E-commerce Platform Retained Personal Data After Account Deletion – Legal Remedies Available

One of my clients recently had a case which I am explaining below and if you are stuck in such similar situation, here is what to do.

Note: Due to attorney-client privilege, I cannot disclose complete case details or identify the actual parties involved. However, I am sharing the essential facts and legal approach so that if you find yourself in a similar situation, you can understand the available solutions and legal remedies.

E-commerce Platform Retained Personal Data After Account Deletion - Legal Remedies Available

Mr.X, a resident of City A, deleted his account with X.brand e-commerce platform in DD/MM/YYYY after receiving confirmation that all personal data would be permanently erased. However, in DD/MM/YYYY, he discovered that X.brand had retained his personal information including order history, contact details, and payment information despite the deletion confirmation. When Mr.X attempted to contact customer service, he was informed that certain data was retained for “business purposes” without his explicit consent. This unauthorized data retention violated privacy policies and raised serious legal concerns about data protection compliance. Mr.X approached our office seeking legal remedies against this breach of privacy and violation of user agreement terms.

Advice in Such Cases

Consult with Lawyer: The very basic and important step to start is talk to Lawyer / advocate. You should not hesitate in paying his consultation fee i.e. might be in range of Rs. 10,000 to 50,000 depends case to case. He is helping you in this situation to come out. He is expert in the domain and can help you explain the procedure which you might have never explored. A good lawyer can get the issues resolved much faster than you think.

Document all communications with the platform including deletion requests, confirmation emails, and subsequent discoveries of data retention. Take screenshots of any personal data still accessible or visible. Send a formal legal notice demanding immediate data deletion and compensation for privacy violations. Consider filing complaints with relevant regulatory authorities for data protection violations.

Applicable Sections of Law

Under the Bharatiya Nyaya Sanhita (BNS), Section 318 deals with cheating and dishonest inducement, applicable when platforms make false promises about data deletion. Section 351 covers criminal intimidation if platforms threaten consequences for demanding data deletion. The Bharatiya Nagarik Suraksha Sanhita (BNSS) Section 173 provides procedures for filing complaints in such matters. Additionally, IT Act provisions regarding data protection, Consumer Protection Act for unfair trade practices, and contractual remedies under Indian Contract Act are applicable in such data retention violations.

If You Are the Complainant

  • Gather all evidence of account deletion requests and platform confirmations
  • Document instances where retained data was discovered or accessed
  • File formal complaints with cyber crime authorities in your jurisdiction
  • Send legal notices demanding compliance with privacy policies and data deletion
  • Approach consumer forums for compensation and directive compliance
E-commerce Platform Retained Personal Data After Account Deletion - Legal Remedies Available

If You Are the Victim

  • Immediately change all passwords and security credentials linked to the platform
  • Monitor your financial accounts for any unauthorized transactions or activities
  • File complaints with data protection authorities regarding privacy violations
  • Demand written confirmation of complete data deletion from the platform
  • Seek compensation for mental harassment and privacy breach through legal channels

How the Police Behave in Such Cases

Cyber crime police typically treat data retention violations seriously, especially when supported by documentary evidence. They usually register FIR under IT Act provisions and initiate technical investigations. However, they may initially suggest approaching consumer forums or attempting resolution through company grievance mechanisms. Police cooperation improves significantly when legal notices and formal complaints demonstrate clear privacy policy violations and potential financial fraud.

FAQs People Normally Have

Can I claim damages for unauthorized data retention? Yes, you can seek compensation through consumer forums and civil courts for privacy violations and mental harassment.

Is email confirmation of deletion legally binding? Yes, such confirmations create legal obligations under contract law and consumer protection regulations.

How long should companies retain data after deletion requests? Most privacy policies specify immediate deletion or within specified timeframes, typically 30-90 days maximum.

Can I approach multiple authorities simultaneously? Yes, you can file complaints with consumer forums, cyber crime authorities, and pursue civil remedies concurrently.

E-commerce Platform Retained Personal Data After Account Deletion - Legal Remedies Available

What Evidence Is Required?

  • Screenshots of account deletion confirmation emails
  • Evidence showing retained personal data after deletion
  • Platform’s privacy policy and user agreement documents
  • Email communications with customer service regarding the issue
  • Bank statements showing transactions if financial data was retained
  • Technical logs or proof of continued data access
  • Witness statements if others experienced similar violations

How Long Will the Investigation Take?

Cyber crime investigations typically take 3-6 months depending on technical complexity and platform cooperation. Consumer forum proceedings usually conclude within 6-12 months. Civil court cases may extend 1-3 years. However, interim relief and urgent directives for data deletion can be obtained within 2-4 weeks through appropriate legal channels and emergency applications.

Advocate Sudhir Rao, Supreme Court of India

Rate this post