every access logged.
  • Write back and say exactly what happened: what has been deleted, what is retained, on what basis, and the date on which it will be destroyed. Naming the date turns a refusal into a commitment, and that is what makes it defensible.
  • Instruct your processors in writing to do the same, and keep both the instruction and the confirmation. The Act requires you to cause them to erase, not merely to ask.
  • Destroy on the stated date, and log the destruction: what, when, how, by whom. Keep only that log line.
  • Suspend the whole schedule the moment any complaint, claim or proceeding is threatened. No exceptions.

The point of that sequence is that the client’s right is not defeated. It is honoured in part and deferred in part, with reasons and a date. A practitioner who does that has done what the Act asks.

What is genuinely unresolved

  • Whether “enforcing any legal right or claim” covers defending one. No authority. The entire defensive-retention position rests on it.
  • Whether the income-tax book-keeping rules treat psychotherapy as a profession, which decides whether the six-year period and the specified books apply to you. Ask a chartered accountant.
  • Whether your State’s clinical establishment rules reach an outpatient psychology practice. This varies by State and the scoping language is contested.
  • The conflict between the national EHR standard, which speaks of lifetime preservation, and data-protection minimisation. Nothing resolves it. Practices joining a national digital health programme inherit it directly.
  • There is no regulator interpreting any of this yet. Everything above is a reading of published text, not settled practice.

Sources

The Act and Rules passages quoted above were read from the official published documents, not from a summary. Prefer the source over this page.

  • Primary: Ministry of Electronics and Information Technology, data protection framework (the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025)
  • Primary: Digital Personal Data Protection Act 2023 on India Code
  • Primary: Mental Healthcare Act 2017
  • Primary: EHR Standards for India

About this guide

We wrote this because the question gets answered badly almost everywhere, usually by quoting a medical council rule at people it does not bind. The statutory passages above were extracted from the official published Act and Rules rather than from a summary, which matters: a widely circulated version of one rule omits a clause and would have led this page to tell practitioners they had a retention duty they do not have.

We are not lawyers or chartered accountants, and we are not authorised to advise on Indian law or tax. We have not reviewed your practice. This is general information about the state of the law as at 1 September 2026, it is not an opinion or a recommendation, and it is not a substitute for advice from a qualified professional who has looked at your situation. If you act on anything here without taking advice, you do so at your own risk.

If you spot an error, write to collective@therapistandco.com and we will correct it and date the correction.

All guides · GST on therapy and counselling in India · Going from a solo practice to a group

Therapist & Co.
GuidesPrivacyTermsLogin
© 2026 Therapist & Co. · Confidential