How long to keep client records in India
The short answer
No Indian law tells a psychotherapist how long to keep a clinical record. The three-year figure that circulates is a rule binding registered medical practitioners in respect of indoor patients. It does not reach a psychologist or a counsellor, and it is not about outpatient therapy.
Nor does the DPDP Act impose one. It requires you to erase when the purpose is served or consent is withdrawn, unless retention is necessary to comply with a law. So the real question is not “what is the required period”, it is “what period can I justify, and have I written down why”. Defensibility comes from having reasoned and disclosed, not from picking a number someone else used.
What actually applies to you, and what does not
| Instrument | Retention duty | Does it bind a therapist? |
|---|---|---|
| Medical council conduct regulations | Three years, indoor patients, from commencement of treatment | No, unless you are a registered medical practitioner, so a psychiatrist rather than a psychologist. And it is written about indoor patients, not outpatient therapy. This is the source of almost every wrong answer on this question. |
| Telemedicine Practice Guidelines 2020 | Records kept for “such period as prescribed from time to time” | Binds registered medical practitioners, and the period is left indeterminate in any case. |
| Mental Healthcare Act 2017 | No express retention period | Its confidentiality duties reach mental health professionals. But a “mental health establishment” is defined around people being admitted to and residing at it, so an outpatient-only practice most likely sits outside that registration regime. |
| EHR Standards for India | Preserve for the lifetime of the person, with records of the deceased made inactive after three years | A standard, in recommendatory language, not a statute. It also points in the opposite direction to data-protection minimisation, and nothing resolves that conflict. Relevant mainly if you join a national digital health programme. |
| Income-tax rules on books of account | Six years from the end of the relevant assessment year | The one clearly binding retention rule most practitioners have never connected to this question. It covers invoices, receipts and ledgers, which contain personal data. Whether psychotherapy counts as a profession for the stricter book-keeping rules is itself open, so confirm it with a chartered accountant. |
What the DPDP Act actually requires
The erasure duty, in the Act’s own words. Note the opening clause, because it is the one that does the work for a clinician:
(7) A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force, (a) erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier; and (b) cause its Data Processor to erase any personal data that was made available by the Data Fiduciary for processing to such Data Processor.
Digital Personal Data Protection Act 2023, section 8(7). Extracted from the Act as published by the Ministry of Electronics and Information Technology.
The Act then illustrates that very exception with a bank, and the illustration is worth reading because it is the shape of the argument a clinician makes too:
X, an individual, decides to close her savings account with Y, a bank. Y is required by law applicable to banks to maintain the record of the identity of its clients for a period of ten years beyond closing of accounts. Since retention is necessary for compliance with law, Y shall retain X’s personal data for the said period.
Illustration (II) to section 8(7) of the same Act
The difficulty for a therapist is immediate. The bank has a statute naming ten years. You do not have one. So the compliance-with-law limb helps you for your financial records and very little else, and you have to look elsewhere for the clinical file.
There is no automatic delete clock for your practice
This is widely misreported, so it is worth being precise. The Act says a purpose is deemed no longer served if the person does not come back to you or exercise their rights for such time period as may be prescribed. That prescription happened in the DPDP Rules 2025, and it is narrow:
(1) A Data Fiduciary, who is of such class and is processing personal data for such corresponding purposes as are specified in Third Schedule, shall erase such personal data, unless its retention is necessary for compliance with any law for the time being in force, or, for the corresponding time period specified in the Third Schedule, if the Data Principal neither approaches such Data Fiduciary for the performance of the specified purpose nor exercises her rights in relation to such processing.
DPDP Rules 2025, rule 8(1)
The Third Schedule names exactly three classes: an e-commerce entity with at least two crore registered users, an online gaming intermediary with at least fifty lakh, and a social media intermediary at a similar scale. A therapy practice is not any of them. So no period has been prescribed for you, and the three-year auto-erasure clock people cite does not apply to your records.
One correction worth making, because the wrong version is circulating. Rule 8(3) is often quoted as imposing a one-year minimum retention of personal data and processing logs on every Data Fiduciary. The actual gazette text ties that duty to “the purposes as specified in the Seventh Schedule”, and the Seventh Schedule is about State access to data. It is not a general one-year retention duty on a private practice, and you should not rely on it as a reason to keep anything.
When a client asks you to erase everything
The right to ask is real, and the answer is not a simple yes or no. The Act gives you two grounds to keep, and the second is wider than most summaries admit:
(3) A Data Principal shall make a request in such manner as may be prescribed to the Data Fiduciary for erasure of her personal data, and upon receipt of such a request, the Data Fiduciary shall erase her personal data unless retention of the same is necessary for the specified purpose or for compliance with any law for the time being in force.
Digital Personal Data Protection Act 2023, section 12(3)
Read that carefully. You may decline where retention is necessary for compliance with a law, or where it is necessary for the specified purpose. The specified purpose is the one you wrote in your own consent notice.
That gives you the single most useful drafting move available: put the retention period inside the specified purpose. A notice that says the purpose is “providing psychotherapy to you, including maintaining a clinical record for the period during which a claim relating to your care could be brought” makes the retention part of the purpose the client agreed to, rather than an exception you invoke against them afterwards.
There is a second, narrower ground:
17. (1) The provisions of Chapter II, except sub-sections (1) and (5) of section 8, and those of Chapter III and section 16 shall not apply where, (a) the processing of personal data is necessary for enforcing any legal right or claim;
Digital Personal Data Protection Act 2023, section 17(1)(a)
The shape of this is exactly right for a clinician: it switches off the erasure duty while leaving intact the obligation to keep the data secure. You may hold it, but you must guard it.
The honest caveat, and it is a real one: the Indian text says “enforcing” a legal right or claim, where the European equivalent says establishment, exercise or defence of legal claims. Whether keeping a record in order to defenda future complaint falls inside “enforcing” has not been decided by anyone. The better view is that it must, because the alternative requires a practitioner to destroy the only evidence of their own competence. But that is a reasoned prediction, not settled law, and you should treat it as such.
The clock that actually matters: how long can you be sued
Since no statute sets your retention period, the practical anchor is how long a claim can still be brought against you.
- Consumer protection: a complaint must generally be filed within two years of the cause of action, and that period can be extended for sufficient cause. This is the most commonly used route for claims against practitioners in India.
- Ordinary civil claims: a residuary limitation period of three years, running from when the right to sue accrues, which in a case of harm discovered late can be later than the last session.
- Clients you saw as minors, and this is the one people miss: where the person was a minor when the right accrued, time runs from when they reach majority. In practice a client seen at fifteen can bring a claim well into their early twenties.
- Professional council complaints generally carry no fixed limitation at all.
A retention schedule you could defend
This is an example with its reasoning shown, not a required period. Adopt it, adapt it or reject it, but be able to say why you chose what you chose.
| Record | Example period | The reason you would give |
|---|---|---|
| Clinical record, adult client | Three years from last contact | Tracks the ordinary civil limitation period, and comfortably covers the shorter consumer one. |
| Clinical record, client seen as a minor | Until the client reaches about twenty-one | Because limitation runs from majority, not from the last session. A uniform three-year rule silently fails here. |
| Anything touched by a live or threatened complaint, claim or proceeding | Until final resolution, then three years | Destroying records after notice of a claim is far worse for you than any retention question. This overrides everything else in the table. |
| Invoices, receipts, ledgers | Six years from the end of the relevant assessment year | Income-tax books of account. Keep these physically separate from clinical notes, so a tax rule never becomes a reason to hold a clinical file. |
| The signed consent and the version of the notice it refers to | As long as the record it authorised, plus a year | The Act puts the burden of proving notice and consent on you, so the proof must outlive the processing. |
| Session recordings | The shortest period you can justify | Separate opt-in consent, and disproportionate risk relative to their clinical value once the specific use has passed. |
| Marketing list, testimonials, newsletter | Delete on withdrawal, immediately | Pure consent processing with no retention justification at all. |
What to actually do when the request arrives
- Acknowledge in writing, quickly. Publish a response period and meet it. The Rules set a long stop, not a target.
- Delete immediately everything with no retention reason: marketing lists, newsletter subscriptions, testimonials, recordings, reminder integrations, anything not part of the clinical or financial record.
- Do not reflexively delete the clinical record. Move it to a closed archive: out of active use, access restricted, encrypted, every access logged.
- Write back and say exactly what happened: what has been deleted, what is retained, on what basis, and the date on which it will be destroyed. Naming the date turns a refusal into a commitment, and that is what makes it defensible.
- Instruct your processors in writing to do the same, and keep both the instruction and the confirmation. The Act requires you to cause them to erase, not merely to ask.
- Destroy on the stated date, and log the destruction: what, when, how, by whom. Keep only that log line.
- Suspend the whole schedule the moment any complaint, claim or proceeding is threatened. No exceptions.
The point of that sequence is that the client’s right is not defeated. It is honoured in part and deferred in part, with reasons and a date. A practitioner who does that has done what the Act asks.
What is genuinely unresolved
- Whether “enforcing any legal right or claim” covers defending one. No authority. The entire defensive-retention position rests on it.
- Whether the income-tax book-keeping rules treat psychotherapy as a profession, which decides whether the six-year period and the specified books apply to you. Ask a chartered accountant.
- Whether your State’s clinical establishment rules reach an outpatient psychology practice. This varies by State and the scoping language is contested.
- The conflict between the national EHR standard, which speaks of lifetime preservation, and data-protection minimisation. Nothing resolves it. Practices joining a national digital health programme inherit it directly.
- There is no regulator interpreting any of this yet. Everything above is a reading of published text, not settled practice.
Sources
The Act and Rules passages quoted above were read from the official published documents, not from a summary. Prefer the source over this page.
- Primary: Ministry of Electronics and Information Technology, data protection framework (the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025)
- Primary: Digital Personal Data Protection Act 2023 on India Code
- Primary: Mental Healthcare Act 2017
- Primary: EHR Standards for India
About this guide
We wrote this because the question gets answered badly almost everywhere, usually by quoting a medical council rule at people it does not bind. The statutory passages above were extracted from the official published Act and Rules rather than from a summary, which matters: a widely circulated version of one rule omits a clause and would have led this page to tell practitioners they had a retention duty they do not have.
We are not lawyers or chartered accountants, and we are not authorised to advise on Indian law or tax. We have not reviewed your practice. This is general information about the state of the law as at 1 September 2026, it is not an opinion or a recommendation, and it is not a substitute for advice from a qualified professional who has looked at your situation. If you act on anything here without taking advice, you do so at your own risk.
If you spot an error, write to collective@therapistandco.com and we will correct it and date the correction.
All guides · GST on therapy and counselling in India · Going from a solo practice to a group