Data Principal rights under DPDP: a practical guide.
The DPDP Act confers a set of rights on every Data Principal — the individual whose data you hold. Most of the operational obligations to honour these rights are scheduled to commence on 13 May 2027, and organisations are preparing their processes in advance. Here's what each right means — and what your employees should actually do when a request arrives.
A "Data Principal" is simply the individual the data belongs to — your customer, a job applicant, an employee. The DPDP Act confers a set of rights on every Data Principal in respect of their own personal data. Most of the operational obligations to honour these rights are scheduled to commence on 13 May 2027, and organisations are preparing their processes in advance. Understanding these rights matters for two reasons: your organisation will need to honour them within a clearly defined process, and your employees need to recognise a request the moment it arrives, in whatever form it takes.
The rights conferred by the Act
- Access — the right to a statutory summary of the personal data an organisation holds and how it's being used. This is not an unrestricted right to every document the organisation has about the person.
- Correction — the right to have inaccurate or outdated personal data corrected or updated.
- Erasure — the right to ask for their personal data to be deleted, once it's no longer needed for the purpose it was collected for (subject to legal exceptions, such as records an organisation is required to retain).
- Grievance redressal — the right to raise a complaint about how their data has been handled, and get a response within the statutory maximum period.
DPDP also provides a separate mechanism — nomination — allowing an individual to appoint another person to exercise these rights on their behalf, in the event of death or incapacity. It's less an operational request an employee will encounter and more an arrangement made in advance.
A request can arrive in any form — but is handled through a formal channel
This is the part most organisations get wrong at both ends: a communication doesn't need to reference the DPDP Act, use legal language, or arrive through your privacy portal before an employee should recognise it as a potential rights request. An email that says "please delete my account," a phone call asking "what information do you have on me," or a casual message asking why an application was rejected — an employee should recognise any of these as potentially relating to personal-data rights and route them to the designated team without delay.
Under Rule 14, the organisation publishes the means by which rights may be exercised and any information the Data Principal needs to provide. Once a communication is routed to the designated team, that team applies the published process — asking the individual to use the formal channel and to provide any required identification. The employee's job is to recognise and route the communication. The formal process is not the employee's decision to bypass or replicate.
The rule employees should actually follow: if someone is asking about their own personal data — to see it, change it, delete it, or complain about how it's handled — route it to your organisation's designated contact (DPO, Grievance Officer, or Compliance Lead) immediately. Don't try to answer it yourself, even if you know the answer and even if it seems simple. Speed matters more than being the one who resolves it.
Why speed matters — and the 90-day grievance rule
Response timelines for different categories of Data Principal rights are set by the organisation as part of its published process. For grievances specifically, the DPDP Rules set a statutory maximum of 90 days for redressal. This 90-day cap applies to grievances only — not to all Data Principal rights, though this is often misreported. Prompt routing matters at every level: any delay in getting a request from an employee's inbox to the designated team eats into the time available for the organisation to respond.
What this looks like day to day
In practice, most employees will encounter this rarely — but when they do, the instinct to "just handle it" is the wrong one. A designated contact exists precisely because handling these requests correctly involves identity verification, legal exceptions, and documentation that a general employee isn't equipped to manage alone.
DPDPA Compliance Training