Skip to main contentChat with us

DPDP Act 2023 · Sections 11–15 · Data Principal Rights

Data Principal
Rights

The DPDP Act 2023 empowers individuals (Data Principals) with fundamental rights over their personal data. Organizations must implement mechanisms to honor these rights.

Four enforceable rights — access, correction & erasure, grievance redressal, and nomination — with corresponding duties under Section 15.

4Enforceable rights
S.11–15Chapter III coverage
500+Audits delivered

DPDP Act 2023 · Chapter III, Sections 11–15 · Last reviewed June 2026

Direct Answer

What rights do data principals have?

Under the DPDP Act 2023, a data principal — the individual a piece of personal data is about — has four enforceable rights: the right to access information about their data (Section 11), to correction and erasure (Section 12), to grievance redressal (Section 13), and of nomination (Section 14), with corresponding duties under Section 15. Data fiduciaries must build accessible mechanisms to honour these rights and respond within the period prescribed by the MeitY DPDP Rules 2025.

Chapter III

Fundamental Rights

Section 11

Right to Access Information

Data Principals have the right to obtain a summary of their personal data being processed and the processing activities.

Summary of personal data being processed
Identities of Data Fiduciaries and Data Processors
Information about any data sharing with third parties
Response within prescribed time period under Rule 14
Section 12

Right to Correction and Erasure

Data Principals can request correction of inaccurate or misleading data, completion of incomplete data, updating of data, and erasure of data.

Correction of inaccurate or misleading personal data
Completion of incomplete personal data
Updating of personal data
Erasure of personal data no longer necessary
Section 13

Right to Grievance Redressal

Data Principals have the right to readily available means of grievance redressal provided by the Data Fiduciary.

Accessible grievance redressal mechanism
Response within prescribed timeframe
Escalation to Data Protection Board if unresolved
Right to file complaint with the Board
Section 14

Right of Nomination

Data Principals can nominate another individual to exercise their rights in the event of their death or incapacity.

Nominate any individual to exercise rights
Applicable in case of death or incapacity
Nominee can access, correct, or erase data
Registration process as per prescribed rules

Section 15

Duties of the Data Principal

While Data Principals have rights, they also have corresponding duties to ensure responsible exercise of these rights.

Comply with applicable laws while exercising rights
Not impersonate another person while providing personal data
Not suppress any material information while providing data
Not register false or frivolous grievances or complaints
Provide authentic and verifiable information when required

At a Glance

Data Principal Rights at a Glance

The complete set of rights and duties under Chapter III of the DPDP Act 2023.

SectionRight / dutyWhat it covers
Section 11Right to access informationA summary of personal data processed, the processing activities, and the identities of fiduciaries and processors with whom data is shared
Section 12Right to correction & erasureCorrect inaccurate or misleading data, complete or update data, and erase data no longer needed for its purpose
Section 13Right to grievance redressalA readily available grievance mechanism with the data fiduciary before approaching the Board
Section 14Right of nominationNominate another individual to exercise rights in the event of death or incapacity
Section 15Duties of the data principalExercise rights lawfully — no impersonation, no false or frivolous complaints, no suppression of material information

Frequently Asked Questions

Common questions on data principal rights, response timelines, and duties.

Who is a data principal under the DPDP Act?

A data principal is the individual to whom the personal data relates — the equivalent of a data subject under the GDPR. Where the individual is a child, the data principal includes the parent or lawful guardian; where the individual is a person with a disability, it includes their lawful guardian.

What rights do data principals have under the DPDP Act?

The DPDP Act 2023 gives data principals four rights: the right to access information about their personal data (Section 11), the right to correction and erasure (Section 12), the right to grievance redressal (Section 13), and the right of nomination (Section 14). Section 15 sets out corresponding duties, such as not filing false or frivolous complaints.

How quickly must a data fiduciary respond to a rights request?

A data fiduciary must respond within the time period prescribed by the DPDP Rules 2025 (Rule 14 addresses the timeframe for access, correction, and erasure requests). Organizations should build request-handling workflows with clear internal SLAs so they can meet the prescribed period and evidence compliance.

Does the DPDP Act include a right to data portability or to object?

No. Unlike the GDPR, the DPDP Act does not provide an explicit right to data portability, a right to object to processing, or rights against solely automated decision-making. Its rights set is narrower, centred on access, correction, erasure, grievance redressal, and nomination.

What is the right of nomination?

Section 14 lets a data principal nominate another individual to exercise their rights — for example, accessing, correcting, or erasing data — in the event of their death or incapacity. The nominee then steps into the data principal’s shoes for the nominated rights, following the process set out in the rules.

Continue your DPDP research

Written By Expert Auditors

Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Last reviewed: June 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations