Every Data Fiduciary under the DPDP Act 2023 must publish the contact details of a person who can answer Data Principals' questions about their data — a Grievance Officer or point of contact (Section 8(9)). Separately, organisations classified as Significant Data Fiduciaries must appoint a Data Protection Officer based in India who reports to the board or governing body (Section 10). This checker tells you which roles you need.
Find out whether you must appoint a Grievance Officer, a Data Protection Officer, or both under the DPDP Act 2023.
These are two different roles. The Grievance Officer (or published point of contact) is required of every Data Fiduciary so that individuals have a clear channel to raise questions and complaints about their personal data. The contact must be published — typically in the privacy notice and on the website.
The Data Protection Officer is a senior, accountable role required only of Significant Data Fiduciaries. The DPO must be based in India, represent the organisation to the Data Protection Board, and report to the board or governing body. Many organisations appoint one person to cover the Grievance Officer function and separately assess whether SDF designation triggers the DPO requirement.
A role description, a published-contact template for your privacy notice, and a complaint-handling workflow.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.