miniOrange Logo

Products

Services

Plugins

Pricing

Resources

Company

Data Principal Rights Under India’s DPDP Act

28th September, 202612 Min Read

The Digital Personal Data Protection Act, 2023 (DPDP Act) gives individuals a defined set of rights over their digital personal data.

These include the right to access information about their personal data (Section 11), seek correction and erasure (Section 12), obtain grievance redressal (Section 13), and nominate another individual to exercise their rights in specified circumstances (Section 14). The Act also provides a right to withdraw consent (Section 6) where consent is the basis for processing.

For businesses, these rights create corresponding operational requirements. A Data Fiduciary must be able to receive and process requests, identify the relevant personal data, determine whether the requested action can be taken, and respond through the prescribed mechanism.

DPDP Rights: Key Implementation Dates and Timeline

  • The DPDP Rules, 2025 were notified on November 13, 2025.
  • The Data Principal rights and grievance provisions are scheduled to take effect on May 13, 2027, after an 18-month transition period.
  • From that date, grievances must be addressed within a reasonable period not exceeding 90 days.

This gives organizations a defined preparation window to establish their rights-request and grievance processes. Until the provisions take effect, it is important to distinguish between rights established by the DPDP Act and those that have not yet commenced.

The DPDP Act Grants Four Rights, Not Every GDPR Right

Data Principal rights under the DPDP Act are primarily set out in Sections 11 to 14. Section 6 separately addresses withdrawal of consent.

The rights

1) Right to Access

Section 11 gives a Data Principal the right to obtain:

  • A summary of the personal data being processed
  • A summary of the processing activities undertaken on that personal data
  • The identities of other Data Fiduciaries and Data Processors with whom the personal data has been shared
  • A description of the personal data shared with those entities

This makes the right to access personal data in India broader than simply asking an organization for a copy of the information it holds. The provision also gives the Data Principal visibility into relevant processing and data-sharing relationships.

2) Right to Correction and Erasure

Section 12 provides the right to correction, completion, updating, and erasure of personal data.

A Data Principal can seek correction where personal data is inaccurate or misleading, completion where it is incomplete, and updating where information has changed. The right to erasure applies subject to the retention conditions specified in the Act.

Organizations therefore need a process that can distinguish between data that should be corrected or deleted and data that must continue to be retained.

3) Right to Grievance Redressal

Section 13 gives a Data Principal the right to readily available grievance redressal.

The Data Principal must first use the grievance mechanism provided by the Data Fiduciary or Consent Manager before approaching the Data Protection Board of India. This makes grievance handling part of the core rights framework rather than a separate customer-service function.

4) Right to Nominate

Section 14 allows a Data Principal to nominate one or more individuals who may exercise the Data Principal’s rights in the event of death or incapacity.

The right to nominate under Section 14 is a distinctive feature of the DPDP Act. Businesses must therefore account for requests made by an authorized nominee as well as requests made directly by the Data Principal.

The withdrawal right

Section 6 (4) provides a separate right to withdraw consent where consent is the basis for processing personal data.

A Data Principal may withdraw consent at any time, and withdrawing consent must be as easy as giving it. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

Organizations should therefore maintain a clear distinction between consent withdrawal and deletion. Withdrawing consent does not automatically require every record relating to the individual to be deleted.

What it does not say

Privacy frameworks are often compared with the GDPR, but the comparison needs to remain precise.

The DPDP Act does not create a general:

  • Right to data portability
  • Right to object to processing
  • Right not to be subject to solely automated decision-making

These rights exist in the GDPR under specific provisions. The distinction is important when defining the scope of a privacy rights program.

Organizations should build their processes around the rights actually provided by the applicable law rather than assuming that rights recognized under another framework automatically apply.

Rights Run Between a Data Principal and a Data Fiduciary

A rights request should begin by identifying the correct Data Fiduciary.

Under the DPDP Act, the Data Fiduciary determines the purpose and means of processing personal data. A Data Processor processes personal data on behalf of the Data Fiduciary. The Data Fiduciary remains responsible for DPDP compliance in relation to processing undertaken by it or on its behalf.

This distinction becomes especially important when personal data is distributed across multiple systems or handled by external service providers. A Data Processor may hold the relevant information, but the Data Fiduciary remains the primary entity responsible for managing the Data Principal’s request.

Rule 14 requires a Data Fiduciary and, where applicable, a Consent Manager to prominently publish the means through which Data Principals can exercise their rights and the identifiers required for making a request. The Rule also addresses requests made to the Data Fiduciary to whom the Data Principal previously gave consent.

For children and persons with disabilities who have a lawful guardian, the statutory framework also allows rights to be exercised through the relevant parent or lawful guardian, subject to the applicable verification requirements.

The Practical Rule

Identify the Data Fiduciary first. Then use the request mechanism and identifiers it has published.

The right belongs to the Data Principal, while the corresponding operational responsibility rests with the Data Fiduciary.

‘Erasure’ Does Not Automatically Mean ‘Delete Everything Now’

The right to erasure under the DPDP Act is not absolute.

Section 12 requires a Data Fiduciary to erase personal data on an erasure request unless retaining it is necessary for the specified purpose or required to comply with any law in force.

That means an organization should not process every erasure request as an instruction to immediately delete every record associated with an individual. The first step is to determine whether the relevant data still needs to be retained.

What should a business check before erasure?

The assessment should answer two questions:

  • Is the personal data still necessary for the specified purpose?
  • Is there a legal requirement to retain it?

Where neither condition applies, the relevant personal data should be erased.

The process should also account for Data Processors that hold the same information. Where deletion is required, the Data Fiduciary should ensure that the relevant processors take the corresponding action.

This is why erasure processes should be connected to the organization’s data retention policy under the DPDP Act, data inventory, processor governance, and legal-hold procedures.

Example

Consider an individual who asks an online retailer to erase personal data used for a marketing purpose after withdrawing consent.

The retailer should determine which information is associated with that purpose and whether any other records must be retained under applicable law. Marketing-related data that no longer has a valid basis for retention may need to be erased, while transaction or accounting records subject to a separate legal retention requirement may need to remain.

The request therefore requires an assessment of purpose and retention rather than an automatic deletion of every record.

Key Takeaway

Before approving an erasure request, determine whether the data is still required for the specified purpose or must be retained by law. A general expectation that the data “may be needed later” does not, by itself, establish a valid retention basis.

A Valid Request Needs Identity, a Channel, and a Clear Ask

A rights process begins with three basic questions: Who is making the request? Which Data Fiduciary should receive it? What specific right is being exercised?

Rule 14 provides the framework for the request mechanism. It requires the Data Fiduciary and, where applicable, Consent Manager to publish the means available for exercising rights and the identifiers that may be needed to identify the Data Principal.

The statutory floor

A request should account for:

  • The correct Data Fiduciary
  • The request mechanism published by that Data Fiduciary
  • The identifier or other particulars required to identify the Data Principal
  • The specific right being exercised

The data access request should also contain accurate and authentic information. Section 15 establishes duties for Data Principals, including prohibitions on impersonation and false or frivolous grievances and requirements relating to verifiably authentic information for certain requests.

What the Business Process Should Add

The statutory requirements need to be translated into an operational workflow.

A well-designed process should include:

  • Identity verification appropriate to the nature and sensitivity of the request
  • Routing from each request type to the relevant business function and system
  • A retention assessment before erasure
  • Coordination with Data Processors where data must be corrected or erased
  • A documented grievance escalation process with a set 90-day ceiling as per Rule 14(3)
  • A record of the request, action taken, and response provided

This is where rights handling intersects with data discovery, records management, retention controls, vendor governance, consent management, and privacy operations.

Data Principal Rights Under the DPDP Act at a Glance

Right What it covers
Right to Access Section 11 of the DPDP Act gives a Data Principal the right to obtain a summary of personal data being processed, the relevant processing activities, and information about other Data Fiduciaries and Data Processors with whom the data has been shared. This provides the statutory basis for a right to access personal data in India and related data-sharing disclosures.
Correction and Erasure Section 12 of the DPDP Act which establishes the right to erasure in India, lets a person seek correction of personal data, complete incomplete data, update it, and erase it where it is no longer needed for the specified purpose or is not required to be retained by law.
Grievance Redressal Section 13 of the DPDP Act provides a right to readily available grievance redressal. The Data Principal must first use the applicable grievance mechanism before approaching the Data Protection Board of India.
Right to Nominate Section 14 of the DPDP Act gives a Data Principal the right to nominate one or more individuals who can exercise the Data Principal’s rights in the event of death or incapacity. The nominee exercises those rights in accordance with the DPDP Act and the Rules.
Withdrawal of Consent Section 6 allows a Data Principal to withdraw consent where consent is the basis for processing. Consent withdrawal must be as easy as giving consent and does not retrospectively affect processing that was lawful before withdrawal.
Data Principal Duties Section 15 of the DPDP Act establishes duties including avoiding impersonation and false or frivolous grievances and providing verifiably authentic information in specified circumstances. A breach may attract a false complaint penalty of up to Rs 10,000 under the Schedule.
Request and Grievance Timeline Under Rule 14 of the DPDP Rules, 2025, a Data Fiduciary must publish the rights request channel and the identifiers required for making a rights request. The Rule also requires grievances to be answered within a 90-day grievance timeline once the provision becomes operative.

Individuals and Businesses See the Same Right Differently

The same Data Principal right creates different responsibilities for the person exercising it and the organization responsible for fulfilling it.

Exercising (Individual)

A Data Principal should:

  • Identify the correct Data Fiduciary and use its published request channel.
  • Clearly state the specific right being exercised and provide the identifier requested.
  • Exhaust the Data Fiduciary’s grievance redressal mechanism before approaching the Data Protection Board.
  • Provide accurate and authentic information in accordance with the duties under Section 15.

Fulfilling (Business)

A Data Fiduciary should:

  • Publish the means for making rights requests, the required identifiers, and the grievance timeline under Rule 14.
  • Verify the Data Principal’s identity and route the request to the appropriate system or team.
  • Check applicable retention requirements and any legal hold before carrying out erasure.
  • Ensure required correction or deletion actions are communicated to relevant Data Processors and record the response.

What they share

Both sides depend on the same core elements:

  • a clear request channel,
  • a verified identity,
  • a defined purpose for the personal data, and
  • a response within the applicable timeline

These elements also depend on an accurate view of the organization’s data environment. When data sources, processing arrangements, or storage locations change, the Data Fiduciary should reassess where the relevant data resides and whether the rights-request process still reflects the current data flow.

A Practical DPDP Workflow for Rights Handling

The DPDP Act does not require ordinary Data Fiduciaries to perform an annual rights audit. The more immediate requirement is to establish an operational process before the relevant provisions commence and to review that process whenever the organization’s processing environment changes.

A practical rights workflow can follow these stages:

A Practical DPDP Workflow for Rights Handling

This workflow should connect with the organization’s privacy and data governance controls rather than operate as a standalone process.

When Should the Workflow Be Reviewed?

Organizations should review or refresh the workflow when:

  • They begin collecting personal data on the basis of consent.
  • A new Data Processor or Consent Manager is introduced.
  • The purpose of processing changes.
  • Retention periods are changed.
  • Processing involving children or lawful guardians begins.
  • The organization receives its first access, correction, erasure, nomination, or grievance request.

For a Significant Data Fiduciary, additional obligations apply, including annual Data Protection Impact Assessments and audits. These requirements create an additional compliance layer and do not replace the baseline rights-handling process.

There Is No General Right Against Automated Decisions

The DPDP Act does not establish a general right to object to processing, a right to data portability, or a right not to be subject to solely automated decisions.

These concepts should remain clearly separated from the rights expressly provided under the DPDP Act. Treating them as part of the Indian framework can lead to inaccurate descriptions of an organization’s statutory obligations.

The Act does, however, contain an important data-quality requirement in Section 8(3). Where personal data is likely to be used to make a decision affecting a Data Principal or is likely to be disclosed to another Data Fiduciary, the Data Fiduciary must ensure that the data is complete, accurate, and consistent.

This is an obligation imposed on the Data Fiduciary. It should not be presented as a standalone individual right to receive an explanation of an automated decision.

The relevant provisions are scheduled to take effect on May 13, 2027 under the current commencement notification.

Rights Obligations Do Not Disappear

The DPDP Act places additional obligations on Significant Data Fiduciaries, including appointing a Data Protection Officer, conducting independent audits and annual Data Protection Impact Assessments, and meeting the additional due-diligence requirements prescribed by the Rules. These obligations are specific to SDFs and do not apply to every Data Fiduciary.

The underlying Data Principal rights framework has broader relevance. Once the applicable provisions commence, every Data Fiduciary will need to provide a mechanism for receiving rights requests, handle access, correction and erasure requests, maintain a grievance redressal mechanism, and implement consent withdrawal where applicable. Rule 14 specifically requires the relevant request mechanism to be published and provides for grievance redressal within a reasonable period not exceeding 90 days.

Organizations do not need to wait until they are classified as a Significant Data Fiduciary to establish these processes. Even a smaller business can begin with a defined rights-request channel, a named grievance contact, a basic verification process, and a documented method for assessing and fulfilling requests. These provide the operational foundation for meeting the applicable rights obligations when they commence.

Four Data Principal Rights Claims to Avoid

Claim What is more accurate
Rights are fully enforceable today Sections 11 to 17 are in the 18-month commencement group. Rule 14 is also in the 18-month commencement group. The scheduled date is May 13, 2027.
Erasure is absolute Section 12 makes erasure subject to retention that is necessary for the specified purpose or required for compliance with a law in force. An erasure request therefore requires a retention assessment.
The DPDP Act provides GDPR-style rights The DPDP Act does not create general rights to data portability, objection, or protection against solely automated decisions. Those rights should not be presented as part of the DPDP Act simply because they appear in the GDPR.
Any grievance can go directly to the Board Section 13 requires the Data Principal to exhaust the opportunity for grievance redressal before approaching the Board. A business’s internal grievance mechanism is therefore an essential part of the statutory process.

Prepare for Data Principal Rights Before May 2027

Understanding data principal rights under the DPDP Act requires looking at both sides of the relationship: the individual exercising a right and the Data Fiduciary responsible for responding to it.

For individuals, the process depends on identifying the relevant Data Fiduciary, using the correct channel, and clearly stating the right being exercised. For businesses, fulfillment requires identity verification, data discovery, purpose and retention analysis, coordination with Data Processors, and documented responses.

The DPDP Rules were notified on November 13, 2025, while the core rights provisions and Rule 14 are scheduled to take effect on May 13, 2027. Organizations should use this period to establish their rights-request and grievance workflows and review them as their data sources, processing purposes, processors, and retention requirements evolve.

Build a Practical Rights-Request Process

Establish a process that can receive, verify, route, fulfill, and document Data Principal requests in line with the DPDP framework.

Frequently Asked Questions

1. What rights does the DPDP Act give Data Principals?

The DPDP Act provides rights relating to access, correction, completion, updating, erasure, grievance redressal, and nomination under Sections 11 to 14. Section 6 separately provides a right to withdraw consent where consent is the basis for processing.

2. How can you make a rights request under the DPDP Act?

A Data Principal should identify the relevant Data Fiduciary, use the request method it publishes, and provide the required identifier and other particulars. Rule 14 sets out the framework for how these request mechanisms are to be made available.

3. Can I ask a company to erase all my data whenever I want?

A Data Principal can request erasure under Section 12, but the right is subject to the Act’s retention conditions. Data may need to be retained where it is necessary for the specified purpose or required by law.

4. Does withdrawing consent delete data that was already processed?

No. Withdrawal of consent does not affect the legality of processing that was carried out before withdrawal. The organization must then assess any continued processing under the applicable legal basis and retention requirements.

5. What is the right to nominate, and why is it unique to India?

Section 14 allows a Data Principal to nominate one or more individuals to exercise their rights in the event of death or incapacity. The nomination mechanism is a distinctive feature of the DPDP Act’s rights framework.

6. How long can a Data Fiduciary take to resolve my grievance?

Rule 14 provides that the grievance redressal period must be reasonable and must not exceed 90 days. Rule 14 is scheduled to take effect on May 13, 2027 under the current commencement notification.

7. Does the DPDP Act give a right to data portability or against automated decisions?

No general right to data portability or a right not to be subject to solely automated decisions is provided by the DPDP Act. These are provided for in the GDPR under Articles 20 and 22, and should not be presented as statutory rights under the Indian framework.

8. When do the Data Principal rights provisions take effect?

Sections 11 to 17 of the DPDP Act are included in the 18-month commencement group under the November 13, 2025 commencement notification. Rule 14 is also in the 18-month group under the DPDP Rules, 2025. The scheduled commencement date is May 13, 2027.

About the Author


Saloni Walimbe

Content Writer

As a seasoned content specialist, Saloni Walimbe specializes in bridging the gap between intricate cybersecurity frameworks and the end-user. With extensive professional experience and a postgraduate degree in Marketing, she has a proven track record of navigating highly technical industries like IT and market research. At miniOrange, she focuses on creating streamlined, strategic narratives that simplify the complexities of the cybersecurity landscape, ensuring mission-critical information is both professional and easy to digest for a global audience.

Leave a Comment