Back to Rights of Data Principals

Exercise and Enforcement of Rights

How Data Principals exercise their rights under the DPDPA and the enforcement mechanisms available including complaints to the Board and penalties.

7 min read

How Rights Are Exercised

Rights under the DPDPA are exercised by making a request to the Data Fiduciary in the manner prescribed by the Rules. Data Fiduciaries must provide accessible mechanisms - including web-based portals - for receiving and processing such requests. Consent Managers may also facilitate the exercise of rights on behalf of Data Principals who have registered with them. This centralised approach can simplify rights management where an individual's data is held by multiple Data Fiduciaries.

Response Obligations and Timelines

For grievances specifically, Rule 14(3) requires the Data Fiduciary to publish the time period, not exceeding 90 days, within which it will ordinarily respond. This is a cap on the response period the Data Fiduciary itself publishes, not a general statutory deadline for every rights request and not an outer limit reserved for complex cases. As practice guidance rather than a rule-based standard, some organisations aim for an acknowledgment within around 7 days and a substantive response within around 30 days; these figures are not sourced to the Act or the Rules and should not be treated as the operative legal standard. Where a response is not received within the Data Fiduciary's published period, or the response is unsatisfactory, the Data Principal may escalate to the Board. Where a request is refused (e.g., on grounds of a legal exemption), the Data Fiduciary must communicate the reasons for refusal. The Data Principal may then escalate to the Board if unsatisfied with the response or the reasons provided.

Filing Complaints with the Board

Where internal grievance redressal is unsuccessful, the Data Principal may file a complaint with the Data Protection Board of India. The Board operates as a digital office and conducts proceedings in a technology-driven manner. The Board has the power to: (a) conduct inquiries following principles of natural justice; (b) summon and examine persons; (c) require production of documents; (d) direct remedial action; and (e) impose financial penalties. The Board's procedures are governed by Rules 17-21, which are already in force.

Duties of Data Principals

The DPDPA uniquely imposes duties on Data Principals alongside their rights. Under Section 15, Data Principals must: (a) comply with applicable laws when exercising rights; (b) not file false or frivolous complaints with the Board; (c) not furnish false particulars or impersonate another person; and (d) not suppress material information when filing complaints. Breach of these duties may attract penalties up to Rs 10,000 under the Schedule. This balances the rights framework by discouraging misuse of the complaint mechanism.

Penalties for Non-Compliance with Rights

The penalty schedule under Section 33 and the Schedule to the Act prescribes penalties for non-compliance with various provisions. Penalty caps are tied to the specific obligation breached: failure to take security safeguards (Section 8(5)) attracts up to Rs 250 crore, and failure to notify a personal data breach (Section 8(6)) up to Rs 200 crore. General non-compliance with Data Principal rights obligations (Sections 11-13) typically falls under the residual category of up to Rs 50 crore (Entry 7 of the Schedule). The Board considers factors including the nature, gravity, and duration of the non-compliance; the type and nature of personal data affected; repetitive nature of the default; and whether the Data Fiduciary has derived any gain from the non-compliance. Penalties are civil in nature - the DPDPA does not create criminal offences.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.