Back to Rights of Data Principals
Right to Correction and Erasure
Understanding the Data Principal's right to request correction of inaccurate data and erasure of personal data under the DPDPA.
7 min read
Statutory Framework
Section 12 of the DPDPA grants Data Principals the right to request correction of inaccurate or misleading personal data, completion of incomplete data, updating of personal data, and erasure of personal data that is no longer necessary for the purpose for which it was collected.
This right is essential for maintaining data accuracy and ensuring that personal data does not persist beyond its useful life. It operates alongside the Data Fiduciary's obligations under the Act to erase personal data when the purpose has been fulfilled or consent is withdrawn.
Right to Correction and Completion
Data Principals can request that inaccurate personal data be corrected and incomplete data be completed. The Data Fiduciary must act upon such requests unless there is a reasonable basis for believing the data is accurate, or if the correction is not feasible due to technical or legal constraints.
The right to correction is particularly important in contexts where personal data is used for decision-making - such as credit scoring, insurance underwriting, or employment decisions. Inaccurate data in these contexts can cause significant harm to individuals.
Right to Erasure
The right to erasure allows Data Principals to request deletion of their personal data when: (a) the data is no longer necessary for the purpose for which it was collected; (b) the Data Principal withdraws consent; or (c) the data has been processed in contravention of the Act.
However, erasure is not absolute. The Data Fiduciary may retain data where retention is required by law or for compliance with a legal obligation. The DPDPA does not create a 'right to be forgotten' in the GDPR sense - there is no provision for requesting delisting from search engines or third-party publications.
Interaction with Data Retention Rules (R.8)
Rule 8 of the DPDP Rules establishes specific retention thresholds. For platform-based Data Fiduciaries, personal data must be erased if the Data Principal has not approached the platform for three years (or such other period as specified). The Data Fiduciary must give 48-hour notice before erasure.
The interplay between the right to erasure and mandatory retention periods (e.g., under tax laws, RBI regulations, or the Telecommunications Act) creates compliance complexities. Data Fiduciaries must maintain clear records of which data is retained under which legal basis.
Practical Implementation
Organisations should implement: (a) a clear process for receiving and verifying correction/erasure requests; (b) mechanisms to propagate corrections to all Data Processors who hold the data; (c) documentation of the legal basis for any refusal to correct or erase; (d) technical capabilities for selective erasure without affecting other data; and (e) audit trails to demonstrate compliance.
The obligation to propagate corrections extends to Data Processors - the Data Fiduciary must ensure that corrections are reflected across all systems where the data is processed.
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
