/The Act · Chapter III · Rights and Duties of Data Principal
Section 13: Right of grievance redressal
DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.
- Provision
- Section 13 of The Digital Personal Data Protection Act, 2023
- Status
- Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
- Rules made under it
- Rule 14
- Source
- Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF
A Data Principal shall have the right to have readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager in respect of any act or omission of such Data Fiduciary or Consent Manager regarding the performance of its obligations in relation to the personal data of such Data Principal or the exercise of her rights under the provisions of this Act and the rules made thereunder.
The Data Fiduciary or Consent Manager shall respond to any grievances referred to in sub-section (1) within such period as may be prescribed from the date of its receipt for all or any class of Data Fiduciaries.
Section 13 gives a Data Principal (the individual whose data is being processed) the right to easily access a grievance redressal system. This system must be provided by the Data Fiduciary (the entity deciding how and why data is processed) or a Consent Manager. It allows the Data Principal to raise complaints if these entities fail to meet their obligations or if the Data Principal cannot exercise their rights under the law.\n\nOnce a complaint is submitted, the Data Fiduciary or Consent Manager is required to respond to it. The exact time limit for this response is not stated in the Act but will be set by future rules, which may specify different time limits for different classes of Data Fiduciaries.\n\nA Data Principal cannot immediately take their complaint to the Board (the Data Protection Board of India). The law requires them to first use the grievance redressal process provided by the Data Fiduciary or Consent Manager and exhaust this option before escalating the matter to the Board.
Key points
- A Data Principal has the right to readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager. [(1)]
- The Data Fiduciary or Consent Manager must respond to the grievance within a time period that will be prescribed by rules. [(2)]
- The Data Principal must exhaust this initial grievance process before they are allowed to approach the Board. [(3)]
Common misreadings
- A Data Principal cannot skip the Data Fiduciary's grievance process and go straight to the Board.
- The exact time limit to respond to a grievance is not fixed in the Act itself, but will be prescribed by future rules.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.