The short answer: Chapter III of the DPDP Act gives a Data Principal four rights: access to information about processing, correction and erasure of their data, grievance redressal, and the right to nominate another person to exercise their rights on death or incapacity. Section 15 imposes five duties on the individual. These provisions commence on 13 May 2027.

Rights and Duties of the Individual

⚖️ Legal structure: Chapter III, ss. 11–15📅 In force from: 13 May 2027🔍 Source: DPDP Act 2023 · Rules 2025
On this page
  1. The four rights
  2. Right to access information — section 11
  3. Right to correction, completion, updating and erasure — section 12
  4. Right of grievance redressal — section 13
  5. Right to nominate — section 14
  6. The five duties — section 15
  7. Rights and what each demands of your systems
  8. How escalation works, in sequence
  9. Frequently asked questions

The four rights

The Act's rights are narrower than GDPR's list but not weaker where they apply, and one of them has no European equivalent at all.

Right to access information — section 11

On request, a Data Principal is entitled to receive from a Data Fiduciary to which she has previously given consent:

Note the second limb carefully. This is a disclosure obligation about your onward sharing chain, and answering it requires knowing not only what you hold but where it went. An organisation without a processor and sharing register cannot answer this request accurately, and answering it inaccurately is its own breach.

Right to correction, completion, updating and erasure — section 12

A Data Principal is entitled to correction, completion, updating and erasure of her personal data for the processing of which she had previously given consent.

On receiving a request, the Data Fiduciary must:

That final clause is the hinge. Erasure is a qualified right, and where a statutory retention mandate applies, the correct response is to retain and explain — not to delete, and not to ignore. This is where DPDP diverges most sharply from a naive "delete on request" implementation. → Retention and Erasure

Right of grievance redressal — section 13

A Data Principal has the right to a readily available means of registering a grievance with a Data Fiduciary or Consent Manager, in respect of the performance of their obligations or the exercise of her rights.

The Data Fiduciary or Consent Manager must respond within the prescribed period. The Data Principal must exhaust this route before approaching the Board — the grievance mechanism is a precondition to complaint, not an alternative to it.

That makes your grievance channel load-bearing in a way that is easy to underestimate. If it is unmonitored, you have not merely provided poor service; you have obstructed the statutory escalation path.

Right to nominate — section 14

A Data Principal may nominate any other individual to exercise her rights under the Act, in the event of her death or incapacity.

This right has no direct GDPR analogue, and it is the one most consistently missing from platforms adapted from European tooling. It requires a nomination record, an identity and authority verification path for the nominee, and a state change on the account that is triggered by an event the individual cannot report themselves.

The five duties — section 15

Uniquely among major data protection statutes, the DPDP Act places duties on the individual. A Data Principal must:

Breach of these duties attracts a penalty that may extend to ₹10,000 under the Schedule.

What this does and does not give you. It does not create a general licence to refuse requests you find inconvenient. It does mean identity verification and anti-abuse controls at intake have statutory backing, and that a demonstrably frivolous complaint has a consequence. s. 8(1) is explicit that a Data Principal's failure to perform her duties does not relieve you of your own obligations.

The rights, and what each one demands of your systems

RightProvisionWhat you need to be able to do
Accesss. 11Produce a processing summary and a full onward-sharing list, per individual
Correction and completions. 12Push corrections through to downstream and decision systems
Erasures. 12Detect retention conflicts, erase where clear, document where not
Grievances. 13A monitored channel, with a response clock and an escalation record
Nominations. 14A nomination record, and nominee verification on an event you don't control

How escalation works, in sequence

  1. The individual raises a grievance with the Data Fiduciary under s. 13, using the readily available means you are obliged to provide.
  2. You respond within the prescribed period.
  3. If unresolved, the individual may complain to the Data Protection Board. The Board considers the complaint and may conduct an inquiry.
  4. The Board may impose a penalty from the Schedule, having regard to the factors in s. 33(2) — including gravity, duration, repetitiveness, gain realised, and whether the person took timely mitigating action.
  5. Appeals lie to the Appellate Tribunal.
Point 4 is worth noting for a reason that isn't obvious: mitigation and timeliness are express statutory factors in setting the penalty. A documented, dated response — even to a request you ultimately declined — is a mitigating record.

Frequently asked questions

What are the rights of a Data Principal under the DPDP Act?

Four: access to information about processing and onward sharing (s. 11), correction, completion, updating and erasure (s. 12), grievance redressal (s. 13), and nomination of another individual to exercise rights on death or incapacity (s. 14).

Is there a right to data portability under the DPDP Act?

No. Portability and the GDPR-style right to object are absent from Chapter III. Vendors describing a DPDP portability right are importing it from European law.

What is the nomination right under the DPDP Act?

s. 14 lets an individual nominate another person to exercise her rights in the event of her death or incapacity. It has no direct GDPR equivalent and is frequently missing from platforms adapted from European products.

Can a Data Fiduciary refuse to erase personal data?

Yes, where retention is necessary for the specified purpose or for compliance with any law in force. Indian sectoral mandates frequently require retention that outlasts an erasure request, in which case the correct action is to retain, explain and document.

Must an individual complain to us before going to the Board?

Yes. The s. 13 grievance route must be exhausted before approaching the Board. That makes an unmonitored grievance channel an obstruction of the statutory escalation path, not merely poor service.

How long do we have to respond to a rights request?

Within the period prescribed by the Rules. Organisations should set an internal target inside that ceiling and staff to it — the response record itself becomes mitigating evidence under s. 33(2) if a matter is ever adjudicated.

See how Consiva handles this automatically

Consiva.ai maps every obligation above to a workflow, dashboard, or automated job — so your team focuses on decisions, not tracking.

Start Free — No Credit Card →

Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Act, 2023, ss. 11–15, 33; DPDP Rules, 2025, Rules 13–14. Reference material about the law, not legal advice — see /disclaimer.