Grievance Redressal Under DPDPA Section 13: Building Your Internal Complaints System

    Section 13 gives every Indian customer the right to complain about how their data is handled. Your business has 48 hours to acknowledge it. Here is how to build the system that makes this manageable.

    OneConsentBlog
    5 min read
    Tuesday, 18 August 2026
    Illustration of a large ear made of soft geometric shapes, with a shield icon and a clock showing 48 hours inside it, surrounded by speech bubbles with checkmarks, symbolising that data privacy complaints are heard and resolved on time.

    A customer emails your company at 11 PM on a Saturday, furious that they're still getting promotional texts three months after they withdrew consent. Under DPDPA, the clock on that complaint started ticking the moment it landed in your inbox — whether anyone read it or not.

    That's the part of Section 13 that catches most businesses off guard. It's not a "we'll get to it Monday" situation anymore.

    What Section 13 Actually Says

    Section 13 of the DPDPA gives every Data Principal, basically, anyone whose personal data you're processing, the right to raise a grievance if they believe their rights under the Act have been violated. In response, the law places a fairly specific set of obligations on you as a Data Fiduciary. You need to appoint a Grievance Officer. You need to make that person's contact details public. And you need an actual process, not just good intentions, for taking in complaints and resolving them.

    The DPDP Rules 2025 sharpen this further by attaching real timelines to the obligation. So this isn't a policy statement sitting in a PDF somewhere. It's meant to function, day to day, like a real customer service operation.

    The Core Requirements, Laid Out Plainly

    Here's what your organisation is on the hook for:

    • Appointing a Grievance Officer whose name and contact information are published on your website and app

    • Offering a way for people to file complaints — both online and offline

    • Acknowledging every complaint within 48 hours of receiving it

    • Resolving complaints within the Board-prescribed timeline, currently understood to be around 90 days

    • Keeping records of every complaint filed and how it was closed out

    None of this is particularly exotic if you've run a grievance desk before. What's new is the legal weight now attached to it.

    Who Actually Qualifies as a Grievance Officer

    This is one detail people tend to get wrong early on. A Grievance Officer has to be an actual person — not a Support Bot address that dumps into a shared inbox nobody checks on weekends. Most companies end up assigning this role to their DPO, a Chief Privacy Officer, or a senior compliance or legal lead. Whoever it is, their name and contact details need to be sitting somewhere the public can actually find them — not buried three clicks deep in a footer link.

    Why 48 Hours Feels Tighter Than It Sounds

    The acknowledgement window is short, and it's non-negotiable. Within 48 hours of a complaint being filed, the person needs confirmation that it was received, along with a case reference number they can use to follow up. That's a hard deadline — it applies regardless of when the complaint comes in.

    And complaints don't respect office hours. Someone filing a data deletion request at 2 AM doesn't care that your compliance team logs off at 6 PM. If your intake process depends on a human being awake and at their desk, you're going to miss that window sooner or later. Realistically, this means you need some form of automated acknowledgement built into your intake channel — even if the actual resolution work still happens manually.

    What Happens If You Miss the Timeline

    If a Grievance Officer fails to resolve a complaint within the prescribed period, the Data Principal isn't stuck waiting indefinitely. They can escalate the matter straight to the Data Protection Board. And that's a different category of problem altogether — Board complaints can trigger formal investigations, carry the risk of becoming part of the public record, and open the door to penalties.

    Put simply: every complaint your team lets slip through the cracks is a potential Board complaint waiting to happen. Treating grievance handling as a checkbox exercise is how organisations end up there.

    What an Actual Grievance System Looks Like

    Getting this right doesn't require reinventing your customer service stack, but it does require a few deliberate pieces working together:

    1. A dedicated intake channel for complaints, a web form, a monitored email address, or a feature built into your app

    2. Automated acknowledgement that generates a case reference number without waiting on a human to click "send"

    3. A case management workflow with clear escalation paths and internal resolution deadlines

    4. Documentation of every complaint received and how it was ultimately resolved

    5. Periodic review of complaint trends, so patterns, not just individual incidents,l get flagged and fixed

    That last point matters more than people give it credit for. One complaint about unwanted marketing emails is a support ticket. Fifty complaints about the same issue is a systemic problem with your consent management, and it's worth catching before it becomes fifty separate Board filings.

    The Complaints You Should Expect

    Based on how these things tend to play out, a handful of complaint types will likely dominate your queue:

    • People still receiving marketing messages after withdrawing consent

    • Requests for personal data that don't return anything in a usable, readable format

    • Erasure requests that were "processed" on paper but not actually followed through on

    • Corrections to inaccurate personal data that never got made

    • Breach notifications that are either too vague to act on or arrive too late to matter

    If you can anticipate these ahead of time, you can build workflows for them specifically, rather than scrambling to invent a process the first time a real complaint lands.

    Closing Thoughts

    It's worth remembering that grievance redressal isn't purely a legal box to tick. At its core, it's a customer service function, and how you handle it says something about how your organisation treats the people whose data it holds. Companies that respond to complaints with transparency and genuine follow-through tend to build trust that outlasts any single incident. The ones that treat every complaint as a threat to be managed and deflected usually end up proving the complainant's point for them.

    Section 13 isn't asking you to do anything radical. It's asking you to build something that already should have existed, a real, working channel for people to be heard when something goes wrong with their data.
    OneConsent's customer portal includes a built-in grievance management workflow with automated acknowledgements and audit-ready resolution records.

    Schedule a Demo

    Frequently Asked Questions

    Have more questions?

    Search our full DPDP knowledge base for more answers.

    See it live

    See OneConsent in action

    Get a personalised walkthrough of how OneConsent helps your teams stay DPDPA compliant.

    • 30-minute walkthrough
    • DPDPA-ready by design
    • Tailored to your stack