At a glanceUnder India’s DPDP Act, every person (the Data Principal) has the right to access a summary of their data and who it was shared with, to correct or complete it, to erase it, to grievance redressal, and to nominate someone to act for them if they die or become incapacitated — plus the standing right to withdraw consent as easily as they gave it. The business holding the data (the Data Fiduciary) must publish how to make these requests and act on them within a stated, reasonable time.
Educational resource only. This explains the rights people have under India’s Digital Personal Data Protection Act, 2023 (DPDP Act), and the duties it places on businesses; it is not formal legal advice.
What rights does the DPDP Act give you?
The DPDP Act sets out a defined set of rights that belong to the Data Principal — the person the data is about — and makes the Data Fiduciary answerable for honouring them. The Act’s rights chapter creates four rights, and consent adds a fifth that runs alongside it: the right to withdraw. These are not aspirational; they are enforceable, and a business that collects personal data has to build a way to deliver each one.
For a business, the useful way to read this list is as a checklist of things your intake and records must be able to do on demand — show a person their data, fix it, delete it, hear a complaint, and honour a nomination. If your current setup (a Google Form, a WhatsApp thread, a folder of PDFs) can’t do those things, it can’t meet the obligation.
The right to access your data
A person can ask a business for a plain summary of the personal data it holds on them, and a list of everyone it was shared with. The law entitles you to a summary of the personal data being processed and the processing activities, the identities of every other Data Fiduciary and Data Processor it was shared with, and a description of what was shared (Section 11).
This is why vague, catch-all record-keeping fails in practice: to answer an access request, the business needs to know exactly what it collected, why, and where it went. If you passed a customer’s KYC documents to a third-party verification vendor, that vendor has to be nameable in your answer.
The right to correct, complete and erase
A person can require a business to fix data that’s wrong and to delete data it no longer has a reason to hold. That covers correcting inaccurate or misleading data, completing what’s incomplete, updating what’s outdated, and erasing data the business no longer needs (Section 12).
The erasure right is real but not absolute — a business can keep data where a law requires it (for example, statutory retention of tax or KYC records). Where no such legal basis applies, a valid erasure request has to be honoured, and the business must also get its processors to delete their copies. How long data can legitimately be kept before it must go is covered in the retention and erasure pillar.
The right to grievance redressal
A person can complain directly to the business first, and the business must have a working channel to hear it. Every Data Principal has a right to readily available means of grievance redressal from the business — or its Consent Manager — over any act or omission affecting their data or rights (Section 13).
Two load-bearing details: the DPDP Rules require the redressal system to respond within a reasonable period not exceeding ninety days, and the person generally must exhaust this grievance route before approaching the Data Protection Board. So the business’s own complaint channel isn’t optional politeness — it’s the first stop the law expects, and it has a clock on it.
The right to nominate
A person can name someone to exercise their rights if they die or can’t act for themselves. A Data Principal can nominate another individual who steps into their rights in the event of death or incapacity — “incapacity” meaning an inability to act due to unsoundness of mind or physical infirmity (Section 14).
For most small businesses this is the rarest request to receive, but the obligation is to allow the nomination and honour it when invoked, not to ignore it.
The right to withdraw consent
Where processing runs on consent, the person can take that consent back at any time — and it must be as easy to withdraw as it was to give. This sits in Section 6 rather than the rights chapter, but in practice it’s one of the most-used rights. When consent is withdrawn, the business must stop the processing that relied on it and make its processors stop too, unless some other lawful basis genuinely applies.
The practical failure here is asymmetry: consent taken with one tap but withdrawal buried behind emails and phone calls. That doesn’t meet the standard. (Some processing doesn’t run on consent at all — see legitimate uses under Section 7 — and withdrawal doesn’t reach those.)
How a business fulfils these rights
Fulfilment is a defined process, and DPDP compliance requires you to have it in place — not to improvise per request. The core of it:
- Publish how to ask. The Rules require a Data Fiduciary to prominently publish, on its website or app, the means by which a person can make a rights request and the details (such as a username or identifier) needed to identify them.
- Verify who’s asking. Acting on a request from the wrong person is itself a data exposure. Identity verification is part of the duty, not a barrier to it.
- Respond within a stated, reasonable time. Publish the timeframe you’ll respond in and meet it; the grievance mechanism specifically must respond within ninety days at most.
- Be able to actually do each action — produce the access summary (including the list of processors), make corrections, carry out erasure and push it to processors, and record nominations.
- Keep the proof. Because the burden of showing valid consent and lawful processing sits on the Data Fiduciary, you need a record of what was requested, when, and how it was handled.
A business that can’t demonstrate these steps hasn’t met the obligation, even if it means well. This is the practical case for collecting data through a system that logs consent and requests from the start, rather than reconstructing it from scattered forms and chats later.
FAQ
How long does a business have to respond to a rights request under the DPDP Act?
The business must publish and honour a reasonable response time. For grievance redressal specifically, the DPDP Rules set a maximum of ninety days.
Can a company refuse to delete my data?
Only where a law requires it to keep the data (such as statutory tax or KYC retention). Where no such legal basis applies, a valid erasure request must be honoured.
Do I have to complain to the company before going to the Data Protection Board?
Generally yes — the Act expects you to use the business’s grievance redressal mechanism first and exhaust it before approaching the Board.
Is withdrawing consent the same as asking for erasure?
No. Withdrawing consent stops further processing that relied on that consent; erasure is a separate request to delete the data already held. They often go together, but they’re distinct rights.