Critically examine whether the Digital Personal Data Protection Act, 2023 adequately addresses the right to be forgotten.

Q. Critically examine whether the Digital Personal Data Protection Act, 2023 adequately addresses the right to be forgotten. (15 marks, 250-350 words)

The right to be forgotten (RTBF) allows an individual to have personal data erased or de-indexed once it no longer serves a legitimate purpose. Flowing from informational privacy under Article 21, recognised in K.S. Puttaswamy (2017) [4], it is only partially served by the DPDP Act, 2023.

Where the Act delivers - Section 12 gives the data principal a right to correction, completion, updating and erasure of personal data processed on her consent [1]. - The data fiduciary must erase data on withdrawal of consent or once the specified purpose is served, unless retention is required by law [1] — a statutory advance over the earlier self-regulatory IT Rules regime. - Purpose and storage limitation plus a Data Protection Board for grievance redressal create an enforcement route that did not previously exist [2].

Where it falls short - The Act does not grant RTBF or data portability; PRS notes both were provided in the 2018 Draft Bill and the 2019 Bill and dropped thereafter [2]. - The Srikrishna Committee (2018) had framed RTBF as instilling "the limitations of memory into an otherwise limitless digital sphere" — a recommendation left unimplemented [3]. - Erasure operates only against the data fiduciary, not against search engines republishing data; it cannot compel de-indexing of third-party results. - Publicly available data and information disclosed in judicial proceedings fall outside the Act, leaving court records and media archives untouched [1]. - Broad state exemptions and a centrally-appointed Board dilute the remedy's reach [1][2].

Judicial gap-filling - Courts have supplied what the statute omits: the Delhi High Court (29 May 2026) directed de-indexing of name-based search results by Google and Indian Kanoon in acquittal, matrimonial and sexual-offence matters [5], resting on Article 21 rather than the Act.

The Act is a foundational but incomplete privacy charter — adequate on consent-linked erasure, inadequate on forgetting. Codifying a calibrated RTBF, with a balancing test against Article 19(1)(a) and the open-court principle, and empowering the Board to decide de-indexing requests, would spare citizens case-by-case litigation and fulfil the promise of Puttaswamy.

(~325 words)

Sources: 1. The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) — Section 12 erasure right, erasure on consent withdrawal, exclusion of publicly available and judicially disclosed data, state exemptions 2. PRS Legislative Research — The Digital Personal Data Protection Bill, 2023 — "does not grant the right to data portability and the right to be forgotten"; presence in 2018 Draft and 2019 Bill; Data Protection Board composition 3. PRS Report Summary — A Free and Fair Digital Economy (Srikrishna Committee, 2018) — committee's framing and recommendation of RTBF 4. K.S. Puttaswamy v. Union of India, Supreme Court of India (24 Aug 2017) — privacy and informational privacy as fundamental rights under Article 21 5. Delhi High Court judgment dated 29.05.2026, W.P.(C) 1021/2016 (Laksh Vir Singh Yadav) — de-indexing directions to Google and Indian Kanoon in sensitive-case categories