Data Principal meaning and rights under DPDPA India.
A Data Principal is the individual to whom personal data relates. Here are the main Data Principal rights under the DPDP Act, what DPDP rights compliance requires operationally, and what employees should do when a request arrives.
Data Principal meaning under the DPDP Act
Under the DPDP Act, a Data Principal is the individual to whom the personal data relates — for example, a customer, job applicant, employee, patient or website user. In simple terms, if the personal data is about you, you are the Data Principal. Most operational obligations for handling Data Principal rights are scheduled to commence on 13 May 2027, so organisations are building the necessary processes in advance.
The rights of Data Principals under the Act
- Access — the right to a statutory summary of the personal data an organisation holds and how it's being used. This is not an unrestricted right to every document the organisation has about the person.
- Correction — the right to have inaccurate or outdated personal data corrected or updated.
- Erasure — the right to request erasure of their personal data. Upon receiving the request, the Data Fiduciary must erase the data unless retention is necessary for compliance with applicable law.
- Grievance redressal — the right to raise a complaint about how their data has been handled, and get a response within the statutory maximum period.
DPDP also provides a separate mechanism — nomination — allowing an individual to appoint another person to exercise these rights on their behalf, in the event of death or incapacity. It's less an operational request an employee will encounter and more an arrangement made in advance.
DPDP Data Principal rights compliance: recognise and route requests
This is the part most organisations get wrong at both ends: a communication doesn't need to reference the DPDP Act, use legal language, or arrive through your privacy portal before an employee should recognise it as a potential rights request. An email that says "please delete my account," a phone call asking "what information do you have on me," or a casual message asking why an application was rejected — an employee should recognise any of these as potentially relating to personal-data rights and route them to the designated team without delay.
Under Rule 14, the organisation publishes the means by which rights may be exercised and any information the Data Principal needs to provide. Once a communication is routed to the designated team, that team applies the published process — asking the individual to use the formal channel and to provide any required identification. The employee's job is to recognise and route the communication. The formal process is not the employee's decision to bypass or replicate.
The rule employees should actually follow: if someone is asking about their own personal data — to see it, change it, delete it, or complain about how it's handled — route it to your organisation's designated contact (DPO, Grievance Officer, or Compliance Lead) immediately. Don't try to answer it yourself, even if you know the answer and even if it seems simple. Speed matters more than being the one who resolves it.
Why speed matters — and the 90-day grievance rule
Response timelines for different categories of Data Principal rights are set by the organisation as part of its published process. For grievances specifically, the DPDP Rules set a statutory maximum of 90 days for redressal. This 90-day cap applies to grievances only — not to all Data Principal rights, though this is often misreported. Prompt routing matters at every level: any delay in getting a request from an employee's inbox to the designated team eats into the time available for the organisation to respond.
What this looks like day to day
In practice, most employees will encounter this rarely — but when they do, the instinct to "just handle it" is the wrong one. A designated contact exists precisely because handling these requests correctly involves identity verification, legal exceptions, and documentation that a general employee isn't equipped to manage alone. This recognition-and-routing behaviour is one of the scenarios covered in Abhisam's DPDPA training for employees.
DPDPA Employee Training