DPDP Fundamentals

Data Principal Rights Under the DPDP Act

The rights Data Principals have under the DPDP Act: access, correction, erasure, and grievance. What businesses must do to honor these rights.

By: ConsentLog Research
Published: 8 September 2026
Last reviewed: 8 September 2026
9 min read

The Four Key Rights

The DPDP Act grants Data Principals four fundamental rights over their personal data.

1. Right to Know (Access)

Data Principals can request access to their personal data and information about how it's being processed.

Timeline: Reasonable timeframe (typically 30 days)

2. Right to Correct

Individuals can request correction of inaccurate or incomplete personal data.

Applies only where consent was given or data voluntarily provided

3. Right to Erasure (Deletion)

Individuals can request deletion of their personal data, subject to exceptions.

Exceptions: Legal obligation, public interest, data processor role

4. Right to Grievance

Individuals can file complaints about violations with the Grievance Officer or Data Protection Board.

Multi-step process: Grievance Officer → Data Protection Board

Business Obligations

Organizations must establish procedures to handle each right:

  • Accept requests through accessible channels
  • Verify the individual's identity
  • Respond within reasonable timeframe
  • Document all requests and responses
  • Handle complex requests appropriately

Key Takeaways

Rights are enforceable: Individuals can escalate to regulators if you don't respond.

You need systems: Manual processes won't scale for rights requests.

Sources & Further Reading

Digital Personal Data Protection Act, 2023 - Sections 8-13

Parliament of India

https://indiacode.gov.in/act/c058fa9f-eaf0-4ca3-98f1-3443b087bca9/sections

Building your DPDP compliance infrastructure?

ConsentLog helps Indian businesses operationalize DPDP consent requirements across their systems. Learn how we're approaching consent infrastructure.