All Insights
Regulation 6 min read2026-06-10

What the DPDP Act Means for Device Buy-Back Programs

Under India's DPDP Act, data-fiduciary obligations attach to whoever accepts a used device. Here is what that means for trade-in and buy-back operators — and what evidence you will be expected to produce.

The obligation follows the device

When a consumer hands a used phone or laptop into a trade-in program, the personal data on that device does not legally evaporate. Under the Digital Personal Data Protection Act, 2023, the organization that accepts the device becomes responsible for the personal data it contains — with the same erasure obligations that apply to any data fiduciary.

This is the structural liability most buy-back programs have not priced in: the moment of intake creates a compliance duty that persists until the data is verifiably destroyed.

Why a factory reset is not enough

A factory reset removes the index to data, not necessarily the data itself. On many storage types, resets leave recoverable content — and critically, a reset produces no evidence. If a Data Protection Board enquiry or an internal audit asks how a specific traded-in device was purged, 'we reset it' is an assertion, not a record.

NIST SP 800-88 Rev.1 defines what verified sanitization actually requires: a method matched to the media type (Clear, Purge, or Destroy), followed by verification, followed by documentation.

The penalty exposure is real

The DPDP Rules were notified on 13 November 2025, with full enforcement expected by 13 May 2027. Maximum penalties reach ₹250 crore per instance, with up to ₹200 crore for failing to implement reasonable security safeguards. For a platform processing thousands of trade-ins a month, an undocumented erasure process is an accumulating liability.

What compliant intake looks like

Certified erasure at the point of intake, before grading or resale routing. A signed, device-level certificate bound to the intake record. Program-level audit exports your legal and risk teams can produce on demand. That is the standard CYVORIQ's marketplace compliance layer was built to meet — embedded in the workflow, not bolted on after resale.

Ready to make device retirement your most documented process?

Talk to our compliance team. Every question answered with evidence, not assurance.