Back to Rights of Data Principals

Exercise and Enforcement of Rights

How Data Principals exercise their rights under the DPDPA and the enforcement mechanisms available including complaints to the Board and penalties.

7 min read

How Rights Are Exercised

Rights under the DPDPA are exercised by making a request to the Data Fiduciary in the manner prescribed by the Rules. Data Fiduciaries must provide accessible mechanisms - including web-based portals - for receiving and processing such requests. Consent Managers may also facilitate the exercise of rights on behalf of Data Principals who have registered with them. This centralised approach can simplify rights management where an individual's data is held by multiple Data Fiduciaries.

Response Obligations and Timelines

Data Fiduciaries must respond to rights requests within the timeframes specified by the Rules. While Rule 14(3) references a 90-day window for the Fiduciary to publish and implement a grievance system (and as the outer limit for complex cases), the standard operational expectation is an acknowledgment within 7 days and a substantive response or resolution within 30 days. After 30 days of inaction or an unsatisfactory response, the Data Principal may escalate to the Board. Where a request is refused (e.g., on grounds of a legal exemption), the Data Fiduciary must communicate the reasons for refusal. The Data Principal may then escalate to the Board if unsatisfied with the response or the reasons provided.

Filing Complaints with the Board

Where internal grievance redressal is unsuccessful, the Data Principal may file a complaint with the Data Protection Board of India. The Board operates as a digital office and conducts proceedings in a technology-driven manner. The Board has the power to: (a) conduct inquiries following principles of natural justice; (b) summon and examine persons; (c) require production of documents; (d) direct remedial action; and (e) impose financial penalties. The Board's procedures are governed by Rules 17-21, which are already in force.

Duties of Data Principals

The DPDPA uniquely imposes duties on Data Principals alongside their rights. Under Section 15, Data Principals must: (a) comply with applicable laws when exercising rights; (b) not file false or frivolous complaints with the Board; (c) not furnish false particulars or impersonate another person; and (d) not suppress material information when filing complaints. Breach of these duties may attract penalties up to Rs 10,000 under the Schedule. This balances the rights framework by discouraging misuse of the complaint mechanism.

Penalties for Non-Compliance with Rights

The penalty schedule under Section 33 and the Schedule to the Act prescribes penalties for non-compliance with various provisions. Penalty caps are tied to the specific obligation breached: failure to take security safeguards (Section 8(5)) attracts up to Rs 250 crore, and failure to notify a personal data breach (Section 8(6)) up to Rs 200 crore. General non-compliance with Data Principal rights obligations (Sections 11-13) typically falls under the residual category of up to Rs 50 crore (Entry 7 of the Schedule). The Board considers factors including the nature, gravity, and duration of the non-compliance; the type and nature of personal data affected; repetitive nature of the default; and whether the Data Fiduciary has derived any gain from the non-compliance. Penalties are civil in nature - the DPDPA does not create criminal offences.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.