DPDP Audits

DPDP Data Principal Rights: Access, Correction, Erasure and Grievances

The rights DPDP gives individuals, what Data Fiduciaries must set up to honour requests, where request handling usually fails, and the duties of Data Principals.

By Ram Krishan Dudeja, CISA CAIIB · Last reviewed 4 October 2026

The DPDP Act 2023 gives every individual whose data is processed, called a Data Principal, a set of rights. Data Fiduciaries must be able to honour them through a published process, and an auditor will test that the process actually works.

The rights of a Data Principal

RightWhat it meansAct
Access to informationA summary of the personal data processed, the processing activities, and the identities of other Fiduciaries and Processors it has been shared withSection 11
Correction and completionCorrect inaccurate data and complete incomplete dataSection 12
ErasureErasure of personal data that is no longer needed for its purpose or legally required retentionSection 12
Grievance redressalA readily available way to raise a grievance, before approaching the BoardSection 13
NominationNominate another person to exercise these rights on death or incapacitySection 14
Withdraw consentWithdraw at any time, as easily as it was givenSection 6

What Data Fiduciaries must put in place

Where requests usually fail

Duties of a Data Principal

The Act also places duties on individuals: comply with applicable laws, do not impersonate another person, do not suppress material information when providing data for official documents, do not file false or frivolous grievances, and furnish only verifiable and authentic information when exercising rights. Breach of these duties can attract a penalty of up to ₹10,000.

Test your request process against the DPDP audit checklist, and see DPDP Rules 2025 explained for timelines.

Frequently asked questions

What rights does a Data Principal have under the DPDP Act?

Access to information about their data, correction and completion, erasure, grievance redressal, nomination of another person to exercise rights, and withdrawal of consent at any time.

Is there a right to data portability under the DPDP Act?

No. Unlike GDPR, the DPDP Act does not include a right to data portability.

Does a Data Principal have any duties under the DPDP Act?

Yes. They include not impersonating another person, not suppressing material information, not filing false or frivolous grievances, and furnishing only verifiable and authentic information. Breach can attract a penalty of up to ₹10,000.

What must a company have in place to handle Data Principal requests?

A published request channel, a way to verify identity, a log tracking each request to closure, timelines that meet the Rules, propagation of corrections and erasure to processors, and a grievance redressal mechanism.

Need an independent DPDP audit?

67 controls, auditor-signed findings, and a remediation roadmap you can act on.

Book a Free Consultation

Related guides

This guide is general information, not legal advice. Refer to the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 as notified for the authoritative text.