INTRODUCTION

We leave behind a data trail while using the internet, either actively or passively, across various websites and platforms. These digital footprints build up over time and incorporate everything from online activities, interactions, and personal information collected by the platforms, often without their users’ explicit consent. One such instance occurred in 2023, when Meta was fined $1.3 billion for violating E.U. data privacy rules. It results in the violation of individual privacy, which is protected under Article 21 of the Constitution of India. Due to the data being collected on a large scale, it becomes imperative to safeguard individual privacy by prohibiting unauthorized storage and processing of personal data.

To address the privacy concerns, the concept of the Right to be Forgotten has emerged, which enables individuals to seek erasure of their personal information in certain situations. The first legal recognition of this right was in the EU in Google Spain SL v. Agencia Española de Protección de Datos (AEPD) and Mario Costeja González (2014), granting people the right to ask organizations to erase their data when it is no longer required. This caused a worldwide movement for the importance of privacy and RTBF.

In the absence of dedicated legislation that explicitly recognizes RTBF, the framework on data protection in India has been profoundly shaped by the seminal case of Justice K.S. Puttaswamy v. Union of India, which established the right to privacy as a fundamental right, leading to the unfolding of significant developments thereafter.

This blog aims to provide a comparative analysis of the data protection framework in India and the EU concerning RTBF. It also offers suggestions on what India can learn from the EU to implement its data protection framework effectively.

RIGHT TO BE FORGOTTEN IN THE EUROPEAN UNION

By the demands and requirements of society, laws relating to RTBF have rapidly evolved over the past few years. However, a significant milestone in this evolution was observed in the Google Spain case, when the European Court of Justice held that “Every individual has the right, under certain conditions, to ask search engines to remove links with personal information about them.” The judgment paved the way for this right to be granted recognition in 2016 under Article 17(1) of the GDPR, which allows Data Subjects to seek prompt erasure of their data from the data controller. This right is applicable under specific conditions, including when:

1. The data is no longer necessary for the purpose for which it was collected;

2. The data subject withdraws consent previously given for processing;

3. The data is being processed unlawfully, or

4. There is a legal obligation to erase the data. 

However, the right is subject to certain exceptions mentioned in Article 17(3) of GDPR, notably, where processing is necessary for the exercise of the right of freedom of expression and information, for public interest, for research or statistical purposes, or to comply with legal obligations. Through this ruling, the court aimed to balance an individual’s right to privacy with the public’s right to access information.

The jurisprudence developed in the Google Spain case laid the groundwork for Google v. CNIL, wherein it was held that under EU law, RTBF is only applicable in its 28 member states, and there is no obligation on Google and other search engines to apply it globally.

Article 51 of GDPR establishes Data Protection Authorities, one of the main elements of the European mechanism of data protection. They are independent public bodies responsible for enforcing the application of the regulation within each EU member state. This includes their ability to ensure compliance, provide guidance to data controllers and processors, handle complaints, and issue fines.

RIGHT TO BE FORGOTTEN IN INDIA

The legal landscape around the concept first surfaced in 2017 after the right to privacy was recognized as a fundamental right under Article 21 of the Constitution of India in the Puttaswamy case. While several cases have been filed seeking enforcement of RTBF, the courts have been hesitant and inconsistent in their application. In Dharamraj Bhanushankar Dave v. State of Gujarat (2015),  a writ petition was filed under Article 226 praying for permanent restraint of the public exhibition of a non-reportable judgment that was displayed on several websites where the petitioner was charged with culpable homicide amounting to murder and other various criminal offenses. He contended that the display of the same had affected his personal as well as professional life, even after he was acquitted by the Sessions Court and, subsequently, the High Court. However, the court dismissed the petition, stating the publication of the judgment did not violate Article 21. However, in Sri Vasunathan v. Registrar General, the Karnataka High Court gave a conflicting ruling, wherein it upheld the petitioner’s claim to remove the name of his daughter from the cause title, stating it was ‘in line with the trend in the western countries’ to protect the modesty and reputation of women involved in sensitive cases. Further, in Zulfiqar Ahman Khan v. Ms. Quintillion Business Media Pvt Ltd., the Delhi High Court directed the removal of defamatory articles concerning #MeToo allegations against the petitioner and recognized the ‘right to be forgotten’ as an integral part of the right to privacy. In 2021, the Delhi High Court in Jorawar Singh Mundy v. Union of India, also acknowledged the need to balance an individual’s right to privacy with the public’s right to information and granted interim relief to the petitioner by directing websites to remove access to the judgments as it infringed the petitioner’s privacy and dignity. 

LEGISLATIVE FRAMEWORK IN INDIA

In the 2019 draft of the Personal Data Protection Bill, the inclusion of RTBF was recommended by the B.N. Srikrishna Committee in cases where data is misleading, outdated, or humiliating. In a welcoming move, the Digital Personal Data Protection Act, 2023,  adopted a revised framework tailored to modern privacy challenges and global best practices. 

A key strength of the DPDP Act is its insistence on explicit consent for data processing,  mandating that personal data cannot be processed without clear authorization unless under specific lawful conditions. It introduces the Right to Erasure, allowing people to request the deletion of their data,  enhancing control over their digital identity, which requires that all personal data breaches be reported both to the Data Protection Board of India and to affected individuals, ensuring transparency. 

However, the Act failed to include the previously proposed rights, such as data portability, raising concerns about the autonomy of users and seamless data mobility between platforms.

COMPARATIVE ANALYSIS OF GDPR AND DPDPA IN THE CONTEXT OF RTBF 

When Indian data protection laws are scrutinized, it becomes evident that a generalized approach is adopted to safeguard personal data; it lacks the specificity found in GDPR, where the clauses are designed to protect the interests of data subjects. The primary focus of GDPR is on its emphasis on the timely compliance with data requests, as it is outlined in Article 12(3) of GDPR that upon a request of a data subject under Articles 15 to 22, the controller needs to take action within one month of the request.  In contrast, Indian law does not stress acting promptly, as there is no time-bound obligation on data fiduciaries to act on the request, which shows the lack of procedural timelines. It shifts from“optics of protection” to “real protection” is essential. It will impose legal obligations on data fiduciaries, which will easier to establish a violation and initiate enforcement action if case time bound is not complied with. Also, public trust grows when they notice that their requests are not only acknowledged but also addressed in a stipulated time frame.

The scope of the Right to Erasure under GDPR is inclusive, allowing individuals to seek deletion of data processed unlawfully, especially without their consent. Conversely, in India, the RTE is solely restricted to digital personal data processed with prior consent. There exists a gap in redressal in case of potential misuse and overreach, also, it interrupts data principals’ control over their digital identity.

The disparity that further persists is the difference in interpreting data. In India, data protection laws apply only to digital personal data or physical data that has been converted into digital format, leaving the places where physical data is widely used, like healthcare, education, and governance. Meanwhile, GDPR  includes any personal information intended for automated processing or data organized within a filing system, regardless of its initial medium.

CHALLENGES AND WAY FORWARD

India’s effort to implement the RTBF is obstructed by many overlapping challenges rooted in the country’s fundamental rights conflict, technological limitations, and public unawareness. Despite the international support for RTBF, India still lags due to foundational gaps.

A significant roadblock is the lack of an explicit statutory framework formally recognizing RTBF. Although the Draft of Digital Personal Data Protection Bill, 2023, implicitly supports the concept, proper scope and enforcement mechanisms are absent. The ambiguity not only leaves the individual uncertain about their request of right to erasure but also creates compliance challenges for data fiduciaries without clear guidance. There is an ongoing constitutional tension between personal privacy and access to information, as judicial interpretation is rendered on a case-by-case basis. Further, the RTBF implementation needs to navigate through Article 19(1) (a) of the Indian Constitution, especially to avoid undue censorship of public interest information.

Technological limitations are one of the major challenges that make erasure of data almost impossible, as the data storage on the internet is distributed, meaning there may exist some archived backup, third-party repost, or mirrored content, which makes erasure of data more difficult. The RTBF requests are difficult for the search engine and tech platform to verify and determine whether they should be complied with. 

A clear first step that needs to be followed is to codify RTBF explicitly in law, which will provide legal certainty, reduce arbitrariness in enforcement. The draft of the Digital Personal Data Protection Act, 2023, lacks a standalone RTBF provision, limiting itself to the right to “correction and erasure,” which is too narrow to address concerns like delisting search results, removal from public records, and balancing privacy with freedom of expression. Adapting from EU model (GDPR Article 17), Legislation should clearly define the scope of erasure request particularly specifying the essentials like unused data or when consent is withdrawn and including strong exception is a must, similar to the GDPR where the erasure is withholds when processing is vital for freedom of expression, public health, archival use, or legal claims to make sure RTBF is not interfere in free flow of information.

A dedicated regulator is essential for enforcement. Under the GDPR,  independent supervisory bodies with adequate funding and autonomy are mandated, which is explicitly mentioned in  Article 52, that the supervisory bodies should act with complete independence. India’s Data Protection Board, as envisioned under the 2023 Act, should be free from political influence, staffed by experts and have the authority to issue binding orders and penalties by introducing procedural guidelines, and resolve complaints promptly.

The foundation of privacy lies in autonomy, but this right is subject to reasonable privacy expectations. Unnecessary data retention infringes this right. When conflicts arise regarding the relevance of data use, a balancing test must weigh personal privacy against the company’s need to retain data.

CONCLUSION

The RTBF reflects the growing crucial aspect of data privacy and the autonomy of the individual to regain control over their personal information in a hyper-connected world.  While the EU has established a strong model through GDPR, India is still in the process of developing a clear, enforceable structure. The DPDPA, 2023, marks a positive step but lacks the explicit recognition and implementation of RTBF. Moving forward, India must maintain a balance between individual privacy and public interest with transparency and strengthen enforcement mechanisms to align with democratic values of the country.

Leave a Reply

Discover more from Kautilya Society

Subscribe now to keep reading and get access to the full archive.

Continue reading