/The Act · Chapter III · Rights and Duties of Data Principal
Section 12: Right to correction and erasure of personal data
DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.
- Provision
- Section 12 of The Digital Personal Data Protection Act, 2023
- Status
- Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
- Rules made under it
- Rule 14
- Source
- Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF
A Data Principal shall have the right to correction, completion, updating and erasure of her personal data for the processing of which she has previously given consent, including consent as referred to in clause (a) of section 7, in accordance with any requirement or procedure under any law for the time being in force.
A Data Fiduciary shall, upon receiving a request for correction, completion or updating from a Data Principal,—
A Data Principal shall make a request in such manner as may be prescribed to the Data Fiduciary for erasure of her personal data, and upon receipt of such a request, the Data Fiduciary shall erase her personal data unless retention of the same is necessary for the specified purpose or for compliance with any law for the time being in force.
A Data Principal (the individual whom the data is about) has the right to ask a Data Fiduciary (the entity that decides how and why data is processed) to correct, complete, update, or erase their personal data. This right applies to personal data that is being processed because the Data Principal previously gave their consent, which includes certain situations where consent is provided for specific legitimate uses.\n\nWhen a Data Fiduciary receives a request to fix data, it must take action. The Data Fiduciary is required to correct any inaccurate or misleading personal data, fill in any incomplete personal data, and update the data as requested by the Data Principal.\n\nTo have data erased, the Data Principal must submit a request in a specific manner that will be prescribed by future rules. Once the Data Fiduciary receives this erasure request, it must delete the personal data. However, there is an exception: the Data Fiduciary does not have to erase the data if keeping it is still necessary for the original specified purpose, or if retaining the data is required to comply with any current law.
Key points
- A Data Principal can request the correction, completion, updating, or erasure of their personal data if it is processed based on their consent. [(1)]
- A Data Fiduciary must correct inaccurate data, complete incomplete data, and update data upon receiving a request. [(2)]
- The exact procedure for making an erasure request will be prescribed by future rules. [(3)]
- A Data Fiduciary must erase the personal data upon request, unless retaining it is necessary for the specified purpose or required by law. [(3)]
Common misreadings
- A Data Fiduciary must always erase data immediately upon request; in fact, they can refuse if retention is still necessary for the specified purpose or required by law.
- This right applies to all personal data held by a Data Fiduciary; the text specifies it applies to data for which the Data Principal previously gave consent.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.