✉ Email Me This Portal Code
Get the HTML code + an implementation guide delivered to your inbox. Free.
✔ Code sent! Check your email in a few minutes.
3 quick steps. Get a ready-to-embed HTML form covering all data principal rights under the DPDP Act 2023 — personalised to your company.
Get the HTML code + an implementation guide delivered to your inbox. Free.
✔ Code sent! Check your email in a few minutes.
What rights do individuals have under the DPDP Act? The DPDP Act 2023 grants data principals — the individuals whose data is being processed — four core rights: the right to access information about their personal data being processed, the right to correction and erasure of inaccurate or incomplete data, the right to grievance redressal through a designated Grievance Officer, and the right to nominate another individual to exercise their rights in the event of death or incapacity. Organisations must respond to data principal requests within 30 days, or such period as prescribed in the rules.
The Digital Personal Data Protection Act 2023 grants individuals (called "Data Principals") six core rights over their personal data: the right to access information about how their data is being used, the right to correct inaccurate data, the right to erasure of data that is no longer needed, the right to raise grievances with your Grievance Officer, the right to nominate a representative in case of death or incapacity, and the right to withdraw consent at any time. Every Data Fiduciary must provide a mechanism for data principals to exercise these rights.
Under Section 11–14 of the DPDP Act 2023, Data Fiduciaries are legally required to provide data principals with a means to exercise their rights. Without a functioning data rights portal, you are in direct violation of the Act. A well-designed portal also builds trust with customers, demonstrates proactive compliance, and reduces the administrative burden of managing ad-hoc requests via email or phone. Enforcement is expected from May 2027.
A DPDP-compliant data rights portal must cover at minimum: (1) Right to Access — allowing data principals to request what personal data you hold about them; (2) Right to Correction — allowing updates to inaccurate or incomplete data; (3) Right to Erasure — processing deletion requests; (4) Right to Grievance Redressal — a clear channel to raise complaints; (5) Right to Nominate — a mechanism for designating a nominee; and (6) Right to Withdraw Consent — as easy to withdraw as it was to give. This tool generates HTML code covering all six rights.
The DPDP Act 2023 requires Data Fiduciaries to respond to data rights requests within a reasonable timeframe. The recommended best practice is 30 days from the date of receipt, matching the global standard set by GDPR. For complex requests, an extension of up to 30 additional days may be granted with written notice to the data principal. Failure to respond within the committed timeframe can result in complaints to the Data Protection Board of India and regulatory penalties.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.