← All posts
Removal

DPDP Act Right to Erasure: What It Says, and What Actually Applies in India in 2026

Jagriti Shekhar
Jagriti Shekhar · ORM LeadAugust 29, 2026 | 19 min read
#dpdp act right to erasure#right to erasure india#section 12 dpdp#delete personal data india#dpdp rules 2025
FameNinja infographic for the article "DPDP Act Right to Erasure": a Google search result for "Delete My Personal Data in India" marked removed and suppressed, with reputation-management steps.

The right is real and it is written into law. It has also not started yet. Here is the honest 2026 position, and what you can actually do in the meantime.

Written by FameNinja Editorial, reviewed by Jagriti Shekhar, ORM Lead. Jagriti leads reputation and removal casework at FameNinja and is not an advocate. Nothing here is legal advice. Last updated 29 August 2026.

An old KYC document a shut-down app never wiped. A phone number a matrimonial site still displays. A home address on a data-broker page that a recruiter, a landlord, or a business rival can pull up in seconds. You wrote asking them to remove it and got silence, a form reply, or a promise that never arrived. Before going further, one check that saves people months: if what you actually want is your name to stop appearing in Google results, that is a different remedy called the Right to Be Forgotten in India, and it works through search engines and courts rather than through the company. If you want the company's own copy of your data gone, read on. The DPDP Act Right to Erasure is the provision people are searching for, and the single most important thing to understand about it in 2026 is that it has been enacted but has not yet commenced.

Want specific personal data taken down?Get a free, honest read on which route actually applies to your case in 2026.
Chat on WhatsApp →

Quick answer

The DPDP Act Right to Erasure sits in Section 12 of the Digital Personal Data Protection Act, 2023. It gives a Data Principal the right to ask a Data Fiduciary to correct, complete, update or erase personal data processed on the basis of her consent. Under the staggered commencement notified alongside the DPDP Rules 2025 on 13 November 2025, Sections 11 to 17 come into force in mid-May 2027. So as of August 2026 Section 12 is law on the statute book but is not yet an enforceable remedy. Until it commences, requests rest on the IT Rules 2021, the SPDI Rules 2011, platform policy and, where warranted, the courts.

Is the DPDP Act right to erasure in force right now?

No. Not in August 2026. This is the question the rest of the article depends on, so it comes first.

The Act received presidential assent in August 2023, but an Act can be passed years before its individual sections are switched on. On 13 November 2025 the Government notified the Digital Personal Data Protection Rules, 2025 and, alongside them, a staggered commencement schedule for the Act itself. That schedule puts different groups of sections into force at three different times.

PhaseDateWhat commences
Stage 113 November 2025Definitions, rule-making powers, and the provisions constituting the Data Protection Board of India (broadly Sections 18 to 26). The institutional shell, not the rights
Stage 2November 2026Consent Manager registration only. Section 6(9), Section 27(1)(d) and Rule 4
Stage 3Mid-May 2027The substance. Sections 3 to 5, 6(1) to (8) and (10), Sections 7 to 17, the rest of Section 27, Sections 28 to 34 including the penalty provision, and Sections 36 to 37

Section 12 sits in Stage 3. So does Section 8, which carries the Fiduciary's own erasure duties. So does Section 13, the grievance-redressal right. So does Section 17, the exemptions. So does Section 33, the penalty provision. None of them are operational today.

Sources differ by a day on the exact Stage 3 date, quoting 12 or 13 May 2027, because it is calculated as eighteen months from the notification. Treat it as mid-May 2027 and check the Gazette notification for the precise day before relying on it.

And the Data Protection Board?

The Board is the body a Data Principal would eventually complain to. Its constituting provisions commenced in November 2025, so the Board exists in law. It does not yet exist in practice.

As of August 2026 no Chairperson and no Members have been appointed. The Government issued notifications in May and June 2026 inviting nominations, but an invitation is not an appointment. A Board with no members cannot convene, cannot hear a party, and cannot pass an order. Indian courts have already run into this: at least one High Court has directed a complainant to the Board only for the remedy to be practically unavailable.

This matters for expectations. Even after May 2027, the enforcement route runs through a body that has to be staffed and running first.

So what is the honest 2026 position? The right exists on the statute book, its commencement date is known, and the enforcement machinery is incomplete. Anyone telling you that you can enforce a DPDP erasure right today is wrong. What you can do today is use the frameworks that have not been switched off, which is covered further down, and prepare properly for May 2027.

What Section 12 actually says, clause by clause

Worth reading the provision rather than a summary of it, because two limits inside it decide whether it will help you at all.

Two definitions first. A Data Principal is you, the individual the data is about. A Data Fiduciary is the person or company that alone or with others determines the purpose and means of processing your personal data.

Section 12(1) gives a Data Principal the right to correction, completion, updating and erasure of her personal data for the processing of which she has previously given consent.

That closing phrase is the limit almost every summary drops. The right as drafted attaches to personal data processed on the basis of your consent. Where a company processes your data on another lawful basis under the Act rather than on your consent, Section 12 does not obviously reach it. How broadly that limit will be read in practice is not settled, and it is one of the first things to ask a lawyer about in a real matter.

Note also that erasure is only one of four things you can ask for. If a data-broker page lists an address you left four years ago, correction or updating may serve you better than erasure, because the entry stays but stops being wrong about you.

Section 12(2) and 12(3): correction, then erasure

Section 12(2) deals with correction. On a request, the Data Fiduciary is to correct inaccurate or misleading personal data, complete incomplete personal data, and update personal data.

Section 12(3) is the erasure mechanism. A Data Principal makes a request in the prescribed manner to the Data Fiduciary for erasure, and on receipt the Data Fiduciary is to erase the personal data unless retention is necessary for the specified purpose or for compliance with any law for the time being in force.

That is the whole of the erasure clause. Note what it does: it creates a request-and-erase mechanism between you and the company holding your data, with two carve-outs. Retention for the specified purpose, and retention required by another law.

What Section 12 does not do

This needs saying plainly, because it is widely misdescribed online.

Section 12(3) does not create a general obligation on a Data Fiduciary to pass your erasure request down a chain to every third party it shared your data with. It is the erasure request provision itself, not a downstream-notification provision. If you have read that claim elsewhere, including in an earlier version of this article, it is not supported by the statutory text.

Section 12 also does not give you a right against a search engine for a result it did not publish, and it does not create a general right to have anything about you removed from the internet.

Does a company have to make its vendors delete your data too?

Partly, and the precision here matters. This is the provision people reach for and usually cite wrongly.

The relevant clause is not in Section 12. It is Section 8(7), which places two duties on a Data Fiduciary unless retention is necessary for compliance with any law in force. First, to erase personal data upon the Data Principal withdrawing consent or as soon as it is reasonable to assume the specified purpose is no longer being served, whichever is earlier. Second, to cause its Data Processor to erase any personal data that the Data Fiduciary made available to that Processor for processing.

Read the second limb carefully, because the category is narrow.

Who holds a copyDoes Section 8(7)(b) reach them
A Data Processor the company engaged to process data on its behalf, such as a cloud host, payroll vendor or analytics providerYes. The Fiduciary must cause the Processor to erase
A separate company that received your data and decides for itself what to do with it, making it its own Data FiduciaryNo, not under this clause. That entity has its own obligations and you would approach it separately
A third-party recipient more generally, such as a data broker that scraped or bought the dataNo. Section 8(7)(b) is about processors acting for the Fiduciary, not about the open market
A search engine displaying a resultNo. Different remedy entirely

So the honest version is this. Where a company engages vendors to handle your data on its behalf, its erasure duty extends to making those vendors erase too. It does not extend to every organisation that ever ended up with a copy. Section 8 sits in the same May 2027 tranche as Section 12, so this duty is also not yet operative.

It is still worth asking. A well-drafted request that asks a company to confirm which processors held your data, and whether they were instructed to erase, is a reasonable question today and a legal one from May 2027.

What can you actually do in August 2026?

Here is where the article earns its keep. The DPDP route is not open yet, but you are not without options, and several of them are the ones people skip while waiting for a law to switch on.

The frameworks that are operative now

The IT Rules 2021 grievance route. Intermediaries operating in India are required to publish a Grievance Officer with contact details and to acknowledge and dispose of complaints within prescribed timelines. This is the operative grievance mechanism for intermediaries today. Note the scope difference: these rules govern intermediaries and their grievance handling, not a general personal-data erasure right. They are a route to a named human with a duty to respond, which is often what an ignored request actually lacks.

The IT Act and the SPDI Rules 2011. Section 43A of the Information Technology Act, 2000 and the sensitive personal data rules made under it remain in force. The DPDP Act contains a consequential provision that will omit Section 43A, but that provision sits in the May 2027 tranche. Until then, the older regime is the one with legal effect for sensitive personal data.

Platform and company policy. Most large companies have account-deletion and data-deletion processes that exist independently of any statute. Using them is faster than any legal route and costs nothing.

The constitutional route. Privacy is a fundamental right under Article 21 following the nine-judge ruling in Justice K.S. Puttaswamy v. Union of India (2017). Indian High Courts have granted relief in individual matters on that basis. This is a court route, not a letter route, and it is proportionate only where the harm is serious.

The request itself, step by step

1. Identify who actually holds the data. For an app it is the company named in the privacy policy, not the brand name. For a people-search page it is whoever operates the site. If your data was passed on, more than one organisation may hold a copy.

2. Find the named grievance contact. Under the IT Rules 2021 an intermediary should publish a Grievance Officer, usually in the privacy policy or a grievance page. Write to that named person, not a general support address. From May 2027 the DPDP framework adds its own requirement for a Fiduciary to publish contact details for a Data Protection Officer or a person who can answer questions about processing, and to run a grievance mechanism.

3. Write a dated request and keep the record. Identify yourself, specify exactly which data you want erased or corrected, and say why: you have closed the account, you are withdrawing consent, the data is inaccurate. Save what you sent and when. If this ever escalates, the dated trail is the case.

4. Ask about processors and onward copies. Ask the company to confirm which processors or vendors held your data and whether they have been instructed to erase. Today that is a reasonable request. From May 2027 it is anchored in Section 8(7).

5. Follow up in writing. A second letter referencing the first, with dates, changes how a compliance team reads the file.

6. Escalate to the right forum for today. Because the Data Protection Board of India cannot yet hear complaints, escalation in 2026 means the platform's own appeal mechanism, the relevant sectoral regulator where one applies, a lawyer's notice, or a court. It does not mean the Board.

7. Run the search-results track separately. Getting data erased at source does not remove an existing search result. Our page on how to remove personal information from Google covers the search side, and for legal records specifically see deindexing of court cases.

Erasure, delisting, or suppression: which one fits your problem?

Pick the wrong remedy and you can spend six months getting nowhere while the right route sits untouched. These are four different jobs with four different odds, and only one of them is a statutory data right.

RemedyWhat it changesWho you go toStatus in August 2026
Section 12 erasureThe company's own copy of data processed on your consentThe Data FiduciaryNot in force. Commences mid-May 2027
Grievance route under the IT Rules 2021Whether a named officer at an intermediary responds and actsThe intermediary's Grievance OfficerIn force now
Right to Be Forgotten delistingWhether a link appears in search results for your nameSearch engines, often only after a court orderJudicially developed, case by case. No standalone statute
Google policy removalA narrow set of results Google's own policy coversGoogle directly, through its removal formsAvailable now, within its stated categories
SuppressionNothing is deleted. The result moves down the pageNobody. It is content and ranking workAlways available. Slow, and the content still exists

A single problem often needs two of these at once. An old page carrying your leaked form data might call for a request to the site holding it and a separate delisting effort against the search result. Treating those as one job is the mistake that stalls people.

One comparison readers make anyway: India's erasure right is drafted more narrowly than the GDPR right it gets measured against, and its enforcement machinery is younger and not yet running. That is not a reason to give up. It is a reason to be precise about which remedy you are actually using.

What Google will and will not remove

People search for a way to delete personal data from Google expecting one button. There is no such button, and understanding why saves a lot of wasted effort.

Google runs two different things. One is the source page, the actual web page where your data lives, hosted by somebody else. The other is the search result, the link pointing to it. Google does not own most source pages, so it generally cannot delete content it did not publish. What it can do is stop showing a result.

Under its own personal information removal policy, Google will consider removing results that expose categories such as your address, phone number or email, government identification numbers, financial account numbers, images of your signature or ID, private records such as medical records, and confidential login credentials. It also says newsworthiness can weigh against removal.

Google is explicit about the limit, and it is worth quoting the substance: even where Google removes something from Search, the content may still exist on the internet and people may still reach it through links, social media or other search engines. Removal from search is not deletion at source.

That cuts both ways, and it is the correction to the most common misunderstanding on this topic. Getting a company to delete its copy of your data does not automatically clear a Google result, and getting a Google result removed does not delete the underlying page. Two problems, two remedies.

For unfavourable coverage rather than raw personal data, the source-page angle is covered in our work on removing negative articles and content.

Where the Right to Be Forgotten fits

Worth separating clearly, because the phrase gets used as though India had a statute that says it. It does not.

The Right to Be Forgotten in India is judicially developed rather than codified. Its foundation is the recognition of privacy as a fundamental right in Justice K.S. Puttaswamy v. Union of India (2017), and Indian High Courts have since decided individual matters on their own facts, sometimes granting name masking or delisting and sometimes refusing it where transparency or public interest weighed more heavily. Outcomes vary between High Courts and the position is still developing.

So it is not the Indian equivalent of a GDPR erasure right, and it is not something you exercise by sending a form. In practice it usually means a court application, and it is aimed at search visibility rather than at a company's database.

Section 12 erasure and the Right to Be Forgotten are therefore different instruments pointed at different targets. One is a statutory data right against a Fiduciary that commences in 2027. The other is an evolving judicial remedy about what shows up when somebody searches your name.

Why deleted does not always mean gone

A short technical note, because it explains something people find genuinely confusing and it has nothing to do with bad faith.

When a system deletes a record, it often marks the space as reusable rather than overwriting it. The record disappears from the interface you can see while the underlying data persists until something writes over it. Engineers call this data remanence. A company can tell you in complete good faith that your data is deleted while copies still sit in places nobody checked.

The usual places are worth naming, because naming them in a follow-up changes the quality of the answer you get:

  • Backups. Snapshots taken on a schedule and stored outside the live database.
  • Logs. Application and access logs that captured details in passing.
  • Caches and search indexes. Internal copies built for speed, refreshed on their own cycles.
  • Analytics and CRM exports. Extracts living outside the main system entirely.
  • Processors. Vendors handling data on the company's behalf, which is the category Section 8(7)(b) is aimed at.

Deletion is a process rather than a moment. That is why a confirmation saying done deserves a follow-up asking what it covered: production only, or backups and processors too.

What changes in May 2027

Planning matters more than waiting. From the Stage 3 commencement date, several things become available that are not available today.

  • Section 12 becomes an enforceable right to correction, completion, updating and erasure for consent-based processing.
  • Section 8(7) obliges a Fiduciary to erase on consent withdrawal or when the purpose is served, and to cause its Processors to erase.
  • Section 13 gives a right to grievance redressal with prescribed response timelines, and requires you to exhaust the Fiduciary's own mechanism before approaching the Board.
  • Section 17 exemptions become operative, defining where the Act does not apply, including certain legal proceedings, crime prevention and investigation, and specified State functions.
  • The penalty provisions commence, which is what gives a compliance team a reason to treat a request seriously.
  • The corresponding DPDP Rules 2025 provisions on erasure, retention and procedure commence with them.

Two honest caveats. The Data Protection Board of India still has to be staffed before it can hear anything, and none of these provisions creates a right to have any content removed from the internet at large.

If you have a live problem now, the practical move is to use the routes that are open, keep a clean dated record, and be ready to re-send under Section 12 once it commences. A documented history of ignored requests is a stronger opening in 2027 than a fresh letter.

An honest closing

The DPDP Act Right to Erasure is a genuine right and it is coming. It is also not here yet, and any page telling you otherwise in 2026 is either out of date or careless with a legal topic where being careless has consequences for the reader.

So match the remedy to the moment. Use the routes that are open now: the company's own process, the Grievance Officer under the IT Rules 2021, the SPDI framework, Google's policy where it applies, and the courts where the harm is serious enough to justify it. Where nothing can be removed, suppression is the honest remaining option, though it deletes nothing. Keep a clean dated record throughout, because it makes your position stronger when Section 12 commences.

Where your real problem is search visibility rather than a database, the Right to Be Forgotten in India route is the one to study, and where a published page is the issue, see removing negative articles and content.

About FameNinja, stated separately from the legal information above. We are a reputation management firm, not a law firm. We handle removal requests, search delisting and long-term reputation work, and we work alongside your lawyer where a matter needs legal advice or court action. We do not guarantee removal, we do not promise timelines, and we will tell you when a remedy is not available. Start with our online reputation management overview or request a free assessment.

Legal disclaimer. This article is general information about Indian law and reputation practice as at 29 August 2026. It is not legal advice and no lawyer-client relationship arises from reading it. The DPDP Act 2023 is being brought into force in stages and the position described here may change. Statutory provisions are summarised, not reproduced in full, and readers should consult the official text and the relevant Gazette notifications. For advice on your specific matter, consult a qualified advocate practising in Indian data protection law.

// FAQ

Frequently asked questions

It is the right in Section 12 of the Digital Personal Data Protection Act, 2023 for a Data Principal to ask a Data Fiduciary to correct, complete, update or erase personal data processed on the basis of consent previously given. On an erasure request the Fiduciary is to erase unless retention is necessary for the specified purpose or for compliance with any law in force.