Erase, Retain, or Refuse? Erasing the Digital Shadow under the DPDP Act, 2023.
Decoding the legal framework governing personal data deletion, website obligations, and individual privacy rights in India.
☆ ABSTRACT :
In the digital age, deleting an online account or removing visible content does not necessarily result in the erasure of the personal data associated with it. Copies of such information may continue to exist in backups, cloud servers, archived databases, or be retained for statutory and regulatory purposes. This raises an important legal question: to what extent can individuals compel websites and online platforms to delete their personal data? Against this backdrop, the Digital Personal Data Protection (DPDP) Act, 2023 introduces a statutory framework governing the collection, processing, retention, and erasure of digital personal data in India.
This article examines the scope and practical application of the Right to Erasure under the DPDP Act, 2023, with particular emphasis on the legal procedure available to individuals seeking the deletion of their personal data. It analyses the constitutional foundations of informational privacy, the obligations imposed upon Data Fiduciaries, and the circumstances in which an erasure request may lawfully be refused. The article further outlines a step-by-step procedural roadmap for exercising this right, beginning with identifying the appropriate Data Fiduciary and culminating in the remedies available before the Data Protection Board of India and other competent legal forums. It also highlights common procedural mistakes that may weaken an erasure request and offers practical guidance for ensuring legal compliance. By bridging statutory analysis with procedural application, the article demonstrates that the Right to Erasure is a legally enforceable mechanism that enables individuals to exercise greater control over their digital footprint while balancing legitimate data retention obligations under Indian law.
☆ INTRODUCTION :-
Every day, we see influencers sharing glimpses of their life on social media. At the same time, millions of ordinary users too post their photos, videos or other updates without giving much thought to where their data ultimately goes.
Now imagine, you posted a photo on your social media account. Later for one reason or another, you delete it, or uninstall the app or even close your account. Do you think the photograph has disappeared? Not Necessarily! While it may no longer be visible to you or your friends on your profile, copies of your personal data may still exist on servers located thousands of kilometers away. This raises a serious question: CAN INDIVIDUALS FORCE WEBSITES TO DELETE THEIR PERSONAL DATA ? IF “YES”, THEN “HOW”? This article examines the answers to all these questions.
Before examining the legal framework, it is necessary to distinguish between deleting visible content and erasing the personal data. While a user may remove a photograph or close an account, the associated personal information still continues to exist in the databases of online platforms. This distinction lies at the heart of debate surrounding the Right to Erasure and explains why legal safeguards have become increasingly necessary in the digital age. Against this backdrop, this article examines the scope of the Right to Erasure under the Digital Personal Data Protection (DPDP) Act, 2023, the practical application, obligations of online platforms, and the challenges involved in enforcing this right.
☆ WHY DOES PERSONAL DATA REMAIN ONLINE ?
Despite growing recognition of privacy as a fundamental right, personal data often remains online even after a user requests its deletion. It doesn’t always disappear from the digital ecosystem immediately. It may continue to exist in archived records, backup systems, cloud infrastructure, search engine indexes, or databases maintained by third parties. In many situations, organizations are also legally permitted or required to retain specific data for purposes such as regulatory compliance, fraud prevention, dispute resolution, or establishment of legal claims. Furthermore, information that has already been copied, shared or publicly disseminated may remain beyond the direct control of the original data fiduciary. These practical and legal limitations explain why complete erasure is often difficult to achieve and underscore the importance of a well defined legal framework, such as Digital Personal Data Protection Act, 2023, which seeks to balance privacy rights with legitimate data retention requirements.
☆ WHAT IS THE RIGHT ERASURE :
Right to Erasure under the Section 12 of DPDP Act empowers individuals to demand the deletion of their personal data from an organization’s systems. This right is triggered once the specific purpose for collecting the information is fulfilled or when the user withdraws their consent.
Consequently, companies must erase this data and ensure their third party processors do the same. However, this right is not absolute. Organisations can legally retain personal information if keeping it is necessary to comply with statutory obligations, resolve legal disputes, or satisfy specific regulatory frameworks under prevailing Indian Laws.
☆ WHY THE RIGHT TO ERASURE MATTERS ?
The right to erasure is essential because it strengthens an individual’s control over personal information in an increasingly data driven world. It enables individuals to withdraw the consent, request deletion of data that is no longer necessary and reduce the risks associated with prolonged storage of personal information, such as identity, theft, profiling or misuse. By requiring data fiduciaries to erase personal data when its retention is no longer justified, the right promotes transparency, accountability, and responsible data governance. At the same time, it preserves a balance between privacy and legitimate public interests by permitting retention where required under law or for lawful purposes. Consequently, the right to erasure serves as a significant safeguard for informational privacy and reinforces trust in the digital ecosystem in the DPDP Act, 2023.
☆ WHEN CAN YOU LEGALLY DEMAND DELETION?
▪︎ Revoking Consent :-
Your consent is not an open-ended voucher. Under tough privacy laws like the GDPR and India’s DPDP Act, you can take back your permission whenever you feel like it. Since a company relies entirely on your green light to track or profile you, pulling that approval completely destroys their legal justification. The moment you say “no more,” their data engines have to shut down. This triggers a legal requirement for the business to scrub your personal info out of their system entirely, from front-end dashboards to deep archive servers and third-party ad networks.
▪︎ Purpose Fulfilled, Erase it :-
Data storage needs a clear end date. Legally, the second a company finishes the exact task they took your information for, their reason to hold onto it vanishes. Storage limits mean businesses cannot just park your digital footprint in their databases forever. If you close an online shopping account or cancel a subscription, that transaction is officially dead. Once that finish line is crossed, keeping your files around without a brand-new agreement is flat-out illegal. At that point, a complete system wipe becomes mandatory.
▪︎ Clearing Digital Footprints :-
Information should never stick around longer than it is actually useful. When keeping your files serves no real business function, the law says it has to be destroyed. Leaving old data sitting in a database violates standard minimization rules and turns you into an easy target if that business gets hacked. If a company hoards your records just to sit on them, they are breaking global privacy rules. Forcing a hard delete clears away your digital history so your old information does not come back to haunt you.
▪︎ Lawful Grounds for Refusal :-
That said, your right to be forgotten is not an automatic pass, because it has to answer to strict legal overrides. A company can, and will, reject your deletion demand if a separate law says they have to keep the files. For instance, tax codes force banks to lock down and store transaction logs for up to ten years. Medical clinics also have to hold onto patient charts for a long time to follow safety rules. Plus, if there is an active legal battle brewing, companies have the right to freeze your records to defend themselves.
☆ LEGAL FRAMEWORK:
▪︎ CONSTITUTIONAL FRAMEWORK:
The Justice K.S. Puttaswamy v. Union of India judgment marked a turning point in India’s privacy jurisprudence by recognising the right to privacy as a fundamental right under Article 21 of the Constitution. The Supreme Court held that informational privacy is an essential aspect of personal liberty, requiring the State to establish an effective legal framework for the protection of personal data in the digital age.
The enactment of the Digital Personal Data Protection Act, 2023 is a legislative response to these constitutional principles. The Act translates the constitutional recognition of informational privacy into enforceable statutory rights and obligations by regulating the collection, processing, retention, and erasure of digital personal data while ensuring greater accountability of Data Fiduciaries.
▪︎DIGITAL PERSONAL DATA PROTECTION ACT, 2023 :-
The Digital Personal Data Protection (DPDP) Act, 2023 provides the statutory framework governing the processing and erasure of digital personal data in India. It applies to entities, known as Data Fiduciaries, that process digital personal data within India or offer goods and services to individuals in India. The Act recognises the individual as the Data Principal, who may exercise certain rights concerning their personal data, including seeking its erasure in circumstances permitted by law.
Correspondingly, Data Fiduciaries are required to process, retain, and erase personal data in accordance with the obligations prescribed under the Act. However, the right to erasure is not absolute and remains subject to statutory exceptions, including situations where retention is mandated under applicable law. Understanding this legal framework is essential before invoking the procedural mechanism for seeking the deletion of personal data from a website or digital platform.
☆ HOW TO LEGALLY COMPEL A WEBSITE TO DELETE YOUR PERSONAL DATA :-
The Right to Erasure under the Digital Personal Data Protection Act, 2023 can be effectively exercised only by following the statutory procedure prescribed under the law. Since the right is subject to specific legal requirements and exceptions, a Data Principal must adopt a structured approach. The following steps outline the legal process for seeking the erasure of personal data from a Data Fiduciary.
Step I: Identify the Appropriate Data Fiduciary
The first and most fundamental step is to identify the entity that determines the purpose and means of processing your personal data. Under the DPDP Act, this entity is referred to as the Data Fiduciary. Many users mistakenly direct their requests to customer support representatives or social media handles, which may delay or misdirect the process. Instead, the legal identity of the organisation should be verified through its privacy policy, terms of service, or corporate disclosures. Addressing the request to the correct legal entity ensures that the statutory obligation to consider the request rests with the organisation responsible for processing the data.
Step II: Examine the Privacy Policy and Grievance Mechanism
Before submitting an erasure request, the privacy policy of the website should be carefully examined. This document ordinarily explains the categories of personal data collected, the purposes for which such data is processed, the period for which it may be retained, and the procedure for raising privacy-related concerns. Particular attention should be paid to the contact details of the Grievance Officer or any other designated authority responsible for handling requests under the DPDP Act. Understanding the organisation’s prescribed procedure enables the Data Principal to submit a request in the manner expected by the Data Fiduciary.
Step III: Submit a Formal Request for Erasure
A request for erasure should always be made through a formal written communication instead of relying solely upon an account deletion option available on the platform. The request should clearly identify the individual, specify the account or data concerned, and expressly state that the request is being made under the applicable provisions of the Digital Personal Data Protection Act, 2023. Where relevant, supporting details such as the registered email address, mobile number, or customer identification number may be included to facilitate verification. A well-drafted request minimises ambiguity and demonstrates that the Data Principal is invoking a statutory right rather than making a casual customer service request.
Step IV: Withdraw Consent, Where Applicable
Where the processing of personal data is based upon consent, the Data Principal may withdraw such consent in accordance with the provisions of the DPDP Act. The withdrawal should be communicated expressly and preferably in writing to avoid future disputes. However, withdrawal of consent does not automatically require the immediate deletion of all information. A Data Fiduciary may continue to retain certain categories of data where such retention is authorised or mandated under any applicable law. Accordingly, while consent withdrawal strengthens the request for erasure, the final obligation of the Data Fiduciary must always be assessed in light of the statutory framework governing data retention.
Step V: Preserve Documentary Evidence
Every stage of the communication process should be properly documented. Copies of emails, acknowledgement receipts, complaint reference numbers, screenshots of online submissions, and any responses received from the organisation should be retained carefully. Maintaining a chronological record of correspondence serves two important purposes. First, it demonstrates that the Data Principal has acted diligently and followed the prescribed procedure. Secondly, it provides valuable documentary evidence if the dispute subsequently reaches the Data Protection Board of India or any other competent legal forum.
Step VI: Invoke the Internal Grievance Redressal Mechanism
If the Data Fiduciary fails to respond satisfactorily or rejects the request without adequate justification, the Data Principal should utilise the organisation’s internal grievance redressal mechanism. A reasoned representation should be submitted to the designated Grievance Officer, referring to the earlier request and seeking reconsideration of the matter. This stage reflects the principle of procedural fairness by providing the organisation with an opportunity to address the grievance before regulatory intervention becomes necessary. It also demonstrates that the Data Principal has exhausted the available internal remedies.
Step VII: Approach the Data Protection Board of India
Where the grievance remains unresolved despite following the prescribed internal mechanism, the Data Principal may pursue the remedies available before the Data Protection Board of India, subject to the provisions governing its jurisdiction and functioning. While initiating the complaint, all relevant documents, including the original erasure request, subsequent correspondence, acknowledgements, and supporting evidence, should accompany the application. A properly documented complaint enables the Board to examine whether the Data Fiduciary has complied with its statutory obligations under the DPDP Act and to take action in accordance with law.
Step VIII: Consider Appropriate Legal Remedies
Where the available statutory mechanisms fail to provide effective relief, or where the continued retention of personal data results in substantial legal prejudice, an affected individual may explore appropriate legal remedies in accordance with the applicable legal framework. Depending upon the facts and circumstances of the case, this may include seeking appropriate judicial relief before a competent court or pursuing any other remedy recognised by law. However, litigation should ordinarily be viewed as a measure of last resort after the statutory procedures under the DPDP Act have been duly exhausted.
The Right to Erasure under the DPDP Act, 2023 is not absolute and must be exercised in accordance with the statutory procedure. A well-documented and legally compliant approach significantly improves the likelihood of obtaining an effective remedy.
☆ WHEN CAN A WEBSITE REFUSE ERASURE REQUEST?
Although the DPDP Act, 2023 recognises an individual’s right to seek the erasure of personal data, this right is not absolute. A Data Fiduciary may lawfully refuse an erasure request where the continued retention of personal data is authorised or required under applicable law.
One of the primary grounds for refusal is compliance with legal obligations. Organisations may be required to retain certain records to fulfil statutory duties under taxation, financial, labour, or other regulatory laws. In such cases, deleting the data would amount to a violation of those legal requirements.
A request may also be declined where the data is required for regulatory compliance or to satisfy directions issued by competent authorities. Similarly, if the information is relevant to ongoing investigations, judicial proceedings, or law enforcement purposes, the Data Fiduciary may retain the data until the legal necessity ceases.
Apart from these situations, the DPDP Act also recognises statutory exceptions where continued processing or retention is legally permissible. Therefore, while individuals possess an important right to seek erasure, its exercise must always be balanced against competing legal obligations imposed upon the Data Fiduciary.
☆ COMMON MISTAKES WHILE SEEKING ERASURE
Many individuals weaken their requests by failing to follow the prescribed legal procedure. One common mistake is assuming that deleting an online account automatically erases all associated personal data. However, account deletion and data erasure are not synonymous.
Another frequent error is failing to withdraw consent where consent forms the basis of processing. Users also submit vague or incomplete requests without clearly identifying the account, the personal data concerned, or the statutory basis of their claim.
Finally, many individuals fail to preserve documentary evidence, such as emails, acknowledgements, complaint reference numbers, and screenshots. These records are essential if the matter is later escalated before the Data Protection Board of India or another competent authority.
☆ Frequently Asked Questions (FAQs)
1. Does deleting my account automatically delete all my personal data?
No. Deleting an account does not necessarily result in the erasure of all personal data. Depending on the purpose of processing and applicable legal obligations, a Data Fiduciary may continue to retain certain information in accordance with the DPDP Act, 2023 and other applicable laws.
2. Can I request the deletion of my personal data even if I no longer use the website?
Yes. A Data Principal may seek the erasure of personal data where the conditions prescribed under the DPDP Act, 2023 are satisfied, particularly when the purpose of processing has been fulfilled or consent has been withdrawn, subject to statutory exceptions.
3. Can a website legally refuse my erasure request?
Yes. The Right to Erasure is not absolute. A Data Fiduciary may lawfully refuse an erasure request where retention of personal data is required under law, necessary for regulatory compliance, connected with ongoing investigations or judicial proceedings, or otherwise permitted under the DPDP Act, 2023.
4. What should I do if my erasure request is ignored?
The Data Principal should first utilise the organisation’s internal grievance redressal mechanism. If the grievance remains unresolved, the matter may be escalated before the Data Protection Board of India in accordance with the procedure prescribed under the DPDP Act, 2023.
5. Is withdrawal of consent the same as deletion of personal data?
No. Withdrawal of consent may require the Data Fiduciary to stop processing personal data where consent is the legal basis for processing. However, deletion of personal data remains subject to the provisions of the DPDP Act, 2023 and any other applicable legal obligations requiring its retention.
6. What documents should I preserve while seeking erasure?
Individuals should retain copies of their erasure request, email correspondence, acknowledgement receipts, complaint reference numbers, screenshots, and any responses received from the Data Fiduciary. These documents may become valuable evidence if the dispute is subsequently escalated before the Data Protection Board of India or another competent authority.
7. Can I force Google or another search engine to remove information about me?
Not necessarily. Erasure of personal data from a website and removal of search results are distinct legal issues. Even if the original website deletes your personal data, search engines may continue to display links until a separate removal request is considered under the applicable legal framework and the platform’s own policies.
☆ CONCLUSION :-
The Right to Erasure under the DPDP Act, 2023 represents a significant step towards strengthening individual control over personal data in the digital environment. However, the effective exercise of this right depends not only on statutory recognition but also on a clear understanding of the legal procedure, the obligations of Data Fiduciaries, and the limitations imposed by law.
Individuals seeking the deletion of their personal data should adopt a systematic approach by identifying the appropriate Data Fiduciary, submitting a well-reasoned erasure request, preserving documentary evidence, and utilising the available grievance redressal mechanisms before pursuing regulatory remedies. As India’s data protection framework continues to evolve, informed exercise of these rights will play an essential role in promoting accountability, transparency, and responsible data governance.
☆ REFERENCES
– Statutes & Legal Authorities
1. The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023).
2. The Constitution of India, 1950 (Article 21).
3. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
– Online Sources:-
1. Ministry of Electronics and Information Technology (MeitY), The Digital Personal Data Protection Act, 2023, available at: https://www.meity.gov.in/dpdp-act-2023
2. Ministry of Electronics and Information Technology (MeitY), Official Website, available at: https://www.meity.gov.in
3. Digital India, Official Portal, available at: https://www.digitalindia.gov.in
4. Supreme Court of India, Justice K.S. Puttaswamy (Retd.) v. Union of India Judgment (2017), available at: https://api.sci.gov.in/supremecourt/2012/35071/35071_2012_Judgement_24-Aug-2017.pdf
5. India Code, The Digital Personal Data Protection Act, 2023, available at: https://www.indiacode.nic.in
6. Press Information Bureau, Government of India, available at: https://pib.gov.in