Skip to main content
Data Principal Rights Under DPDP: Access, Correction, Erasure and Grievances
Compliance Guides
DPDP Act
Data Principal Rights
Right to Erasure
Grievance Redressal
DPDP Rules 2025

Data Principal Rights Under DPDP: Access, Correction, Erasure and Grievances

Access, correction, erasure and grievances under Sections 11 to 13 of the DPDP Act and Rule 14, with the limits and an 8-step checklist.

Consently Team
8 October 2026
7 min read

Sooner or later a customer will write in to ask what you hold about them, tell you it is wrong, or ask you to delete it. Under the Digital Personal Data Protection Act, 2023, these are not customer service favours. They are Data Principal rights, and from 13 May 2027 you will have to answer them through a published, working process.

The ground is already contested. The Delhi High Court is hearing appeals over how far a "right to be forgotten" reaches into online court records. In September 2026, UIDAI revised its procedure for Aadhaar name corrections, grading each request by the proof it needs. This guide explains what Sections 11 to 13 of the Act and Rule 14 of the DPDP Rules, 2025 require, and where the limits are.

Key takeaways

  • Sections 11 to 14 give Data Principals four rights: access, correction and erasure, grievance redressal, and nomination.
  • The access and correction rights run against the Data Fiduciary to whom the person gave consent, including data she provided voluntarily under Section 7(a).
  • Access means a summary of the data and the processing, plus the identities of everyone the data was shared with (Section 11).
  • Erasure is not absolute. You may keep data that is necessary for the specified purpose or to comply with a law (Section 12(3)).
  • Rule 14 requires you to publish how to make a request, and to answer grievances within a reasonable period of no more than ninety days.

Which Data Principal rights does the DPDP Act create?

Chapter III of the DPDP Act sets out four rights:

  • Section 11: access to information about her personal data.
  • Section 12: correction, completion, updating and erasure.
  • Section 13: readily available means of grievance redressal.
  • Section 14: nomination of another individual to exercise her rights on death or incapacity.

Sections 11 and 12 speak of the Data Fiduciary "to whom she has previously given consent", and include consent under Section 7(a), which covers data a person voluntarily provides for a specified purpose. The grievance right in Section 13 is wider. It covers any act or omission relating to your obligations or her rights.

In practice, reply to every request and decide the scope of what you must provide afterwards.

Access, correction and erasure: what each request requires

Access (Section 11)

On request, you must give the Data Principal a summary of the personal data being processed and the processing activities, the identities of all other Data Fiduciaries and Data Processors with whom the data has been shared, with a description of what was shared, and any other information that may be prescribed.

Two points follow. The Act asks for a summary, not a copy of every record. And you need to know your processors and sharing partners by name before the request arrives. Section 11(2) carves out one case: sharing with a Data Fiduciary authorised by law that asked in writing for the prevention, detection or investigation of offences or cyber incidents.

Correction, completion and updating (Section 12(2))

When a request arrives, you must correct inaccurate or misleading personal data, complete incomplete data and update it. The Data Principal has a matching duty. Under Section 15(e) she must furnish only information that is verifiably authentic when exercising the right to correction or erasure.

So asking for proof is legitimate, as long as it is proportionate. UIDAI's revised procedure is a useful model: a spelling fix needs an identity document, while a complete change of name needs a Gazette notification. Grade your own correction requests by risk in the same way.

Erasure (Section 12(3))

On an erasure request, you must erase the personal data unless retention is necessary for the specified purpose or for compliance with any law for the time being in force. Both exceptions are narrow. "We might need it later" is not a specified purpose. If you rely on a law, be ready to name it.

Erasure also travels: Section 8(7) expects you to cause your Data Processors to erase the data you made available to them.

Grievance redressal and the ninety-day ceiling

Section 8(10) requires every Data Fiduciary to establish an effective mechanism to redress grievances. Section 13 gives the Data Principal the right to use it and requires a response within the prescribed period. Rule 14(3) of the DPDP Rules, 2025 supplies that period: a reasonable period not exceeding ninety days, which you must publish on your website or app. The same sub-rule requires appropriate technical and organisational measures so that you can respond in time.

Ninety days is a ceiling, not a target. The test is what is reasonable. The Rules also set no separate deadline for the first reply to an access, correction or erasure request, so set your own targets well inside ninety days.

Under Section 13(3), a Data Principal must exhaust your grievance process before approaching the Data Protection Board. A slow or silent process is the shortest route to the Board. A breach of these provisions falls under the residual penalty in the Schedule, which goes up to Rs 50 crore.

What you must publish, and when you can refuse

What to publish

Rule 14(1) requires you to prominently publish, on your website or app, the means by which a Data Principal can make a request and the particulars you need to identify her, such as a username or other identifier. Rule 14(5) lists examples, including an email address or a mobile number.

Rule 9 adds that you must publish the business contact information of your Data Protection Officer, or of a person who can answer questions about processing, and mention it in every response to a rights communication.

When you can refuse

  • You are not the right Data Fiduciary. Under Rule 14(2), requests go to the Data Fiduciary to whom the person gave consent.
  • Retention is justified. The data is still necessary for the specified purpose, or a law requires you to keep it.
  • An exemption applies. Section 17 exempts certain processing, such as processing necessary to enforce a legal right or claim.
  • The grievance is false or frivolous. Section 15(b) bars these, but treat this as rare and record your reasons.

In every case, reply, give the reason and tell the person how to raise a grievance.

A Data Principal rights checklist

  1. Map where requests arrive today (support email, app, social media, branches) and route them to one queue.
  2. Publish the means of making a request and the identifiers you need.
  3. Decide how you will verify identity for each request type, in proportion to the risk.
  4. List every Data Processor and Data Fiduciary you share personal data with, so that access responses can name them.
  5. Write down the retention reason for each data category, purpose or law, so that erasure decisions are consistent.
  6. Set internal response targets, and publish your grievance response period of no more than ninety days.
  7. Make sure your processors can correct and erase on instruction, and say so in the contract.
  8. Log every request: when it was received, how identity was verified, what was decided and why, and when you replied.

Our DPDPA consent guide covers the consent side, since withdrawal and erasure often arrive together. Once requests arrive in numbers, see DSAR automation in 2026 for running the workflow at volume.

How Consently helps

Consently is a DPDP-native consent management platform built by G. Giri & Partners LLP. Its request centre gives your team workflows for access, correction and erasure requests, and it supports the right to nominate under Section 14. Data Principals can review, update or withdraw consent from a preference centre, with access verified by email OTP, and reports and compliance dashboards give you oversight. Decisions on what to retain and when to refuse still belong to your legal team.

Not sure where your organisation stands? Try our DPDP compliance calculator, or book a demo to see the request centre.

FAQ

How long do we have to respond to a Data Principal rights request?

The Rules set no separate deadline for access, correction or erasure requests. Rule 14(3) requires grievances to be answered within a reasonable period not exceeding ninety days. Set shorter internal targets for requests.

Do we have to give a full copy of a person's data?

Section 11 requires a summary of the personal data and the processing activities, plus the identities of the Data Fiduciaries and Data Processors it was shared with. It does not ask for a copy of every record.

Can we refuse an erasure request?

Yes, where retention is necessary for the specified purpose or a law requires you to keep the data. Explain the reason, erase what you can, and tell the person how to raise a grievance.

When do Data Principal rights start to apply?

From 13 May 2027, eighteen months after the DPDP Rules were notified on 13 November 2025.

This article is for general information and is not legal advice. Please consult a qualified lawyer for advice on your specific situation.

Share this article

Related Articles

Verifiable Parental Consent Under DPDP: What Section 9 Demands
Compliance Guides

Verifiable Parental Consent Under DPDP: What Section 9 Demands

Under the DPDP Act, anyone below 18 is a child. Section 9 needs verified parental consent and bans tracking and targeted ads for children. What Rule 10 asks for, and an 8-step checklist.

2 Oct 20267 min
DPDP Granular Consent: Why One Checkbox Is No Longer Enough
Compliance Guides

DPDP Granular Consent: Why One Checkbox Is No Longer Enough

One checkbox covering terms, marketing, WhatsApp and partner sharing is unlikely to hold up under the DPDP Act. Here is what Section 6 and Rule 3 require, what purpose-level consent looks like on a real form, and a checklist to finish before 13 May 2027.

29 Sept 20267 min
13 November 2026 Is Not Your DPDP Deadline. Here Is What It Actually Starts.
Compliance Guides

13 November 2026 Is Not Your DPDP Deadline. Here Is What It Actually Starts.

13 November 2026 opens Consent Manager registration under Rule 4 of the DPDP Rules, 2025. It places no new obligation on an ordinary Data Fiduciary. Your notice, consent, security, breach and rights obligations start on 13 May 2027. Here is who should act in November, and how to use the months in between.

29 Sept 20268 min