Under the DPDP Act 2023, Data Principals (individuals whose data is processed) have four core rights: the right to information (Section 11), right to correction and erasure (Section 12), right to grievance redressal (Section 13), and right to nominate (Section 14). Organisations must fulfil rights requests within a reasonable timeframe — the DPDP Rules 2025 specify 30–72 hours for certain requests. Failure to comply attracts penalties up to ₹50 crore.
data principal rights DPDP India — Complete DPDP Compliance Guide
A complete guide to the rights of individuals (data principals) under India's DPDP Act 2023 — access, correction, erasure, grievance redressal, and nomination.
Quick AnswerDPDP Act 2023 grants data principals five core rights: right to access information, right to correction and erasure, right to grievance redressal, right to nominate a representative, and right to withdraw consent.
DPDP Compliance Checklist
Right to Access: Request information about what personal data is being processed and for what purpose
Right to Correction: Require correction of inaccurate or incomplete personal data
Right to Erasure: Request deletion of personal data where processing is no longer necessary
Right to Grievance Redressal: File complaint with the data fiduciary's grievance officer
Right to Nominate: Designate a representative to exercise rights in case of death or incapacity
Right to Withdraw Consent: Withdraw previously given consent at any time
Right to approach Data Protection Board: Escalate unresolved grievances to the Board
Organisations must respond to data access requests within prescribed timelines
Organisations cannot charge excessive fees for DSAR processing
Data principals can nominate a person to exercise rights on their behalf
Download Full Compliance Guide (Free)
Get the complete sector-specific checklist, risk areas, and 30-day action plan — delivered to your inbox.
Frequently Asked Questions
Can a data principal demand deletion of all their data?+
Yes, but with limitations. If the data fiduciary is legally required to retain data (e.g., tax records, court orders), retention overrides the deletion right for that specific data.
How quickly must organisations respond to access requests?+
DPDP and DPDP Rules set response timelines. Current best practice is 30 days — the Rules may specify shorter timelines.
What can a data principal do if their rights are ignored?+
First: file a complaint with the data fiduciary's Grievance Officer. If unresolved: escalate to the Data Protection Board.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.