The Act's rights are narrower than GDPR's list but not weaker where they apply, and one of them has no European equivalent at all.
On request, a Data Principal is entitled to receive from a Data Fiduciary to which she has previously given consent:
A Data Principal is entitled to correction, completion, updating and erasure of her personal data for the processing of which she had previously given consent.
On receiving a request, the Data Fiduciary must:
That final clause is the hinge. Erasure is a qualified right, and where a statutory retention mandate applies, the correct response is to retain and explain — not to delete, and not to ignore. This is where DPDP diverges most sharply from a naive "delete on request" implementation. → Retention and Erasure
A Data Principal has the right to a readily available means of registering a grievance with a Data Fiduciary or Consent Manager, in respect of the performance of their obligations or the exercise of her rights.
The Data Fiduciary or Consent Manager must respond within the prescribed period. The Data Principal must exhaust this route before approaching the Board — the grievance mechanism is a precondition to complaint, not an alternative to it.
A Data Principal may nominate any other individual to exercise her rights under the Act, in the event of her death or incapacity.
This right has no direct GDPR analogue, and it is the one most consistently missing from platforms adapted from European tooling. It requires a nomination record, an identity and authority verification path for the nominee, and a state change on the account that is triggered by an event the individual cannot report themselves.
Uniquely among major data protection statutes, the DPDP Act places duties on the individual. A Data Principal must:
Breach of these duties attracts a penalty that may extend to ₹10,000 under the Schedule.
| Right | Provision | What you need to be able to do |
|---|---|---|
| Access | s. 11 | Produce a processing summary and a full onward-sharing list, per individual |
| Correction and completion | s. 12 | Push corrections through to downstream and decision systems |
| Erasure | s. 12 | Detect retention conflicts, erase where clear, document where not |
| Grievance | s. 13 | A monitored channel, with a response clock and an escalation record |
| Nomination | s. 14 | A nomination record, and nominee verification on an event you don't control |
Four: access to information about processing and onward sharing (s. 11), correction, completion, updating and erasure (s. 12), grievance redressal (s. 13), and nomination of another individual to exercise rights on death or incapacity (s. 14).
No. Portability and the GDPR-style right to object are absent from Chapter III. Vendors describing a DPDP portability right are importing it from European law.
s. 14 lets an individual nominate another person to exercise her rights in the event of her death or incapacity. It has no direct GDPR equivalent and is frequently missing from platforms adapted from European products.
Yes, where retention is necessary for the specified purpose or for compliance with any law in force. Indian sectoral mandates frequently require retention that outlasts an erasure request, in which case the correct action is to retain, explain and document.
Yes. The s. 13 grievance route must be exhausted before approaching the Board. That makes an unmonitored grievance channel an obstruction of the statutory escalation path, not merely poor service.
Within the period prescribed by the Rules. Organisations should set an internal target inside that ceiling and staff to it — the response record itself becomes mitigating evidence under s. 33(2) if a matter is ever adjudicated.
Consiva.ai maps every obligation above to a workflow, dashboard, or automated job — so your team focuses on decisions, not tracking.
Start Free — No Credit Card →Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Act, 2023, ss. 11–15, 33; DPDP Rules, 2025, Rules 13–14. Reference material about the law, not legal advice — see /disclaimer.