The Right to Nominate: DPDPA's Unique Provision and What It Means for Your Platform

    India's DPDPA includes a right you won't find in GDPR or CCPA: the right to nominate someone to exercise your data rights after death or incapacity. Every business that holds long-term customer data must prepare for this.

    OneConsentBlog
    7 min read
    Monday, 7 September 2026
    Split-screen infographic in navy and gold. Left side shows an Indian family home, right side shows a server room. A glowing legal nomination document bridges the two, passing through a verification checkpoint icon.

    India's Digital Personal Data Protection Act shares several ideas with GDPR and CCPA. Consent sits at the centre of all three, and access and correction are recognised alongside it. Erasure and grievance redressal appear too, each in a slightly different form. One difference is easy to miss when you use international frameworks as your reference point: the right to nominate. It sits alongside the wider set of DPDPA data principal rights, and the organisation needs to build a process for it the same way it has for the rest of that list.

    Read the full breakdown of these rights in Data Principal Rights Under DPDPA.

    Section 14 of the DPDPA lets a Data Principal name someone else, such as a family member or another trusted individual, to act on their behalf if they die or become incapacitated. Most existing data-rights workflows already cover access and erasure requests. Nomination is not yet part of that pattern for many teams. The organisation therefore needs a structured workflow to record a nomination and verify it, connected to the applicable Data Principal rights processes it already runs.

    Why the Right to Nominate Matters Under the DPDPA

    The right to nominate becomes particularly relevant in long-term relationships between individuals and institutions. Financial and healthcare relationships can continue for years after the person who started them has passed away. A life insurance policy may remain untouched for years before someone needs to take action. A fixed deposit may mature after the account holder has died. A patient's medical history can still matter to an authorised person long after the patient's last visit.

    In situations like these, consent alone does not explain what should happen next. The person who gave consent may no longer be able to make a request. The data may still exist, though, and an authorised nominee may have grounds to exercise applicable rights on the Data Principal's behalf. Section 14 addresses this directly. Rule 13 of the DPDP Rules, 2025 sets out how Data Fiduciaries must support the nomination process in practice. Together, they recognise that personal data can remain relevant to families and institutions long after the relationship that created it has ended.

    What the Right to Nominate Provides

    A Data Principal can nominate one person to act in their place under the Act if the Data Principal dies or loses capacity. A nominee may exercise relevant rights on the Data Principal's behalf, subject to the applicable conditions. That can include:

    • Requesting access to data

    • Asking for a correction

    • Requesting erasure

    • Filing a grievance

    Legal teams should verify the exact scope against the Act before relying on this list for a specific case.

    The right to nominate allows authority over certain data rights to pass to another person. A data principal rights management process needs defined steps for recording and verifying a nomination. Acting on it should never be an ad hoc response built at the moment a request arrives.

    Which Organisations Should Prioritise This

    The operational importance of nomination varies across organisations. For some, nominee requests are rare. A few sectors see them more often, because customer relationships in these sectors can run for years or decades:

    • Life insurance companies

    • Pension administrators

    • Banks managing fixed deposits or long-term savings accounts

    • Healthcare organisations that retain records for extended periods

    • Wealth and investment management firms

    For DPOs and compliance leads at organisations in one of these categories, nomination and verification deserve a specific line item in DPDPA readiness planning, alongside the existing DPDPA rights request management workflow.

    Building Infrastructure for DPDPA Data Principal Rights

    The right to nominate becomes a practical technology and compliance issue at this stage. Existing customer and data-rights systems do not always treat nomination as a dedicated data element. Teams need to add that support directly. A Data Principal should be able to register a nominee by providing who the nominee is and how to reach them. The Data Principal should also be able to change the nomination or remove the nominee whenever required.

    How an organisation retains nomination records matters as much as how it captures them. These records interact with account closure and retention timelines, so they may need to stay available long enough to support a valid request. This is the underlying job a DPDPA consent management platform is built for: giving nomination its own dedicated record instead of retrofitting it into workflows built for something else.

    Nominee Verification Under the DPDPA

    Registering a nominee covers only part of the process. Greater complexity shows up once a nominee tries to exercise the Data Principal's rights. The organisation then needs to establish who the nominee is and how they relate to the Data Principal. It also needs to confirm that the triggering event, death or incapacity, has occurred. Depending on the circumstances, supporting documentation may be needed for both.

    Nominee verification should follow a defined, auditable process. An informal exchange of documents or emails does not leave the kind of record a regulator would expect to see. The organisation needs a record of what was checked and why the claim was accepted. That record means the process and evidence can be produced without reconstruction if a regulator or court later asks.

    Operational Challenges of Implementing the Right to Nominate

    Implementing the right to nominate adds a few concrete tasks on top of the legal assessment:

    • Add a nomination section to the customer portal

    • Build nominee verification into the existing data-rights process

    • Connect that verification to the systems used to retrieve or delete data

    • Define the supporting documents required for different scenarios

    Coordinating these steps into one connected flow is the more demanding part of implementation, compared with completing each task on its own. These requirements create a need for coordinated workflows that connect nomination records and verification with the organisation's broader Data Principal rights processes. A DPDPA consent management platform can provide the centralised records and workflow controls needed to manage these activities consistently, with an audit trail attached to each action.

    How Nomination Affects Data Retention

    Data retention decisions directly affect how nomination can be exercised in practice. Its value depends partly on whether relevant personal data is still around when a nominee tries to use it. If personal data gets deleted immediately after account closure, the organisation may need to rethink how a valid nominee request would even be handled. Retention decisions should be aligned with legal and record-keeping requirements from the outset, not adjusted after the first nominee request arrives.

    What Organisations Should Consider

    Section 14 can look narrow in isolation. Nomination carries practical weight because it connects directly to verification and to retention decisions. Include nomination and nominee verification as specific items on the DPDPA compliance checklist, alongside consent and erasure. This reflects a common reality in India: insurance policies and medical histories can stay relevant long after the people who created them are gone. Setting up nomination and verification processes in advance helps teams handle nominee requests consistently.

    Managing the right to nominate means connecting nomination records to the wider consent and data rights management process, while keeping clear, auditable records the organisation can produce on demand.

    How OneConsent Supports Nomination and Data Principal Rights

    Recording a nomination and verifying a nominee both connect back to the existing data-rights workflow. Managing that on a single platform is simpler than doing it across scattered spreadsheets and manual checks. OneConsent operates as a DPDPA consent and Data Principal rights management platform: it centralises consent records and Data Principal Request management, including nomination-related requests, with an auditable trail the organisation can produce on demand. Nomination sits alongside access and erasure requests as one of several rights workflows the platform supports, not a standalone feature bolted onto consent management.

    For DPOs and compliance leads evaluating a broader DPDPA compliance software approach to handling rights requests, nomination is one of the workflows worth including in that evaluation.

    Explore the OneConsent platform: https://oneconsent.ai/

    Book a demo to see nomination workflows in action: https://oneconsent.ai/book-demo

    Frequently Asked Questions

    Have more questions?

    Search our full DPDP knowledge base for more answers.

    See it live

    See OneConsent in action

    Get a personalised walkthrough of how OneConsent helps your teams stay DPDPA compliant.

    • 30-minute walkthrough
    • DPDPA-ready by design
    • Tailored to your stack