Data Principal rights under the DPDP Act, and how to handle them
Updated 26 Sep 2026 · 6min read · Reviewed by ConsentLo's DPDP audit team
The DPDP Act gives every individual, called a Data Principal, a set of rights over their personal data. For a Data Fiduciary, each right is an operational process with a deadline. Here is what each right means and how to run it.
Right to information (Section 11)
A Data Principal who gave consent can ask for a summary of their personal data and the processing done with it, the identities of other Data Fiduciaries and Data Processors it was shared with, and the data shared.
Right to correction and erasure (Section 12)
People can ask you to correct, complete or update their data, and to erase it. You must erase it unless keeping it is necessary for the purpose or required by law. When you erase, your processors must erase too.
Right to withdraw consent
Withdrawal must be as easy as giving consent. After withdrawal you, and your processors, must stop processing within a reasonable time, unless another lawful basis applies.
Right of grievance redressal (Section 13)
You must provide a readily available way to raise grievances and answer within the period set by the DPDP Rules, 2025: a reasonable period of not more than 90 days. A person must use your process before complaining to the Data Protection Board.
Right to nominate (Section 14)
A Data Principal can nominate another person to exercise their rights in the event of death or incapacity.
Duties of Data Principals (Section 15)
Individuals also have duties: to follow applicable laws, not to impersonate anyone, not to suppress material information, not to file false or frivolous complaints, and to provide only authentic information when correcting data. Breaching these duties can attract a penalty of up to ₹10,000.
Running rights requests well
A reliable process has:
- Published ways to make a request, on your website or app.
- Identity verification proportionate to the request.
- A deadline clock on every request, with escalation before it is missed.
- Legal-hold checks before erasure, and a recorded reason when data is kept.
- Cascades to processors, and evidence that they acted.
Frequently asked questions
How long does a company have to respond to a DPDP rights request?
The DPDP Rules require grievances to be answered within a reasonable period of not more than 90 days. Aim to respond much faster, and publish your own timelines.
Is there a right to data portability under DPDP?
No. The DPDP Act gives rights to information, correction, erasure, grievance redressal and nomination, but not a GDPR-style portability right.
Can a company refuse an erasure request?
Yes, if keeping the data is necessary for the specified purpose or is required by law. Record the reason and tell the person.