NEWS ANALYSIS4 mins

Supreme Court Mandates 30-Day Erasure SLA Under DPDP Act

The Supreme Court of India has interpreted the Right to Erasure under the DPDP Act, 2023, imposing a strict 30-day deadline for platforms to remove outdated personal data, heavily impacting enterprise liability and vendor contracts.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What Happened

On 25 August 2026, the Supreme Court of India issued a landmark interpretation of the Right to Erasure under the Digital Personal Data Protection Act (DPDPA), 2023. The Court ruled that search engines and social media platforms must legally comply with user requests to delist or remove outdated personal data within a strict 30-day timeframe. The ruling also establishes a critical caveat: data considered to be in the public interest is explicitly exempt from the removal mandate. This judicial development activates the operational framework of the DPDPA, passed on 9 August 2023, which formally established the Data Protection Board of India (DPBI) as the regulatory authority.

Does The DPDP Act Apply Here

Section 3 of the Digital Personal Data Protection Act, 2023 dictates that the law applies to the processing of digital personal data within the territory of India, and processing outside India connected to offering goods or services to Data Principals in India. While this specific ruling targets search engines and social media platforms, the precedent affects any enterprise acting as a Data Fiduciary. This ruling specifically activates the Right to Erasure, which sits alongside other core user rights such as the Right to Information, Right to Correction, and Right to Grievance Redressal. General Counsels must recognize that under Section 15 of the Act, Data Principals are obligated to furnish verifiably authentic information when exercising their erasure rights. If your organization surfaces user profiles, professional directories, or public-facing transaction records, it must evaluate its deletion capabilities to comply with these expanded obligations.

Legal Implications Under DPDP

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. However, once consent is withdrawn or the specified purpose is fulfilled, the Right to Erasure activates. Crucially, the Supreme Court mandate of a 30-day timeline creates a hard statutory Service Level Agreement that General Counsels must enforce across their entire supply chain. This ruling traces its constitutional foundation back to the Supreme Court's 2017 K.S. Puttaswamy vs Union of India judgment, which established privacy as a Fundamental Right under Article 21 of the Constitution. While the concept of a right to be forgotten has historical roots in the EU GDPR from May 2018, this domestic ruling codifies how the mechanism will be enforced in India, shifting the burden of proof for the public interest exemption entirely onto the enterprise.

Could This Happen To You

For a Legal Head overseeing corporate risk, a failure to honor an erasure request within 30 days is no longer just an operational delay, it is a direct violation of a Supreme Court mandate and the DPDP Act. If a Data Principal demands the removal of outdated data, an auditor or the DPBI will demand an evidence trail proving the request was received, authenticated, and deleted across all primary databases and vendor backups. Can your current compliance architecture produce that immutable record promptly upon regulatory inquiry? Without automated erasure workflows and ironclad indemnities in your processor contracts, your organization carries the full financial and reputational liability for vendor failures.

What Companies Should Do In The Next 30 Days

1. Legal Teams: Audit and amend existing Data Processor contracts to mandate 15-day erasure SLAs, ensuring sufficient buffer to meet the overarching 30-day statutory deadline and securing robust limitation of liability clauses. 2. Compliance Leadership: Map all external-facing applications and vendor environments to identify where historical personal data is indexed or publicly accessible. 3. Outside Counsel: Draft formal, privileged review guidelines defining the exact thresholds for the public interest exception, specific to your industry, to ensure defensibility during contested erasure requests. 4. IT and Operations: Deploy automated, centralized request fulfillment mechanisms that integrate with identity verification protocols and instruct analysts to review current data erasure mechanisms to meet the 30-day SLA.

What To Watch

Regulatory scrutiny will intensify as the DPBI begins formalizing its enforcement mechanisms regarding Data Principal rights. General Counsels must monitor how the Board interprets the public interest exception in subsequent adjudications. With exactly 257 days remaining until the DPDP hard compliance deadline of 13 May 2027, the window for theoretical legal review has closed. Enterprises must urgently modernize their data lifecycle management to ensure statutory readiness. To evaluate vendor defensibility and test your risk profile, visit freescan.complydp.com.

Sources

Frequently asked questions

Does the Supreme Court ruling on the 30-day erasure deadline apply to all companies?

While the ruling specifically targeted search engines and social media platforms, the Right to Erasure under the Digital Personal Data Protection Act, 2023 applies to all Data Fiduciaries. Any enterprise retaining or publishing outdated personal data must be prepared to execute verified deletion requests within statutory timelines.

What is the primary basis for processing personal data under the DPDP Act?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. When consent is withdrawn by the Data Principal, the organization must initiate the erasure process across its systems and downstream processors unless a valid legal retention requirement exists.

How do the DPDP Rules, 2025 impact data erasure procedures?

The DPDP Rules, 2025 outline the operational mechanics for executing Data Principal rights, including stringent identity verification requirements. General Counsels must ensure their systems can authenticate erasure requests reliably, as Section 15 of the Act requires Data Principals to provide verifiably authentic information.

What happens if a third-party vendor fails to delete data within 30 days?

Under the DPDP Act, the Data Fiduciary retains ultimate liability for the processing activities of its Data Processors. Legal teams must secure robust indemnities and flow down strict 15-day SLAs in vendor contracts to prevent downstream failures from triggering DPBI penalties against the primary enterprise.

Are there exceptions to the 30-day data removal mandate?

Yes, the Supreme Court established an exception for retaining data that serves the public interest. Legal heads should engage outside counsel to define defensible thresholds for this exception within their specific industry to protect against contested or frivolous delisting demands.