Vendors describe products as GDPR compliant or DPDP compliant as though the regulations contain a specification a product could meet. They do not. Not one of the four below names an overwrite pattern, a pass count or a standard. What they name is an outcome and an obligation to be able to show you achieved it.
India's DPDP Act
Personal data must be erased once the purpose it was collected for is served, unless retention is required by law. The obligation runs to the data fiduciary, and it does not stop at the live database — it covers the laptop that held an export and the server that was decommissioned last quarter.
GDPR
Article 17 gives the right to erasure and Article 5 requires storage limitation; Article 5(2) adds accountability, which is the part that matters here. You must be able to demonstrate compliance, and a disposal process that produces no per-asset record cannot demonstrate anything.
HIPAA
The Security Rule requires policies for the final disposition of electronic protected health information and for the media it lives on. It explicitly expects media reuse to be addressed, which is precisely the case where clearing is insufficient and purging is required.
PCI-DSS
Cardholder data must be rendered unrecoverable when it is no longer needed, and the requirement is specific about media disposal rather than leaving it to general practice. Of the four this is the one that comes closest to prescribing method, and even it stops short of naming a standard.
The common thread
All four ask the same question at an audit: show me this asset, and show me what happened to it.
Which means the compliance question is not "which method is compliant". It is whether your disposal process produces a record per device, whether that record includes the verification result, and whether it survives long enough to be produced years later. Choose the method for the media; choose the process for the auditor.


