What are Data Principal rights under the DPDP Act? Data Principals have the right to access, correct and request deletion of their personal data, to withdraw consent, and to file grievances. OneConsent's DPAR product manages these requests from intake through verification, processing and resolution.
Read more How does OneConsent help organizations manage access, correction and deletion requests? Requests are logged, the requester's identity is verified, relevant personal data is located through data discovery, and the request is routed to the right team with an SLA. Every step, including the final response, is recorded in an audit trail.
Read more If a customer asks what data we have about them, what exactly do we need to provide? You must provide a clear summary of personal data being processed, along with the purpose and how it is used. This should be understandable, not technical.
Read more If a customer asks us to delete their data, can we retain it for internal analytics or business use? You can only retain data if there is a valid legal or operational requirement. Otherwise, it must be deleted once the purpose is fulfilled or upon request.
Read more Do we need a system to handle user requests like access, correction, or deletion? Yes, DPDP requires a structured and trackable grievance system to handle such requests efficiently.
Read more What happens if we ignore or delay customer data requests? Customers can escalate complaints to the Data Protection Board, which can investigate and impose penalties.
Read more Can a user appoint someone else to manage their data rights? Yes, users can nominate another individual to exercise their rights in case of death or incapacity.
Read more What happens when a customer withdraws consent? Retailers must immediately stop marketing communication, suppress the user across all channels, and delete or anonymize personal data unless retention is legally required. This must be enforced across all systems without delay.
Read more