What are the Data Principals rights under the DPDP Act

    The DPDPA gives individuals four powerful rights over their personal data. Every business that holds customer data must be operationally ready to honour all four — on demand.

    OneConsentBlog
    6 min read
    Thursday, 11 June 2026
    Data Principal rights under the DPDP Act including access, correction, erasure and grievance redressal

    Under the DPDP Act, India 2023, individuals are granted specific rights over how their personal data is collected and used.

    There's a tendency in compliance conversations to focus almost entirely on what businesses have to do with their consent flows, their data inventories, their processing notices. All of that matters.

    But Chapter 3 of DPDPA, Sections 11 to 15, is written from a completely different direction. It's written from the individual's side. It's the part of the Act that gives the person whose data you're holding a set of tools to find out what you have, fix what's wrong, remove what shouldn't still be there, and in one uniquely Indian provision, designate someone else to act on their behalf after they're gone. These are legally enforceable entitlements, not opt-in features. And every organisation holding customer data needs to be operationally capable of honouring them, not theoretically willing to, but actually ready to respond when a request lands.

    Right 1: The Right to Access (Section 11)

    A Data Principal, meaning the individual whose personal data you hold, has the right to ask any Data Fiduciary for a summary of what personal data is being processed about them, a description of what processing activities are being carried out, details of any data that has been shared with other Data Fiduciaries or Processors, and the identities of those recipients. Read that list twice. It's not asking for a privacy policy or a general statement about your data practices. It's asking for a specific, individual account of what data you hold about this particular person, what you're doing with it, and who else you've given it to.

    Operationally, that means your organisation needs to be able to produce a complete, accurate inventory of everything you hold about any single customer across every system, your CRM, data warehouse, marketing platforms, analytics tools, and any third-party processors, on request, typically within 30 days. Most organisations cannot do that today without significant manual effort. That gap is exactly the problem.

    Right 2: Correction and Erasure (Section 12)

    Every Data Principal can request correction of inaccurate personal data, completion of data that is incomplete, and erasure of data that is no longer necessary for the purpose it was collected for, or for which consent no longer exists.

    Correction is operationally manageable. Erasure is where things get genuinely difficult. A deletion request isn't just a delete button in your CRM. It requires the ability to remove data across every system where it lives: your primary database, your data warehouse, your email marketing platform, your backup systems, your analytics environment, and any third-party processors you've shared the data with. If you've built a loyalty programme with multiple partner integrations, a deletion request has to reach every one of those systems. The erasure obligation makes that issue more concrete: every integration point you've created is also a deletion point you'll need to manage.


    Related reads: DPDPA for Retail and Loyalty Programmes

    Right 3: Grievance Redressal (Section 13)

    If a Data Principal believes their rights under DPDPA have been violated, they can file a complaint with the Data Fiduciary's designated Grievance Officer. Under the DPDP Rules, the Grievance Officer must acknowledge the complaint within 48 hours and work toward resolution within a defined timeline. Unresolved complaints can be escalated to the Data Protection Board.

    A few things worth noting here. Having a Grievance Officer on paper isn't enough. That person or function needs an actual process: a way to receive complaints, log them, investigate them, and close them with documentation, all within the required timelines. The 48-hour acknowledgment window is tight. Complaints that arrive on a Friday afternoon still need a response by Sunday. Building this capability means making it a workflow, not a job description item sitting in an HR document.

    Right 4: The Right to Nominate (Section 14)

    This is the right that gets the least attention in most DPDPA compliance discussions, and it's worth pausing on because it's genuinely distinctive. India's DPDPA includes a specific right for every Data Principal to nominate another individual to exercise their data rights on their behalf in the event of their death or incapacity. No other major privacy framework has built this in at the legislative level.

    The practical implications are significant, particularly for organisations that hold long-term personal data such as insurance companies, banks, hospitals, and investment platforms. Your DSAR processes need to be built to accept nomination registrations, verify them, and honour them when a nominee acts on behalf of a deceased or incapacitated individual. That's not a feature most current systems have considered, let alone built.

    What Data Principals Are Actually Responsible For (Section 15)

    Rights come with corresponding duties, and Section 15 makes them explicit. Data Principals must not register false or frivolous complaints with the Data Protection Board, must not impersonate another person in a consent or DSAR request, and must not provide false information in dealings with a Data Fiduciary. Violations of these duties attract penalties of up to Rs 10,000. This isn't a major deterrent in absolute terms, but it does establish that the Act treats data rights as a two-sided responsibility, not an unlimited entitlement to abuse compliance processes.

    What You Actually Need to Build

    The legal rights are clear enough. The harder question is what technical and operational capability is required to honour them at any meaningful scale. At minimum: a centralized data inventory that can retrieve all personal data held about any individual across every system; a DSAR management workflow with defined timelines, clear ownership, and escalation paths; deletion capabilities that extend to backup systems and third-party processors, not just primary databases; a grievance management system with audit trails and documented resolution timelines; and a nomination registry for managing Section 14 nominations.

    None of this can be built retrospectively on the fly when requests start arriving. The architecture decisions need to happen before the requests come in, which means now is the right time, not after the first escalation to the Data Protection Board.

    For enterprises, honoring these rights isn't optional it's central to DPDP compliance.

    The Trajectory to Keep in Mind

    Consumer awareness of DPDPA rights will grow. The Data Protection Board's early enforcement actions will get covered, shared, and discussed. The volume of DSAR requests and grievances filed against Indian businesses will increase significantly over the next two to three years, mirroring exactly what happened in Europe in the years following GDPR's introduction. Organisations that build the capability to honour these rights proactively will spend that period running a well-organised process. Organisations that don't will spend it firefighting.

    Businesses looking to operationalize these rights should evaluate DPDP compliance tools that automate consent tracking, erasure workflows, and audit logs.

    OneConsent includes a customer rights portal that enables Data Principals to exercise all four DPDPA rights: access, correction, erasure, and nomination, in a structured, auditable workflow that connects directly to the underlying consent records your organisation holds. Explore OneConsent to see how consent management and rights fulfilment work as a single system rather than two separate compliance problems.

    Frequently Asked Questions

    Have more questions?

    Search our full DPDP knowledge base for more answers.

    See it live

    See OneConsent in action

    Get a personalised walkthrough of how OneConsent helps your teams stay DPDPA compliant.

    • 30-minute walkthrough
    • DPDPA-ready by design
    • Tailored to your stack