Cyber Law • Data Protection • DPDP Act • Individual Rights
Data Principal rights under the DPDP Act: what changes and when?
The Digital Personal Data Protection Act, 2023 creates a statutory rights framework for individuals whose digital personal data is processed by Data Fiduciaries. These rights are principally contained in Sections 11 to 15 and cover access, correction, completion, updating, erasure, grievance redressal, nomination and corresponding duties of the Data Principal.
However, an important timing point is often missed: as of 20 August 2026, these provisions are enacted but are not yet operative. The Central Government’s commencement notification dated 13 November 2025 provides that Sections 11 to 17 will come into force eighteen months from publication, i.e. on 13 May 2027. Rule 14 of the Digital Personal Data Protection Rules, 2025 follows the same eighteen-month commencement schedule.
Businesses should therefore use the present transition period to build rights-request workflows before the statutory obligations become enforceable.
Who is a Data Principal?
A Data Principal is the individual to whom the personal data relates. Where the individual is a child, the expression includes the parent or lawful guardian. In the case of a person with disability who has a lawful guardian, the lawful guardian is included for the purposes specified by the Act.
The concept is central because the rights under Sections 11 to 14 are exercised by or on behalf of the Data Principal against the Data Fiduciary processing the relevant personal data.
When do Sections 11 to 15 actually commence?
The DPDP Act was brought into force in phases. The notification dated 13 November 2025 immediately commenced selected institutional and rule-making provisions, while the substantive processing obligations and rights framework were deferred.
Under the notification, Sections 11 to 17 commence eighteen months after 13 November 2025. This means the access, correction, erasure, grievance and nomination rights become operative on 13 May 2027.
The DPDP Rules follow a parallel schedule. Rule 14, which prescribes the operational mechanism for exercising Data Principal rights, also comes into force eighteen months after the Rules were published.
For the broader implementation timeline, see DPDP Act Compliance in India: 2025 Rules, 2026–27 Timeline, Consent, Data Breaches, Children’s Data and Penalties.
Section 11: right to access information about personal data
Section 11 gives the Data Principal the right to obtain specified information from a Data Fiduciary to whom she has previously given consent for processing of personal data.
In broad terms, the Data Principal may seek:
- a summary of the personal data being processed and the processing activities undertaken;
- the identities of Data Fiduciaries and Data Processors with whom the personal data has been shared, together with a description of the data shared; and
- other information relating to the personal data and its processing as may be prescribed.
This right is designed to make processing visible to the individual. A company that cannot map where personal data is stored, who receives it, or which processor handles it will struggle to respond reliably once the right becomes operative.
What should businesses prepare for access requests?
Organisations should establish a rights-response process that can locate personal data across:
- CRM systems;
- HR systems;
- cloud storage;
- email archives;
- support platforms;
- payment or billing systems;
- marketing systems;
- analytics tools;
- third-party processors; and
- backup or archival environments where legally relevant.
A workable response process requires a data inventory, identity-verification method, processor coordination and a documented approval workflow.
Section 12: correction, completion and updating
Section 12 gives a Data Principal the right to seek correction of inaccurate or misleading personal data, completion of incomplete data and updating of personal data.
On receiving a valid request, the Data Fiduciary is required to:
- correct inaccurate or misleading data;
- complete incomplete data; and
- update personal data where necessary.
This right has practical significance in employment records, KYC databases, financial profiles, delivery records, customer accounts, insurance systems and other settings where an inaccurate field can produce adverse downstream consequences.
Section 12: right to erasure
Section 12 also gives the Data Principal a right to request erasure of personal data. But the right is not absolute.
Upon a valid erasure request, the Data Fiduciary is required to erase the personal data unless retention remains necessary:
- for the specified purpose for which the data continues to be processed; or
- for compliance with another law in force.
This means a request for deletion does not automatically override statutory retention duties under tax, corporate, employment, financial-services, anti-money-laundering, litigation-hold or other applicable laws.
Erasure is different from account deletion
A common operational error is to treat deletion of a user account as equivalent to erasure of all personal data. They are not necessarily the same.
A platform may deactivate or delete a user-facing account while retaining certain information because of:
- legal retention obligations;
- fraud-prevention requirements;
- ongoing dispute preservation;
- security logs;
- financial records; or
- other lawful purposes.
The organisation should therefore maintain a retention schedule identifying which data can be erased immediately and which data must remain segregated or retained for a defined legal period.
Rule 8 and retention periods
The DPDP Rules, 2025 add a structured retention framework for specified classes of Data Fiduciaries. Rule 8 also creates minimum retention requirements for certain processing logs and associated data.
This makes erasure a lifecycle-governance issue rather than a simple delete-button function. Privacy teams, IT teams, legal teams and records-management teams must coordinate the response.
Section 13: right of grievance redressal
Section 13 gives the Data Principal the right to readily available grievance redressal from the Data Fiduciary or Consent Manager in respect of acts or omissions concerning:
- performance of obligations under the Act and Rules; or
- exercise of the Data Principal’s rights.
The Data Principal is expected to use the organisation’s grievance mechanism before approaching the Data Protection Board.
Rule 14: grievance response period
Rule 14 requires every Data Fiduciary and Consent Manager to prominently publish, on its website or app, the period within which grievances will be responded to. That period must be reasonable and cannot exceed 90 days.
Organisations should not treat the 90-day ceiling as a target for every case. A simpler request may need a substantially faster internal service level if the system is to remain effective.
What should a grievance mechanism contain?
A defensible grievance framework should include:
- a clearly visible privacy-rights or grievance link;
- an acknowledgement mechanism;
- ticket or reference number;
- identity-verification safeguards;
- internal ownership and escalation matrix;
- processor-response process where third parties are involved;
- documented reasons for rejection or partial compliance;
- a response timeline within the Rule 14 ceiling; and
- preservation of the grievance record for audit and Board proceedings.
Section 14: right to nominate
Section 14 creates a distinctive right allowing the Data Principal to nominate another individual who may exercise her rights in the event of her death or incapacity.
Rule 14 provides that nomination may be made in accordance with the Data Fiduciary’s terms of service and applicable law.
This will require platforms and employers to think beyond ordinary account access and build a legally controlled nomination process, especially where the account contains sensitive financial, professional, health-related or identity information.
Nomination is not the same as password sharing
A valid nominee mechanism should not be reduced to informal password access. The organisation should establish:
- nominee registration;
- identity verification;
- proof of death or incapacity;
- scope of rights the nominee may exercise;
- conflict checks where multiple claimants exist; and
- controls to prevent unauthorised disclosure.
Section 15: duties of the Data Principal
The rights framework is accompanied by statutory duties. Section 15 requires the Data Principal, among other things, to comply with applicable law while exercising rights and not to impersonate another person.
The Data Principal must not suppress material information while providing personal data for documents, identifiers, proofs or services issued by the State or its instrumentalities, and must not register false or frivolous grievances or complaints.
Accordingly, the DPDP framework is not designed as a one-way compliance burden. It combines rights with duties and procedural responsibility.
How Rule 14 requires rights to be made accessible
Rule 14 requires the Data Fiduciary and, where applicable, the Consent Manager to prominently publish on its website or app:
- the means by which a Data Principal may make a rights request; and
- the particulars, such as username or other identifier, needed to identify the individual under the applicable terms of service.
The Data Principal may then exercise the relevant rights by using the published method and furnishing the required particulars.
This effectively requires a discoverable rights interface. Hiding the mechanism deep inside a privacy policy is unlikely to be a sound implementation strategy.
Access request vs grievance: do not confuse them
These are different functions.
| Request | Legal basis | Purpose |
|---|---|---|
| Access request | Section 11 | Obtain information about personal data and processing |
| Correction/update | Section 12 | Correct inaccurate, incomplete or outdated data |
| Erasure | Section 12 | Request deletion subject to retention exceptions |
| Grievance | Section 13 | Complain about breach of obligations or interference with rights |
| Nomination | Section 14 | Authorise another individual to exercise rights on death or incapacity |
What if a company refuses an erasure request?
A refusal should be reasoned and linked to a lawful retention basis. A generic statement that “company policy requires retention” may be inadequate if the policy has no statutory, contractual or specified-purpose foundation.
The organisation should record:
- the request received;
- the data categories involved;
- the purpose of processing;
- the legal retention obligation;
- the retention period;
- whether access to retained data has been restricted; and
- the response communicated to the Data Principal.
What if personal data has been shared with a processor?
The Data Fiduciary remains responsible for compliance with its statutory obligations even where processing is carried out by a Data Processor on its behalf.
Processor contracts should therefore contain operational provisions requiring the processor to assist with:
- access searches;
- correction;
- erasure;
- grievance investigation;
- security logs;
- breach response; and
- documented retention and deletion.
For the contractual framework, see Data Processing Agreements Under the DPDP Act: Mandatory Clauses, Processor Liability, Security, Breaches and Cross-Border Data.
Rights requests and data breaches
A Data Principal rights request should not be confused with a personal data breach complaint. Where a breach has occurred, separate statutory notification and incident-response obligations may apply.
Can an individual directly approach the Data Protection Board?
Section 13 contemplates exhaustion of the Data Fiduciary’s or Consent Manager’s grievance opportunity before the Data Principal approaches the Board.
Accordingly, the internal grievance record can become part of the later regulatory record. Organisations should therefore ensure that responses are legally reasoned, consistent and capable of being audited.
How companies should prepare before 13 May 2027
The transition window should be used to implement a rights-readiness programme. A practical checklist includes:
- map all personal-data repositories;
- identify every Data Processor;
- document data-sharing flows;
- create an access-request workflow;
- create correction and update workflows;
- build an erasure and retention decision matrix;
- create a grievance portal or clearly published channel;
- set internal response SLAs below the statutory maximum;
- design nomination functionality;
- train customer-support and HR personnel;
- update Data Processing Agreements;
- test identity verification and fraud-prevention controls;
- preserve an audit trail for every rights request; and
- conduct a pre-commencement dry run before May 2027.
Data Principal rights for employees
The DPDP framework is relevant not only to consumers but also to employees where personal data is processed digitally and the Act applies.
Employers should therefore prepare for requests involving:
- identity records;
- attendance data;
- payroll records;
- performance data;
- background verification material;
- workplace access records;
- company-device logs; and
- other employee personal data.
However, erasure may be restricted where labour, tax, social-security, litigation or other laws require retention.
Common implementation mistakes
- assuming the rights are already fully in force in August 2026;
- waiting until May 2027 to build workflows;
- treating account deletion as full legal erasure;
- failing to distinguish Data Fiduciary and Data Processor roles;
- having no central record of where personal data is stored;
- using vague retention policies;
- failing to publish a visible rights-request channel;
- not training frontline support teams;
- allowing processors to ignore rights requests;
- using weak identity-verification controls; and
- failing to preserve a response audit trail.
Frequently asked questions
Are Data Principal rights under Sections 11 to 14 already enforceable in August 2026?
No. The commencement notification dated 13 November 2025 provides that Sections 11 to 17 commence eighteen months later, on 13 May 2027.
When does Rule 14 of the DPDP Rules come into force?
Rule 14 is part of the Rules scheduled to commence eighteen months after publication of the Rules on 13 November 2025, i.e. on 13 May 2027.
Can a Data Principal demand deletion of all personal data?
A Data Principal may request erasure under Section 12, but erasure is subject to continued necessity for the specified purpose and retention required by law.
How long can a company take to respond to a grievance?
Rule 14 requires the Data Fiduciary or Consent Manager to publish a reasonable grievance-response period that cannot exceed 90 days.
Can a nominee exercise DPDP rights after death?
Section 14 permits nomination of another individual to exercise the Data Principal’s rights in the event of death or incapacity, subject to the Act, Rules, terms of service and applicable law.
Is a rights request the same as a complaint to the Data Protection Board?
No. A rights request is first made to the Data Fiduciary. For grievances, the Data Principal is expected to exhaust the internal grievance opportunity before approaching the Board.
Can a company refuse an erasure request because of another law?
Yes. Section 12 preserves retention where necessary for compliance with law. The organisation should identify and document the specific retention basis.
Primary legal sources
- Digital Personal Data Protection Act, 2023 — India Code
- Digital Personal Data Protection Rules, 2025 — Ministry of Electronics and Information Technology
Conclusion
Sections 11 to 15 create the operational rights layer of India’s data-protection framework. The most important immediate compliance point in August 2026 is timing: the rights are legislated, but the principal rights provisions and Rule 14 are scheduled to become enforceable only on 13 May 2027.
That transition period should not be treated as inactivity. Organisations that wait until commencement to map data, processors, retention rules and grievance workflows may find themselves unable to respond within a defensible legal process once the rights become operative.
This article is for legal education and general information only. It is not solicitation or case-specific legal advice. The application of the DPDP Act depends on the nature of the processing, statutory commencement provisions, exemptions, sector-specific law and the factual role of the entity processing personal data.