Glossary · Data Principal Rights
What Are Data Principal Rights Under DPDPA?
Every customer, employee, patient or student whose data you hold can demand access, correction, erasure, a working grievance channel, and a nominee. Sections 11–14 set the rights; Rule 14(1) is the published request route, and Rule 14(3) is the 90-day grievance outer clock. Have the workflow ready before 13 May 2027.
Last reviewed: 14 August 2026
Definition
Data Principal rights are the things a person can demand from you about their own personal data. Sections 11 to 14 of the DPDP Act, 2023 give four: the right to access a summary of their data and the list of everyone you shared it with (Section 11); the right to have it corrected, completed, updated or erased (Section 12); the right to a working grievance channel before they escalate to the Data Protection Board (Section 13); and the right to nominate someone to exercise these rights if they die or lose capacity (Section 14). Sections 11(1) and 12(1) apply where the Data Principal previously gave consent, including consent as referred to in Section 7(a) — they are not a flat overlay on every Section 7 head. Separately, Section 6(4) lets them withdraw consent at any time, as easily as it was given. Rule 14(1) requires you to publish how a request is made and any identifier you need; Rule 14(3) requires the grievance system to respond within a period not exceeding ninety days; Rule 14(4) covers nomination.
How this matters in practice
Section 11 is the one that catches SMBs out: you must name every processor and partner you shared the data with. If your vendor list lives in someone's head, that request is unanswerable. Privigo maintains the sharing map per Data Principal, so an access request returns a real answer — plus correction and erasure workflows that propagate downstream and log the outcome.
Frequently asked questions
How quickly do I have to respond to a rights request?
The Act does not fix a single deadline for access, correction or erasure. Rule 14(1) requires you to publish, on your website or app, the means by which a person makes a request and any identifier you need to find them. Rule 14(3) is a separate clock: the grievance system must respond within a period not exceeding ninety days. Ninety days is the grievance outer limit, not the SLA for every rights request. A gap scan usually finds SMBs have no published means and no stated timeline at all, which is the failure, not slowness.
If someone asks me to delete their data, do I have to?
Not always. Section 12(3) lets you refuse erasure where you are required to retain the data to comply with a law, or where retention is still necessary for the specified purpose. A lender keeping KYC records under RBI rules, or a school keeping academic records under state education regulations, can say no and should say why. What you cannot do is keep data purely because it's convenient — once consent is withdrawn or the purpose is served, Section 8(7) requires erasure unless a legal retention rule applies. Note also the floors: Rule 6(1)(e) and Rule 8(3) set a one-year minimum for certain logs and related personal data.
Can a Data Principal complain to the Board straight away?
No. Section 13(3) requires them to exhaust your grievance redressal mechanism first before approaching the Data Protection Board. That makes your internal channel a genuine buffer — but only if it exists, is published, and actually responds. Rule 9 also requires you to publish the business contact information of a named person who can answer questions about processing. Note also Section 15: Data Principals have duties too, including not filing false or frivolous grievances, and the Schedule allows a penalty of up to ₹10,000 on the individual for breaching them. Rights obligations run to the 13 May 2027 substantive deadline, so build backwards from there.
Build a rights-request workflow that holds up
Book a 30-minute call to map how you will answer access, correction and erasure requests — including the vendor list Section 11 requires you to name — before enforcement tightens.
Book a demo
Free Gap Analysis
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.