THE GAP GDPR CLOSED, AND INDIA DIDN’T: RECONCILING THE DPDP ACT WITH THE RIGHT TO BE FORGOTTEN

INTRODUCTION

When the European Union legislated a right to be forgotten, it didn’t just grant individuals the power to demand erasure — it also wrote down, in the same breath, when that power stops. Article 17 of the GDPR does not grant an unconditional right to erasure — it entitles a data subject to erasure only on specified grounds (for instance, that the data is no longer necessary for the purpose it was collected for, or that consent has been withdrawn), and Article 17(3)(a) then relieves the controller of that obligation to the extent processing is necessary for exercising the right to freedom of expression and information.[1] The balance between an individual’s digital past and the public’s right to know is, in the EU, a matter of legislative text, not judicial improvisation.

India’s Digital Personal Data Protection Act 2023 does something narrower. Section 12 grants a data principal the right to correction, completion, updating, and erasure, but only of personal data for the processing of which she has previously given consent — including the deemed consent recognised under Section 7(a) — to a data fiduciary.[2] A newspaper archive, a legal database, or a search engine indexing a decade-old arrest report was never asked for that person’s consent in the first place, so Section 12 does not reach it. The DPDP Act, in other words, never enters the room where the right to be forgotten actually gets contested in India. That fight has been left entirely to the Constitution — to Articles 19 and 21, litigated case by case, without the ready-made statutory balance the EU built in. This piece asks what India’s courts are doing to recreate, through constitutional proportionality, the balance GDPR simply legislated — and whether the DPDP Act should be amended to close that gap directly.

TWO STATUTORY MODELS, ONE MISSING PIECE

Section 12’s mechanics are consent-bound by design: a data principal can ask for erasure of data she “previously gave consent” for a fiduciary to hold, and the fiduciary must comply unless retention is required by law. That is a meaningful right, but it is a private, transactional one — it governs the relationship between an individual and the company or platform that collected her data directly. It was never built to touch third-party editorial content: an old crime report, a published judgment, a journalist’s archive. Those are precisely the categories GDPR’s drafters anticipated would collide with erasure claims, which is why Article 17 exists at all — not as an afterthought, but as the provision that makes the right survivable alongside a free press.[3]

That asymmetry has consequences. India’s silence on the free-expression side of erasure is not a legislative choice in favour of free expression — it simply reflects the fact that Section 12’s scope never extends that far to begin with. An acquitted individual seeking to have an old arrest report de-indexed in India therefore has no statutory right to point to; she has to build her claim from constitutional first principles instead.

THE CONSTITUTIONAL BACKFILL

This is where Articles 19 and 21 have had to do the work a data protection statute might otherwise do. The Supreme Court read personal liberty broadly in Maneka Gandhi v Union of India,[4] and Justice K S Puttaswamy (Retd) v Union of India later held that this liberty under Article 21 extends to informational privacy — a right distinct from, but foundational to, any subsequent right to be forgotten, which Indian courts have since had to derive from that privacy right rather than from any standalone statutory source.[5] On the other side, Article 19(1)(a) protects the media’s right to maintain a historical archive, and Article 19(2) makes clear that speech was never treated as absolute in the first place.[6] The asymmetry between how an arrest is publicised and how an acquittal is not compounds the problem: an accusation generates engagement in a way a court’s finding of innocence rarely does, so an “unedited historical record” in practice preserves the accusation and lets the outcome quietly disappear — a distortion the DPDP Act, with its narrow consent-based scope, was never positioned to fix.

BORROWING GDPR’S BALANCE WITHOUT BORROWING ITS TEXT

Puttaswamy did more than recognise privacy in the abstract — it supplied a four-part proportionality test: any restriction on a fundamental right must pursue a legitimate aim, be a suitable means to it, be the least restrictive option available, and carry adequate safeguards.[7] And in Kaushal Kishor v State of Uttar Pradesh, the Court confirmed that the rights under Articles 19 and 21 of the Constitution of India can be enforced horizontally, against private actors and not merely the State[8] — which means search engines and legal databases, not just government bodies, can be held to this proportionality standard.

Read together, Puttaswamy‘s proportionality test and Kaushal Kishor‘s horizontal application arguably come close to functioning as an Indian, judge-made analogue to GDPR’s Article 17(3)(a) — a mechanism for weighing erasure against free expression, built without a single line of legislative text saying so, though it remains a case-by-case judicial construct rather than a settled rule of general application. Applying that test suggests both extremes should fail: permanent, unconditional archiving of an acquitted person’s identity would likely fail the “least restrictive means” prong, since a case’s precedential value survives perfectly well without the individual’s name attached; but wholesale deletion of the judgment would fail it too, since the underlying reasoning retains real public value. This piece’s own proposed middle ground is targeted anonymisation — de-indexing the person’s name and identifying details while preserving the facts, reasoning, and outcome of the case — which would be functionally close to what GDPR’s built-in exemption already accomplishes by statute for EU citizens, though this is offered here as a recommendation for reform rather than a description of settled Indian law.

CONCLUSION

India does not lack the constitutional resources to strike this balance — Puttaswamy and Kaushal Kishor show that the judiciary is capable of building, case by case, something that functions like GDPR’s Article 17(3)(a) exemption. What Indian law currently lacks, however, is the legislative certainty of having that balance written into the DPDP Act itself, rather than left to be re-litigated in every fresh petition. The following is accordingly offered as this piece’s own proposal for reform, not as a description of the existing legal position: a targeted amendment to Section 12, explicitly extending a narrow, anonymisation-based erasure right to cover published third-party archives, modelled on GDPR’s approach but calibrated to India’s own free-speech jurisprudence, would let Parliament do in statute what courts are currently only able to improvise case by case. In the second part of this series, we turn from this doctrinal and statutory gap to judicial reality: how Indian High Courts have actually ruled on Right to be Forgotten petitions, how that record compares internationally, and what a concrete legislative fix might look like.

Author(s) Name: Tehzeeb Shaikh

References:

[1] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) [2016] OJ L119/1, art 17(1), (3)(a).

[2] Digital Personal Data Protection Act 2023, s 12(1) read with s 7(a).

[3] Regulation (EU) 2016/679 (n 1) art 17.

[4] Maneka Gandhi v Union of India (1978) 1 SCC 248.

[5] Justice KS Puttaswamy (Retd) v Union of India (2017) 10 SCC 1.

[6] Constitution of India 1950, art 19(2).

[7] Puttaswamy (n 5).

[8] Constitution of India 1950, arts 19, 21; Kaushal Kishor v State of Uttar Pradesh (2023) 4 SCC 1.

Sign Up to Our Newsletter

Be the first to know the latest updates

Whoops, you're not connected to Mailchimp. You need to enter a valid Mailchimp API key.