Back to Rights of Data Principals

Right to Access Information

A detailed analysis of the Data Principal's right to access information about their personal data processing under Section 11 of the DPDPA.

7 min read

Statutory Basis - Section 11

Section 11 of the DPDPA grants every Data Principal the right to obtain from the Data Fiduciary a summary of their personal data that is being processed and the processing activities undertaken with respect to such data. This right is foundational to the entire rights framework - without knowing what data is held and how it is used, a Data Principal cannot meaningfully exercise other rights such as correction, erasure, or consent withdrawal. The right is not absolute; it is subject to reasonable limitations prescribed by the Rules and the general exemptions under Section 17. The Data Fiduciary must respond within the timeframe specified in the Rules.

Scope of Information Available

The summary that must be provided includes: (a) the categories of personal data being processed; (b) the purposes for which the data is being processed; (c) the identities of all Data Fiduciaries and Data Processors with whom the personal data has been shared; and (d) any other information as may be prescribed by the Rules. This is notably narrower than the GDPR's right of access under Article 15, which also requires information about retention periods, the source of data, and the existence of automated decision-making. The DPDPA focuses on a 'summary' rather than a copy of the actual data.

How the Right Is Exercised

The Data Principal exercises this right by making a request to the Data Fiduciary in the manner prescribed by the Rules. Under Rule 14, Data Fiduciaries must provide a web-based mechanism for receiving such requests. The Data Fiduciary must process the request and provide the information within the prescribed timeline. The request can be made through a Consent Manager if the Data Principal has engaged one. The Data Fiduciary is not required to provide information that would reveal trade secrets or intellectual property.

Obligations on Data Fiduciaries

Upon receiving an access request, the Data Fiduciary must: (a) verify the identity of the Data Principal; (b) collate the relevant information from its records and those of its Data Processors; (c) provide the summary in a clear and accessible format; and (d) respond within the prescribed timeframe. Failure to comply with a valid access request can result in complaints to the Data Protection Board and potential penalties. The Board may direct the Data Fiduciary to provide the requested information and impose penalties for non-compliance.

Comparison with GDPR Article 15

The GDPR's right of access is broader in several respects. Under Article 15, data subjects can obtain a copy of their personal data (not merely a summary), information about retention periods, the right to lodge a complaint, the source of data if not collected directly, and information about automated decision-making including profiling. The GDPR also requires the information to be provided in a commonly used electronic format if requested. The DPDPA's approach is deliberately simpler, focusing on enabling Data Principals to understand the broad contours of processing rather than providing granular data exports. This may reduce the compliance burden on Data Fiduciaries but also limits the Data Principal's ability to verify specific data points.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.