Author: Aditya Sharma
Abstract
The Digital Personal Data Protection Act, 2023 (DPDP Act) marks a watershed moment in India’s journey toward a comprehensive data protection framework. Among its most significant provisions is the right granted to Data Principals to request the erasure of their personal data. This article provides a detailed examination of the statutory framework governing the right to erasure under Sections 8 and 12 of the DPDP Act, its constitutional foundation in Article 21 as established in Justice K.S. Puttaswamy v. Union of India (2017), the circumstances under which companies may lawfully refuse deletion requests, the enforcement mechanisms available through the Data Protection Board of India, and the practical challenges that arise in implementation. The article also compares India’s framework with the GDPR’s right to erasure and analyses recent judicial developments that signal the evolving contours of informational privacy in India.
Introduction
India’s digital transformation has accelerated dramatically over the past decade. With initiatives like Digital India and the widespread proliferation of smartphones, daily life has increasingly moved online from financial transactions and healthcare consultations to education and social interaction. Every online interaction generates a digital trail: names, phone numbers, home addresses, bank records, biometric data, and even location signals are collected, stored, and often retained indefinitely across servers and databases.
This data, while valuable for improving services and driving innovation, also creates significant risks. Data breaches have become increasingly common, leading to identity theft, financial fraud, and reputational harm. The absence of a comprehensive data protection framework left individuals with limited recourse against misuse of their personal information.
The constitutional foundation for data protection in India was firmly established by the Supreme Court in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) (2017) 10 SCC 1, where a nine-judge bench unanimously held that the right to privacy is a fundamental right protected under Article 21 of the Constitution. The Court recognised that informational privacy the right to control the dissemination of personal information is an essential aspect of human dignity and personal liberty.
Building on this constitutional mandate, Parliament enacted the Digital Personal Data Protection Act, 2023 on 11 August 2023. The Act establishes a comprehensive framework for the protection of digital personal data in India, setting out the obligations of entities handling such data (Data Fiduciaries) and the rights of individuals (Data Principals). The Act follows the SARAL approach Simple, Accessible, Rational and Actionable using plain language and clear illustrations to facilitate understanding and compliance.
Key Definitions and Statutory Framework
Data Principal
Under Section 2(j) of the DPDP Act, a Data Principal is the individual to whom the personal data relates. Each Data Principal holds specific legal rights under the Act, including the right to access information about how their data is processed, the right to correction and updating of inaccurate data, the right to erasure, and the right to grievance redressal. For children, the Data Principal includes a parent or lawful guardian; for persons with disabilities who cannot act independently, it includes the lawful guardian acting on their behalf.
Data Fiduciary
A Data Fiduciary is defined under Section 2(i) as any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data. This may include individuals, businesses, agencies, or organisations. Data Fiduciaries bear specific obligations under the Act, including implementing reasonable security safeguards, notifying the Board and affected individuals of data breaches, erasing data when no longer necessary, and responding to Data Principal requests.
Processing of Personal Data
“Processing” under the DPDP Act encompasses a wide range of operations, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction of personal data. Deletion is therefore not merely an administrative housekeeping function but a legally mandated component of proper data management.
Right to Erasure: Statutory Provisions
Section 12: Right to Correction and Erasure
Section 12 of the DPDP Act establishes the right to erasure. Section 12(1) provides that a Data Principal shall have the right to correction, completion, updating, and erasure of her personal data for which she has previously given consent.
Section 12(3) is the key provision governing erasure requests. It grants a Data Principal the right to erasure of personal data that is:
No longer necessary for the purpose for which it was collected; or Where consent has been withdrawn.
The Data Fiduciary shall erase such data unless retention is necessary for the specified purpose or for compliance with any law for the time being in force. The use of the word “shall” indicates a mandatory obligation, not a discretionary power.
Section 8(7): Fiduciary-Initiated Erasure
Significantly, the obligation to erase data is not solely triggered by a Data Principal’s request. Section 8(7) imposes a proactive duty on Data Fiduciaries: they must erase personal data once the purpose for which it was collected is no longer served, unless retention is necessary for compliance with any law.
This creates a dual-track obligation: user-triggered erasure under Section 12(3) and fiduciary-initiated erasure under Section 8(7). The fiduciary must monitor purpose status and act independently, without waiting for the user to file a request.
Section 6(4): Consent Withdrawal
Section 6(4) provides that when a Data Principal withdraws consent, the Data Fiduciary must stop all processing tied to that consent. Withdrawal is not a request for the fiduciary to consider; it is a legal event that starts the erasure clock. The fiduciary has no discretion to continue processing because the data is “useful” or “already integrated into our systems.”
Grounds for Refusal: When a Company Can Say No The right to erasure is not absolute. The DPDP Act provides specific grounds on which a Data Fiduciary may lawfully refuse a deletion request.
Legal Necessity
Under Sections 8(7) and 12(3), a Data Fiduciary may retain or refuse to erase data if retention is necessary for compliance with any law for the time being in force. This includes:
Banking and KYC records: Banks must retain customer identification and transaction data for prescribed periods under RBI and anti-money-laundering rules typically at least ten years after account closure.
Tax documentation: Businesses must preserve invoices and accounting records for prescribed periods under income-tax and GST laws.
Employment records: Employers may need to retain payroll or compliance data to defend legal claims or meet labour-law requirements.
Specified Purpose
If the data is still necessary for the original lawful purpose for which it was collected, the fiduciary may continue to retain it. Once that purpose is served, however, the obligation to erase under Section 8(7) arises.
Duty to Communicate
Even when refusal is justified, the Data Fiduciary must inform the Data Principal clearly that erasure cannot be performed because of a legal requirement, specify the law or regulation under which retention is required, and erase the data once the legal obligation ends. Failure to communicate transparently can be treated as non-compliance with Sections 8 and 12. Constitutional Foundation: Article 21 and the Puttaswamy Judgment
The right to erasure finds its constitutional moorings in Article 21 of the Constitution of India, which guarantees the right to life and personal liberty. The Supreme Court in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) 10 SCC 1 held that privacy is an attribute of human dignity and a fundamental right.
The Court explicitly recognised a “right to control dissemination of personal information” and acknowledged the concept of the right to be forgotten. However, the Court emphasised that this right is not absolute and requires a careful balance with free speech (protected under Article 19(1)(a)), judicial transparency, and legitimate public interest.
Justice Chandrachud, writing for himself and the Chief Justice, observed that privacy safeguards one’s freedom to make personal choices and control significant aspects of their life. The judgment overruled earlier decisions in M.P. Sharma v. Satish Chandra (1954) and Kharak Singh v. State of U.P. (1963), which had denied the existence of a constitutional right to privacy.
In a significant recent development, on 28 November 2025, a Delhi court at Patiala House issued a “John Doe” order directing Indian Kanoon, prominent media organisations, and Google LLC to remove or de-index online content naming a man previously accused in the 2019 Moser Baer money-laundering case, who was fully exonerated on merits in 2024. The court held that digital records of past accusations served no legitimate interest and caused ongoing reputational harm after acquittal, concluding that continued availability of the articles undermined the man’s dignity, integrity, and peace of mind protected under Article 21.
Comparison with GDPR’s Right to Erasure
The EU’s General Data Protection Regulation (GDPR) establishes a broader right to erasure under Article 17. A data subject can demand deletion on multiple grounds, including where the data is no longer necessary, consent is withdrawn, the data subject objects to processing, the data has been processed unlawfully, or there is a legal obligation to erase.
The DPDP Act’s right to erasure is narrower and more conditional. It is not a free-standing demand right but is anchored specifically to two conditions: withdrawal of consent or cessation of the purpose for which the data was collected. Unlike the GDPR, which applies to both digital and offline data, the DPDP Act applies exclusively to digital personal data.
The GDPR’s right to be forgotten is broader and more enforceable than the DPDP Act’s narrower erasure provision. However, the DPDP Act has drawn inspiration from global privacy regulations while tailoring provisions to suit India’s digital and cultural context.
Enforcement Mechanism: The Data Protection Board of India
Strong rights require credible enforcement mechanisms. The DPDP Act establishes the Data Protection Board of India (DPB) as an independent adjudicatory authority.
Powers and Functions
The Board is empowered to:
Investigate breaches and examine non-compliance by Data Fiduciaries
Adjudicate complaints from Data Principals alleging failure by a Data Fiduciary to comply with its obligations or honour statutory rights (access, correction, erasure, grievance redressal, nomination)
Impose monetary penalties up to ₹250 crore per breach Issue corrective directions, including orders for erasure, cessation of processing, or compliance upgrades
Penalty Framework
The Act prescribes different penalty slabs depending on the nature of breach:
Failure to take reasonable security safeguards: Up to ₹250 crore
Failure to notify personal data breach: Up to ₹200 crore
Non-fulfilment of Data Principal rights (including erasure): Up to ₹50 crore
Operational Status
The DPDP Rules, 2025 were notified on 14 November 2025 after nationwide consultations that received 6,915 inputs. The implementation is being phased in:
13 November 2025: Constitution of the Data Protection Board of India and definitions
13 November 2026: Registration and oversight of Consent Managers
13 May 2027: Substantive provisions governing notice, consent, Data Principal rights, fiduciary obligations, and key penalty clauses Practical Challenges in Implementation
Technical Complexity
Wiping data clean across modern technology systems presents significant challenges. Personal data is often distributed across databases, cloud storage, backups, and third-party vendors. Complete erasure requires coordinated effort across multiple systems and may not always be technically feasible.
Conflicting Legal Obligations
Data Fiduciaries frequently face conflicting obligations statutory retention requirements under tax laws, banking regulations, or court orders may override individual deletion requests.
Lack of Awareness
Most individuals remain unaware of their rights under the DPDP Act. Without effective public education and awareness campaigns, the right to erasure may remain largely unexercised.
Delayed Enforcement
Although the DPDP Act was enacted in August 2023, the substantive provisions including the right to erasure will not become fully operational until May 2027. This prolonged implementation timeline creates uncertainty for both Data Principals and Data Fiduciaries.
Recommendations
Establish clear timelines: The DPDP Rules require Data Fiduciaries to respond to Data Principal requests within a maximum of 90 days. This timeline should be strictly enforced, with the Board empowered to impose penalties for unreasonable delays.
Mandate automatic deletion protocols: The Rules already mandate automatic deletion for specified classes of Data Fiduciaries and defined use cases if the Data Principal does not engage for a prescribed period. This approach should be expanded to cover more categories of data.
Enhance public awareness: The government should launch comprehensive awareness campaigns to educate citizens about their rights under the DPDP Act, including the right to erasure.
Strengthen Board capacity: The Data Protection Board must be adequately staffed and resourced to handle the expected volume of complaints and inquiries.
Provide clear compliance guidance: MeitY should issue detailed guidance on erasure workflows, including technical standards for data deletion and anonymisation.
Conclusion
The DPDP Act, 2023 represents a paradigm shift in India’s approach to data protection. The right to erasure, while narrower than the GDPR’s right to be forgotten, establishes a crucial mechanism for individuals to exercise control over their personal data. The dual-track obligation user-triggered under Section 12(3) and fiduciary-initiated under Section 8(7) creates a comprehensive framework that places responsibility on both individuals and organisations.
The constitutional foundation laid by the Supreme Court in Puttaswamy ensures that the right to erasure is not merely a statutory creation but flows from the fundamental right to privacy under Article 21. Recent judicial developments, including the Delhi court’s 2025 order, signal that Indian jurisprudence is moving toward a clearer recognition of informational autonomy and the right to be forgotten.
However, significant challenges remain. The phased implementation timeline means that substantive rights will not become fully operational until May 2027. Technical complexity, conflicting legal obligations, and lack of public awareness continue to impede effective exercise of the right to erasure.
The ultimate success of India’s data protection framework will depend on robust enforcement by the Data Protection Board, clear compliance guidance from regulators, and meaningful public awareness of the rights conferred by the Act. As India’s digital economy continues to grow, the right to erasure will play an increasingly vital role in safeguarding individual privacy and dignity in the digital age.
References
Digital Personal Data Protection Act, 2023, §§ 6, 8, 12.
Constitution of India, Art. 21.
Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
General Data Protection Regulation (EU) 2016/679, Art. 17.
Digital Personal Data Protection (DPDP) Rules, 2025.
Ministry of Electronics and Information Technology, DPDP Rules, 2025 Notified: A Citizen-Centric Framework for Privacy Protection and Responsible Data Use (PIB, 17 Nov. 2025).
Ministry of Electronics and Information Technology, Government Notifies DPDP Rules to Empower Citizens and Protect Privacy (PIB, 14 Nov. 2025).
Justice B.N. Srikrishna Committee Report on Data Protection (2018).
“Right to Erasure Under DPDP: What Users Can Demand and When,” Digio.in.
“Penalties and Adjudication under the DPDP Act, 2023: Powers of the Data Protection Board and Quantum of Fines,” KS&K.
“Decrypting India’s Data Protection Regime: The Data Protection Board of India,” Clyde & Co (2025).
“Right to be Forgotten and Right to Erasure,” Chambers and Partners (8 Dec. 2025).
“Rights of Data Principals under the DPDP Act, 2023: Access, Correction, Erasure, and Grievance Redressal,” KS&K (8 Oct. 2025).