DPDP Wiki Talk to us

/The Act · Chapter III · Rights and Duties of Data Principal

Section 11: Right to access information about personal data

DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) G.S.R. 843(E)Chapter III: Rights and Duties of Data Principal
Provision
Section 11 of The Digital Personal Data Protection Act, 2023
Status
Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
Rules made under it
Rule 14
Source
Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF

Section 11. Right to access information about personal data

Verbatim from the Gazette of India
(1)

The Data Principal shall have the right to obtain from the Data Fiduciary to whom she has previously given consent, including consent as referred to in clause (a) of section 7 (hereinafter referred to as the said Data Fiduciary), for processing of personal data, upon making to it a request in such manner as may be prescribed,—

(a)

a summary of personal data which is being processed by such Data Fiduciary and the processing activities undertaken by that Data Fiduciary with respect to such personal data;

(b)

the identities of all other Data Fiduciaries and Data Processors with whom the personal data has been shared by such Data Fiduciary, along with a description of the personal data so shared; and

(c)

any other information related to the personal data of such Data Principal and its processing, as may be prescribed.

(2)

Nothing contained in clause (b) or clause (c) of sub-section (1) shall apply in respect of the sharing of any personal data by the said Data Fiduciary with any other Data Fiduciary authorised by law to obtain such personal data, where such sharing is pursuant to a request made in writing by such other Data Fiduciary for the purpose of prevention or detection or investigation of offences or cyber incidents, or for prosecution or punishment of offences.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data PrincipalData FiduciaryData Processor

Section 11 gives a Data Principal (the individual to whom the personal data relates) the right to ask a Data Fiduciary (the person or entity deciding how and why data is processed) for information about their personal data. This right applies if the Data Principal previously gave consent to that Data Fiduciary. The request must be made in a manner that will be prescribed by future rules.\n\nWhen a request is made, the Data Fiduciary must provide a summary of the personal data it is processing and the specific processing activities it is doing. The Data Fiduciary must also reveal the identities of any other Data Fiduciaries or Data Processors (entities that process data on behalf of a Data Fiduciary) with whom it has shared the data, along with a description of exactly what data was shared. The Data Fiduciary must also provide any other information about the data and its processing that may be prescribed by rules.\n\nThere is an exception to sharing the identities of other entities and the description of shared data. A Data Fiduciary does not have to provide this information if the data was shared with another Data Fiduciary that is authorized by law to obtain it. This exception only applies if the other Data Fiduciary made a written request for the data to prevent, detect, or investigate offences or cyber incidents, or to prosecute or punish offences.

Key points

  • A Data Principal can request information about their personal data from a Data Fiduciary to whom they previously gave consent. [(1)]
  • The Data Fiduciary must provide a summary of the personal data being processed and the processing activities. [(1)(a)]
  • The Data Fiduciary must disclose the identities of other Data Fiduciaries and Data Processors with whom the data was shared, and describe the shared data. [(1)(b)]
  • The Data Fiduciary must provide any other information related to the data and its processing as may be prescribed by rules. [(1)(c)]
  • The Data Fiduciary does not have to disclose sharing details if the data was shared with a legally authorized Data Fiduciary for law enforcement or cyber incident purposes based on a written request. [(2)]

Common misreadings

  • A Data Fiduciary must always disclose every entity it shares data with. (Correction: They do not have to disclose sharing with legally authorized entities for investigating offences or cyber incidents.)
  • This right applies to all personal data held by the Data Fiduciary regardless of how it was obtained. (Correction: The text specifies this right applies to a Data Fiduciary to whom the Data Principal has previously given consent.)

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.