CHAPTER III - RIGHTS AND DUTIES OF DATA PRINCIPAL

Section 12 - Right to correction and erasure of personal data

Official text

(1)A Data Principal shall have the right to correction, completion, updating and erasure of her personal data for the processing of which she has previously given consent, including consent as referred to in clause (a) of section 7, in accordance with any requirement or procedure under any law for the time being in force.

(2)A Data Fiduciary shall, upon receiving a request for correction, completion or updating from a Data Principal,—

(a)correct the inaccurate or misleading personal data;

(b)complete the incomplete personal data; and

(c)update the personal data.

(3)A Data Principal shall make a request in such manner as may be prescribed to the Data Fiduciary for erasure of her personal data, and upon receipt of such a request, the Data Fiduciary shall erase her personal data unless retention of the same is necessary for the specified purpose or for compliance with any law for the time being in force.

Cross-references

Section 12

Commentary

1.1 Detailed clause-by-clause commentary read with Rule 14 of the DPDP Rules, 2025

1.2 Statutory structure

Section 12 creates four related but distinct rights:

  1. correction of inaccurate or misleading personal data;

  2. completion of incomplete personal data;

  3. updating of personal data;

  4. erasure of personal data.

The first three rights are addressed operationally in Section 12(2). Erasure is addressed separately in Section 12(3).

That separation is significant. Correction, completion and updating operate by reference to the condition of the personal data. Erasure operates by reference to whether the personal data may still be retained for the specified purpose or under another law.

Section 12 does not create an unrestricted right to have every item of personal data deleted merely because the Data Principal requests deletion. Nor does it allow a Data Fiduciary to retain information indefinitely by making a generic claim of “business necessity.” The legal position depends on the purpose, the applicable ground, the status of the data, and any legal requirement or procedure governing correction, updating, completion, erasure or retention.

2. Section 12(1): “A Data Principal shall have the right”

The opening words create an enforceable statutory entitlement in favour of the Data Principal.

A Data Principal is the individual to whom the personal data relates. In the case of a child, the statutory definition includes the parent or lawful guardian. In the case of a person with disability, it includes the lawful guardian acting on her behalf.

Depending on the circumstances, the right may therefore be exercised by:

  • the adult individual concerned;

  • the parent or lawful guardian of a child;

  • the lawful guardian of a qualifying person with disability;

  • a valid nominee under Section 14 when the statutory conditions for nomination apply.

The right does not depend upon proof that the Data Fiduciary has acted wrongfully. A Data Principal does not need to establish:

  • financial loss;

  • a personal data breach;

  • bad faith;

  • discrimination;

  • damage to reputation;

  • an intended legal proceeding.

The Data Principal must, however, identify the correction, completion, updating or erasure sought with sufficient clarity to enable the Data Fiduciary to act upon the request.

3. Four separate rights within Section 12(1)

The words “correction, completion, updating and erasure” should not be treated as interchangeable.

Each addresses a different condition.

4. Correction

Correction applies where personal data is inaccurate or misleading.

Example

Examples include:

  • an incorrect date of birth;

  • a wrong bank-account number;

  • an inaccurate employment designation;

  • a fraud marker attributed to the wrong customer;

  • a medical result linked to the wrong patient;

  • an applicant incorrectly recorded as having failed a qualification check.

Correction ordinarily involves replacing, amending or qualifying the incorrect information so that the record ceases to be inaccurate or misleading.

5. Completion

Completion applies where the information is incomplete.

The existing part of the record may be factually correct but deficient because relevant information is missing.

Example

For example:

  • an employee record states that disciplinary proceedings were initiated but omits that the employee was cleared;

  • a customer record contains a failed-payment entry but omits that the failure arose from the Data Fiduciary’s technical error;

  • an applicant’s educational record lists a degree as pending but omits the subsequently supplied completion certificate;

  • an insurance record contains a claim but omits that the claim was accepted and settled.

Completion does not require the Data Fiduciary to collect every conceivable detail about the individual. It requires completion of the personal data where incompleteness makes the record deficient for the relevant processing.

6. Updating

Updating addresses personal data that may once have been correct but is no longer current.

Example

Examples include:

  • a previous residential address;

  • an old telephone number;

  • former employment status;

  • an expired nominee;

  • an outdated bank account;

  • a change in marital or dependent status where relevant to the processing;

  • a customer’s previous communication preference.

Updating is particularly important where outdated personal data continues to influence:

  • account access;

  • delivery;

  • employment benefits;

  • insurance coverage;

  • fraud detection;

  • financial decisions;

  • communications.

7. Erasure

Erasure concerns removal of personal data from processing, subject to the exceptions in Section 12(3).

The Data Principal may request erasure, but the Data Fiduciary need not erase the information where retention remains necessary:

  • for the specified purpose; or

  • for compliance with a law in force.

Erasure therefore requires a separate retention analysis. The Data Fiduciary cannot decide an erasure request merely by asking whether the request is genuine. It must determine whether continued retention remains authorised under the statutory exceptions.

8. “Her personal data”

The right applies only to personal data relating to the requesting Data Principal.

It does not create a general right to alter or erase:

  • another person’s personal data;

  • purely corporate information;

  • a record that does not relate to an identifiable individual;

  • anonymous information;

  • business records unrelated to the requester.

A request may concern information that relates simultaneously to more than one individual.

Example

For example:

  • an email exchange may contain personal data of the requester and another employee;

  • a joint bank account contains information about both holders;

  • a complaint record contains information about the complainant, accused person and witnesses;

  • CCTV footage may contain several identifiable individuals.

Section 12 does not expressly prescribe how mixed personal data must be handled. The Data Fiduciary should correct, complete, update or erase the requesting individual’s personal data to the extent required without unnecessarily altering or disclosing another person’s information.

Like Section 11, Section 12 contains an express prior-consent limitation.

The right applies to personal data for the processing of which the Data Principal has previously given consent.

This is narrower than a universal right to correct or erase every item of personal data processed under any lawful ground.

The clearest application is where personal data is processed under Section 6 consent.

Example

Examples include:

  • account registration;

  • optional marketing;

  • loyalty programmes;

  • publication of a testimonial;

  • future applicant-pool retention;

  • voluntary research participation;

  • optional location-based services.

The Data Principal who previously gave consent may invoke Section 12 in respect of that personal-data processing.

Section 12 states:

“the right to correction, completion, updating and erasure of her personal data for the processing of which she has previously given consent.”

This suggests a connection between:

  • the personal data concerned;

  • its processing; and

  • the consent previously given.

The provision is therefore more naturally read as processing-basis-specific than as a universal right triggered merely because the Data Principal once consented to some unrelated activity carried out by the same Data Fiduciary.

Example

For example, if an employee consents to publication of a promotional photograph, that consent does not necessarily bring every payroll, security and statutory employment record within Section 12. The statutory right concerns personal data processed with the Data Principal’s prior consent, including the Section 7(a) situation.

Section 12 expressly includes processing under Section 7(a).

Section 7(a) allows a Data Fiduciary to process personal data for the specified purpose for which the Data Principal voluntarily provided it, where the Data Principal has not indicated that she does not consent to its use for that purpose.

Although Section 7(a) is classified as a certain legitimate use rather than Section 6 consent, Section 12 expressly extends correction and erasure rights to that relationship.

12. Pharmacy illustration

A customer supplies a mobile number to receive a digital receipt.

If the pharmacy records the wrong number, the customer may request correction.

If the number is missing a digit, she may request completion.

If the customer later changes the number while the transaction-related purpose remains active, she may seek updating where relevant.

Once the receipt purpose is served, she may request erasure, subject to any lawful retention requirement.

13. Real-estate broker illustration

An individual gives a broker her contact details, budget and housing preferences to locate a rented property.

She may request:

  • correction of an incorrect budget;

  • completion of missing locality preferences;

  • updating of her move-in date;

  • erasure after she no longer requires the broker’s assistance.

Section 7(a) itself also requires the broker to stop processing once she indicates that assistance is no longer required. Section 12 provides a corresponding rights mechanism.

14. Processing under other Section 7 grounds

Section 12 does not expressly extend to every legitimate use under Section 7.

The other grounds include:

  • State benefits and services;

  • State functions;

  • legally required disclosures;

  • compliance with judgments and orders;

  • medical emergencies;

  • epidemics or public-health threats;

  • disasters;

  • employment.

The text does not state that correction and erasure rights apply universally to all personal data processed under those grounds.

This limitation matters significantly.

15. Employment

An employer may process salary, attendance, access logs and employment records under Section 7(i).

If the processing rests solely on Section 7(i), Section 12’s prior-consent condition may not be satisfied.

It should therefore not be stated without qualification that Section 12 creates a universal employee right to alter or erase the complete employment file.

Other provisions remain relevant. In particular, Section 8(3) requires completeness, accuracy and consistency where personal data is likely to be used for an affecting decision or disclosed to another Data Fiduciary. An employer may therefore be independently obligated to correct inaccurate information even where Section 12’s consent-based right is unavailable.

16. Medical emergency

A hospital may process information about an unconscious person under Section 7(f). The patient may not previously have consented to that processing.

Section 12 may therefore not apply on its literal terms to that emergency processing. Other healthcare laws, professional duties, Section 8(3), and the hospital’s own record-correction procedures may nevertheless require accurate and complete records.

17. State processing

The State may process personal data under Section 7(b) or 7(c) without consent.

Section 12 does not create a general right against every such processing operation. Correction or erasure may instead be governed by:

  • the law under which the State performs the function;

  • the relevant scheme;

  • administrative procedure;

  • public-record requirements;

  • another statutory right.

The phrase “in accordance with any requirement or procedure under any law” becomes particularly important in these situations.

18. Interaction with Section 8(3)

Section 12 and Section 8(3) should be distinguished.

Section 12 creates a right exercisable by the Data Principal where its consent-related condition is satisfied.

Section 8(3) imposes an independent obligation on the Data Fiduciary where personal data is likely to be:

  • used to make a decision affecting the Data Principal; or

  • disclosed to another Data Fiduciary.

In those circumstances, the Data Fiduciary must ensure completeness, accuracy and consistency.

Therefore:

SECTION 12

A request-based right connected with prior consent or the Section 7(a) relationship

SECTION 8(3)

A proactive Data Fiduciary obligation concerning affecting decisions and disclosures

A Data Fiduciary should not retain information it knows is inaccurate merely because it considers the Data Principal ineligible to exercise Section 12.

Example

For example, an employer that discovers an incorrect disciplinary finding in an employee’s record cannot knowingly use that inaccurate record for a promotion decision merely because employment processing rests on Section 7(i).

19. “In accordance with any requirement or procedure under any law for the time being in force”

This phrase qualifies the Section 12 rights.

Correction, completion, updating and erasure must operate consistently with requirements and procedures imposed by other applicable laws.

Section 12 does not override every recordkeeping, evidentiary or sectoral rule.

20. Sectoral correction procedures

Another law may prescribe:

  • documents required to change a legally recorded name;

  • evidence required to amend a date of birth;

  • procedure for correcting tax records;

  • process for amending educational certificates;

  • method for changing ownership or licence details;

  • formal medical-record amendment procedures.

The Data Principal must follow those requirements where applicable.

21. Records that cannot simply be rewritten

Certain records may need the original entry to remain visible, together with a correction or annotation.

Example

For example:

  • accounting records;

  • transaction records;

  • audit trails;

  • medical records;

  • records used in litigation;

  • regulated registers.

Section 12 does not necessarily require destruction of the historical entry where another law requires preservation of the original record.

Correction may instead require:

  • retaining the original entry;

  • marking it as incorrect;

  • recording the correct information;

  • preserving the date and source of correction;

  • preventing continued reliance on the inaccurate version.

22. “For the time being in force”

The expression directs the Data Fiduciary to the law applicable when the request is handled.

If retention or correction requirements change, the organisation should apply the law then in force.

A contract, internal policy or business custom is not itself “law for the time being in force.” The Data Fiduciary should not treat an internal retention preference as a statutory requirement.

23. Section 12(2): “Upon receiving a request”

The duties in subsection (2) arise upon receipt of a request from the Data Principal.

The Data Fiduciary is not required by Section 12(2) to correct every record automatically without any request. However, Section 8(3) may independently require proactive accuracy in affecting decisions and disclosures.

The request should enable the Data Fiduciary to determine:

  • the Data Principal’s identity;

  • the personal data concerned;

  • whether correction, completion or updating is sought;

  • the proposed accurate or additional information;

  • any legally required supporting evidence.

The Act does not require the Data Principal to use precise legal labels.

A request stating:

“My profile still shows my old address. Please replace it with my current address”

is substantively an updating request even if the person does not use the word “updating.”

24. Rule 14: Means of making the request

In the final DPDP Rules, the rights procedure appears in Rule 14.

The Data Fiduciary and, where applicable, the Consent Manager must prominently publish on the website or application:

  • the means through which the Data Principal may exercise rights; and

  • the particulars required to identify her under the terms of service.

The Data Principal may then exercise the right using the published means and supplying the required particulars.

25. Prominent publication

The request mechanism should be reasonably visible and usable.

A route may not be prominent where it is:

  • buried in lengthy terms;

  • hidden behind unrelated support categories;

  • unavailable to former users;

  • accessible only through a closed account;

  • described in unclear language.

The Rule does not prescribe a particular button, page location or user-interface design. It requires practical prominence.

26. Permissible means

The Data Fiduciary may use:

  • an account setting;

  • online form;

  • privacy portal;

  • email address;

  • application feature;

  • another published mechanism.

The Rules do not require one universal format.

Where applicable, a Consent Manager may facilitate exercise of rights. The duty to correct or erase remains with the relevant Data Fiduciary that processes the personal data.

28. Identification particulars

Rule 14 permits the Data Fiduciary to require particulars needed to identify the Data Principal.

An “identifier” may include:

  • customer identification file number;

  • customer acquisition form number;

  • application reference number;

  • enrolment ID;

  • email address;

  • mobile number;

  • licence number.

The identity process serves two functions:

  1. locating the relevant record;

  2. preventing unauthorised alteration or erasure.

An attacker who successfully submits a false erasure request could cause loss or interruption of services. A person who changes another individual’s bank details could cause direct financial harm. Appropriate identity verification is therefore part of protecting the integrity of personal data.

At the same time, verification should not be used to obstruct the right.

Where the request comes from an authenticated account, a complete identity document may be unnecessary unless the nature of the request or record creates additional risk.

The Data Fiduciary should not require Aadhaar or another high-detail identifier merely because it is administratively convenient, unless law or genuine risk justifies it.

29. Verification of the substance of a correction request

Identity verification establishes who is making the request. It does not establish that the proposed correction is accurate.

The Data Fiduciary may need to verify the substance of the requested change.

Example

For example:

  • changing a delivery address may require no documentary proof;

  • changing a date of birth in a regulated record may require supporting evidence;

  • changing a legal name may require prescribed documents;

  • disputing a fraud classification may require investigation;

  • correcting a medical entry may require review by an authorised professional.

The evidence should correspond with:

  • significance of the field;

  • risk of fraud;

  • applicable law;

  • effect on other persons;

  • consequences of error.

The Data Fiduciary should not require disproportionate evidence for simple, low-risk changes.

30. Section 12(2)(a): Correct inaccurate personal data

The Data Fiduciary must correct inaccurate personal data after receiving a valid request.

“Inaccurate” means the personal data is factually wrong in the context in which it is processed.

Example

Examples include:

  • incorrect name spelling;

  • wrong account number;

  • incorrect transaction attribution;

  • wrong employment status;

  • misidentified person in CCTV metadata;

  • false record of non-payment;

  • incorrect qualification status.

31. Objective facts

Correction is generally straightforward where the dispute concerns an objectively verifiable fact.

If the customer’s address is wrong and reliable evidence establishes the correct address, the incorrect field should be amended.

32. Contested facts

Difficulty arises where the parties disagree about events.

Example

For example, an employer’s record states that an employee engaged in misconduct. The employee denies it.

Section 12 does not provide a mini-trial procedure for contested allegations.

The Data Fiduciary should distinguish:

  • factual statement;

  • allegation;

  • conclusion;

  • opinion;

  • investigation outcome.

A record may be corrected by changing:

“Employee committed theft”

to:

“A theft allegation was made against the employee; the allegation remains disputed and no final finding has been made.”

The correction may concern the inaccurate presentation of an allegation as an established fact.

33. “Misleading personal data”

Section 12(2)(a) covers personal data that is inaccurate or misleading.

Information can be literally accurate but misleading because it lacks context or creates a false impression.

34. Disciplinary example

The record states:

“Employee was suspended on 10 January.”

That fact may be accurate. If the record is used without noting that the suspension was revoked and the employee was cleared, it may be misleading.

35. Payment example

A record states:

“Customer failed to make payment by the due date.”

If the payment failed because the Data Fiduciary’s system rejected a valid payment, the statement may be misleading without that context.

36. Applicant example

A recruitment record states:

“Candidate withdrew.”

If the application was automatically closed because the platform failed to send an interview notification, the description may be misleading.

Correction may therefore require:

  • qualification;

  • annotation;

  • contextual information;

  • removal of an incorrect implication.

37. Opinions and professional judgments

Personal data may include opinions, evaluations and professional judgments.

Example

Examples include:

  • manager performance comments;

  • medical opinions;

  • credit assessments;

  • interview evaluations;

  • complaint conclusions.

An opinion is not necessarily inaccurate because the Data Principal disagrees with it.

The Data Fiduciary should ask whether the record accurately represents:

  • whose opinion it is;

  • when it was formed;

  • the information considered;

  • whether it remains operative;

  • whether later facts materially altered it.

Example

For example, the Data Principal may not have a Section 12 right to replace a manager’s genuinely held evaluation with the employee’s preferred evaluation. However, she may request correction where:

  • the evaluation is attributed to the wrong manager;

  • it relies on demonstrably incorrect attendance data;

  • it is recorded as a proven fact rather than opinion;

  • a successful appeal is omitted;

  • the opinion has been altered or misquoted.

Completion may also permit recording the Data Principal’s rebuttal or later review where needed to prevent the record from being misleading.

38. Section 12(2)(b): Complete incomplete personal data

Completion concerns material omission.

A record may be incomplete where the absence of information affects its meaning, reliability or use.

Example

Examples include:

  • a medical file records an initial diagnosis but omits the corrected diagnosis;

  • a disciplinary file records suspension but omits exoneration;

  • a loan record has default information but omits settlement;

  • an applicant file omits documents submitted before the deadline;

  • an insurance file omits a dependent validly enrolled.

39. Completion does not mean unlimited collection

The Data Fiduciary need not add every detail the Data Principal wants included.

The missing information should be relevant to the personal data and the processing purpose.

A customer cannot require an e-commerce provider to add an unrelated biography to an order record merely because the biography concerns her.

Completion should make the relevant record sufficiently whole for the purpose for which it is processed.

40. Completion through supplementary statement

In some circumstances, the correct method may be addition of a supplementary statement rather than alteration of the historical record.

Example

For example:

  • original diagnosis preserved;

  • later medical opinion added;

  • original allegation retained;

  • final exoneration recorded prominently.

This approach may satisfy both:

  • accuracy and completeness;

  • legal requirements to preserve original records.

41. Section 12(2)(c): Update personal data

Updating applies where information has changed over time.

A field may have been accurate when collected but no longer reflect the current position.

Example

Examples include:

  • address;

  • phone number;

  • email;

  • employment role;

  • dependent status;

  • nominee;

  • licence status;

  • payment details.

42. When current information matters

Updating is especially important where current information affects:

  • communication;

  • account security;

  • benefits;

  • delivery;

  • payments;

  • eligibility;

  • access.

43. Historical information

The right to update does not necessarily require deletion of historically accurate information.

If a customer changes address, the current account should be updated. The Data Fiduciary may still retain the historical delivery address where necessary for:

  • transaction history;

  • legal requirements;

  • fraud investigation;

  • accounting.

The record should distinguish:

  • former address;

  • current address.

Replacing every historical occurrence with the new address could make prior transaction records inaccurate.

44. Time-sensitive status

Updating may require a system capable of recording effective dates.

Example

For example:

  • employee transferred from Department A to Department B on 1 July;

  • licence expired on 30 June;

  • nominee changed on 15 August.

The Data Fiduciary should not overwrite history in a way that falsely represents the earlier period.

45. Propagation of correction, completion and updating

Section 12(2) directs the Data Fiduciary receiving the request to correct, complete or update the personal data.

The subsection does not expressly state that the Data Fiduciary must notify every previous recipient of the correction.

However, several related obligations are relevant.

If the personal data is likely to be:

  • used for an affecting decision; or

  • disclosed to another Data Fiduciary,

Section 8(3) requires completeness, accuracy and consistency.

A correction made only in one visible interface while inaccurate data remains active in:

  • a decision engine;

  • processor system;

  • reporting database;

  • downstream disclosure flow;

may fail to resolve the underlying inaccuracy.

46. Data Processors

Because the Data Fiduciary remains responsible for processor activities under Section 8(1), it should ensure that current processor-held records are corrected where necessary.

A customer changing her address should not have the old address continue in the active delivery system merely because the customer-profile database was updated.

47. Other Data Fiduciaries

The Act does not expressly prescribe a universal duty to command an independent recipient to alter its records.

The originating Data Fiduciary should at least avoid future disclosure of inaccurate data. Where the recipient continues to rely on the incorrect information, the original Data Fiduciary may need to take reasonable steps consistent with Section 8(3), the applicable relationship and other law.

The recipient, as a separate Data Fiduciary, must determine its own compliance obligations.

48. Derived data, inferences and scores

Correction rights become difficult where the personal data is inferred rather than directly supplied.

Example

Examples include:

  • fraud-risk score;

  • credit category;

  • customer segment;

  • applicant ranking;

  • performance prediction;

  • inferred interest.

The Data Principal may dispute either:

  1. an underlying factual input; or

  2. the inference itself.

49. Incorrect input

If an applicant-ranking model uses an incorrect employment date, the underlying personal data should be corrected.

The Data Fiduciary should determine whether:

  • the score must be recalculated;

  • the prior decision must be reviewed;

  • the corrected data must be transmitted to the processor;

  • the inaccurate version remains active elsewhere.

50. Disputed inference

An inference is not automatically inaccurate merely because the Data Principal disagrees with it.

The Data Fiduciary should assess:

  • whether the inference is presented as fact;

  • whether the method used correct data;

  • whether the inference remains current;

  • whether material context is missing;

  • whether the label is misleading;

  • whether the processing purpose remains valid.

Example

For example, a model output stating “high risk of attrition” is a prediction, not a fact that the employee intends to resign. Recording it as “employee will resign” would be misleading.

Section 12 does not create a general right to demand that every adverse prediction be replaced with a favourable one. It does require personal data to be corrected where it is inaccurate or misleading and completed where materially incomplete.

51. AI model training and correction

Where inaccurate personal data has entered an AI training dataset, correction is technically and legally complex.

Different objects may exist:

  • source record;

  • training copy;

  • feature store;

  • embedding;

  • model parameters;

  • generated profile;

  • output;

  • logs.

The clearest Section 12 obligation is to correct the inaccurate personal data being processed by the Data Fiduciary.

The Act does not expressly prescribe:

  • machine unlearning;

  • retraining after every correction;

  • removal of influence from model weights;

  • destruction of the entire model.

The Data Fiduciary should nevertheless determine whether the inaccurate personal data continues to be processed through:

  • retrievable training records;

  • active features;

  • individual profiles;

  • future outputs.

Correcting the source database while continuing to use the known inaccurate feature for affecting decisions would not meaningfully satisfy the correction right.

The appropriate technical response depends on the architecture. The law should not be overstated as containing a universal machine-unlearning requirement.

52. Section 12(3): Separate erasure request

Subsection (3) provides that the Data Principal shall make an erasure request in the prescribed manner.

Erasure is therefore request-driven under Section 12.

This is distinct from Section 8(7), which independently obliges the Data Fiduciary to erase personal data when:

  • the Data Principal withdraws consent; or

  • it is reasonable to assume that the specified purpose is no longer being served, whichever occurs earlier, unless retention is necessary for compliance with law.

The relationship is:

SECTION 8(7)

Proactive Data Fiduciary erasure obligation

SECTION 12(3)

Data Principal’s request-based erasure right

A Data Fiduciary cannot retain data indefinitely merely because no Section 12 request has been made if Section 8(7) already requires erasure.

53. “Upon receipt of such a request, the Data Fiduciary shall erase”

Once a valid request is received, erasure is mandatory unless one of the stated retention exceptions applies.

The word “shall” means the Data Fiduciary must either:

  • erase the personal data; or

  • establish that retention remains necessary for the specified purpose or under law.

The subsection does not authorise continued retention merely because:

  • storage is inexpensive;

  • the data might be useful;

  • the organisation prefers historical analytics;

  • the information may assist future marketing;

  • deletion is technically inconvenient;

  • the customer might return.

The relevant test is necessity under one of the statutory exceptions.

54. Meaning of erasure

The Act does not define a separate technical standard for erasure in Section 12.

Erasure should ensure that the personal data is no longer processed for the erased purpose and is removed from active use, subject to justified retained copies.

Depending on the system, erasure may involve:

  • deletion;

  • destruction;

  • removal of account association;

  • irreversible anonymisation;

  • deletion instructions to processors;

  • removal from active datasets;

  • expiry from backups under a controlled cycle.

Simple suppression may not amount to erasure if the personal data remains fully accessible and available for ordinary use.

Conversely, restricted retention under a legal obligation is not necessarily inconsistent with erasure of the data from ordinary commercial use.

55. First exception: Retention necessary for the specified purpose

The Data Fiduciary may refuse or defer erasure where retention remains necessary for the specified purpose.

“Specified purpose” means the purpose referred to in the notice given to the Data Principal under Section 5.

This prevents erasure from undermining an active purpose that the Data Principal originally authorised.

56. Active service

A customer asks an online marketplace to erase the delivery address while an order is in transit.

The marketplace may need to retain the address until delivery or cancellation is completed because it remains necessary for the specified purpose.

It should not retain the address indefinitely after the purpose ends merely because it was previously necessary.

57. Pending refund

A customer asks for erasure while a refund is pending.

The Data Fiduciary may retain the information necessary to complete the refund.

It should distinguish between:

  • information required for refund;

  • information used for marketing;

  • information no longer necessary.

58. Open complaint

Personal data may remain necessary to investigate and resolve an active complaint initiated by the Data Principal.

Once the complaint and related purpose conclude, continued retention requires further justification.

59. Necessity is data-specific

The fact that some personal data remains necessary does not justify retaining every field.

If a pending refund requires:

  • order number;

  • payment reference;

  • bank or payment information;

it may not require:

  • browsing history;

  • marketing profile;

  • advertising identifier;

  • precise location history.

The Data Fiduciary should retain only what remains necessary for the specified purpose.

A tension can arise where the Data Principal both:

  • withdraws consent; and

  • requests erasure.

Section 8(7) requires erasure upon withdrawal unless retention is necessary for compliance with law. Section 12(3) allows retention where necessary for the specified purpose or legal compliance.

The better reading is that the Data Fiduciary cannot rely on an ordinary consent-dependent specified purpose after the Data Principal has withdrawn consent, because the basis for continuing that purpose has ended.

However, limited processing may continue where required to:

  • complete cessation;

  • settle consequences of withdrawal;

  • comply with law;

  • preserve necessary records under another lawful basis.

Example

For example, withdrawal of marketing consent ends the marketing purpose. The Data Fiduciary cannot invoke that same marketing purpose to retain the profile.

61. Second exception: Compliance with law

The Data Fiduciary may retain personal data where retention is necessary for compliance with a law in force.

This exception should be interpreted precisely.

The Data Fiduciary should identify:

  • the applicable law;

  • the relevant provision;

  • the data required;

  • the retention period;

  • the purpose;

  • the date when erasure will occur.

A broad statement such as:

“We retain information for legal and business purposes”

does not demonstrate necessity for compliance with law.

62. Banking example

A customer closes a bank account and requests erasure. Banking law may require retention of specified identity and transaction records for a prescribed period.

The bank may retain those records for that period.

The exception does not automatically permit:

  • continued marketing;

  • unrestricted employee access;

  • unrelated profiling;

  • retention beyond the legal period.

63. Tax and accounting

Tax or accounting law may require retention of invoices, payment information or transaction records.

The Data Fiduciary may retain the legally required information while erasing unrelated customer-profile data.

Where another law, court order or legally applicable preservation obligation requires retention, the Data Fiduciary may retain the relevant records.

The preservation should be:

  • limited to relevant personal data;

  • access restricted;

  • reviewed after the proceeding or preservation period ends.

65. Contractual obligations

A contract alone is not “law for the time being in force.”

The Data Fiduciary cannot rely solely on:

  • its terms of service;

  • a customer contract;

  • a processor agreement;

  • an internal policy;

as the legal-compliance exception.

A contract may be relevant to the specified purpose, but it is not equivalent to a statutory retention requirement.

66. Partial erasure

Section 12(3) does not require an all-or-nothing response.

Different categories may have different retention justifications.

Example

For example, after account closure:

Data categoryPossible treatment
Marketing profileErase if no continuing purpose or ground
Account preferencesErase if no longer needed
Transaction invoiceRetain if tax law requires
Identity recordRetain only if an applicable law requires
Security logRetain for the applicable Rule 6 period
Complaint recordRetain only while necessary for legal or complaint purposes
Processor copiesErase or restrict consistently with the Data Fiduciary’s decision

The Data Fiduciary should explain partial retention by category rather than issue a blanket refusal.

67. Processor erasure

Section 12(3) directs the Data Fiduciary to erase the personal data.

Section 8(7)(b) separately requires the Data Fiduciary to cause its Data Processor to erase personal data made available to the processor.

Accordingly, a Section 12 erasure process should not stop at the Data Fiduciary’s primary database.

It should address active personal-data copies held by:

  • cloud providers;

  • payroll providers;

  • customer-support vendors;

  • marketing processors;

  • AI vendors;

  • document-management providers;

  • subprocessors acting within the processing chain.

The Data Fiduciary remains responsible under Section 8(1).

A processor contract should therefore support:

  • deletion instruction;

  • confirmation;

  • subprocessor propagation;

  • treatment of backups;

  • termination;

  • legal-retention segregation.

A processor’s general desire to retain data for “service improvement” does not permit the Data Fiduciary to disregard its statutory obligations.

68. Separate Data Fiduciaries

Where personal data was disclosed to another Data Fiduciary acting for its own purpose, the original Data Fiduciary does not necessarily control that recipient’s retention.

The receiving Data Fiduciary must independently determine:

  • its lawful ground;

  • purpose;

  • legal retention;

  • erasure obligations.

Section 12(3) does not expressly require the original Data Fiduciary to command every independent Data Fiduciary to erase its records.

The Data Principal may need to direct a separate request to the recipient, provided Section 12’s prior-consent condition is satisfied in relation to that recipient.

The originating Data Fiduciary should not continue further disclosures once the relevant processing basis or purpose has ended.

69. Backups

Erasure from backups raises practical questions not fully answered by Section 12.

A backup may be:

  • inaccessible in ordinary operations;

  • retained for disaster recovery;

  • immutable for a limited period;

  • overwritten according to a fixed cycle.

The Act does not expressly require immediate reconstruction of every backup to remove a single record.

A defensible process may involve:

  • immediate erasure from active systems;

  • restriction against restoration for ordinary use;

  • expiry from backups according to the controlled cycle;

  • reapplication of the erasure if a backup is restored;

  • documentation of the retention basis and period.

The Data Fiduciary should not rely on “backup” as a label for indefinitely accessible duplicate databases.

If employees can search and use the backup normally, it is effectively active storage rather than a restricted recovery copy.

70. Anonymisation as erasure

Irreversible anonymisation may achieve the practical result of erasure where the information can no longer identify the individual.

Pseudonymisation is different.

Replacing a name with a customer number does not erase personal data if the customer can still be identified through:

  • a mapping table;

  • account linkage;

  • device identifier;

  • other information.

For anonymisation to function as erasure, re-identification must not remain reasonably possible in the circumstances.

Section 12 does not prescribe a formal anonymisation standard. The Data Fiduciary bears the risk of calling information anonymous when it remains personal data.

71. AI models, embeddings and erasure

Erasure in AI systems must be analysed at the level of the actual personal-data objects.

Potential objects include:

  • source records;

  • training files;

  • feature stores;

  • embeddings;

  • vector databases;

  • prompts;

  • conversation logs;

  • user profiles;

  • outputs;

  • model parameters.

72. Retrievable personal data

If the Data Principal’s record remains retrievable in:

  • training dataset;

  • vector database;

  • prompt log;

  • feature store;

it remains a clear candidate for erasure unless retention is justified.

73. Model parameters

The Act does not state that every trained model parameter is personal data merely because personal data contributed to training.

Nor does it prescribe a universal machine-unlearning obligation.

The relevant questions include:

  • whether the model can reproduce the Data Principal’s information;

  • whether the individual is identifiable from the model output;

  • whether a separate profile remains;

  • whether the source information is retained;

  • whether future processing continues to use an identifiable representation.

A Data Fiduciary should not claim complete erasure if the individual’s retrievable profile remains active in the AI architecture. Equally, Section 12 should not be overstated as automatically requiring destruction of every model trained on any personal data.

74. CCTV erasure

A Data Principal may request erasure of identifiable CCTV footage where Section 12 applies.

The Data Fiduciary must assess:

  • prior-consent condition;

  • whether the footage remains stored;

  • whether the specified security purpose continues;

  • whether an incident is under investigation;

  • whether another law requires retention;

  • whether the footage relates to other individuals.

An incident under active investigation may justify temporary retention for the specified purpose or legal compliance.

Routine footage whose purpose has ended should be erased according to the applicable retention cycle.

Section 12 does not necessarily require the Data Fiduciary to edit a multi-person recording to remove one individual immediately where the recording remains necessary for a lawful purpose. Once no exception applies, continued identifiable retention requires justification.

75. Employment records

Employment records may rest primarily on Section 7(i), creating the threshold issue under Section 12(1).

Where Section 12 does apply, the employer must still distinguish among different records.

75.1 Correction

An incorrect salary, designation, bank account or attendance record may require correction.

75.2 Completion

An investigation record omitting the employee’s exoneration may require completion.

75.3 Updating

Contact, dependent or bank details may require updating.

75.4 Erasure

Some optional employee information may be erased when no longer necessary. Other information may remain subject to:

  • employment purpose;

  • statutory retention;

  • claims;

  • tax and payroll law.

Separately, Section 8(3) requires accuracy, completeness and consistency where employment data is used for affecting decisions or disclosures. The employer cannot knowingly rely on inaccurate records merely because it disputes the availability of Section 12.

76. Marketing data

Marketing data commonly rests on consent, making Section 12 directly relevant.

The Data Principal may request correction or updating of:

  • name;

  • contact information;

  • stated preferences;

  • interest profile;

  • consent status.

She may also request erasure.

Where consent is withdrawn, Section 8(7) independently requires erasure unless legal retention applies.

77. Suppression lists

A Data Fiduciary may need to retain minimal information in a suppression list to ensure that the individual is not marketed to again.

This creates a distinction between:

  • retaining the full marketing profile; and

  • retaining a minimal “do not contact” record.

The purpose of the suppression record is to honour the withdrawal or objection rather than continue marketing.

The Data Fiduciary should limit:

  • fields;

  • access;

  • use;

  • retention.

The suppression record should not be used to rebuild the marketing profile.

78. Children’s data

For a child, the parent or lawful guardian may exercise Section 12 as part of the statutory definition of Data Principal.

Potential requests include:

  • correction of age or school information;

  • completion of educational records;

  • updating parent contact details;

  • erasure of an optional service profile;

  • removal of photographs;

  • correction of behavioural or learning classifications.

The Data Fiduciary must also consider Section 9.

Even valid parental consent cannot authorise processing likely to harm the child’s well-being or prohibited tracking and targeted advertising outside an applicable exemption.

Where the child reaches eighteen, the Data Fiduciary should ensure that the now-adult individual can exercise Section 12 directly. A former parent’s request should not automatically control the adult’s personal data.

79. Persons with disabilities and lawful guardians

A lawful guardian may act on behalf of the qualifying person with disability.

The Data Fiduciary should verify the guardian’s authority according to Rule 11 and applicable guardianship law.

Disability alone does not entitle a family member or caregiver to alter or erase another person’s records.

Where the individual is capable of decision-making with appropriate support, the Data Fiduciary should enable the individual to exercise the right directly through accessible means.

80. Historical records and audit trails

Correction does not always require overwriting the historical record.

A regulated system may need to preserve an audit trail showing:

  • original value;

  • corrected value;

  • date of correction;

  • person authorising the correction;

  • reason.

This may be necessary for:

  • transaction integrity;

  • record accountability;

  • fraud prevention;

  • legal compliance.

The historical value should not remain active as though it were current and accurate.

Example

For example, an original incorrect bank-account entry may remain in a restricted audit log while the active payroll system uses the corrected account.

The Data Fiduciary should ensure that users and systems do not continue relying on the superseded value.

81. Consequences of correction for prior decisions

Section 12 does not expressly create a right to reopen every prior decision made using inaccurate personal data.

However, if a current or continuing decision rests on data now known to be inaccurate or misleading, correction of the field alone may not resolve the effect.

The Data Fiduciary should determine whether:

  • a score should be recalculated;

  • an active classification should be changed;

  • a blocked account should be reviewed;

  • an employment outcome remains operative;

  • a recipient should be informed.

Section 8(3) is particularly relevant where the data was used to make an affecting decision.

A past decision that is complete and legally final may be governed by another applicable procedure. Section 12 itself does not prescribe an appeal regime for substantive decisions.

82. Fraudulent or disputed correction requests

Section 15 requires Data Principals to furnish verifiably authentic information while exercising correction or erasure rights.

A Data Fiduciary may therefore reject or investigate a request based on:

  • forged documents;

  • impersonation;

  • manipulation;

  • false supporting information.

The existence of Data Principal duties does not relieve the Data Fiduciary of its own Section 8 and Section 12 obligations.

A suspicious request should be assessed rather than automatically refused without reason.

The Data Fiduciary should preserve evidence of:

  • identity verification;

  • documents reviewed;

  • inconsistency found;

  • reasons for refusal;

  • grievance route.

83. Response time

Section 12 does not prescribe a fixed period within which a correction, completion, updating or erasure request must be completed.

Rule 14(3) requires the Data Fiduciary and Consent Manager to publish a grievance-response period that is reasonable and does not exceed ninety days. That provision concerns grievances, not expressly the initial rights request.

It would therefore be inaccurate to state that Section 12 requests universally carry a ninety-day statutory response time.

Nevertheless, the right must be practically effective. Unreasonable delay may lead to a grievance under Section 13.

The Data Fiduciary should adopt an operational period appropriate to:

  • request complexity;

  • systems involved;

  • identity verification;

  • legal-retention analysis;

  • processor involvement.

The organisation should not use the absence of a fixed statutory deadline to delay requests indefinitely.

84. Refusal and partial refusal

Section 12 does not prescribe a detailed refusal format.

A request may be refused or partially refused where:

  • the requester cannot be identified;

  • the data relates to another person;

  • the proposed correction is not substantiated;

  • the information is not inaccurate, misleading, incomplete or outdated;

  • Section 12’s prior-consent condition is not met;

  • the specified purpose still requires retention;

  • another law requires retention;

  • another law prescribes a different procedure.

A reasoned response should identify, where applicable:

  • what was corrected;

  • what was completed;

  • what was updated;

  • what was erased;

  • what was retained;

  • the retention basis;

  • the grievance route.

Where another law requires confidentiality, the explanation may need to be limited accordingly.

85. Rule 14(3): Grievance redressal

If the Data Principal is dissatisfied with:

  • failure to respond;

  • refusal;

  • incomplete correction;

  • continued use of outdated data;

  • processor non-erasure;

  • unjustified legal-retention claims;

she may invoke the grievance mechanism under Section 13.

Rule 14 requires the Data Fiduciary to publish the grievance-response period, which must be reasonable and cannot exceed ninety days, and to implement technical and organisational measures to respond within that period.

The grievance mechanism should be capable of reviewing the original rights decision rather than merely repeating it automatically.

For an SDF, the DPO is the statutory grievance point of contact under Section 10.

86. What Section 12 does not create

Section 12 should not be expanded beyond its text.

It does not expressly create:

  • a universal right to correction and erasure for every Section 7 ground;

  • a right to rewrite genuinely held opinions;

  • a right to delete legally required records;

  • a right to erase data still necessary for the specified purpose;

  • a right to destroy every historical audit trail;

  • a universal machine-unlearning duty;

  • a right to require every independent recipient to erase information;

  • a fixed thirty-, sixty- or ninety-day response period;

  • a right to have every prior decision automatically reversed;

  • a general right to data portability;

  • a right to delete another individual’s personal data.

Those matters may be affected by other provisions or laws. They should not be attributed to Section 12 without a legal basis.

87. Consolidated interpretation

Section 12 creates four separate consent-connected rights.

Correction applies to inaccurate or misleading personal data. Completion applies where relevant information is missing. Updating applies where information has changed and the active record no longer reflects the current position. Erasure applies where continued retention is not necessary for the specified purpose or under law.

The prior-consent condition is fundamental. The right extends expressly to Section 7(a), but it does not expressly extend to every other legitimate use under Section 7. This does not allow a Data Fiduciary to use inaccurate information freely, because Section 8(3) separately requires completeness, accuracy and consistency for affecting decisions and disclosures.

Other applicable laws may prescribe the evidence, procedure or record-preservation method for correction and erasure. Section 12 does not authorise the alteration of regulated records in a manner that destroys legally required history.

The duties in Section 12(2) are mandatory upon a valid request. Correction may require annotation rather than simple overwriting. Completion may require adding a later outcome. Updating should distinguish current information from historically accurate information.

Erasure under Section 12(3) is not absolute. The Data Fiduciary may retain personal data only where necessary for the specified purpose or legal compliance. Those exceptions should be applied at the level of particular data categories, not as a blanket justification for retaining the whole profile.

Section 12 must be read with Section 8(7). The Data Fiduciary already bears a proactive duty to erase data when consent is withdrawn or the purpose ends, subject to legal retention. A Data Principal should not need to make a Section 12 request where Section 8 already requires erasure.

Processors form part of the Data Fiduciary’s compliance chain. Correction and erasure must be operationally propagated where processor-held data remains active. Independent Data Fiduciaries require their own legal analysis.

Key point

The controlling proposition is:

Key point

Section 12 requires a Data Fiduciary to ensure that consent-based personal data remains accurate, complete and current, and to erase it upon request unless continued retention is demonstrably necessary for the specified purpose or required by law. The right protects the integrity and lifecycle of personal data, but it does not authorise the rewriting of history, the deletion of legally required records or the erasure of data still necessary for an active specified purpose.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.