Back to articles
DPDP Act

Rights of Data Principals — And How to Honour Them

Access, correction, erasure, grievance redressal and nomination — what each right means and the SLAs you should design for.

March 25, 2025 7 min read Vrushali Borade

The Five Key Rights

Chapter III of the DPDP Act grants Data Principals five substantive rights. The right to information (Section 11) allows them to obtain a summary of the personal data being processed, the processing activities undertaken, and the identities of other Data Fiduciaries and Processors with whom the data has been shared.

The right to correction and erasure (Section 12) requires Data Fiduciaries to correct inaccurate or misleading data, complete incomplete data, update outdated data, and erase data that is no longer necessary for the purpose for which it was collected — unless retention is required by law.

The right to grievance redressal (Section 13) obliges every Data Fiduciary to provide a readily-available mechanism for complaints, and to respond within a period to be prescribed by the Rules (currently expected to be 30 days).

The right of nomination (Section 14) permits a Data Principal to nominate another person to exercise their rights in the event of death or incapacity — a novel provision without direct GDPR parallel.

The right to withdraw consent (Section 6(4)) must be exercisable as easily as consent was given, and withdrawal must not affect the lawfulness of processing done before withdrawal.

Operational SLAs and Tooling

You need a user-facing rights portal — or, at minimum, a monitored email intake — with published turnaround times. We recommend an internal SLA of 7 days for access requests, 14 days for correction requests, and 30 days for erasure and grievance requests, with an audit log capturing every action taken.

Build a lightweight case-management workflow: intake → identity verification → routing to data owner → action → response to Data Principal → closure log. Identity verification is often overlooked but is essential: honouring an erasure request from an imposter is itself a personal data breach.

Instrument your systems so that a single 'delete user X' command propagates across production databases, analytics warehouses, marketing tools, backup snapshots and third-party processors. Manual erasure across a fragmented stack is where most compliance programmes fail an audit.

Refusing or Restricting a Request

Not every request must be honoured. The Act and forthcoming Rules permit refusal or partial fulfilment where the request is manifestly unfounded or excessive, where erasure would violate a legal retention obligation (tax, KYC, employment records), or where disclosure would infringe another person's rights.

Where you refuse, you must give reasons in writing, cite the specific ground, and inform the Data Principal of their right to escalate to the Data Protection Board of India. A silent refusal — or a template 'we cannot process this request' response — is itself a breach of the grievance-redressal obligation and invites regulatory attention.

Duty of the Data Principal (Section 15) is also enforceable: false or frivolous complaints can attract penalties up to ₹10,000. In genuinely abusive cases, document the pattern and cite Section 15 in your refusal.

RightsOperations

Have questions on this topic?

Book a confidential consultation with Vrushali Borade.

Book Consultation