What Is a Data Principal Under the DPDP Act?

A Data Principal is any individual whose personal data is being processed by a Data Fiduciary. The term is defined in Section 2(j) of the Digital Personal Data Protection Act 2023.

In practice, if you have ever signed up for a mobile app, purchased something online, visited a hospital, applied for a loan, or shared your phone number with any Indian business, you are a Data Principal under the DPDP Act. The Data Fiduciary is the organisation on the other side of that transaction — the company that decides what to do with your personal data.

One important nuance: when the Data Principal is a minor (a child below 18 years of age), the parent or legal guardian acts as the Data Principal and exercises all rights on the child's behalf. The Data Fiduciary must also obtain verifiable parental consent before processing a child's data, and is prohibited from processing data in a manner that is detrimental to the child's wellbeing.

The distinction between Data Principal and Data Fiduciary is foundational to understanding the DPDP Act. Every right in Sections 11–14 is a right the Data Principal holds against the Data Fiduciary. Every obligation in Sections 8–10 is an obligation the Data Fiduciary owes to the Data Principal.

What Are the Rights of a Data Principal Under the DPDP Act?

The DPDP Act grants Data Principals four statutory rights, contained in Sections 11 through 14 of the Act. Unlike GDPR, which contains eight rights, the DPDP Act is deliberately focused: four carefully defined rights, each with a corresponding obligation on the Data Fiduciary to respond and comply.

01
Right of Access to Information
Section 11
02
Right to Correction, Completion & Erasure
Section 12
03
Right of Grievance Redressal
Section 13
04
Right to Nominate
Section 14

Each right is enforceable. A Data Fiduciary that ignores or improperly refuses a Data Principal's request faces escalation to the Data Protection Board of India, which has the power to investigate and impose financial penalties. Let us examine each right in detail.

1. Right of Access to Information (Section 11)

Under Section 11, a Data Principal has the right to request — and receive — two categories of information from the Data Fiduciary:

  • A summary of personal data being processed: What personal data the Data Fiduciary holds about you, and what processing activities it is carrying out with that data.
  • Identities of other Data Fiduciaries and Data Processors: The names of all other Data Fiduciaries and Data Processors with whom the Data Fiduciary has shared your personal data, along with a description of what data was shared.

This is India's equivalent of GDPR's "right of access" (Article 15), though narrower in scope. The Data Principal is not automatically entitled to a full copy of all their data — they are entitled to a summary of what is held and a disclosure of where it has gone.

The Data Fiduciary must respond within the timeframe specified in the DPDP Rules (the draft Rules suggest 30 days as the expected standard). The grounds on which a Data Fiduciary may refuse to provide access have not been fully specified in the Rules yet, but national security interests and active legal proceedings are expected to feature as permissible grounds for refusal — as is the case in comparable global frameworks.

For organisations building compliance programmes, Section 11 creates a practical requirement: you must maintain an accurate, queryable record of what personal data you hold about each individual and who you have shared it with. An ad-hoc data inventory managed in spreadsheets will not support this at scale.

2. Right to Correction, Completion and Erasure (Section 12)

Section 12 bundles four related but distinct sub-rights into a single provision:

  • Correction: The right to correct personal data that is inaccurate or misleading.
  • Completion: The right to have incomplete personal data completed.
  • Updation: The right to have outdated personal data updated.
  • Erasure: The right to request the deletion of personal data that is no longer necessary for the purpose for which consent was originally given.

The right to correction, completion, and updation are relatively straightforward: if a Data Fiduciary holds wrong, partial, or stale information about you, you can require them to fix it. This is particularly important in contexts like healthcare records, credit bureau data, and KYC information, where inaccurate data can cause direct and significant harm.

The right to erasure is more nuanced. It is not an absolute right — the Data Fiduciary can retain personal data if retention is required or authorised by law (for example, tax records or financial transaction logs that must be kept for prescribed periods). Outside of such legally mandated retention, if the purpose for which consent was given has been fulfilled or is no longer relevant, the Data Principal can require deletion.

Critically, Section 12 creates a linked obligation that organisations must operationalise: when a Data Principal withdraws consent, the Data Fiduciary is automatically required to cease processing and erase the personal data — unless legal retention requirements apply. Consent withdrawal triggers erasure; it is not a separate request that needs to be made independently.

Operational implication

Section 12 means your data systems must support selective deletion at the individual level. If your databases were designed with data permanence as the default, retrofitting deletion capability is one of the more technically demanding aspects of DPDP compliance — and one of the most commonly underestimated.

3. Right of Grievance Redressal (Section 13)

Section 13 gives every Data Principal the right to raise a grievance against a Data Fiduciary — and to receive a meaningful response. The process has two tiers:

Tier 1 — Grievance with the Data Fiduciary: The Data Principal can file a complaint directly with the Data Fiduciary through its designated grievance redressal mechanism. The Data Fiduciary is required to acknowledge and respond to the grievance within the period specified in the DPDP Rules (expected: 30 days). The response must be substantive — a blanket refusal without explanation does not satisfy this obligation.

Tier 2 — Escalation to the Data Protection Board of India: If the Data Principal is unsatisfied with the response received from the Data Fiduciary, or does not receive a response within the stipulated period, they can escalate the matter to the Data Protection Board of India. The Board has the power to investigate the complaint, direct remedial action, and impose financial penalties on the Data Fiduciary.

For organisations, Section 13 creates a concrete compliance requirement: a publicly accessible, functional grievance redressal mechanism must exist. This is not optional, and it must actually work. A broken contact form, an unmonitored email address, or a grievance officer who never responds will result in escalations to the Board — and the Board's penalties for non-compliance are substantial.

The Board's penalty for failing to implement adequate security safeguards or to honour Data Principal rights can reach up to ₹50 crore per instance, depending on the nature and severity of the violation. The DPDP Act establishes a tiered penalty structure across different categories of breach.

4. Right to Nominate (Section 14)

The right to nominate is perhaps the most distinctively Indian of the four DPDP Act rights — there is no equivalent in GDPR. Under Section 14, a Data Principal can nominate another individual to exercise their data rights in the event of the Data Principal's death or incapacity.

The mechanism works similarly to a nominee designation in a bank account or a life insurance policy. The Data Principal identifies a trusted person — a family member, a legal representative — who will be empowered to exercise the right of access, the right to correction and erasure, and the right of grievance redressal on the Data Principal's behalf, should the Data Principal no longer be able to do so themselves.

Key features of the right to nominate:

  • The nomination can be changed or revoked by the Data Principal at any time during their lifetime.
  • The nominated person inherits the Data Principal's rights — they do not acquire any new or greater rights than the Data Principal themselves held.
  • The Data Fiduciary must create a mechanism through which nominations can be registered and subsequently updated or revoked.
  • This right reflects a practical recognition that personal data persists beyond death, and that families and legal representatives need a lawful mechanism to manage that data when the individual can no longer do so.

The right to nominate is a thoughtful addition to the DPDP framework that addresses a gap present in most global privacy laws. In a country where digital financial accounts, health records, and social media profiles increasingly outlive their creators, a formal nomination mechanism has practical significance beyond a simple compliance checkbox.

How Can a Data Principal Exercise Their Rights?

The DPDP Act requires every Data Fiduciary to provide a mechanism through which Data Principals can exercise their rights. The specific channels — an online portal, a designated email address, an in-app request flow — are left to the Data Fiduciary to implement, subject to the requirement that they be reasonably accessible and functional.

The practical process for a Data Principal exercising their rights:

  1. Identify the Data Fiduciary's designated channel: This should be published in the organisation's privacy notice. All organisations subject to the DPDP Act are required to make their rights request mechanism accessible to Data Principals.
  2. Submit the request through the designated channel: The request must be made in the prescribed manner. The DPDP Rules are expected to specify what information must accompany a request (for example, identity verification steps).
  3. Await a response within the stipulated period: The Data Fiduciary must respond within the timeframe set by the Rules (expected: 30 days). The response must either fulfil the request or explain — with reasons — why it cannot or will not be fulfilled.
  4. Escalate to the Data Protection Board if unsatisfied: If the response is inadequate, delayed, or absent, the Data Principal can file a complaint with the Data Protection Board of India, which operates as an adjudicatory body for DPDP Act grievances.

Importantly, requests cannot be rejected without reason. A Data Fiduciary that summarily dismisses a Data Principal's request — without explaining the legal basis for refusal and the Data Principal's right to escalate — is in breach of its obligations under Section 13.

DPDP vs GDPR — Rights Comparison

For teams already familiar with GDPR compliance, understanding the differences in the rights framework is important — both to avoid over-engineering DPDP compliance based on GDPR assumptions, and to identify genuine gaps if you are building a unified privacy programme for Indian and EU operations.

RightGDPRDPDP Act
Right of accessYes — Article 15; full copy of data + supplementary informationYes — Section 11; summary of data + disclosure of sharing
Right to rectificationYes — Article 16Yes — Section 12 (correction, completion, updation)
Right to erasureYes — Article 17 ("right to be forgotten")Yes — Section 12; linked to consent withdrawal
Right to restrict processingYes — Article 18No direct equivalent
Right to data portabilityYes — Article 20No — not included in DPDP Act
Right to objectYes — Article 21Limited — only via consent withdrawal
Rights re: automated decisionsYes — Article 22Not explicitly in Act; may come via SDF rules
Right of grievance redressalRight to lodge complaint with supervisory authorityYes — Section 13; two-tier: Data Fiduciary then Board
Right to nominateNo equivalentYes — Section 14; unique to DPDP Act

The headline difference: GDPR has 8 rights; the DPDP Act has 4. The DPDP Act does not include a right to data portability, a right to restrict processing, or an explicit right to object to processing beyond withdrawing consent. Organisations operating under both frameworks need to maintain GDPR's more expansive rights mechanisms for EU individuals while building the DPDP-specific four-right framework for Indian Data Principals.

The absence of a right to data portability is a deliberate policy choice, not an oversight. India's DPDP Act prioritises individual control through access and erasure over the interoperability mechanisms that data portability was designed to promote. This may evolve in future amendments or sector-specific rules.

What Happens If a Data Fiduciary Ignores a Data Principal's Request?

A Data Fiduciary that fails to honour a Data Principal's rights request — whether by ignoring the request, failing to respond within the stipulated period, or refusing without lawful grounds — exposes itself to escalation and penalty.

The Data Principal's recourse is clear: escalate to the Data Protection Board of India. The Board is an independent adjudicatory body established under the DPDP Act with the power to investigate complaints, direct corrective action, and impose financial penalties.

Penalty exposure for failures related to Data Principal rights:

  • Failure to implement reasonable security safeguards: up to ₹250 crore
  • Failure to notify the Board and affected Data Principals of a data breach: up to ₹200 crore
  • Breach of obligations related to children's data or Significant Data Fiduciary obligations: up to ₹150 crore
  • Failure to honour Data Principal rights or observe other Data Fiduciary obligations: up to ₹50 crore

These penalties are per instance and can accumulate. An organisation that systematically ignores Data Principal access requests across thousands of individuals faces compounding exposure that can reach very significant sums.

Ready to map your obligations?

For the complete picture of DPDP Act compliance obligations — including all Data Fiduciary duties, the consent framework, breach notification requirements, and the full penalty structure — see our DPDP Act guide. Or book a free 30-minute assessment to map your organisation's data principal rights framework against the Act's requirements.