Who must be appointed as Grievance Officer under the DPDP Act? Every Data Fiduciary under the DPDP Act 2023 must designate a Grievance Officer — an individual, based in India, who is responsible for receiving and resolving data protection complaints from data principals. The Grievance Officer's name, designation, and contact details (email address and phone number) must be published on the organisation's website and included in the Privacy Policy. The Grievance Officer must acknowledge complaints within 48 hours and resolve them within 30 days. For Significant Data Fiduciaries, a Data Protection Officer (DPO) at the senior management level must also be designated.
Section 13 of the DPDP Act requires every Data Fiduciary to designate a Grievance Officer. Check your compliance status and get fully appointed in minutes.
Secured by Razorpay · UPI, cards, net banking accepted
Every Data Fiduciary under the DPDP Act is required to designate a Grievance Officer. A Data Fiduciary is any entity — company, startup, government body — that decides the purpose and means of processing personal data. This includes IT companies, HRMS platforms, e-commerce businesses, healthcare providers, CA firms, BPOs, and essentially any organisation that processes the personal data of Indian citizens.
Section 13 of the Digital Personal Data Protection Act, 2023 mandates that every Data Fiduciary make the name, contact details, and mode of grievance submission of the Grievance Officer publicly available — typically in the Privacy Policy. This is not optional: it is one of the baseline compliance obligations that every Data Fiduciary must meet, regardless of size or sector.
Significant Data Fiduciaries (SDFs), which are organisations notified by the Central Government based on the volume or sensitivity of data they process, face additional obligations. For SDFs, the Grievance Officer role is even more critical and subject to stricter scrutiny by the Data Protection Board of India. Non-SDF organisations are still fully subject to Section 13 — SDFs simply face higher penalties.
The law does not restrict who can be appointed as Grievance Officer. An existing employee — such as the HR head, legal counsel, or a designated Data Protection Officer — or an external consultant can serve in this role. However, the person must be accessible, empowered to resolve complaints, and must respond to grievances within the period prescribed under the DPDP Act and its Rules, currently expected to be 30 days under the draft DPDP Rules 2025.
The Grievance Officer under DPDP Act Section 13 is the designated point of contact for Data Principals — individuals whose personal data is processed by the organisation. Their core responsibilities include receiving, acknowledging, and resolving grievances filed by Data Principals about the exercise of their rights under the Act.
Specific responsibilities include: (1) receiving complaints about denial of data rights such as access, correction, erasure, and nomination; (2) responding to grievances within prescribed timelines; (3) escalating unresolved complaints to the Data Protection Board of India where required; (4) maintaining a formal Grievance Register; and (5) coordinating internally with HR, legal, and IT teams to honour Data Principal requests.
The Grievance Officer is also the first escalation point for Data Principals who wish to withdraw consent, correct inaccurate data, or nominate another person to exercise their rights. If a grievance is not resolved to the Data Principal's satisfaction, they can approach the Data Protection Board, which has adjudicatory and penalty-imposing powers.
Failure to designate a Grievance Officer or failure to resolve a grievance attracts penalties under the DPDP Act. If a Data Fiduciary fails to address a grievance, the Data Principal may approach the Data Protection Board, which can impose penalties. Draft DPDP Rules propose penalties of up to ₹10,000 per complaint for non-resolution of individual grievances by the Data Fiduciary. Repeated non-compliance can attract higher penalties under Section 17, which provides for penalties of up to ₹250 crore for serious breaches. Beyond regulatory penalties, organisations without a visible Grievance Officer face reputational damage, employee trust issues, and increased regulatory scrutiny during audits. Designating a Grievance Officer is one of the simplest compliance steps a Data Fiduciary can take — and the NitiBharat Grievance Officer Kit makes it a 15-minute task.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.