Back to Rights of Data Principals

Right to Grievance Redressal

The Data Principal's right to grievance redressal under the DPDPA - mechanism, timelines, and escalation to the Data Protection Board.

7 min read

The Right to Grievance Redressal

Section 13 of the DPDPA grants every Data Principal the right to have readily available means of grievance redressal provided by the Data Fiduciary in respect of any act or omission of the Data Fiduciary or Data Processor regarding the discharge of obligations or exercise of rights under the Act. This right is the primary enforcement mechanism available to Data Principals before escalation to the Data Protection Board. It ensures that organisations maintain accessible channels for addressing data protection concerns.

Grievance Mechanism Under Rule 14

Rule 14 of the DPDP Rules operationalises the grievance redressal right with specific requirements: (a) the Data Fiduciary must publish the contact details of a designated person responsible for addressing grievances; (b) a web-based mechanism must be provided for submitting grievances; (c) the designated person must acknowledge receipt of the grievance; and (d) the grievance must be resolved within 90 days from receipt. The response must be in a structured format with clear reasons. If the Data Fiduciary's response is unsatisfactory or no response is received within 90 days, the Data Principal may escalate to the Data Protection Board.

Escalation to the Data Protection Board

Where the Data Principal is not satisfied with the Data Fiduciary's response, or receives no response within the prescribed period, they may file a complaint with the Data Protection Board of India. The Board then initiates an inquiry into the complaint, following principles of natural justice. The Board has the power to: (a) direct the Data Fiduciary to take remedial action; (b) impose penalties for non-compliance; and (c) refer matters for further investigation. This two-tier mechanism - first internal grievance, then Board complaint - is designed to resolve disputes at the lowest possible level while ensuring effective recourse.

Practical Requirements for Organisations

Organisations must implement: (a) a dedicated web portal or form for grievance submission; (b) an internal process for triaging, investigating, and resolving grievances within 90 days; (c) a designated officer with sufficient authority and resources; (d) record-keeping of all grievances received and actions taken; and (e) a mechanism for communicating responses in a clear, structured format. The designated person should be senior enough to make binding decisions on behalf of the organisation. For Significant Data Fiduciaries, the Data Protection Officer may serve this role or supervise the grievance function.

Comparison with GDPR Approach

The GDPR does not prescribe a mandatory internal grievance mechanism with fixed timelines. Instead, it provides for the right to lodge a complaint directly with a Supervisory Authority (Article 77) and the right to an effective judicial remedy (Article 79). The DPDPA's approach of mandating internal resolution before Board escalation may reduce the burden on the Board but places significant operational requirements on Data Fiduciaries. The 90-day timeline is generous compared to the GDPR's one-month response period for data subject requests (extendable by two months). However, the DPDPA's timeline covers the entire resolution process, not merely an initial response.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.