Ask any Indian brand to delete your data.
Under Section 12, you can ask a Data Fiduciary to erase the personal data they hold on you, as long as they do not need it for an ongoing purpose or a specific law. Most people never ask because they cannot find who to write to. We solved that part.
Pick a brand, click the button, edit the two blanks, send.
Banks (8)
E-commerce (14)
Edtech (6)
Fintech & Payments (17)
Food delivery (2)
Real-money gaming (3)
Healthtech (8)
Hospitality (1)
Insurance (6)
Streaming & media (8)
Ride-hailing (3)
NBFCs (3)
Quick commerce (3)
Retail (1)
SaaS (7)
Social & platforms (12)
Telecom (3)
Travel & booking (5)
When they can refuse
A bank cannot delete your KYC before the RBI-mandated retention ends (5 years post account closure, 10 for STR-flagged accounts). An ecommerce platform can retain invoice data as required under tax law. Ongoing service purpose is also a valid ground. But "our CRM does not have a delete button" is not.
What actually happens
Most brands will first ask you to verify your identity. That is fine. Then a real erasure means: your account row is deleted or anonymised, your data is removed from analytics warehouses, your data is removed from third-party processors they shared it with. Ask for confirmation of all three.
Keep a copy of everything
Your original email, their acknowledgement, their final response. If you ever have to escalate to the Data Protection Board under Section 13, the paper trail is what the Board looks at. Reply-to-reply chain, not a screenshot of an app ticket.
Building a compliance product?
The dcomply DSR Portal handles the other side of this. Requests from data principals land in a queue, get routed to the right team, and get answered inside SLA. Used by 200+ Indian businesses.
See the DSR Portal →