Chapter III · Rights and Duties of Data Principal
Section 12: Right to correction and erasure of personal data
Section 12 lets a person have their personal data corrected, completed, updated or erased, so long as no active purpose or legal-retention duty requires the data to stay.
- Chapter
- Chapter III · Rights and Duties of Data Principal
- Status
- Enacted · phased commencement
- Full compliance
- 13 May 2027
- Applies to
- Data Principals & Data Fiduciaries
- Official citation
- DPDP Act, 2023, s.12
- Reading time
- 6 min
- Updated
- August 2026
At a glance
Section 12 gives a Data Principal, for personal data processed with her prior consent (including data voluntarily provided under Section 7(a)), the right to have that data corrected, completed, updated or erased. On a correction request the Data Fiduciary must fix inaccurate or misleading data, complete incomplete data and update changed data [12(2)]. On an erasure request it must delete the data unless retention is necessary for the specified purpose or to comply with a law in force [12(3)]. This request-driven right sits alongside the proactive deletion duty in Section 8(7). It is scheduled to take effect on 13 May 2027, with rights requests handled within the Rule 14 window of a reasonable period not exceeding 90 days.
Key takeaways
- These are four distinct rights: correction, completion, updating and erasure, each needing a different response [12(1), 12(2)].
- Erasure is conditional, not absolute: you must delete unless retention is genuinely needed for the specified purpose or a law in force [12(3)].
- A refusal to erase must be narrow and documented, naming the data category, the legal basis and a review or deletion date, not "business purposes".
- It is separate from consent withdrawal under Section 6: one stops future processing, the other removes stored data.
- Do not wait for a request: Section 8(7) makes you erase when consent is withdrawn or the purpose is served, and cause processors to erase too.
- The right applies to consent-based data (including Section 7(a)); Section 17(4) disapplies the erasure right for certain State processing.
Who should read this
Read this if you store personal data on consent, because Section 12 tests whether you can fix and delete records reliably across every system and vendor, not just your main database.
In plain language
Section 12 bundles four different asks into one right. Correction fixes data that is wrong or misleading, completion fills a gap, updating reflects a change, and erasure removes data. Each needs its own response, and correction covers data that is merely misleading, not only factually wrong.
Erasure is the part most people misread. It is not "delete everything now". You must erase unless retention is genuinely necessary for the purpose you already notified, or for a specific law in force, and you should be able to name which. "The person once had an account" is not a live purpose.
Correcting and updating is not just customer service. Section 8(3) separately requires you to keep data complete, accurate and consistent where it feeds a decision about someone or is shared onward, so a working update path supports a core statutory duty.
The text of the law
Section 12: Right to correction and erasure of personal data
12(1) A Data Principal has the right to correction, completion, updating and erasure of personal data processed on the basis of her prior consent (including consent as referred to in Section 7(a)), in accordance with any requirement or procedure under any law in force.
12(2) On a request for correction, completion or updating, the Data Fiduciary shall correct inaccurate or misleading personal data, complete incomplete data, and update the data.
12(3) On a request for erasure, the Data Fiduciary shall erase the personal data unless retention is necessary for the specified purpose or for compliance with any law in force.
Wording summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.
What this means for you
- Correct or update at the system of record, then propagate the change to replicas in CRM, billing, support, analytics and email, a fix in one place is not a complete fix.
- For erasure, run a retention decision: delete, partially delete, retain with restriction, or refuse under a documented exemption.
- Give a specific answer, not "we cannot delete for legal reasons": name the retained category, the exact obligation, the period, the access restriction and the deletion date.
- Handle backups by secure expiry rather than unsafe alteration, but ensure restricted data is not restored into live processing.
- Keep an audit trail: request, identity check, systems searched, decision-maker, legal basis for any retention, processor actions and the response.
- Not sure your systems could actually complete a deletion today? Take the readiness assessment or find a specialist.
Frequently asked questions
Is the right to erasure absolute?
When can a company refuse to delete my data?
How is erasure different from withdrawing consent?
Does Section 12 mean my data is deleted from backups too?
When does Section 12 take effect?
Sources
- Digital Personal Data Protection Act, 2023Ministry of Electronics and IT (MeitY)
- DPDP Rules, 2025Notified 13–14 November 2025
This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.