DPDP Wiki Talk to us

/The Act · Chapter III · Rights and Duties of Data Principal

Section 12: Right to correction and erasure of personal data

DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) G.S.R. 843(E)Chapter III: Rights and Duties of Data Principal
Provision
Section 12 of The Digital Personal Data Protection Act, 2023
Status
Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
Rules made under it
Rule 14
Source
Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF

Section 12. Right to correction and erasure of personal data

Verbatim from the Gazette of India
(1)

A Data Principal shall have the right to correction, completion, updating and erasure of her personal data for the processing of which she has previously given consent, including consent as referred to in clause (a) of section 7, in accordance with any requirement or procedure under any law for the time being in force.

(2)

A Data Fiduciary shall, upon receiving a request for correction, completion or updating from a Data Principal,—

(a)

correct the inaccurate or misleading personal data;

(b)

complete the incomplete personal data; and

(c)

update the personal data.

(3)

A Data Principal shall make a request in such manner as may be prescribed to the Data Fiduciary for erasure of her personal data, and upon receipt of such a request, the Data Fiduciary shall erase her personal data unless retention of the same is necessary for the specified purpose or for compliance with any law for the time being in force.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data PrincipalData Fiduciary

A Data Principal (the individual whom the data is about) has the right to ask a Data Fiduciary (the entity that decides how and why data is processed) to correct, complete, update, or erase their personal data. This right applies to personal data that is being processed because the Data Principal previously gave their consent, which includes certain situations where consent is provided for specific legitimate uses.\n\nWhen a Data Fiduciary receives a request to fix data, it must take action. The Data Fiduciary is required to correct any inaccurate or misleading personal data, fill in any incomplete personal data, and update the data as requested by the Data Principal.\n\nTo have data erased, the Data Principal must submit a request in a specific manner that will be prescribed by future rules. Once the Data Fiduciary receives this erasure request, it must delete the personal data. However, there is an exception: the Data Fiduciary does not have to erase the data if keeping it is still necessary for the original specified purpose, or if retaining the data is required to comply with any current law.

Key points

  • A Data Principal can request the correction, completion, updating, or erasure of their personal data if it is processed based on their consent. [(1)]
  • A Data Fiduciary must correct inaccurate data, complete incomplete data, and update data upon receiving a request. [(2)]
  • The exact procedure for making an erasure request will be prescribed by future rules. [(3)]
  • A Data Fiduciary must erase the personal data upon request, unless retaining it is necessary for the specified purpose or required by law. [(3)]

Common misreadings

  • A Data Fiduciary must always erase data immediately upon request; in fact, they can refuse if retention is still necessary for the specified purpose or required by law.
  • This right applies to all personal data held by a Data Fiduciary; the text specifies it applies to data for which the Data Principal previously gave consent.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.