What are data principal rights under DPDP — complete guide
The DPDP Act grants individuals five core rights over their personal data. Here is what each right means and how organisations must honour it.
Right 1: The right to access personal data
A data principal can ask the Data Fiduciary to provide: a summary of the personal data being processed; the processing activities being undertaken with that data; the identities of all Data Processors who process the data on the Fiduciary's behalf; and other Fiduciaries with whom the data has been shared. The response must be provided within the government-prescribed period (expected 30 days). The access right enables individuals to verify compliance and spot inaccuracies — it is the foundation from which correction and erasure rights are exercised.
Right 2: The right to correct and erase personal data
A data principal can request correction of inaccurate, incomplete, or misleading personal data. They can also request erasure of personal data that is no longer necessary for the processing purpose or for any other lawful basis. The Fiduciary must action the request within the prescribed period or explain why it cannot be actioned (for example, statutory retention requirements prevent erasure). Update your systems to record correction and deletion requests and track their resolution. An unresponded-to erasure request is an independent violation.
Right 3: The right to grievance redressal
Every Data Fiduciary must publish a contact for a grievance officer and operate a grievance mechanism. Data principals can file grievances about any DPDP non-compliance — failure to respond to access requests, continued processing after consent withdrawal, insufficient breach notification. The Fiduciary must respond within the prescribed period. If unsatisfied with the response, the data principal can escalate to the Data Protection Board. Grievance redressal is the first tier of the enforcement system — an effective internal grievance mechanism keeps disputes from escalating to the Board.
Right 4: The right to nominate
The data principal can nominate a person to exercise their data rights on their behalf in the event of death or incapacity. The nominee steps into the data principal's position and can exercise all rights — access, correction, erasure — on behalf of the deceased or incapacitated principal. Fiduciaries must accept nominations and have a process for verifying nominee identity and authority when the nomination is activated. Implement a nomination field in your account settings or provide a nomination form.
Right 5: The right to withdraw consent
Consent can be withdrawn at any time without penalty. The withdrawal mechanism must be as easy as the consent mechanism. On withdrawal: stop processing that is based solely on the withdrawn consent; notify your Processors to stop processing for that purpose; and confirm the withdrawal to the data principal. If the data principal withdraws consent for processing that was necessary for a service, you may lawfully stop providing that service — but you cannot penalise them for withdrawing consent for non-essential processing by degrading the core service.
How do you operationalise rights at scale?
Build a data rights portal or designated inbox: a web form or email address where data principals submit requests; an identity verification step (verify the requestor is who they claim to be); a workflow to locate and compile the relevant data across all systems; a response template with the required information; a tracking system to manage open requests and deadlines; and a log of all requests and responses for audit purposes. For high-volume consumer businesses, self-service tools (account settings with download and delete options) are essential — manual processing of thousands of access requests is not operationally viable.
Frequently asked questions
Can a Fiduciary charge a fee for responding to data rights requests?
Generally no. Data principal rights requests must be actioned free of charge. The Act may allow the government to prescribe a fee for manifestly unfounded or excessive requests, but standard rights requests — access, correction, erasure — must be free. Charging fees for data access is a GDPR violation too, and enforcement globally has treated fee-charging as a deterrent to rights exercise, which is itself a violation.
What happens if a data principal makes a frivolous rights request?
If a request is manifestly unfounded (for example, someone submitting dozens of access requests clearly intended to harass) or disproportionate, the Fiduciary may be able to charge a fee or decline to act on it. Document your reasoning for treating a request as manifestly unfounded — the default position must be to respond, and declining requires justification. Never decline based on inconvenience or system limitations.
Do data principal rights apply to historical data collected before DPDP enforcement?
Rights under the Act apply from the enforcement date. For data held at the enforcement date, rights apply going forward. A data principal can exercise their access right to see data collected before enforcement; they can exercise the correction right for inaccurate pre-enforcement data; and they can exercise the erasure right for pre-enforcement data that has no ongoing lawful basis for retention. Pre-enforcement data does not get a 'grandfather' protection from individual rights claims.
Build your data principal rights mechanism
Niti Bharat's Data Principal Rights Portal guidance covers all five rights — access, correction, erasure, nomination, withdrawal — with intake form design, verification workflow, and Board escalation protocol.
Design Your Rights Portal