At a glanceUnder India’s DPDP Act you complain in two stages. First, raise a grievance with the business itself — through its grievance officer or Data Protection Officer — and give it the time it has published to respond. If it ignores you or the answer is unsatisfactory, you escalate to the Data Protection Board of India, which can inquire and penalise. You must try the business first; the Board expects that step to be exhausted before it takes up your complaint.
Educational resource only. This explains how to raise a data-protection grievance under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.
The situation
You asked a company to delete your data, or to tell you what it holds, and got silence. Or you found out a service leaked your details and did nothing. You know the DPDP Act gives you rights — but not who to actually tell, or in what order. The order matters, because going to the wrong place first gets you sent back.
Why you can’t go straight to the regulator
The law deliberately makes the business your first stop — the Board is the escalation, not the front desk. The DPDP Act gives you a right to grievance redressal directly from the Data Fiduciary (the company that decides why and how your data is used) or its Consent Manager (Section 13). Every business that handles personal data must provide a way to raise a grievance and must publish who to contact.
Here’s the load-bearing part: you’re required to exhaust that grievance route before approaching the Data Protection Board of India (DPB). If you complain to the Board without first giving the business a fair chance to fix it, the Board can decline to take the matter up. So the two-stage order isn’t bureaucratic box-ticking — skipping stage one can cost you stage two.
Step by step: the two stages
Stage one is the business; stage two is the Board — and you keep records at every step.
Stage 1 — Raise it with the business
- Find the grievance channel. Look in the company’s privacy notice or app for its grievance officer or Data Protection Officer (DPO) — contact details it is required to publish. For a Significant Data Fiduciary (a larger, higher-risk company named by the government), this must be a senior, named contact.
- Put your grievance in writing. State what went wrong and what you want — for example, that you exercised your right to have data deleted (Section 12) and got no response. Reference the DPDP Act plainly.
- Note the clock. The Rules require the business to respond within the timeframe it publishes for grievances. Keep that date; it’s what unlocks your escalation.
Stage 2 — Escalate to the Board
- Confirm you’ve exhausted stage one. Either the response was unsatisfactory, or the published period passed with no adequate reply.
- File your complaint with the Board digitally. The Board is built to receive complaints online (it functions as a digital office), so you shouldn’t need to appear in person to lodge one.
- Attach your trail. Your original request, the business’s reply (or proof there was none), and dates.
| Stage 1 — The business | Stage 2 — The Board | |
|---|---|---|
| Who | Grievance officer / DPO | Data Protection Board of India |
| When | First — always | Only after stage 1 fails |
| What they do | Must respond within its published period | Inquires; can penalise |
| You provide | Written grievance + your details | The above + your stage-1 trail |
What to put in your complaint
A good complaint is specific, dated, and evidenced — it makes the Board’s job easy. Include:
- Who the business is and what it did (or failed to do).
- Which right or duty is in play — deletion, access, correction, a breach that wasn’t notified.
- Your stage-1 record — the grievance you raised and how the business responded, with dates.
- What you want — the specific outcome, stated plainly.
A useful discipline: keep everything in writing from the start. Email beats phone calls here, because the paper trail is exactly what turns a vague grievance into a complaint the Board can act on.
If the business ignores you
Silence is itself a trigger — a non-response is grounds to escalate, not a dead end. If the published response window passes with no adequate reply, you’ve met the “exhausted grievance redressal” condition and can take the matter to the Board. You don’t need the company’s cooperation to escalate; you need your own record showing you asked and waited.
One honest caveat on expectations: the Board enforces the law and can penalise the company, but it is not a route to personal compensation — penalties go to the government, not to you. If your goal is money back, that’s a different track. If your goal is to make the company comply and to hold it accountable, this is the path.
FAQ
Can I complain directly to the Data Protection Board without contacting the company first?
Generally no. You’re expected to exhaust the business’s grievance-redressal process first; the Board can decline a complaint that skipped that step.
How long does the business have to respond to my grievance?
Within the period it publishes for grievance redressal, which the Rules require it to state. If that period lapses without an adequate response, you can escalate.
Does filing a complaint cost anything?
Lodging a grievance with the business does not. The Board is designed as a digital office to keep the complaint process accessible.
Will I get compensation if I win?
No. The Board imposes penalties that go to the government, not damages paid to you. Its role is enforcement, not compensation.
What if I don’t know who the company’s grievance officer is?
Businesses must publish this. Check the privacy notice, the app’s help/“contact” section, or the website footer; a company that hides it is itself failing a duty you can note in your complaint.