What is a Data Principal under DPDP — rights and protections

What is a Data Principal under DPDP — rights and protections
Concepts

What is a Data Principal under DPDP — rights and protections

The DPDP Act is built around the rights of the Data Principal. Here is what the term means and what rights it carries.

Quick Answer: Under the DPDP Act 2023, the Data Principal is the individual whose personal data is being processed — the customer, the employee, the patient, the app user. The Act is built to protect Data Principals from misuse of their personal data by granting them enforceable rights: the right to access their data, correct inaccurate data, erase data that is no longer needed, nominate a person to exercise their rights if they become incapacitated, and file complaints directly with the Data Protection Board. Data Principals must give free, specific, informed, and unambiguous consent before their data is processed for non-essential purposes. They can withdraw consent at any time, and the Data Fiduciary must stop processing within a reasonable period. Minors are Data Principals with additional protections including mandatory parental consent.

Who is a Data Principal under the DPDP Act?

Any living individual whose personal data is collected and processed is a Data Principal. This includes customers, employees, job applicants, website visitors, app users, patients, students, and any other natural person. The term applies to Indian citizens and residents. Foreign nationals whose personal data is processed in India (for example, a foreign tourist whose hotel check-in data is processed by an Indian hotel) are also Data Principals. Companies, LLPs, and other legal entities are not Data Principals — the Act protects individuals, not organisations.

What is the right to access personal data?

The Data Principal has the right to obtain from the Data Fiduciary: a summary of the personal data being processed; the processing activities being undertaken with that data; and the identities of all Data Processors and other Fiduciaries with whom the data has been shared. This right enables individuals to verify that the Fiduciary is processing only what was consented to and for the stated purposes. The Fiduciary must respond within the period prescribed by government Rules.

What is the right to correct and erase personal data?

The Data Principal can request: correction of inaccurate or misleading personal data; completion of incomplete data; and updating of data. They can also request erasure of personal data that is no longer necessary for the processing purpose — provided there is no statutory or legal obligation requiring the Fiduciary to retain it. The right to erasure is not absolute — data needed for legal proceedings, statutory compliance, or legitimate ongoing purposes can be retained. But data held beyond its purpose must be deleted on request.

What is the right to nominate under DPDP?

The DPDP Act introduces a uniquely Indian right: the Data Principal can nominate another individual to exercise their data rights on their behalf in the event of death or incapacity. This is particularly important for elderly individuals, persons with severe disabilities, and those managing digital estates. The nomination can be provided to the Data Fiduciary through a specified mechanism. This right ensures that data rights are not lost when an individual can no longer exercise them directly.

What special protections do minors have as Data Principals?

Minors (individuals under 18) are Data Principals with enhanced protections: their data cannot be processed without verifiable parental or guardian consent; Fiduciaries must implement age verification mechanisms; data processing that causes harm to minors — tracking, profiling, behavioural advertising — is prohibited regardless of parental consent. Significant Data Fiduciaries with large minor user populations must implement robust parental consent systems. Processing children's data without these protections is one of the most serious violations under the Act.

How can a Data Principal enforce their rights?

If a Data Fiduciary fails to honour a Data Principal's rights — does not respond to an access request, refuses to correct data without justification, ignores a withdrawal of consent — the Data Principal can: first, raise a complaint with the Fiduciary's grievance mechanism (Fiduciaries must provide a grievance redressal mechanism); if unsatisfied, file a complaint with the Data Protection Board. The Board investigates and can direct the Fiduciary to comply and impose penalties. Data Principals cannot directly sue Fiduciaries in civil courts under the DPDP Act — the Board is the exclusive enforcement mechanism.

Frequently asked questions

Can a Data Principal appoint a representative to exercise rights on their behalf?

The Act specifically provides for nomination for death or incapacity. For a living, capacitated individual, there is no general right to delegate data rights to a representative (unlike GDPR where representatives are permitted in some contexts). However, for minors, the parent or guardian exercises the rights on behalf of the minor Data Principal.

Do Data Principals have the right to data portability under DPDP?

The DPDP Act does not include a general right to data portability (the right to receive your data in a machine-readable format and transfer it to another Fiduciary), unlike GDPR Article 20. The government may prescribe data portability requirements for specific categories of Fiduciaries or data types by notification — for example, portability for financial account data or health records is expected in the digital financial inclusion context. Until such notification, portability is not a mandatory DPDP right.

What happens if a Data Principal withdraws consent and the Fiduciary ignores it?

Ignoring a consent withdrawal is a violation of the Act. The Fiduciary must stop processing within a reasonable period after withdrawal. If they continue, the Data Principal can file a grievance with the Fiduciary and, if unsatisfied, a complaint with the Data Protection Board. Continued processing after withdrawal is treated as processing without a lawful basis — one of the most fundamental DPDP violations, potentially attracting a penalty of up to ₹250 crore.

Honour your data principals' rights

Niti Bharat's Data Principal Rights Portal guidance covers DSAR intake, verification, response assembly, grievance mechanism design, and Board complaint handling under DPDP.

Design Your Rights Portal
Previous Post Next Post

Get Free DPDP Checklist