AMLEGALS — Strategic Lawyering
Rights Management

How to Implement the Right to Erasure

Building systems capable of deleting personal data upon request

Updated 10 January 2025

Executive Summary

The right to erasure enables Data Principals to request deletion of their personal data. Implementing this right requires both technical capability to locate and delete data across all systems and procedural frameworks to handle requests appropriately. This guide addresses the practical aspects of erasure implementation.

Key Takeaways

  • 1
    Map all locations where personal data is stored before designing deletion capabilities
  • 2
    Implement both logical deletion and eventual physical deletion mechanisms
  • 3
    Address backup and archive data in deletion procedures
  • 4
    Document exceptions where retention is legally required
  • 5
    Verify deletion completion across all systems

1Understanding the Erasure Right

Section 12 provides that upon withdrawal of consent, the Data Fiduciary shall erase personal data unless retention is required for compliance with law. This creates both a right for Data Principals and an obligation for organisations to implement deletion capabilities.

2Mapping Data for Deletion

You cannot delete what you cannot find. Comprehensive data mapping underpins effective erasure.

1

Primary Systems

Identify all databases, applications, and systems that store personal data in structured form.

2

Unstructured Data

Locate personal data in unstructured repositories including documents, emails, and file shares.

3

Derived Data

Identify personal data created through processing, such as profiles, scores, and predictions.

4

Backup Systems

Catalogue backup infrastructure where personal data copies reside.

5

Archive Systems

Document archived data locations and retention periods.

6

Third Party Holdings

Identify personal data held by processors and partners on your behalf.

3Designing Deletion Capabilities

Technical systems must support deletion requests. This often requires specific development.

1

Unique Identifier Propagation

Establish consistent identifiers that allow the same individual to be found across systems. Without this, comprehensive deletion is difficult.

2

Deletion APIs

Build or configure APIs that can accept deletion requests and execute them across relevant systems.

3

Cascading Deletion

Where data is linked across systems, implement cascading deletion that follows relationships.

4

Verification Mechanisms

Build in verification that deletion actually occurred, not just that a deletion command was issued.

Practical Tips

  • •Design for deletion from the start of system development; retrofitting is harder
  • •Consider soft delete followed by hard delete to allow recovery from errors

4Handling Backup and Archive Data

Backup systems present particular challenges for erasure because they are designed for data preservation.

1

Assess Backup Architecture

Understand how backups work, retention periods, and whether selective deletion is technically feasible.

2

Deletion from Active Backups

Where feasible, delete personal data from backup systems. Modern backup solutions increasingly support selective deletion.

3

Lifecycle Expiry

Where selective deletion is not feasible, document that data will be deleted when backups naturally expire through retention policy.

4

Restoration Procedures

If a backup containing deleted data is restored, procedures should ensure the previously deleted data is re-deleted.

Important Warnings

  • •Backup systems not designed for selective deletion may require architectural changes
  • •Claiming inability to delete from backups may not satisfy regulatory expectations

5Processing Erasure Requests

Establish procedures for receiving and actioning erasure requests.

1

Request Intake

Provide clear channels for submitting erasure requests. Link these from privacy notices and account settings.

2

Identity Verification

Verify requester identity before deleting data. Deleting the wrong person's data creates its own compliance problem.

3

Scope Confirmation

Confirm what data the requester wants deleted. Full erasure or specific data? All services or specific products?

4

Execution and Tracking

Execute deletion across all identified systems and track completion status.

5

Confirmation

Confirm deletion completion to the requester within prescribed timelines.

6Exceptions to Erasure

Not all data must be deleted upon request. Document and apply exceptions appropriately.

1

Legal Retention Requirements

Where law requires data retention (tax records, transaction logs, regulatory filings), this overrides erasure requests.

2

Legitimate Continued Processing

Where processing continues on a basis other than consent (legal obligation, legitimate interest), erasure may not be required.

3

Document Exceptions

When declining erasure based on an exception, document the specific basis and communicate it to the requester.

4

Partial Erasure

Where some data is subject to exception but other data is not, delete what can be deleted and retain only what must be retained.

7Third Party Notification

Where data has been shared with third parties, consider obligations to notify them of erasure.

1

Identify Recipients

Determine which third parties received the data subject to erasure.

2

Assess Notification Duty

Consider whether you have an obligation to notify recipients of the erasure request.

3

Execute Notification

Where appropriate, notify recipients and request they delete their copies.

4

Track Compliance

Follow up to verify third party deletion where feasible.

Frequently Asked Questions

Need Implementation Support?

Our data protection team can help translate these guidelines into organisation-specific policies, procedures, and technical implementations.

Get Expert Guidance

Implement Right To Erasure: questions and answers

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What must a DPDPA privacy notice contain?

Section 5 read with Rule 3 requires a notice, understandable independently of other information, that itemises the personal data and the specified purpose, and explains how the Data Principal may withdraw consent, exercise rights and complain to the Board. A Data Principal has the right to access the notice in English or any language specified in the Eighth Schedule to the Constitution. The design of translation operations is an implementation matter.

When must personal data be erased under DPDPA?

Section 8(7) requires erasure once the specified purpose is no longer served or consent is withdrawn, unless retention is required by law. Rule 8 and the Third Schedule prescribe time periods for specified classes of Data Fiduciaries, with prior intimation to the Data Principal before erasure.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Implement Right To Erasure?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Implement Right To Erasure under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Implement Right To Erasure under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Implement Right To Erasure?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Implement Right To Erasure rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Implement Right To Erasure?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Implement Right To Erasure · DPDPA Exposure Assessment