DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr

Quick Answer

Who must be appointed as Grievance Officer under the DPDP Act? Every Data Fiduciary under the DPDP Act 2023 must designate a Grievance Officer — an individual, based in India, who is responsible for receiving and resolving data protection complaints from data principals. The Grievance Officer's name, designation, and contact details (email address and phone number) must be published on the organisation's website and included in the Privacy Policy. The Grievance Officer must acknowledge complaints within 48 hours and resolve them within 30 days. For Significant Data Fiduciaries, a Data Protection Officer (DPO) at the senior management level must also be designated.

Free Checklist Appointment Kit ₹999 Section 13 DPDP Act

DPDP Grievance Officer Kit — Designate, Train & Manage Your GO

Section 13 of the DPDP Act requires every Data Fiduciary to designate a Grievance Officer. Check your compliance status and get fully appointed in minutes.

DPDP Act 2023 · Section 13 — Grievance Officer designation is mandatory for every Data Fiduciary · Enforcement deadline: May 2027
Step 1 of 2
Organisation Details
Please fill in all required fields before continuing.
Grievance Officer Compliance Checklist
Sample: Grievance Officer Appointment Notice Free Preview

Appointment of Grievance Officer

This appointment shall take effect from the date hereof and shall remain in force until further notice. The Grievance Officer shall be responsible for receiving, acknowledging, and resolving grievances filed by Data Principals within thirty (30) days of receipt, in accordance with the timelines prescribed under the DPDP Act and the Rules thereunder.

The Grievance Officer shall maintain a Grievance Register and shall forward any unresolved grievances to the Data Protection Board of India, as required.

Signed for and on behalf of [Organisation Name]

______________________
Authorised Signatory
[Name & Designation]
[Date]

🔒
Full document included in the ₹999 Kit

Board Resolution + Privacy Policy section + 3 Response Templates

Full Grievance Officer Kit
₹999 one-time · instant delivery
  • Board Appointment Resolution (board-ready Word doc)
  • Privacy Policy GO Section — ready to paste into your existing policy
  • GO Response Templates (3 types: acknowledgement, resolution, escalation)
  • Grievance Register Template (Excel format)
  • Data Principal FAQ Sheet (for your website/intranet)
  • Section 13 Compliance Certificate — NitiBharat verified

Secured by Razorpay · UPI, cards, net banking accepted

Need a complete DPDP compliance programme? Book a free consultation →

Who must appoint a Grievance Officer under the DPDP Act?

Every Data Fiduciary under the DPDP Act is required to designate a Grievance Officer. A Data Fiduciary is any entity — company, startup, government body — that decides the purpose and means of processing personal data. This includes IT companies, HRMS platforms, e-commerce businesses, healthcare providers, CA firms, BPOs, and essentially any organisation that processes the personal data of Indian citizens.

Section 13 of the Digital Personal Data Protection Act, 2023 mandates that every Data Fiduciary make the name, contact details, and mode of grievance submission of the Grievance Officer publicly available — typically in the Privacy Policy. This is not optional: it is one of the baseline compliance obligations that every Data Fiduciary must meet, regardless of size or sector.

Significant Data Fiduciaries (SDFs), which are organisations notified by the Central Government based on the volume or sensitivity of data they process, face additional obligations. For SDFs, the Grievance Officer role is even more critical and subject to stricter scrutiny by the Data Protection Board of India. Non-SDF organisations are still fully subject to Section 13 — SDFs simply face higher penalties.

The law does not restrict who can be appointed as Grievance Officer. An existing employee — such as the HR head, legal counsel, or a designated Data Protection Officer — or an external consultant can serve in this role. However, the person must be accessible, empowered to resolve complaints, and must respond to grievances within the period prescribed under the DPDP Act and its Rules, currently expected to be 30 days under the draft DPDP Rules 2025.

What are the Grievance Officer's responsibilities?

The Grievance Officer under DPDP Act Section 13 is the designated point of contact for Data Principals — individuals whose personal data is processed by the organisation. Their core responsibilities include receiving, acknowledging, and resolving grievances filed by Data Principals about the exercise of their rights under the Act.

Specific responsibilities include: (1) receiving complaints about denial of data rights such as access, correction, erasure, and nomination; (2) responding to grievances within prescribed timelines; (3) escalating unresolved complaints to the Data Protection Board of India where required; (4) maintaining a formal Grievance Register; and (5) coordinating internally with HR, legal, and IT teams to honour Data Principal requests.

The Grievance Officer is also the first escalation point for Data Principals who wish to withdraw consent, correct inaccurate data, or nominate another person to exercise their rights. If a grievance is not resolved to the Data Principal's satisfaction, they can approach the Data Protection Board, which has adjudicatory and penalty-imposing powers.

Penalties for not having a Grievance Officer

Failure to designate a Grievance Officer or failure to resolve a grievance attracts penalties under the DPDP Act. If a Data Fiduciary fails to address a grievance, the Data Principal may approach the Data Protection Board, which can impose penalties. Draft DPDP Rules propose penalties of up to ₹10,000 per complaint for non-resolution of individual grievances by the Data Fiduciary. Repeated non-compliance can attract higher penalties under Section 17, which provides for penalties of up to ₹250 crore for serious breaches. Beyond regulatory penalties, organisations without a visible Grievance Officer face reputational damage, employee trust issues, and increased regulatory scrutiny during audits. Designating a Grievance Officer is one of the simplest compliance steps a Data Fiduciary can take — and the NitiBharat Grievance Officer Kit makes it a 15-minute task.

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
Grievance Officer Response Letter TemplatesHealth App Privacy Policy GeneratorHealthcare App Privacy Policy GeneratorDPDP Act 2023 for Fintech CompaniesSee all Generators & Reports tools →📝 How to Negotiate DPA DPDP📝 DPDP Privacy Policy Check