Tool · For individuals
Check your rights over your personal data, and when they start
Pick what you want to do and see what the framework gives you, the steps to take, and the exact official provisions behind each one. This page is for individuals; the company compliance tools live separately.
Timing note: the rights sections of the Act (sections 11 to 14) are in the group due 18 months after the publication of commencement notification G.S.R. 843(E), and the request machinery in Rule 14 is in the matching Rules group (both computed as 13 May 2027, interpretation until confirmed). See the timeline for the current verified position.
What information does an organisation have about me?
From a Data Fiduciary you previously gave consent to, you can obtain a summary of your personal data and the processing activities, plus the identities of the other Data Fiduciaries and Data Processors it shared your data with and a description of what was shared. Sharing with authorities for offence prevention and similar purposes is carved out.
Steps
- Find the organisation's published means for rights requests on its website or app.
- Make the request using those means, giving the identifiers its terms of service require, such as your username.
- If the response does not come or does not satisfy you, use the grievance channel below before approaching the Board.
Your duties when exercising rights. The Act also places duties on you when exercising rights: comply with applicable laws, do not impersonate anyone, do not suppress material information when providing your personal data for any document, unique identifier, proof of identity or proof of address issued by the State or its instrumentalities, do not file false or frivolous grievances or complaints, and furnish only verifiably authentic information for correction or erasure.
The provisions this tool rests on
The provisions below are the sources for the legal statements on this page. Each links to the official document it was verified against, and to the provision on this site wherever this site publishes that provision. The label says whether the site is reporting a requirement, explaining it, reading it, recommending something, or pointing at a text it does not restate.
DPDP Act 2023, s. 11
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(1) The Data Principal shall have the right to obtain from the Data Fiduciary to whom she has previously given consent, including consent as referred to in clause (a) of section 7 (hereinafter referred to as the said Data Fiduciary), for processing of personal data, upon making to it a request in such manner as may be prescribed,— (a) a summary of personal data which is being processed by such Data Fiduciary and the processing activities undertaken by that Data Fiduciary with respect to such personal data; (b) the identities of all other Data Fiduciaries and Data Processors with whom the personal data has been shared by such Data Fiduciary, along with a description of the personal data so shared; and (c) any other information related to the personal data of such Data Principal and its processing, as may be prescribed. (2) Nothing contained in clause (b) or clause (c) of sub-section (1) shall apply in respect of the sharing of any personal data by the said Data Fiduciary with any other Data Fiduciary authorised by law to obtain such personal data, where such sharing is pursuant to a request made in writing by such other Data Fiduciary for the purpose of prevention or detection or investigation of offences or cyber incidents, or for prosecution or punishment of offences.
DPDP Rules 2025, r. 14, (1)
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(1) For enabling Data Principals to exercise their rights under the Act, the Data Fiduciary and, where applicable, the Consent Manager, shall prominently publish on its website or app, or both, as the case may be, — (a) the details of the means using which a Data Principal may make a request for the exercise of such rights; and (b) the particulars, if any, such as the username or other identifier of such a Data Principal, which may be required to identify her under its terms of service.
Rule 14 on this site Official source ↗ Also on MeitY (byte identical) ↗
DPDP Act 2023, s. 12
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(1) A Data Principal shall have the right to correction, completion, updating and erasure of her personal data for the processing of which she has previously given consent, including consent as referred to in clause (a) of section 7, in accordance with any requirement or procedure under any law for the time being in force. (2) A Data Fiduciary shall, upon receiving a request for correction, completion or updating from a Data Principal,— (a) correct the inaccurate or misleading personal data; (b) complete the incomplete personal data; and (c) update the personal data. (3) A Data Principal shall make a request in such manner as may be prescribed to the Data Fiduciary for erasure of her personal data, and upon receipt of such a request, the Data Fiduciary shall erase her personal data unless retention of the same is necessary for the specified purpose or for compliance with any law for the time being in force.
DPDP Act 2023, s. 13
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(1) A Data Principal shall have the right to have readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager in respect of any act or omission of such Data Fiduciary or Consent Manager regarding the performance of its obligations in relation to the personal data of such Data Principal or the exercise of her rights under the provisions of this Act and the rules made thereunder. (2) The Data Fiduciary or Consent Manager shall respond to any grievances referred to in sub-section (1) within such period as may be prescribed from the date of its receipt for all or any class of Data Fiduciaries. (3) The Data Principal shall exhaust the opportunity of redressing her grievance under this section before approaching the Board.
DPDP Rules 2025, r. 14, (3)
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(3) Every Data Fiduciary and Consent Manager shall prominently publish on its website or app, or both, as the case may be, within a reasonable period not exceeding ninety days under its grievance redressal system for responding to the grievances of Data Principals and shall, for ensuring the effectiveness of the system in responding within such period, implement appropriate technical and organisational measures.
Rule 14 on this site Official source ↗ Also on MeitY (byte identical) ↗
DPDP Act 2023, s. 40, (2)(o)
Interpretation, requires judgment · Verified 26 August 2026
In force since 13 November 2025
Section 40 on this site Official source ↗
Rule 14(3) as printed carries no object for "publish", so what the words "not exceeding ninety days" cap is not stated on the face of the text. This site reads them as capping the response period the organisation must publish, because section 40(2)(o) describes the thing to be prescribed as "the period within which the Data Fiduciary shall respond to any grievances under sub-section (2) of section 13", and the same sub rule requires measures for responding "within such period". That reading is this site's and not a statement the printed rule makes.
DPDP Act 2023, s. 14
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(1) A Data Principal shall have the right to nominate, in such manner as may be prescribed, any other individual, who shall, in the event of death or incapacity of the Data Principal, exercise the rights of the Data Principal in accordance with the provisions of this Act and the rules made thereunder. (2) For the purposes of this section, the expression “incapacity” means inability to exercise the rights of the Data Principal under the provisions of this Act or the rules made thereunder due to unsoundness of mind or infirmity of body.
DPDP Rules 2025, r. 14, (4)
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(4) To exercise the rights of the Data Principal under the Act, she may, in accordance with the terms of service of the Data Fiduciary and such law as may be applicable, nominate one or more individuals, using the means and furnishing the particulars required by such Data Fiduciary for the exercise of such right.
Rule 14 on this site Official source ↗ Also on MeitY (byte identical) ↗
DPDP Rules 2025, r. 9
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
Every Data Fiduciary shall prominently publish on its website or app, and mention in every response to a communication for the exercise of the rights of a Data Principal under the Act, the business contact information of the Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary the questions of the Data Principal about the processing of her personal data.
Rule 9 on this site Official source ↗ Also on MeitY (byte identical) ↗
DPDP Act 2023, s. 15
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
A Data Principal shall perform the following duties, namely:— (a) comply with the provisions of all applicable laws for the time being in force while exercising rights under the provisions of this Act; (b) to ensure not to impersonate another person while providing her personal data for a specified purpose; (c) to ensure not to suppress any material information while providing her personal data for any document, unique identifier, proof of identity or proof of address issued by the State or any of its instrumentalities; (d) to ensure not to register a false or frivolous grievance or complaint with a Data Fiduciary or the Board; and (e) to furnish only such information as is verifiably authentic, while exercising the right to correction or erasure under the provisions of this Act or the rules made thereunder.
Sources cited on this page
- [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 11, p. 9. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
- [2]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 14, (1), p. 29. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026
- [3]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 12, p. 10. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
- [4]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 13, p. 10. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
- [5]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 14, (3), p. 30. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026
- [6]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 40, (2)(o), p. 18. Published 11 August 2023. Official source ↗ · Interpretation, requires judgment · Verified 26 August 2026Rule 14(3) as printed carries no object for "publish", so what the words "not exceeding ninety days" cap is not stated on the face of the text. This site reads them as capping the response period the organisation must publish, because section 40(2)(o) describes the thing to be prescribed as "the period within which the Data Fiduciary shall respond to any grievances under sub-section (2) of section 13", and the same sub rule requires measures for responding "within such period". That reading is this site's and not a statement the printed rule makes.
- [7]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 14, p. 10. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
- [8]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 14, (4), p. 30. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026
- [9]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 9, p. 27. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026
- [10]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 15, p. 10. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
Read the guide
Data Principal rights under the DPDP Act, explained What each right reaches, the consent gate on sections 11 and 12, and the rights people believe exist but do not.