DPDP data principal rights are the practical core of India’s Digital Personal Data Protection Act, 2023, because they decide what an ordinary person can ask of your organization and what you must do when they ask. Businesses that collect personal data from people in India, whether they are based there or serve the market from abroad, will need a working process for these requests before the main obligations start.
This guide explains the rights, who they apply to, how the DPDP Rules 2025 shape the response, what the timeline looks like and how to build a workflow that can be evidenced. It is written for privacy, legal and operations teams. The rules have phased dates and may be amended, so confirm current text and commencement dates with official sources and counsel before you rely on any date here.
Free gap assessment
Could you demonstrate GDPR compliance today?
Score yourself against what a supervisory authority actually asks for, free — the records, not the policy.
Run the free GDPR gap assessment → or View premium report sample
What DPDP data principal rights are
In the DPDP Act, the individual whose personal data is processed is the data principal, and the organization that decides how and why to process it is the data fiduciary. The Act gives data principals a set of rights and gives fiduciaries duties to honor them. The rights include access to information about the personal data processed, correction and erasure, grievance redressal and the right to nominate another person to exercise rights in the event of death or incapacity.
The DPDP Rules, 2025 were notified on 13 or 14 November 2025, depending on how sources date the gazette publication, and they describe procedures for exercising these rights. A government summary of the Rules lists access, correction, updating, erasure in certain situations, withdrawal of consent and nomination. For the wider legal picture, see our overview of the DPDP Act and the guide to the DPDP Rules 2025.
When do these obligations apply?
The Rules phase in from their notification. Commentary confirms that the provisions on consent manager registration start one year after publication, in November 2026, and that most of the remaining rules, including those on notices, security, breach notification and data principal rights, start eighteen months after publication, in May 2027. The Ministry of Electronics and Information Technology consulted on shortening the timeline in early 2026, but a summary published in August 2026 reports that no compression has been notified. Confirm the position again before you finalize your plan.
Even with a May 2027 date, preparation takes time. Searching systems, mapping data and building a verified process can take many months, so start now.
How to respond: the 90-day window
According to the government summary of the Rules, data fiduciaries have a maximum of 90 days to respond to requests relating to access, correction, updating or erasure. Treat that as an outer limit and aim for much faster handling, because slow responses generate grievances and complaints. Confirm the exact wording in the Rules text and build your internal target, such as 30 days, inside the legal limit.
A response should be accurate, in plain language and complete. If you cannot fulfil a request, for example because the law requires you to retain the data, explain the reason. Keep a record of every request, how you verified the individual, what you did and when.
| Right | What the individual can do | What the data fiduciary should prepare |
|---|---|---|
| Access | Obtain a summary of personal data processed and the processing activities | Search process, response template |
| Correction and updating | Ask for inaccurate or incomplete data to be corrected or updated | Correction workflow, propagation to processors |
| Erasure | Ask for erasure in certain situations | Retention rules, exceptions, deletion procedure |
| Consent withdrawal | Withdraw consent as easily as it was given | Withdrawal channel, stop-processing steps |
| Grievance redressal | Raise a grievance with the fiduciary first | Grievance officer contact, tracker, response timeline |
| Nomination | Nominate another person to exercise rights in case of death or incapacity | Nomination form and verification |
Verification and scope of each right
Verify identity in proportion to the risk, using data you already hold where you can. For access requests, prepare a summary of the personal data processed, the processing activities and the identities of other fiduciaries and processors with whom data is shared, where the Act requires it. For correction, update records and tell processors and recipients who hold the data. For erasure, delete unless retention is required for a specified purpose or by law, and instruct processors to delete as well.
Consent withdrawal must be as easy as giving consent. If a person gave consent with one click, do not require a letter to withdraw it. See our guide on the DPDP consent manager for how managed consent platforms may interact with these rights.
Children and significant data fiduciaries
Extra duties apply for children’s data, where verifiable parental consent is required; see verifiable parental consent. Larger or riskier organizations can be designated as significant data fiduciaries with additional duties, such as a data protection officer and audits; read about a significant data fiduciary. If you fall in either group, your rights workflow needs additional checks.
A workflow for DPDP data principal rights
A dependable process has clear steps. Adjust them to your systems and staff.
- Provide easy channels: web form, email and in-product options
- Log every request with an ID, date and type
- Acknowledge receipt and explain next steps
- Verify identity proportionately
- Search all systems and processors
- Decide, document and respond within your internal target
- Propagate corrections or deletions to processors
- Record the outcome and handle grievances through the named contact
Breaches, penalties and how rights connect
Rights handling sits alongside other obligations. Breach notification must reach affected individuals in plain language with contact details; see DPDP breach notification. Penalties under the Act can be large, with reported ceilings up to ₹250 crore for failures to maintain security safeguards; read DPDP penalties for the structure. Comparing with other regimes can also help: DPDP vs GDPR and DPDP Act vs GDPR explain the differences in rights and duties.
Templates for rights handling
Request forms, acknowledgment letters, verification checklists, response templates, grievance logs and nomination forms are the working documents. The DPDP Act Toolkit includes editable versions for these, so you can get a consistent process in place quickly and then adapt it to your systems.
For a reference summary of the Rules, see the Government of India press information on the DPDP Rules, 2025. Keep your documentation aligned to the official text, and test the process with mock requests before the obligations start.
Preparing your systems for DPDP data principal rights
The hardest part of rights handling is finding the data. Start with a data map that lists each system holding personal data, the categories stored, the owner, the processors involved and the retention period. Add a way to search by identifier, such as email address or customer ID, across those systems. Where search is manual, write a short runbook for each system and test it on a dummy record. For deletion, decide how backups, logs and analytics copies will be treated and document the rule, because these are the places where data survives by accident.
Give your support team a short script and escalation path. Most requests will arrive as a support ticket or an email, and staff must recognize them and route them on the same day. Track the time from receipt to closure for each request and report the figures monthly. The numbers will show whether the process is ready for the DPDP data principal rights obligations before the main commencement date arrives.
Processors and vendors
Data fiduciaries remain responsible when a processor holds the data. Update contracts to require processors to assist with requests, act on correction and deletion instructions within a set time and confirm completion in writing. Keep a register of processors with contacts, systems and the types of data handled. During vendor reviews, ask how the vendor would respond to a deletion request, and keep the answer with your due diligence record.
Governance and reporting
Assign an executive owner for rights handling and review the metrics each quarter: volumes by type, median response time, requests escalated, grievances received and outcomes. Use the results to refine the process and to brief leadership on readiness. A documented review cycle is also the best evidence that your organization takes the obligations seriously, and that the process will keep working as the business and its systems change.
Why DPDP data principal rights deserve early attention
Rights handling touches every system, every vendor and every customer-facing team, so it takes longer than most compliance tasks. Starting early turns DPDP data principal rights from a scramble into a routine, and gives your team time to test and improve.
Common mistakes with DPDP data principal rights
Organizations often plan only for requests that arrive through a web form and forget requests to customer support. They do not tell processors to act. They set internal targets that are longer than the legal limit. They collect extra identity documents to verify. And they leave the grievance process to a generic mailbox. Test every channel, assign an owner and audit a sample of requests each quarter.
DPDP Data Principal Rights FAQ
What rights do data principals have?
The Act and Rules provide rights to information or access, correction and updating, erasure in certain situations, withdrawal of consent, grievance redressal and nomination.
How long does a fiduciary have to respond?
A government summary of the Rules gives a maximum of 90 days for access, correction, updating and erasure requests. Check the exact text and aim for faster handling.
When do the rights provisions start?
Commentary places most obligations at eighteen months after notification, in May 2027, with consent manager provisions starting in November 2026. Confirm current dates.
Does DPDP apply to foreign companies?
The Act can apply to processing outside India in connection with offering goods or services to people in India. Get legal advice on your situation.
Who handles grievances?
The fiduciary must provide a grievance mechanism and contact details. Individuals generally must raise a grievance with the fiduciary before approaching the Data Protection Board.