The Right to Be Forgotten in India

Introduction
The “right to be forgotten” has moved from being an abstract academic proposition to a live constitutional controversy in India. At its core, the right allows an individual to seek the removal, de-indexing, or masking of personal information from the digital space when the continued, unrestricted availability of that information no longer serves any legitimate purpose. The doctrine assumes urgency in an era where a single FIR, an acquittal, or a settled matrimonial dispute can follow a person permanently through a name-based Google search or a legal database query, long after the underlying proceeding has lost all contemporary relevance. This tension between the permanence of the internet and the transient nature of human error and rehabilitation was addressed comprehensively by the Delhi High Court in its landmark judgment in Laksh Vir Singh Yadav v. Union of India (decided 29 May 2026), a decision that is now itself under appellate challenge by Indian Kanoon before a Division Bench of the same court. This article traces the right from its comparative origins in European data protection law, through its constitutional recognition in India, to the concrete procedure by which an aggrieved individual may invoke it today.
The Comparative Origin: Google Spain and the GDPR's Right to Erasure
Any rigorous account of the right to be forgotten must begin with the decision of the Court of Justice of the European Union (CJEU) in Google Spain SL, Google Inc. v. Agencia Española de Protección de Datos (AEPD) and Mario Costeja González, Case C-131/12 (13 May 2014). Costeja González, a Spanish national, had sought removal of links to two 1998 newspaper notices concerning a real-estate auction connected to attachment proceedings for the recovery of social security debts, debts that had since been fully resolved. He argued that Google's continued indexing of these notices, more than a decade later, was entirely irrelevant to his current life. The CJEU's Grand Chamber held that the operator of a search engine is obliged to remove, from the list of results displayed following a name-based search, links to web pages containing information relating to that person, even where the information was lawfully published by the original source and remains on that source. The Court reasoned that where personal data is “inadequate, irrelevant or no longer relevant, or excessive in relation to the purposes for which they were processed and in the light of the time that has elapsed,” its continued processing becomes incompatible with data protection principles, even if the initial processing was lawful. Crucially, the Court also held that the data subject may address a delisting request directly to the search engine operator (as the data controller), which must then examine the request on its merits — establishing the private, extra-judicial complaint mechanism that later became the template for erasure requests across Europe.
Following this ruling, the European Union codified the right to be forgotten as the “right to erasure” under Article 17 of the General Data Protection Regulation (GDPR), which came into force in May 2018. Article 17(1) obliges a data controller to erase personal data without undue delay where any one of six specified grounds applies: the data is no longer necessary for the purpose for which it was collected; the data subject withdraws consent and no other legal ground exists; the data subject objects to processing under Article 21 and no overriding legitimate ground exists; the data has been unlawfully processed; erasure is required to comply with a legal obligation; or the data was collected in connection with an offer of information-society services to a child. However, the right is expressly not absolute. Article 17(3) carves out five categories where the right to erasure does not apply: a) where processing is necessary for exercising the right of freedom of expression and information; b)for compliance with a legal obligation or performance of a task in the public interest or official authority; c) for reasons of public interest in the area of public health; d)for archiving, scientific, historical, or statistical purposes where erasure would seriously impair those objectives; e) or for the establishment, exercise, or defence of legal claims. The UK Information Commissioner's Office (ICO), which continues to apply the retained UK GDPR, further permits an organisation to refuse a request that is “manifestly unfounded” (for instance, where it is used to harass an organisation or targets a specific employee out of personal grudge) or “manifestly excessive” (for instance, where it repeats or overlaps with earlier requests), in which case the organisation may either charge a reasonable fee or decline to act, while still informing the requester of their right to complain to the supervisory authority or seek a judicial remedy.
This EU framework is significant for the Indian discussion for two reasons. First, it demonstrates that even in the jurisdiction where the right originated, it was never conceived as an unqualified entitlement to erase history; it has always operated as a structured balancing exercise between privacy and countervailing public interests — precisely the template the Delhi High Court adopted in fashioning its own three-tier test for de-indexing. Second, it clarifies that the GDPR distinguishes between erasure (deletion of data at its source) and de-referencing or delisting (removal from a search engine's name-based index while the underlying source remains intact) — a distinction that maps closely onto the Delhi High Court's own separation of “de-indexing” from “masking” discussed below. India's Digital Personal Data Protection Act, 2023, discussed in the next section, borrows the erasure terminology from this framework but, unlike the GDPR, does not extend it into name-based search delisting or judicial-record contexts.
Constitutional Basis: Article 21 and Informational Privacy
The right to be forgotten in India is not a creature of statute; it is a judicially evolved facet of the fundamental right to privacy under Article 21 of the Constitution. The starting point is the nine-judge Bench decision in K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1, which held that privacy is an intrinsic and inalienable component of the right to life and personal liberty. Justice Nariman's opinion in that case identified informational privacy as one of three distinct dimensions of the privacy right, alongside privacy of the person and privacy of choice, and located it under Article 21, recognising that an individual has control over the dissemination of material personal to them. Justice S.K. Kaul, in his separate concurring opinion, went furthest in expressly articulating the right to be forgotten, observing that the right of an individual to exercise control over their personal data and their own life necessarily encompasses “his right to control his existence on the internet.” Kaul J. captured the core anxiety animating this right in his oft-quoted observation that “humans forget, but the internet does not forget and does not let humans forget,” while cautioning that this is not an absolute right and does not permit a criminal to obliterate their past entirely. Notably, Kaul J.'s opinion itself drew directly on the EU's 2016 GDPR Regulation as the comparative reference point for what such a right could mean in the Indian context.
Building on this foundation, the Delhi High Court in Laksh Vir Singh Yadav held that the protection under the right to informational privacy is not merely against disclosure of personal information, but against an individual being “involuntarily and perpetually defined in the digital domain” by an isolated event, regardless of the eventual outcome of the underlying proceeding. The Court also invoked the reasoning in R. Rajagopal v. State of Tamil Nadu, (1994) 6 SCC 632, and reaffirmed that while information forming part of public records generally loses the protection of privacy, this general proposition must be read alongside the constitutional value of dignity: once an accused is honourably acquitted, discharged, or has proceedings quashed, the permanent digital visibility of the original accusation creates what the Court termed an “incongruity” between the legal and digital realities of the person's life. Crucially, the Court held that fundamental rights under Article 21, as clarified in Kaushal Kishor v. State of U.P., (2023) 4 SCC 1, are horizontally enforceable, meaning they can be asserted not only against the State but also against private, non-State actors such as search engines, legal databases, and media platforms. This was pivotal in overcoming the threshold objection that a writ of mandamus under Article 226 cannot ordinarily issue against private entities that perform no public function.
Absence of a Standalone Statute: The DPDP Act, 2023 and the IT Act
Unlike the European Union, where the right to be forgotten is codified as a directly enforceable, self-contained right under Article 17 GDPR, India has no equivalent standalone statutory right. The Digital Personal Data Protection Act, 2023 (DPDP Act), India's principal data protection legislation recognises a right of correction and erasure of personal data within its consent-based framework (broadly analogous to Article 17 GDPR's erasure grounds relating to withdrawal of consent and data no longer being necessary for its original purpose), but it does not extend this right into a freestanding entitlement to de-index or delist name-based search results, and it carves out express exemptions for processing of personal data connected with judicial functions and legal proceedings — exemptions considerably broader than the narrow “legal claims” and “freedom of expression” carve-outs under Article 17(3) GDPR. During arguments before the Delhi High Court, respondents including Google specifically relied on this gap, contending that the absence of statutory backing meant courts could not judicially graft a right to be forgotten onto judicial records.
The Information Technology Act, 2000 supplies adjacent regulatory architecture rather than a direct right. Section 69A empowers the Central Government to direct blocking of online content only on limited grounds such as sovereignty, security of the State, and public order — grounds that do not naturally extend to privacy-based takedown requests. Section 79, the safe-harbour provision for intermediaries, read with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (“IT Rules, 2021”), requires intermediaries to act only upon receiving actual knowledge through a court order or government notification, a standard drawn from the Supreme Court's ruling in Shreya Singhal v. Union of India, (2015) 5 SCC 1. It is against this statutory vacuum that Indian courts, drawing on Article 21, have had to construct the right to be forgotten as a matter of constitutional adjudication rather than legislative entitlement in marked contrast to the EU model, where the right operates primarily as a direct, extra-judicial request mechanism against the data controller, with courts and supervisory authorities entering the picture only upon refusal.
The Delhi High Court's Framework in Laksh Vir Singh Yadav
The judgment in Laksh Vir Singh Yadav v. Union of India arose from a batch of connected writ petitions filed by individuals, including persons acquitted, discharged, or whose FIRs were quashed, as well as parties to settled matrimonial disputes and persons named only incidentally in judicial records seeking removal, de-indexing, or masking of judicial records and news reports bearing their names from Google Search, Indian Kanoon, X (formerly Twitter), and various media platforms. Justice Sachin Datta's analysis proceeds along two distinct but complementary reliefs.
De-indexing (or de-linking) operates at the level of the search engine or legal database and refers to disabling a name from functioning as a retrieval key for a particular record, without deleting the underlying judgment or article, which remains accessible via case number, citation, or other purposive search. This tracks the CJEU's own distinction in Google Spain between de-referencing (removal from name-based search results) and erasure of the source. The Court held that de-indexing does not offend the principle of open justice, since open justice requires that records exist and remain accessible to those with a legitimate interest, not that any casual searcher be able to surface a record instantly by typing a name into a commercial search algorithm optimised for engagement rather than accuracy. The Court specifically found that Google's crawling, indexing, and serving functions amount to active processing of personal data, not a passive, library-index-like function, because Google derives advertising revenue from search results and algorithmically prioritises engagement over accuracy, a finding that echoes the CJEU's reasoning in Google Spain that a search engine's activity is additional to, and distinct from, that of the original publisher.
Masking, by contrast, operates at the level of the court record itself: a direction to the court's registry to substitute a neutral identifier for a party's name in the publicly accessible digital version of the judgment, while the unredacted version is preserved for internal judicial and institutional use. The Court clarified that masking relief can only be granted by the very court that passed the original order, since only that court possesses supervisory control over its own records.
To decide when de-indexing should be granted, the Court laid down a three-tier test, framed in language that closely parallels Article 17 GDPR's balancing structure:
1. Character of information and outcome of proceedings — where proceedings ended in acquittal, discharge, quashing, or settlement, de-indexing should ordinarily be granted, since the presumption of innocence must have real effect, including in the digital domain.
2. Public role of the individual — public officials and those exercising public functions have a diminished claim to privacy concerning conduct in their official capacity, following R. Rajagopal, though this does not extend to unrelated personal or matrimonial matters.
3. Accuracy and continuing relevance — drawing directly on the CJEU's reasoning in Google Spain, even lawfully published, accurate information may lose its justification for continued processing where it becomes inadequate, irrelevant, excessive, or outdated relative to any legitimate purpose — language lifted almost verbatim from the CJEU's own formulation of when processing becomes incompatible with data protection principles.
The Court simultaneously carved out categories where de-indexing or masking would not be appropriate: convictions for offences against women or children (where public-safety interest does not diminish with time, reinforcing the legislative philosophy of the POCSO Act, 2012), and convictions involving breach of public trust by public servants or elected officials, where public accountability considerations outweigh privacy claims. These carve-outs perform a function analogous to the Article 17(3) GDPR exceptions for freedom of expression, public interest, and legal obligations, though framed in terms specific to Indian criminal and constitutional law rather than the GDPR's own categories. Where the underlying proceedings abated by the death of the accused without any merits-based determination, the Court held that the right does not arise in its primary form, but de-indexing may still be warranted on proportionality grounds to protect surviving family members, particularly children, from continuing and disproportionate harm.
The Procedure to Claim the Right to Be Forgotten
Because India has no dedicated statute creating a self-standing right to be forgotten comparable to Article 17 GDPR, there is no single prescribed form or portal through which a claimant can invoke it in every case — unlike the EU model, where a data subject can approach the controller directly under Article 17 and escalate to a supervisory authority on refusal. Instead, the procedure that has crystallised through Laksh Vir Singh Yadav and the line of cases preceding it operates through four distinct channels in India, depending on where the offending material is hosted and what relief is sought. A claimant should generally attempt these in the following order.
Step One: Direct Representation to the Platform or Publisher
Before approaching a court, an aggrieved person should first send a written representation — typically an email or an online grievance form — directly to the entity hosting or indexing the content. This includes the original publisher (a newspaper or news portal), the legal database (such as Indian Kanoon), and the search engine (Google, Microsoft Bing, or Yahoo), mirroring the CJEU's holding in Google Spain that a data subject may address a delisting request directly to the search-engine operator, which must examine it on its merits. Each of these Indian entities is required under the IT Rules, 2021 to appoint a Grievance Officer whose name and contact details must be published on the platform. The representation should identify the specific URL(s), state the underlying judicial outcome (acquittal, discharge, quashing order, settlement, or decree), and explain why continued name-based accessibility causes disproportionate harm. Under Rule 3(2) of the IT Rules, 2021, intermediaries are required to acknowledge such a complaint within twenty-four hours and to dispose of it, as far as possible, within fifteen days. In practice, however, platforms frequently decline such requests absent a court order, since Section 79(3)(b) of the IT Act, 2000 (as construed in Shreya Singhal) protects intermediaries from being compelled to independently adjudicate contested claims of unlawfulness — they generally act only upon receiving “actual knowledge” in the form of a judicial order. This is a marked departure from the EU position, where the controller itself is expected to weigh the Article 17 grounds and exceptions in the first instance.
Step Two: Application Before the Court That Passed the Original Order (for Masking)
Where the relief sought is masking — that is, substitution of the party's name with a neutral identifier in the digital version of a judgment or order — the application must be filed before the same court (or its Registrar General) that originally passed the order, since masking operates on the court's own record and only that court has supervisory control over it. In the Delhi High Court, this takes the form of an application (typically a CM/CRL.M.A. in a pending matter, or a fresh writ petition under Article 226 if the underlying case has concluded and no other proceeding is pending) seeking a direction to the Registrar General to redact the petitioner's name from the publicly accessible digital record, while preserving the unredacted version for internal use. The Delhi High Court's own Registry has, since 2023, operationalised a masking software module integrated into its e-filing system: advocates and parties-in-person can select an option requesting identity protection at the time of e-filing, and the module implements masking once the Court so directs. Litigants before other High Courts or subordinate courts should similarly move an application before the court of record concerned, supported by an affidavit annexing certified copies of the acquittal, discharge, quashing order, or settlement, and demonstrating the disproportionate and continuing harm caused by unrestricted digital searchability.
Step Three: Writ Petition Under Article 226 (for De-indexing and Composite Relief)
Where the relief sought is de-indexing from a search engine or legal database, or a composite relief combining de-indexing with masking, the appropriate remedy is a writ petition under Article 226 of the Constitution before the jurisdictional High Court, since informational privacy is a fundamental right under Article 21 and is enforceable even against private, non-State actors such as Google, Indian Kanoon, and media houses, following Kaushal Kishor v. State of U.P. The petition should ordinarily:
· Identify each specific URL, judgment, article, video, or post sought to be de-indexed or masked, rather than seeking a blanket removal of the petitioner's digital footprint.
· Annex certified copies of the underlying judicial record establishing the outcome relied upon — an acquittal, discharge order, quashing order under Section 482 CrPC/528 BNSS, settlement or compounding order, or decree — since the three-tier test applied by the Court turns heavily on this outcome.
· Plead the specific harm suffered — to employment, marriage prospects, creditworthiness, professional standing, or mental well-being — supported, where possible, by documentary evidence such as rejection communications or medical records.
· Implead the relevant respondents: the search engine operator(s) (Google LLC/Google India, Microsoft, Yahoo), the legal database (if applicable), the original publisher or media house, and, where masking of a court record is also sought, the Registrar General of the concerned High Court.
· Address why the case falls outside the categories where relief is inappropriate — namely, convictions for offences against women or children, or convictions for breach of public trust by public officials — and, where the petitioner is a public figure, confine the relief sought to matters unconnected with their public role.
On such a petition, the Court examines maintainability first (confirming that Article 21 rights bind non-State actors), and then applies the three-tier test described above, balancing the petitioner's informational privacy against open justice and freedom of expression, before granting de-indexing (directed at the search engine/database), masking (directed at the court of record), or both. Because de-indexing relief attaches to specific URLs and re-crawling by search engines can cause delisted content to reappear if the source page still exists, effective relief often additionally requires a direction to the original publisher to remove or mask the underlying article, not merely a delisting direction against the search engine — a practical limitation also recognised by the CJEU in Google Spain, where delisting removes a URL from name-based results without touching the source page.
Step Four: Correction/Erasure Request Under the DPDP Act, 2023 (Where Applicable)
Where the grievance concerns personal data held by a private data fiduciary outside the judicial-record context, for instance, inaccurate or outdated personal data retained by a company, app, or platform after the purpose of collection has ended, analogous to the first Article 17(1)(a) GDPR ground (“no longer necessary for the purposes for which they were collected”) — a data principal may submit a correction/erasure request directly to the data fiduciary's Grievance Officer under the consent-withdrawal and correction/erasure provisions of the DPDP Act, 2023, and escalate an unresolved grievance to the Data Protection Board of India once it becomes fully operational. This route, however, does not apply to information forming part of judicial records or proceedings, since the Act exempts processing connected with the exercise of judicial functions, and cannot presently be used as a substitute for the writ remedy described above.
Comparative and Precedential Lineage
The Delhi High Court situated its ruling within a broader lineage of Indian and comparative jurisprudence. Domestically, it traced the doctrine through Vasunathan v. Registrar General, 2017 SCC OnLine Kar 424 (an early Karnataka High Court recognition of the concept in a matrimonial context), Jorawer Singh Mundy v. Union of India, 2021 SCC OnLine Del 2306, Zulfiqar Ahman Khan v. Quintillion Business Media Pvt. Ltd., 2019 SCC OnLine Del 8494, Subhranshu Rout v. State of Odisha, 2020 SCC OnLine Ori 878, and the Kerala High Court's detailed taxonomic treatment in Vysakh K.G. v. Union of India, 2022 SCC OnLine Ker 7337, which distinguished between the right to rehabilitation, the right to erasure/deletion, the right to delisting/de-indexing, the right to obscurity, and the right to oblivion — a classification drawn from the scholarship of Voss and Castets-Renard. It also noted the Madras High Court's decision in Karthick Theodore v. Registrar General, which ordered removal of a judgment from an online database on right-to-be-forgotten grounds, though that ruling remains stayed by the Supreme Court in the pending iKanoon Software Development Pvt. Ltd. v. Karthick Theodore, SLP(C) No. 15311 of 2024.
On the comparative front, beyond Google Spain and the GDPR discussed above, the Court also relied on the subsequent CJEU Grand Chamber decision in Google LLC v. CNIL, C-507/17 (24 September 2019), which held that a search engine operator is not required to carry out de-referencing on all versions of its search engine globally, but only across EU member-state domains, illustrating the territorial limits that also feature in the Delhi High Court's discussion of cross-border enforceability. It also relied on the UK Queen's Bench decision in NT1 v. Google LLC [2018], where the Court granted a delisting order in respect of a rehabilitated offender's spent conviction while dismissing a parallel claim by a claimant whose conviction remained relevant to ongoing public interest — illustrating that the right operates on a fact-sensitive, case-by-case basis rather than as a blanket entitlement.
The Open Justice Objection and the Indian Kanoon Appeal
The judgment's most significant doctrinal challenge concerns the principle of open justice, which requires that judicial proceedings and records remain publicly accessible to sustain confidence in the administration of justice, as affirmed by the Supreme Court in Swapnil Tripathi v. Supreme Court of India, (2018) 10 SCC 639. Indian Kanoon, a widely used online repository of Indian case law, has appealed the single-judge ruling before a Division Bench of the Delhi High Court, in iKanoon Software Development Pvt. Ltd. v. Laksh Vir Singh Yadav & Ors. Indian Kanoon's central contentions are that the direction to disable name-based search functionality is overbroad; that once information forms part of public court records, privacy claims ordinarily do not survive except in recognised statutory exceptions such as sexual offence cases, juvenile matters, and matrimonial proceedings; that standards such as information no longer being “relevant” or serving a “legitimate public purpose” are vague and invite arbitrary censorship; and that name-based search is integral to legal research relied upon by lawyers, students, and even judges, such that restricting it disproportionately burdens the platform's freedom to carry on trade under Article 19(1)(g) of the Constitution. The appeal was listed before the Division Bench on 14 July 2026 and subsequently adjourned, underscoring that the contours of this right remain actively contested and unsettled even as this article goes to press.
The Way Forward
The Laksh Vir Singh Yadav ruling has identified two principal gaps. First, in the continued absence of a dedicated statute and given divergent approaches across High Courts, there remains a pressing need for an authoritative Supreme Court pronouncement laying down a uniform framework governing the availability, scope, and enforcement of de-indexing and masking reliefs nationally, and, ideally, a standard procedural form or portal — akin to the EU's direct-to-controller Article 17 mechanism — so that claimants are not required to file a full writ petition for every instance. Second, the practical necessity of building de-indexing and masking capability directly into the search architecture of court websites and case-management portals, since most High Courts currently permit unrestricted name-based search of their own digital records, a technical gap that judicial pronouncements alone cannot bridge. The Delhi High Court's own registry has already taken a step in this direction through its operational masking software module, following deliberations of the Delhi High Court Information Technology Committee dating back to 2016.
Conclusion
The right to be forgotten in India today occupies an unusual constitutional position: firmly rooted in Article 21 as an aspect of informational privacy following Puttaswamy, consciously modelled on the reasoning of Google Spain and the erasure architecture of Article 17 GDPR, elaborately structured through judicial tests and a workable (if litigation-heavy) procedure in Laksh Vir Singh Yadav, yet still without a codified statutory anchor comparable to the GDPR, and now facing a direct appellate challenge that pits informational privacy against the equally fundamental values of open justice and freedom of trade and expression. For a claimant today, the practical path runs through a representation to the platform's Grievance Officer, followed — if that fails, as it usually does absent a court order — by an application before the court of record for masking and/or a writ petition under Article 226 for de-indexing, supported by clear documentary proof of the underlying judicial outcome and a precise, URL-specific prayer. Until the Supreme Court authoritatively resolves the pending appeals and clarifies the doctrine's outer boundaries, the right will continue to develop, as Indian privacy jurisprudence generally has, on a case-by-case basis — balancing the dignity of the individual seeking to move beyond a settled or vindicated past against the public's legitimate interest in transparent, accountable, and accessible judicial records.