DPDP Wiki Talk to us

/Guides · Individuals

Your rights and duties as a Data Principal

What an individual can ask a Data Fiduciary for under the DPDP Act, how those requests are made and answered, and the duties the Act places on the individual.

Interpretation · not legal adviceUpdated 9 September 20267 min read
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation. Every statement links to the official provision it rests on.

The Act calls the individual whose personal data is being processed a Data Principal, and gives that individual four rights and five duties. This guide sets out what each right covers, how a request is made and answered under the Rules, and what happens when a duty is breached.

Who counts as a Data Principal#

A Data Principal is "the individual to whom the personal data relates", and section 2(j) stretches that to two situations where she cannot act alone. Where the individual is a child, the term includes "the parents or lawful guardian of such a child". Where she is a person with disability, it includes "her lawful guardian, acting on her behalf". A child is anyone "who has not completed the age of eighteen years" (section 2(f)), and the Act uses "she" for an individual of any gender (section 2(y)).

The Rules add verification around both. Before a child's personal data is processed, the Data Fiduciary must take appropriate technical and organisational measures to obtain verifiable consent of the parent, and observe due diligence in checking it (rule 10). Where someone identifies herself as the lawful guardian of a person with disability, the fiduciary must "observe due diligence to verify that such guardian is appointed by a court of law, or by a designated authority or by a local level committee, under the law applicable to guardianship" (rule 11).

When these rights start#

Sections 11 to 15 are not in force yet. G.S.R. 843(E) brings them into force eighteen months from publication of that Gazette, which is 13 May 2027. Rule 9 and rule 14 start the same day under rule 1(4).

The right to know what is being processed#

Section 11(1) lets a Data Principal obtain three things from a Data Fiduciary to whom she has previously given consent: a summary of the personal data being processed and of the processing activities on it, the identities of all other Data Fiduciaries and Data Processors it has shared that data with plus a description of what was shared, and any other prescribed information.

Two limits sit in the text. The right runs against a fiduciary "to whom she has previously given consent, including consent as referred to in clause (a) of section 7", so it reaches consent-based processing and the legitimate use where she voluntarily provided her data and did not object (section 7(a)). The sharing-related parts fall away where data goes to another Data Fiduciary authorised by law to obtain it, on a written request, for preventing, detecting or investigating offences or cyber incidents, or for prosecution or punishment (section 11(2)). The Central Government may also notify fiduciaries, including startups, to whom section 11 does not apply (section 17(3)).

The right to correction, completion, updating and erasure#

Section 12(1) covers correction, completion, updating and erasure of personal data processed on the basis of consent, again including consent under section 7(a), exercised "in accordance with any requirement or procedure under any law for the time being in force".

On a request for correction, completion or updating, the fiduciary must correct inaccurate or misleading data, complete what is incomplete and update what is out of date (section 12(2)). Erasure carries a condition: on a request in the prescribed manner the fiduciary "shall erase her personal data unless retention of the same is necessary for the specified purpose or for compliance with any law for the time being in force" (section 12(3)).

For processing by the State or an instrumentality of the State, section 17(4) switches off section 12(3), and switches off section 12(2) as well where the purpose does not include making a decision that affects the Data Principal.

The right to be heard#

Section 13(1) requires a Data Fiduciary or Consent Manager to provide "readily available means of grievance redressal" for any act or omission about its obligations or about the exercise of her rights. A response must come within a prescribed period (section 13(2)), and the Data Principal must exhaust that route before approaching the Data Protection Board (section 13(3)).

Rule 14(3) sets the outer limit. Each Data Fiduciary and Consent Manager must prominently publish, on its website or app, the period "within a reasonable period not exceeding ninety days under its grievance redressal system for responding to the grievances of Data Principals", and implement measures so the system responds inside it. Section 8(10) separately requires an effective redressal mechanism.

The right to nominate#

Section 14(1) lets a Data Principal nominate another individual to exercise her rights if she dies or becomes incapable. "Incapacity" is defined narrowly, as inability to exercise those rights "due to unsoundness of mind or infirmity of body" (section 14(2)). Under rule 14(4) she may nominate one or more individuals, using the means and particulars the fiduciary requires.

How a request is made and answered#

Rule 14(1) puts the burden of making the route visible on the Data Fiduciary and, where applicable, the Consent Manager. Each must prominently publish the means by which a request can be made and the particulars, such as a username or other identifier, needed to identify the person under its terms of service. An identifier can be an enrolment ID, email address, mobile number or licence number (rule 14(5)).

The request goes to the fiduciary to whom she previously gave consent, using those means and particulars (rule 14(2)). Every Data Fiduciary must publish, and repeat in every response to a rights-related communication, the business contact information of its Data Protection Officer where one applies, or of a person who can answer on its behalf (rule 9).

Withdrawing consent is separate from these rights. It can be done at any time where consent is the basis of processing, "with the ease of doing so being comparable to the ease with which such consent was given" (section 6(4)).

Five duties, and the one penalty aimed at individuals#

Section 15 places five duties on the Data Principal.

DutyWording in section 15
Obey the law when exercising rights"comply with the provisions of all applicable laws" in force while exercising rights under the Act
Do not impersonate"not to impersonate another person while providing her personal data for a specified purpose"
Do not suppress material information"not to suppress any material information" when giving personal data for a document, unique identifier, proof of identity or proof of address issued by the State or its instrumentalities
Do not file false or frivolous complaints"not to register a false or frivolous grievance or complaint with a Data Fiduciary or the Board"
Give authentic information"furnish only such information as is verifiably authentic" when exercising the right to correction or erasure

Entry 5 of the Schedule attaches a penalty to those duties: for a "Breach in observance of the duties under section 15", the penalty "May extend to ten thousand rupees". It is the only entry tied to a Data Principal's own duties, and the Board may impose it only if an inquiry ends in a finding that the breach is significant, after a hearing (section 33(1)). A false or frivolous complaint can also draw a warning or costs (section 28(12)).

A failure by the individual does not shift responsibility. The Data Fiduciary must comply "irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties" (section 8(1)).

Key provisions#

/MYND · DPDP practice

Want help applying this?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.