Data Principal rights under the DPDP Act: sections 11 to 14
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 24 min read
What rights do individuals have under the DPDP Act?
The short answer
Once Chapter III of the Act is in force, it carries 4 rights, and section 6(4) carries a fifth that sits outside the chapter. Section 11 is the right to obtain a summary of your personal data and of the processing, the identities of all other Data Fiduciaries and Data Processors it was shared with, and a description of what was shared, except, under section 11(2), sharing on a written request with a Data Fiduciary authorised by law for the prevention, detection or investigation of offences or cyber incidents, or prosecution or punishment of offences. Section 12 is the right to correction, completion, updating and erasure, but under section 12(3) erasure yields where retention is necessary for the specified purpose or for compliance with law. Section 13 is the right to readily available grievance redressal from the Data Fiduciary or Consent Manager, which must be exhausted before approaching the Board. Section 14 is the right to nominate another individual to exercise the rights on death or incapacity. Section 6(4) is the right to withdraw consent at any time, with ease comparable to the ease with which it was given. Sections 11 to 15 and section 6(4) all sit in the 18 month commencement group of notification G.S.R. 843(E), so none of them binds anyone as at 29 September 2026. Sections 11 and 12 are written with a consent gate, and whether they reach processing on the section 7 legitimate uses other than clause (a) is unsettled.

The framework is usually written up from the company's side. This page is the other side of it: what the Digital Personal Data Protection Act, 2023 actually gives the individual it calls a Data Principal, what each right reaches, and the 3 separate ways the Act takes them away again. The most useful planning fact comes first, because almost no page on this topic states it: not one of these rights is in force today. If the framework itself is new to you, what DPDP is introduces the Act and the Rules first.
The 5 rights, and the date each one starts
Chapter III is titled "Rights and Duties of Data Principal" and holds 4 rights and 1 list of duties. A fifth right, the right to withdraw consent, sits in Chapter II instead, which is why a flat count of 4 does not describe what the Act gives you.
| Right | Provision | What it reaches | Commencement group |
|---|---|---|---|
| Access to a summary, and to who your data went to | Section 11 | Only a Data Fiduciary you previously gave consent to | 18 months |
| Correction, completion, updating, erasure | Section 12 | Only a Data Fiduciary you previously gave consent to | 18 months |
| Readily available grievance redressal | Section 13 | Any Data Fiduciary or Consent Manager, no consent gate | 18 months |
| Nomination on death or incapacity | Section 14 | No consent gate in its own words; section 14 names no fiduciary, and Rule 14(4) routes it through terms of service | 18 months |
| Withdrawal of consent | Section 6(4) | Wherever consent is the basis of the processing | 18 months |
| Duties, with a penalty behind them | Section 15 | The individual, when exercising rights and when providing personal data | 18 months |
Section 17 can remove every row in that table, and how it does so is set out below.
The grouping is not an editorial choice. Commencement notification G.S.R. 843(E) puts "sections 11 to 17" and "sub-sections (1) to (8) and (10) of section 6" in the same paragraph (c) group, due 18 months after publication. Rule 14, the rule that prescribes the request and nomination manner, sits in the Rule 1(4) group with the same period. Computed from the publication date printed on Gazette issue No. 757, that lands on 13 May 2027, which is interpretation until officially confirmed: the notification states a period rather than a date, it does not say how the period is counted, and the eGazette record of the same issue carries 14 November 2025 in its file code, which would move it by 1 day. The 1 day discrepancy is set out separately.
So on 26 August 2026 there is no enforceable right to demand a summary, no duty to erase on request and no grievance clock. What does exist is section 39, in force since 13 November 2025, which bars civil courts from any matter the Board is empowered over. The jurisdiction bar arrived before the rights it clears the way for, which is why you cannot sue under the DPDP Act and cannot yet complain to the Board either.
Section 11: a summary, and a list of everyone it went to
"The Data Principal shall have the right to obtain from the Data Fiduciary to whom she has previously given consent, including consent as referred to in clause (a) of section 7 (hereinafter referred to as the said Data Fiduciary), for processing of personal data, upon making to it a request in such manner as may be prescribed,—"
3 things can be asked for. A summary of the personal data being processed and of the processing activities. The identities of all other Data Fiduciaries and Data Processors the data was shared with, with a description of what was shared. And anything else prescribed by rules.
The second limb is the one worth reading closely, because it asks for more than most summaries of this right suggest. It is not a right to categories of recipient. Section 11(1)(b) says "the identities of all other Data Fiduciaries and Data Processors with whom the personal data has been shared", which on its face means named organisations, and Data Processors are named alongside Data Fiduciaries, so the vendors behind a product are inside the words rather than outside them. That has a build consequence for whoever has to answer: a policy document listing categories of partner does not satisfy a request phrased in the words of the section, and only a record of actual sharing does.
The third limb is currently empty. The notified Rules never mention section 11 at all, so nothing has been prescribed under section 11(1)(c), and on this site’s reading the request manner referred to in the opening words is supplied only by the generic route in Rule 14(2), which is an inference from 2 provisions read together, because Rule 14 names no section.
What section 11 does not give you is a file. There is exactly 1 machine readable entitlement in the whole framework and it is not this one: under Part B item 4(b) of the First Schedule, a Consent Manager must, on request and in accordance with its terms of service, make available in machine readable form the information in the record it keeps of your consents, of the notices that preceded them and of sharing with a transferee Data Fiduciary, and item 4(c) makes it keep that record for at least 7 years. That is a copy of your consent history, not a copy of your personal data. It is also the earlier of the 2 dates: the First Schedule operates with Rule 4, which Rule 1(3) puts in the 1 year group, computed at 13 November 2026 and interpretation until officially confirmed, so that obligation becomes capable of applying roughly 6 months before section 11 does, though it binds a registered Consent Manager, and none can be registered yet, because Rule 4 carries the registration procedure and sits in the same 1 year group as section 6(9), which is the registration duty itself. Both readings of a Schedule's start date are this site's, because the commencement instruments name sections and rules and never Schedules.
Section 11(2) then removes the recipient list, and only the recipient list, in 1 defined case: sharing with another Data Fiduciary authorised by law to obtain the data, on a request made in writing, for prevention, detection or investigation of offences or cyber incidents, or for prosecution or punishment of offences. The boundary is narrower than "law enforcement" as usually paraphrased, because all 3 elements have to be present. The summary in section 11(1)(a) is untouched by it.
Section 12: correct it, complete it, update it, erase it
Section 12(1) is 1 right with 4 verbs, and it carries a qualifier that is easy to read past: the right is exercisable "in accordance with any requirement or procedure under any law for the time being in force". Where another statute already prescribes how a particular record is corrected, that procedure governs.
The duty to erase has 2 named limits and no third:
"A Data Principal shall make a request in such manner as may be prescribed to the Data Fiduciary for erasure of her personal data, and upon receipt of such a request, the Data Fiduciary shall erase her personal data unless retention of the same is necessary for the specified purpose or for compliance with any law for the time being in force."
A bank keeping identity records that a banking law requires is the standard case of the second limit. The first limit does more work than it looks like it does: while the specified purpose is still live, retention necessary for that purpose defeats the request, so an erasure request made during an active service relationship is answered by the purpose rather than by the request.
There is a separate route to erasure that nobody has to ask for. Under Rule 8 with the Third Schedule, an ecommerce entity with at least 2 crore registered users in India, an online gaming intermediary with at least 50 lakh and a social media intermediary with at least 2 crore must erase after 3 years in which the individual neither approached them for the specified purpose nor exercised her rights, running from the later of that last contact and the commencement of the Rules, and unless retention is necessary for compliance with any law in force. Rule 8(2) requires at least 48 hours notice first. Each Third Schedule row excepts the data needed to let her reach her user account and any stored virtual token, so this is not account deletion. Rule 8 is itself in the Rule 1(4) group and starts when the rights do. The retention mechanics are set out in full separately.
Section 13: the grievance channel comes before the Board
Section 13(1) gives a right to readily available means of grievance redressal from a Data Fiduciary or Consent Manager, covering any act or omission about its data obligations or about the exercise of rights. Section 13(3) then fixes the order: exhaust that channel before approaching the Data Protection Board.
Unlike sections 11 and 12, this right carries no consent gate in its own words. Section 13(2) leaves the response period to be prescribed, and the sub rule that was meant to prescribe it reaches the Gazette missing its object, which is covered where it belongs, in what Rule 14(3) says about 90 days.
Section 14: nomination, and why it has no analogue
"A Data Principal shall have the right to nominate, in such manner as may be prescribed, any other individual, who shall, in the event of death or incapacity of the Data Principal, exercise the rights of the Data Principal in accordance with the provisions of this Act and the rules made thereunder."
This is the distinctive provision in the Indian framework, and it is the one competitor summaries reduce to a line. Section 14(2) defines incapacity narrowly, as inability to exercise the rights due to unsoundness of mind or infirmity of body, so it is not a general power of attorney and does not turn on age or absence. What the nominated person gets is the exercise of the rights, not the data. Note the word: "nominee" appears 0 times in the Act and 0 times in the Rules. The Act gives a right to nominate and never names the person nominated, so the widely used phrase "digital nominee" is borrowed vocabulary rather than a term of this framework.
Rule 14(4) supplies the manner and adds a condition the Act does not contain: nomination happens "in accordance with the terms of service of the Data Fiduciary and such law as may be applicable", using the means and particulars that the fiduciary requires. 1 or more individuals may be nominated. So the practical availability of this right runs through a product surface that today, before commencement, essentially no Indian service exposes, and through terms of service the individual does not write.
Three further claims made about this right are not in the framework at all, and each is worth checking against the text rather than against a summary.
Nothing passes to legal heirs. The words "heir" and "heirs" appear 0 times in the Act and 0 times in the Rules. Section 14 confers a power to nominate and stops: it sets out no default, no order of priority and no fallback. That a Data Principal who nominates nobody leaves the Act silent on who may exercise her rights, rather than leaving them to pass to a relative, is our reading of that silence and not a rule. Whether general succession law reaches a statutory right of this kind sits outside this framework, and we hold no official source on it, so this site does not answer it.
A search for the answer will find the wrong provision. "Succession" does appear in the Act, exactly once, and it has nothing to do with inheritance: section 18(2) gives the Data Protection Board "perpetual succession and a common seal" as a body corporate.
No certificate is prescribed. No court letter, medical certificate, death certificate or probate is required anywhere for making or acting on a nomination. "Certificate" does appear in the Rules, but only in the State subsidy and licence provisions and in the Board members' medical assistance entitlements. Section 14(2) defines incapacity by its 2 causes and prescribes no way of proving either.
One consequence of the Rule 14(4) delegation deserves stating plainly, because it decides how much work this right takes: there is no single nomination and no central register. Nothing done at 1 company reaches another, so when section 14 commences a person has to nominate separately with every bank, insurer, hospital and platform holding data that would matter, in whatever way each chooses to offer, and keep it current as accounts change. Where a company offers no route at all, the provision to point at is Rule 14(1), which requires every Data Fiduciary to publish prominently the means of making a rights request and the particulars needed to identify the person making it.
2 of the 4 rights only reach a company you consented to
Sections 11 and 12 both open with a consent gate, in different words. Section 11(1) gates on the recipient of the request, "the Data Fiduciary to whom she has previously given consent, including consent as referred to in clause (a) of section 7". Section 12(1) gates on the processing instead, "her personal data for the processing of which she has previously given consent, including consent as referred to in clause (a) of section 7". Rule 14(2) uses the section 11 form for the request route. Sections 13 and 14 carry no such words.
Section 7 is why this matters rather than being a technicality. It lists 9 legitimate uses that permit processing without consent, and only clause (a), data you voluntarily provided for a specified purpose and in respect of which you did not indicate that you do not consent, is written back into sections 11 and 12. The other 8, which include an employer processing for employment purposes and compliance with a judgment or order, are not. Clause (b) is the exception inside the exception: its own sub clause (i) applies where she "has previously consented to the processing of her personal data by the State or any of its instrumentalities" for a subsidy, benefit, service, certificate, licence or permit, so processing on that limb may satisfy the section 11 gate on its own terms. For the rest, whether the access and correction rights reach the processing at all is unsettled: nothing in the Act says they do not, and nothing supplies the consent that the opening words of both sections require. This site reads the gate as written and treats the question as open until the Board or a court decides it.
The Rules point the other way on this, and the point is worth stating against our own reading. The Second Schedule, which applies to State processing under section 7(b), requires the fiduciary to specify, in an intimation given to the individual, the means "using which such Data Principal may exercise her rights under the Act". That assumes there are rights to exercise, and because clause (b)(i) is already consent preceded, the assumption bites on clause (b)(ii). Weigh it carefully rather than treating it as decisive: the same formula appears in Rule 3(c)(ii) for ordinary consent based notices, so it may be drafting boilerplate rather than a considered statement about non consent processing. It names no section either, so it does not settle which rights, and the question stays open. What section 7 does and does not allow is covered separately.
Where all 4 rights disappear
3 different mechanisms remove Chapter III, and only 1 of them is widely reported.
Section 17(1) removes the whole chapter in 6 situations. Its opening words name Chapter III expressly, alongside Chapter II, except sections 8(1) and 8(5) which survive, and section 16. The 6 cases follow in clauses (a) to (f): processing necessary for enforcing any legal right or claim; processing by a court or tribunal or other body entrusted by law with a judicial, quasi judicial, regulatory or supervisory function, where the processing is necessary for the performance of that function; processing in the interest of prevention, detection, investigation or prosecution of any offence or contravention of any law in force in India; processing of data of individuals outside India, by a person based in India, under a contract with a person outside India; a court approved merger, demerger or reconstruction; and ascertaining the financial information, assets and liabilities of a loan defaulter. Read the first and last of those against a real dispute. Where processing is necessary for enforcing a legal claim, or where someone is ascertaining the assets and liabilities of a person who defaulted on a loan or advance from a financial institution, and that processing accords with the disclosure provisions of any other law as clause (f) requires, there is no section 11 right, no section 12 right, no section 13 grievance right and no section 14 nomination right in respect of that processing. Clause (c) is one of the provisions a writ petition filed in 2026 asks the Supreme Court to declare ultra vires, which is a pleading and not a ruling.
Section 17(3) allows the access right to be switched off by notification. It permits the Central Government, "having regard to the volume and nature of personal data processed", to notify Data Fiduciaries or classes of them, "including startups", to whom sections 5, 8(3), 8(7), 10 and 11 shall not apply. Section 11 is named in the list. No notification under it had been traced as at 26 August 2026, on a check of the archived official sources and a search of the public record on that date, and section 17(3) does not itself commence until the 18 month group. The power exists all the same, and the coverage of section 17(3) as a startup exemption rarely mentions that the right of access is inside it.
Section 17(4) takes the erasure duty off the State entirely.
"In respect of processing by the State or any instrumentality of the State, the provisions of sub-section (7) of section 8 and sub-section (3) of section 12 and, where such processing is for a purpose that does not include making of a decision that affects the Data Principal, sub-section (2) of section 12 shall not apply."
Section 12(3) is the erasure request and the duty to erase. Section 12(2) is the duty to correct, complete and update. For processing by the State, the first never applies, and the second stops applying wherever the purpose does not include making a decision that affects you. The same sub section also disapplies section 8(7), the general duty to erase on withdrawal or once the specified purpose is no longer served, so both routes to erasure against the State close together. Section 12(1), which confers the right, is not itself disapplied. This site reads the result as a right left without the machinery that answers it rather than as an express removal of the right, which is an inference from 2 provisions read together and not a statement printed in either. Section 17 in full, including sub sections 17(2) and 17(5), is worth reading before relying on any right in this chapter.
The duties, and the Rs 10,000 behind them
Section 15 attaches 5 duties to the individual: comply with applicable laws while exercising rights under the Act, do not impersonate another person when providing your personal data for a specified purpose, do not suppress material information when providing personal data for a document, unique identifier, proof of identity or proof of address issued by the State, do not register a false or frivolous grievance or complaint with a Data Fiduciary or the Board, and furnish only verifiably authentic information when exercising the right to correction or erasure.
These are not advisory. Entry 5 of the Schedule to the Act sets the penalty for "Breach in observance of the duties under section 15" at an amount which "May extend to ten thousand rupees", imposable by the Board under section 33(1) only where it determines on conclusion of an inquiry that the breach is significant, and only after an opportunity of being heard. It is the only entry that names a Data Principal duty, and at Rs 10,000 against the Rs 250 crore top entry it is smaller by a factor of 250,000. Like the rights themselves, sections 15, 28 and 33 are all in the 18 month group, so the exposure begins when the rights do. How the Board sizes any penalty is set out separately.
The complaint itself cannot be signed away. The Act illustrates it: an individual buying an insurance policy consents both to the processing needed to issue the policy and to waiving her right to file a complaint to the Board, and section 6(2) makes the waiver invalid while leaving the rest of the consent standing.
What the notified rule changed from the draft
Rule 14 is the only rule that prescribes what Chapter III leaves to be prescribed, though Rule 3(c)(ii), Rule 9 and Second Schedule item (g)(ii) also touch how rights are exercised, and section 5(1)(ii) does the same at Act level. Setting it against draft rule 13 of the draft Rules of 3 January 2025, G.S.R. 02(E), shows 6 changes. The draft is superseded text, quoted only as evidence of what moved, and what the movement means is this site's reading rather than anything either instrument states.
| In the draft rule | In the notified rule | What changed |
|---|---|---|
| Draft rule 13(2) opened "To exercise the rights of the Data Principal under the Act to access information about personal data and its erasure" | Rule 14(2) opens "To exercise the rights of the Data Principal under the Act" | The request route was written for 2 named rights and now carries no such limit |
| Draft rule 13(4) opened "To exercise the rights of the Data Principal under the Act to nominate" | Rule 14(4) drops the words "to nominate" | The same words removed from the nomination route |
| Draft rule 13(1) and 13(3) required the fiduciary to "publish" | Rule 14(1) and 14(3) require it to "prominently publish" | Visibility became part of the duty |
| Draft rule 13(5) defined an identifier by reference to a customer identification file number, customer acquisition form number, application reference number, enrolment ID or licence number | Rule 14(5) adds "email address, mobile number" to that list | The particulars a fiduciary may require before answering a request were widened |
| Draft rules 13(2) and 13(4) referred to particulars "published by" the fiduciary | Rule 14(2) and 14(4) refer to particulars "required by" the fiduciary | What the individual must furnish is no longer tied to what was published |
| Draft rule 13(3) read "publish ... the period under its grievance redressal system" | Rule 14(3) reads "prominently publish ... within a reasonable period not exceeding ninety days under its grievance redressal system" | The words "not exceeding ninety days" arrived and the object went, so what they cap is no longer stated |
The first 2 rows are the useful ones. Both draft sub rules named the specific right they served, and neither notified sub rule names any, so 1 request mechanic now carries every right in the chapter. What did not change is the consent gate sitting in the middle of the same sentence: the request still goes "to the Data Fiduciary to whom she has previously given consent". Worth noting that Rule 14(2) stops there, where section 11(1) continues "including consent as referred to in clause (a) of section 7". Section 40(1) allows rules "not inconsistent with the provisions of this Act", and section 40(2)(m) is the rule making entry Rule 14(2) answers, the manner of a request under section 11(1), so this site reads the omission as shorthand rather than as a limit. That is our reading; neither instrument says which it is.
What the framework never gives you
| Claim in circulation | What the text actually supports |
|---|---|
| DPDP gives a right to data portability | "Portability" appears 0 times in the Act and 0 times in the Rules. Section 11 gives a summary and a recipient list, not an export. The single machine readable entitlement in the framework is Part B item 4(b) of the First Schedule, and it runs against a Consent Manager, for the record of your consents rather than for your personal data |
| DPDP gives a right to be forgotten | The phrase appears nowhere. Section 12(3) gives an erasure right defeated by 2 named limits, retention necessary for the specified purpose and retention necessary for compliance with any law in force |
| DPDP gives a right to object to processing, or to restrict it | Neither exists as a right. The nearest things are section 6(4) withdrawal, which works only where consent is the basis, and the limb inside section 7(a) that turns off that legitimate use where the individual has indicated she does not consent |
| DPDP gives rights against automated decisions or profiling | "Profiling" appears 0 times in the Act. "Automated" appears 3 times and every one is inside a definition, of "automated", of "data" and of "processing". No automated decision right is conferred on the individual. The subject is not absent from the Act: section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children, subject to exemptions, including those Rule 12 and the Fourth Schedule set for listed classes and purposes on their conditions, and section 8(3) attaches an accuracy duty where data is likely to be used for a decision that affects you. Both are duties in Chapter II, not rights in Chapter III |
| A company must answer a rights request within 30 days | No period is fixed for section 11 or section 12 anywhere in the Act or the Rules. Rule 14(3) is the only place a period appears in the rights and grievance rules, 90 days, and the printed sentence has no object for "publish", so what the 90 days caps has to be read from the rest of the sub rule; on this site's reading it caps the response period the fiduciary must publish |
| Exercising a right is free | The Act and the Rules say nothing either way, prescribing neither a fee nor a prohibition on charging one. The only fee named in the framework for an individual is the appeal fee under section 29(2) with Rule 22(2) |
| You can go straight to the Board | Section 13(3) requires the grievance channel to be exhausted first, and section 39 bars civil courts from matters the Board is empowered over |
| The rights apply to any company holding your data | Sections 11 and 12 are written with a consent gate, including consent under section 7(a). Whether they reach processing on the other legitimate uses is unsettled, and the reading on this page is this site's |
| The rights are in force, because the Act commenced in November 2025 | G.S.R. 843(E) brought sections 1(2) and 2, sections 18 to 26, sections 35 and 38 to 43, and section 44(1) and (3) into force on 13 November 2025. Sections 11 to 17 are in paragraph (c), the 18 month group |
What to do before the 18 month date
If you are an individual, the honest answer is that there is nothing to enforce before the 18 month date, computed as 13 May 2027 and interpretation until officially confirmed, and any service answering a DPDP rights request today is doing it voluntarily. That is still worth doing, because a voluntary answer tells you what a company can actually produce. The rights assistant walks each pathway and names the provision behind it, and the individuals section lists the rights against their official headings and commencement status.
If you are on the receiving side, 3 things are worth building before the date rather than after it, ordered by how hard they are to retrofit. A record of actual sharing, because section 11(1)(b) asks for identities rather than categories and no policy document can answer it. A published request route under Rule 14(1), which must be prominent and must state the means and the identifying particulars, if any, that you will ask for. And a nomination surface under Rule 14(4), which is the one requirement here with no analogue in any framework your vendors have implemented before. The company plan sequences these against the rest of the framework.
The individuals section →Section 11, official text →Section 12, official text →Grievance redressal: what Rule 14(3) says about 90 days →Section 17 exemptions →