DPDP Wiki Talk to us

/The Rules · 2025

Rule 14: Rights of Data Principals

DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) · rule 1(4)
Provision
Rule 14 of The Digital Personal Data Protection Rules, 2025
Status
Comes into force on 13 May 2027 (phase 3)
Made under
s. 11 Right to access information about personal datas. 12 Right to correction and erasure of personal datas. 13 Right of grievance redressals. 14 Right to nominate
Source
Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF

Rule 14. Rights of Data Principals

Verbatim from the Gazette of India
(1)

For enabling Data Principals to exercise their rights under the Act, the Data Fiduciary and, where applicable, the Consent Manager, shall prominently publish on its website or app, or both, as the case may be, —

(a)

the details of the means using which a Data Principal may make a request for the exercise of such rights; and

(b)

the particulars, if any, such as the username or other identifier of such a Data Principal, which may be required to identify her under its terms of service.

(2)

To exercise the rights of the Data Principal under the Act, she may make a request to the Data Fiduciary to whom she has previously given consent for processing of her personal data, using the means and furnishing the particulars required by such Data Fiduciary for the exercise of such rights.

(3)

Every Data Fiduciary and Consent Manager shall prominently publish on its website or app, or both, as the case may be, within a reasonable period not exceeding ninety days under its grievance redressal system for responding to the grievances of Data Principals and shall, for ensuring the effectiveness of the system in responding within such period, implement appropriate technical and organisational measures.

(4)

To exercise the rights of the Data Principal under the Act, she may, in accordance with the terms of service of the Data Fiduciary and such law as may be applicable, nominate one or more individuals, using the means and furnishing the particulars required by such Data Fiduciary for the exercise of such right.

(5)

In this rule, the expression “identifier” shall mean any sequence of characters issued by the Data Fiduciary to identify the Data Principal and includes a customer identification file number, customer acquisition form number, application reference number, enrolment ID, email address, mobile number or licence number that enables such identification.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data FiduciaryData PrincipalConsent Manager

A Data Fiduciary (the entity deciding how and why personal data is processed) and a Consent Manager (an entity that manages consent on behalf of individuals) must clearly publish instructions on their website or app. These instructions must explain how a Data Principal (the individual to whom the data belongs) can exercise their rights under the law. They must also list any specific details needed to identify the individual, such as a username or other identifier. An identifier can be any sequence of characters issued by the Data Fiduciary, such as an email address, mobile number, or customer ID. To exercise their rights, a Data Principal can submit a request to a Data Fiduciary to whom they previously gave consent. The individual must use the specific methods and provide the identifying details required by that Data Fiduciary. Additionally, a Data Principal has the right to nominate one or more individuals to exercise these rights on their behalf, following the Data Fiduciary's terms of service and applicable laws. Data Fiduciaries and Consent Managers must also prominently publish details about their grievance redressal system on their website or app. This system must respond to the grievances of Data Principals within a reasonable period, which cannot exceed ninety days. To guarantee that grievances are handled within this ninety-day limit, these entities must put appropriate technical and organizational measures in place.

Key points

  • Data Fiduciaries and Consent Managers must prominently publish how Data Principals can exercise their rights and what identifying details are required. (1)
  • Data Principals can exercise their rights by making a request using the methods and details required by the Data Fiduciary. (2)
  • A grievance redressal system must be published and must respond to grievances within a reasonable period not exceeding ninety days. (3)
  • Data Fiduciaries and Consent Managers must implement technical and organizational measures to ensure grievances are answered within the ninety-day limit. (3)
  • Data Principals can nominate one or more individuals to exercise their rights, subject to the Data Fiduciary's terms and applicable law. (4)
  • An identifier includes any sequence of characters issued to identify the Data Principal, such as an email, mobile number, or customer ID. (5)

Common misreadings

  • People might assume a Data Fiduciary has an unlimited amount of time to respond to a grievance, but the rule explicitly caps the response time at a reasonable period not exceeding ninety days.
  • People might think a Data Principal can only nominate a single person to exercise their rights, but the text allows the nomination of one or more individuals.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.