/The Act · Chapter III · Rights and Duties of Data Principal
Section 15: Duties of Data Principal
DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.
- Provision
- Section 15 of The Digital Personal Data Protection Act, 2023
- Status
- Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
- Rules made under it
- None identified
- Source
- Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF
A Data Principal shall perform the following duties, namely:—
comply with the provisions of all applicable laws for the time being in force while exercising rights under the provisions of this Act;
to ensure not to impersonate another person while providing her personal data for a specified purpose;
to ensure not to suppress any material information while providing her personal data for any document, unique identifier, proof of identity or proof of address issued by the State or any of its instrumentalities;
to ensure not to register a false or frivolous grievance or complaint with a Data Fiduciary or the Board; and
to furnish only such information as is verifiably authentic, while exercising the right to correction or erasure under the provisions of this Act or the rules made thereunder.
Section 15 sets out the duties that a Data Principal (the individual to whom the personal data relates) must follow under the Act. First, when exercising any rights under this law, the Data Principal must comply with all other applicable laws currently in force.\n\nThe section also strictly prohibits certain deceptive actions. A Data Principal must not impersonate another person when providing personal data for a specific purpose. Additionally, when providing personal data for any State-issued document, unique identifier, or proof of identity or address, the Data Principal must not hide or suppress any material information.\n\nFinally, the law requires honesty in complaints and data requests. A Data Principal must not register a false or frivolous grievance or complaint with a Data Fiduciary (the entity determining the purpose and means of processing data) or the Board. When asking to correct or erase personal data, the Data Principal must only provide information that is verifiably authentic.
Key points
- A Data Principal must comply with all applicable laws when exercising their rights under this Act (a).
- A Data Principal must not impersonate someone else when providing personal data for a specified purpose (b).
- A Data Principal must not suppress material information when providing data for State-issued IDs or documents (c).
- A Data Principal must not file false or frivolous complaints with a Data Fiduciary or the Board (d).
- A Data Principal must provide verifiably authentic information when requesting data correction or erasure (e).
Common misreadings
- People might assume the Act only imposes obligations on organizations, but this section specifically places legal duties on the Data Principal.
- A Data Principal cannot demand correction or erasure using unverified information; the law requires the new information to be verifiably authentic.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.