Consent, Purpose Limitation & Data Retention in Practice - Interview-Ready Framework
In 2022, IRCTC explored monetising passenger data and quickly faced a privacy backlash - not because data itself was useless, but because millions of people had shared it to book trains, not to become a marketing database. That is the whole topic in one scene: consent answers βmay we collect?β, purpose limitation answers βfor what exactly?β, and retention answers βfor how long?β
- Consent must be free, specific, informed, unambiguous, affirmative, and easy to withdraw.
- Purpose limitation means data collected for one stated purpose cannot quietly be reused for another incompatible purpose.
- Data retention means keeping personal data only as long as needed for the stated purpose or a legal obligation.
- In India, the Digital Personal Data Protection Act, 2023 makes the organisation a Data Fiduciary and the individual a Data Principal.
- The practical control is a data-purpose-retention map: every data field must have a purpose, legal basis, owner, and deletion rule.
- Strong privacy design is not βcollect less data onlyβ - it is collect the right data, use it transparently, and delete or anonymise it on schedule.
- The interview trap: treating consent as a one-time checkbox while ignoring purpose creep and indefinite storage.
The Big Picture
Think of privacy compliance as a pipeline, not a policy document. A business must translate a user-facing promise into back-end controls - notice, consent or legal basis, limited use, retention schedule, and deletion proof.
Core Explanation: The Three Controls That Make Privacy Practical
The concept becomes easy when you stop seeing consent, purpose limitation, and retention as legal jargon. They are three business controls over the data lifecycle.
1. Consent - permission with real choice
Consent is valid permission from a person before processing their personal data. In practice, it must answer four questions clearly: what data, for what purpose, with whom it may be shared, and how the person can withdraw.
Good consent is not buried in a long privacy policy. It is granular, affirmative, and revocable. For example, a fintech app may need PAN details for KYC, bank SMS access for cash-flow underwriting, and notification permission for reminders. These should not be forced into one vague βI agree to everythingβ bundle unless the processing is genuinely inseparable.
2. Purpose limitation - the anti-purpose-creep rule
Purpose limitation says data collected for one stated purpose should not be reused for a materially different purpose without a proper basis. This is where many businesses slip. A user may share location to get food delivered; using the same location history to infer lifestyle segments for unrelated advertising is a different proposition.
The practical question is: Would a reasonable user expect this use from the notice they saw? If not, the company needs fresh consent, a different lawful basis, or should not do it.
3. Data retention - deletion as a discipline
Data retention is the rule for how long data stays identifiable. A company may need data for service delivery, accounting, fraud prevention, dispute handling, tax, sectoral regulation, or litigation holds. But βwe may need it somedayβ is not a retention policy.
A strong retention system separates three states: active use, archived legal/business need, and deletion or irreversible anonymisation.
Definitions You Can Say in One Breath
- GDPR Article 4(11): consent is βfreely given, specific, informed and unambiguousβ agreement.
- GDPR Article 5(1)(b): purpose limitation requires βspecified, explicit and legitimate purposes.β
- GDPR Article 5(1)(e): storage limitation means keeping identifiable data βno longer than is necessary.β
- India DPDP Act, 2023: the person is the Data Principal; the organisation deciding processing purpose is the Data Fiduciary.
The Practical Framework: Map Data to Purpose to Deletion
For a manager, the best working tool is a data-purpose-retention register. It prevents three failures: over-collection, unauthorised reuse, and zombie data sitting forever in systems.
Five-Step Implementation Process
KPIs That Show Privacy Is Actually Working
In interviews, do not say βwe will monitor complianceβ vaguely. Name measurable controls. Privacy KPIs are usually threshold-based: the strongest number is often 100 percent compliance or zero exceptions, not an industry benchmark.
Mini Case Study: IRCTC and the Passenger Data Monetisation Backlash
IRCTC showed why data collected for service delivery cannot be casually reframed as a monetisation asset without consent, purpose clarity, and public trust.

Situation: IRCTC holds highly sensitive travel-related information because passengers use it to search, book, cancel, and manage train journeys. The original user expectation is functional: complete the transaction, receive service updates, handle refunds, and comply with operational or legal requirements.
The move: In 2022, IRCTC explored hiring a consultant for digital data monetisation. The proposal triggered concerns from privacy advocates and policymakers because the new commercial use appeared wider than the original booking purpose. The issue was not that organisations can never use customer data; the issue was that the purpose, consent basis, safeguards, and retention boundaries were not yet credible to the public.
Outcome and lesson: IRCTC withdrew the tender. The lesson for managers is powerful: data strategy must start with purpose legitimacy, not just revenue potential. The primary driver of the backlash was purpose mismatch; supporting drivers included the sensitivity of travel data, absence of a mature personal data protection regime at that moment, and low user visibility into downstream use.
So what: The best answer is not βIRCTC should never use data.β The sharper answer is: any secondary use must be purpose-tested, consent-backed where required, minimised, time-bound, and accountable.
How AI Changes Consent, Purpose Limitation & Data Retention
AI makes this topic more important because models turn old, scattered data into new inferences. The privacy risk moves from βwhat did we collect?β to βwhat can we now infer, combine, retain, and reuse?β
For 2026 interviews, mention one operational safeguard: before using personal data in an AI model, run a model data intake review covering data source, original purpose, consent or lawful basis, sensitive fields, retention of training data, prompt logging, vendor processing, and user rights.
Interview Relevance
βSuppose a consumer app wants to use existing customer data to launch an AI-based personalised offer engine. How would you evaluate consent, purpose limitation and retention?β
Use this line in an answer: βI would not approve the project merely because data is available; I would approve it only if the use is expected, explained, necessary, time-bound and auditable.β
Common Mistake
The costly mistake is saying, βWe already took consent, so we can use the data.β Consent is not a blank cheque - it is tied to a specific purpose and time-bound need. Fix: always answer with the triangle: consent validity, purpose compatibility, and retention/deletion control.
What to Revise Next
You now understand how data is collected, used and deleted responsibly. Next, move from data governance to decision governance: revise Bias, Proxy Discrimination & Fairness in Models, then Explainability & Accountability for Automated Decisions. Together, these complete the privacy-to-AI-risk journey.