/The Act · Chapter III · Rights and Duties of Data Principal
Section 11: Right to access information about personal data
DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.
- Provision
- Section 11 of The Digital Personal Data Protection Act, 2023
- Status
- Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
- Rules made under it
- Rule 14
- Source
- Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF
The Data Principal shall have the right to obtain from the Data Fiduciary to whom she has previously given consent, including consent as referred to in clause (a) of section 7 (hereinafter referred to as the said Data Fiduciary), for processing of personal data, upon making to it a request in such manner as may be prescribed,—
a summary of personal data which is being processed by such Data Fiduciary and the processing activities undertaken by that Data Fiduciary with respect to such personal data;
the identities of all other Data Fiduciaries and Data Processors with whom the personal data has been shared by such Data Fiduciary, along with a description of the personal data so shared; and
any other information related to the personal data of such Data Principal and its processing, as may be prescribed.
Nothing contained in clause (b) or clause (c) of sub-section (1) shall apply in respect of the sharing of any personal data by the said Data Fiduciary with any other Data Fiduciary authorised by law to obtain such personal data, where such sharing is pursuant to a request made in writing by such other Data Fiduciary for the purpose of prevention or detection or investigation of offences or cyber incidents, or for prosecution or punishment of offences.
Section 11 gives a Data Principal (the individual to whom the personal data relates) the right to ask a Data Fiduciary (the person or entity deciding how and why data is processed) for information about their personal data. This right applies if the Data Principal previously gave consent to that Data Fiduciary. The request must be made in a manner that will be prescribed by future rules.\n\nWhen a request is made, the Data Fiduciary must provide a summary of the personal data it is processing and the specific processing activities it is doing. The Data Fiduciary must also reveal the identities of any other Data Fiduciaries or Data Processors (entities that process data on behalf of a Data Fiduciary) with whom it has shared the data, along with a description of exactly what data was shared. The Data Fiduciary must also provide any other information about the data and its processing that may be prescribed by rules.\n\nThere is an exception to sharing the identities of other entities and the description of shared data. A Data Fiduciary does not have to provide this information if the data was shared with another Data Fiduciary that is authorized by law to obtain it. This exception only applies if the other Data Fiduciary made a written request for the data to prevent, detect, or investigate offences or cyber incidents, or to prosecute or punish offences.
Key points
- A Data Principal can request information about their personal data from a Data Fiduciary to whom they previously gave consent. [(1)]
- The Data Fiduciary must provide a summary of the personal data being processed and the processing activities. [(1)(a)]
- The Data Fiduciary must disclose the identities of other Data Fiduciaries and Data Processors with whom the data was shared, and describe the shared data. [(1)(b)]
- The Data Fiduciary must provide any other information related to the data and its processing as may be prescribed by rules. [(1)(c)]
- The Data Fiduciary does not have to disclose sharing details if the data was shared with a legally authorized Data Fiduciary for law enforcement or cyber incident purposes based on a written request. [(2)]
Common misreadings
- A Data Fiduciary must always disclose every entity it shares data with. (Correction: They do not have to disclose sharing with legally authorized entities for investigating offences or cyber incidents.)
- This right applies to all personal data held by the Data Fiduciary regardless of how it was obtained. (Correction: The text specifies this right applies to a Data Fiduciary to whom the Data Principal has previously given consent.)
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.