June, 2026

From Acquittal to Anonymity: The Delhi High Court's Ruling on the Right to Be Forgotten and What Comes Next

From Acquittal to Anonymity: The Delhi High Court's Ruling on the Right to Be Forgotten and What Comes Next

Despite an acquittal from criminal charges, an individual may still face adverse consequences when records of those allegations remain discoverable online. A prospective employer conducting a routine search may encounter records of the past charges (without the acquittal appearing alongside it), even after the legal proceedings have ended. As the Indian employee background verification services market grows, with projections estimating a market size of INR 2450 crore by 2027, this problem becomes harder to ignore. Digital archives often foreground accusations over acquittals, raising deeper questions about who controls personal information and when its continued availability ceases to serve any legitimate purpose.

Against this backdrop, the High Court of Delhi (DHC) delivered India’s first detailed and applicable judicial framework for the Right to Be Forgotten (RTBF), a prominent concept under data protection norms. This article examines the DHC’s judgment and its relationship to the intertwined nature of the Digital Personal Data Protection Act, 2023 (DPDP Act), and Artificial Intelligence (AI) systems. The article also considers the parallel implications of the Supreme Court of India’s draft Regulations for the Use of AI in Courts, 2026 (Draft AI Regulations), which address similar concerns about judicial data and AI governance.

The Right to Be Forgotten Framework

The RTBF, originating from the French concept of droit à l’oubli, allows individuals to seek the removal or restriction of access to their personal information that no longer serves a legitimate purpose. In India, this principle gained recognition through the concurring opinion by HMJ Sanjay Kishan Kaul in Justice (Retd.) K.S. Puttaswamy (2017), linking it to the broader fundamental right to informational privacy under Article 21 of the Constitution. The Supreme Court, however, made clear that this right is not absolute and must be weighed against competing interests, such as freedom of speech and expression, as well as the public’s right to information.

This balance lies at the heart of the debate surrounding the RTBF. While individuals may seek greater control over personal information that continues to affect their lives, Articles 19(1) and 21 of the Constitution protect broader interests in free expression, access to information, and transparency. These tensions become significant in the context of judicial records, where the principle of open justice has traditionally favored public access to court proceedings. The DHC’s proportionality-based framework seeks to reconcile these competing interests rather than prioritize one over the other. Even so, many constitutional questions remain unresolved and may ultimately require clarification by the Supreme Court in the case examining the RTBF or by legislative intervention.

Judgment of the High Court of Delhi 

Nine years after Justice Kaul’s concurring opinion, the DHC’s judgment in Laksh Vir Singh Yadav (2026) brought considerably more specificity to what the RTBF actually requires. The DHC was dealing with over 30 consolidated petitions from individuals, primarily those acquitted in criminal matters or parties to private disputes, who continued to suffer reputational harm from searchable online records. The DHC affirmed that the RTBF is part of the right to informational privacy, and that allowing individuals to remain perpetually searchable for matters that have been legally resolved is inconsistent with the constitutional protection of privacy, dignity, and autonomy.

To make the right practically meaningful, the DHC drew a workable distinction between two forms of relief. De-indexing requires search engines to remove links to judicial records from name-based searches; the underlying record survives, but it no longer surfaces in casual searches. Masking goes somewhat further: it involves anonymizing names and identifying details in publicly accessible digital versions of judgments, while retaining the original unredacted record in court archives. The DHC also tied RTBF compliance into the existing intermediary due diligence framework under Rule 3(1)(d) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (IT Rules), effectively requiring platforms to build structured processes for receiving and acting on RTBF requests rather than handling them on an ad hoc basis.

The DHC was also explicit about what the RTBF does not cover. Relief would not ordinarily be available in cases involving offences against women or children, breaches of public trust, or situations where an ongoing public interest in accessibility outweighs the petitioner’s claim to informational privacy. This judgment is not a general license to erase inconvenient history.

The Right to Be Forgotten in Foreign and Indian Law

Global Provisions Regulating the Right to be Forgotten

The recognition of RTBF is not unique to India. The European Court of Justice, in Mario Costeja González (2014), held that search engines must remove links to personal data that is inadequate or no longer relevant, even if the original publication was lawful. Beyond this judgment, several comparable jurisdictions have addressed RTBF in this manner:

JurisdictionProvisionKey Feature
European
Union
Article 17, General Data Protection Regulation (GDPR)16Explicit RTBF, subject to exceptions for freedom of expression, legal obligations, public interest, archiving, research, and legal claims. Controllers must take reasonable steps to inform other controllers processing the data.
South KoreaArticle 36, Personal Information Protection Act17Rights to correction, deletion, and suspension of processing. Data subjects may request deletion or correction of inaccurate or unlawfully processed data, including data shared with third parties in certain circumstances.
United
Kingdom
Article 17, UK GDPR18Explicit right to erasure, subject to exemptions including freedom of expression, legal obligations, public interest, public health, research, and legal claims; interpreted alongside the principle of open justice.
BrazilArticle 18(VI), Lei Geral de Proteção de Dados Pessoais19Right to deletion/elimination of personal data processed based on consent and to review unnecessary, excessive, or non-compliant processing; enforced by the Data Protection Authority.

A reading of these foreign legislations shows that they do not converge on a common model; each reflects its own constitutional and statutory context. The EU and UK iterations of the GDPR establish an explicit statutory right to erasure with clearly defined exceptions. Brazil’s LGPD is structurally closer to India’s current position, limiting deletion rights to consent-based processing. South Korea, through successive amendments to its data protection statute, has gradually broadened the scope of correction and deletion rights across processing purposes: a trajectory worth watching while the Indian framework matures. India’s position at present is that RTBF enforcement primarily rests on judicial interpretation rather than a dedicated legislative provision, and the DPDP Act’s erasure rights cover considerably less ground than the scenarios now before courts.

The Current Legal Position in India

The Digital Personal Data Protection Act, 2023

The DPDP Act provides a limited basis for erasure rights. Section 12 of the DPDP Act grants a Data Principal who previously consented to processing the right to request erasure from the relevant Data Fiduciary. Section 6(4) of the DPDP Act permits the withdrawal of consent, and Section 6(6) of the same requires the Data Fiduciary to cease processing and to erase personal data accordingly. Section 8(7) of the DPDP Act separately requires deletion once the original purpose for collection is no longer served.

While the DPDP Act provides a basis for erasure rights, the judgment in Laksh Vir Singh Yadav (2026) has exposed some gaps in how the legislative provisions may apply to personal data that enters the public domain through judicial acts. Firstly, Section 12 of the DPDP Act creates structural tensions regarding consent for processing personal data. The cases before the DHC involved personal data that entered the public domain not through consensual processing but through judicial and investigative procedures. These individuals never agreed to have their information processed in the relevant sense; it became public as a function of criminal proceedings. The consent-centric architecture of the DPDP Act was framed with a different category of personal data processing in mind. It may not readily extend to the personal data addressed in the judgment.

Secondly, the issue of legitimate use also remains unresolved. Section 7 of the DPDP Act permits processing that complies with judicial orders and legal obligations, but does not address whether the continued online availability of concluded proceedings serves any ongoing legitimate purpose once the original rationale for disclosure has passed. This gap is compounded by the absence of a data governance framework within the eCourts ecosystem that covers retention periods, masking standards, and compliance with the right to be forgotten.

Thirdly, the balance of equities does not favor Data Fiduciaries. The right to erasure under Section 12 of the DPDP Act applies only to Data Fiduciaries, while Section 17 of the DPDP Act exempts processing needed for court functions or legal investigations. The right to erasure under the Act is, therefore, narrower than the right to be forgotten, which addresses de-indexing across third-party platforms and public records, and it is here that the harm of persistent digital exposure tends to be felt most.

The Draft Regulations for Use of AI in Courts, 2026

The Draft AI Regulations address the gaps mentioned above by mandating that processing of personal data through AI systems be governed by data privacy by design, in accordance with the DPDP Act, and that the right to privacy shall be ensured in all AI-related judicial proceedings. The significance of this is not purely procedural: by adopting DPDP principles as a baseline even where the statute does not strictly compel it, the Draft AI Regulations signal that institutional governance can, and perhaps must, move ahead of legislative resolution.

AI Systems and the Right to Be Forgotten: What the Judgment Does Not Resolve

The DHC’s judgment is a significant step forward, but it was written for a particular kind of problem: information discoverable through search engine queries. It does not address what is arguably the harder problem: personal data already embedded in Large Language Models (LLMs).

While de-indexing removes links from search results, it cannot erase information already embedded within an LLM's training data. Consequently, personal data contained in publicly accessible judicial records may continue to surface in AI-generated outputs even after a successful RTBF claim. Concerns arise about the effectiveness of RTBF in the digital age, especially given that LLMs may be trained on court records. The Supreme Court’s Draft AI Regulations seek to address this by prohibiting the retraining of AI models using court data without approval and by requiring the anonymization of personal data. They mandate that training data be accurate, representative, and lawfully obtained, while banning datasets that are unlawfully collected or biased. However, the Draft AI Regulations apply only to court actors and do not address legacy data in existing LLMs, so addressing this may fall to the DPDP framework.

Although the emerging field of machine unlearning seeks to develop methods for removing specific data from trained models, no reliable or verifiable standard for such erasures currently exists. In light of this, three practical implications warrant attention. The lack of standardized audit mechanisms makes it challenging to verify successful machine unlearning and test RTBF compliance in AI systems. Stronger regulatory requirements at the model training stage may also be needed to enforce data minimization, especially for judicial records, unless justified by public interest. Finally, it remains unclear which party, the model developer, deployer, or distributor, bears RTBF obligations in the AI context.

Further, while regulatory developments in jurisdictions such as the EU AI Act’s General-Purpose AI Code of Practice and the GDPR have begun to address the interaction between AI systems and data protection rights, guidance on AI-generated outputs or obligations relating to training data remains absent in the DPDP Act and the Digital Personal Data Protection Rules, 2025. This gap in the Indian interpretation of the RTBF is likely to become one of the more consequential issues in future data governance debates.

Sector-Specific Compliance Implications

The DHC’s judgment sets in motion a layered compliance challenge spanning multiple sectors. By integrating RTBF relief into existing intermediary due diligence obligations, the court has made it clear that erasure requests can no longer be treated as exceptional or case-by-case matters.

Search engines and legal databases face the most immediate pressure. The DHC’s reading of Rule 3(1)(d) of the IT Rules means intermediaries are now expected to have defined intake workflows and turnaround timelines for RTBF requests, treating erasure as a baseline expectation, not an aspirational standard. Background verification firms and HR technology companies also face a distinct risk: a record de-indexed from a search engine may still appear in a background verification product if the firm pulls judicial data through direct API access to eCourts or proprietary scraped databases. Building RTBF status flags into data ingestion pipelines is now a governance imperative, not a future consideration.

Data Protection Officers, or equivalent officers in the case of non-Significant Data Fiduciaries, can draw on the DHC's proportionality framework as a working template for assessing internal erasure requests: acquittal and discharge as strong triggers for relief, with offences against women, children, or public trust as exclusions. This applies even before the DPDP Act's grievance mechanisms become fully operational in May 2027. There is also the challenge of cross-border enforcement. While the DHC’s de-indexing directions are aimed at search engines and platforms, many of these entities are incorporated outside India. Although Section 16 of the DPDP Act applies to Data Fiduciaries processing the personal data of Indian Data Principals, regardless of location, the enforceability of RTBF orders against foreign entities and their alignment with global platform compliance frameworks remain unclear. Organizations relying on judicial data, particularly through foreign-incorporated API providers, may seek legal advice on their cross-border obligations.

From an AI perspective, organizations developing or deploying AI tools in the judicial ecosystem face a further compliance layer under the Draft AI Regulations. Specific AI systems require pre-deployment approval; human oversight is mandatory for outputs that could affect judicial decisions; and opaque or solely algorithmic decision-making in judicial outcomes is prohibited. Developers of legal AI tools, including transcription and case management systems, will need to navigate both the DHC's RTBF framework and the finalized version of the Draft AI Regulations.

The broader signal is this: India's RTBF jurisprudence is moving faster than its statute. Organizations that wait for legislative clarity before building erasure infrastructure are not managing risk; they are accumulating it.

Policy Recommendations and the Way Forward

The RTBF offers an opportunity for policymakers, judicial institutions, regulators, and industry stakeholders to develop a more coherent, future-ready approach as its jurisprudence evolves in India. While recent judicial developments have provided important guidance, greater regulatory clarity would support consistent implementation across the digital ecosystem.

The DPDP Act’s erasure framework should be extended beyond consent-based processing. Legislators and policymakers could consider whether supplementary guidance or targeted amendments can bring the personal data that enters the public domain through judicial or investigative purposes within the ambit of erasure rights under the DPDP Act, with appropriate carve-outs for public interest.

Secondly, the eCourts ecosystem would benefit from a comprehensive data governance policy covering the full lifecycle of judicial records, not just specific use cases. The Supreme Court’s e-Committee and the National Informatics Centre, which regulates the functioning of the eCourts platform, could develop standards for retention, masking, and de-indexing of judicial records, along with mechanisms to communicate RTBF decisions to downstream users, including background verification firms, legal databases, and search engines.

Upon constitution, the Data Protection Board could also issue guidance on RTBF complaints involving judicial records ahead of the DPDP framework’s full operational date in May 2027. The DHC’s proportionality framework serves as a useful model: it identifies acquittals and discharges as key triggers, while excluding offences against women, children, and public trust from the RTBF. Additionally, any legislative undertaking could clarify exceptions for journalistic, historical, and academic uses of judicial data. India, at the moment, does not have a provision equivalent to Article 85 of the GDPR, which balances data protection rights with freedom of expression for various purposes. A targeted amendment to the DPDP Act or guidance through subordinate legislation would reduce uncertainty for media, legal publishers, and researchers, helping to prevent RTBF obligations from impeding legitimate expression and research.

Perhaps the most forward-looking gap concerns AI. The DPDP framework currently does not address machine-unlearning standards or obligations regarding AI-generated outputs. India would benefit from genuine multi-stakeholder engagement (industry, academia, and civil society) before this framework calcifies around assumptions that may not hold for long. The Draft AI Regulations’ insistence on human oversight and prohibition of sole algorithmic decision-making in high-stakes contexts offer a useful reference point for the broader discussion, and their human-in-the-loop requirement for outputs affecting individual rights may also inform future DPDP legislation.

Conclusion

The DHC's judgment in Laksh Vir Singh Yadav(2026) is a meaningful step forward for India's data protection framework, giving the RTBF practical shape for the first time. Important gaps, however, remain in the legislative and regulatory framework concerning personal data. A de-indexing order for search engines does not resolve issues within the DPDP Act’s consent-based structure or the challenge of personal data in AI training. The DHC’s recognition of the reputations of legally exonerated individuals presents a balanced approach to privacy and transparency. As AI reshapes how information is stored and surfaced, India's RTBF framework must address unresolved questions, including the persistence of personal data in AI datasets, standards for machine unlearning, and the responsibilities of AI developers when using judicial records.

Anahida Bhardwaj is an Associate in the Privacy and Policy Team at DSCI. Based in Delhi, she is interested in emerging tech, internet governance, and AI. She can be reached at : anahida.bhardwaj@dsci.in or policy@dsci.in

Author: Anahida Bhardwaj