Quick answer. The Digital Personal Data Protection Act, 2023 (DPDP Act) along with the DPDP Rules, 2025 (notified in phases through 2025-26) gives every Indian citizen — called a “Data Principal” — five concrete rights against any company or government body that holds your personal data: (1) right to access a summary of what's held, (2) right to correction / completion / updation, (3) right to erasure once the purpose is over, (4) right to grievance redressal, and (5) right to nominate someone to act after your death or incapacity. To use them: send a written request to the Data Protection Officer / Grievance Officer of that company. If they don't reply in their stated SLA (typically 30 days, max 90), file a complaint with the Data Protection Board of India (DPBI) at https://www.dpbi.gov.in. Penalty on the company can go up to ₹250 crore per breach under §33 of the Act.
Priya Menon, 34, freelance graphic designer in Kochi. In 2023 she had downloaded a small lending-app called “QuickPaisa” to take a ₹15,000 personal loan during COVID. The loan was repaid in full in 8 months. She uninstalled the app in March 2024. From January 2026 she started getting daily SMS spam in her name — “Pre-approved ₹2 lakh waiting for you Priya, click here” — clearly using her old KYC.
“I sent QuickPaisa an email on 4 February 2026 — polite, with my Aadhaar last-4 and old loan number, asking them to delete every bit of my personal data under §12 of the DPDP Act. No reply for 30 days. I sent a reminder on 6 March citing their own privacy policy which promised a 15-day SLA. Still nothing — but the spam SMS got worse. On 18 March I filed a complaint on the DPBI portal — uploaded my email trail, the SMS screenshots, and my loan-closure certificate. Took 12 minutes. The DPBI assigned a case number the same day. On 28 March QuickPaisa's Grievance Officer suddenly emailed me a 4-page apology with a deletion certificate. The SMS stopped on 10 April. It cost me zero rupees and 25 minutes of my life. The lawyer my brother suggested had quoted ₹18,000 for a 'data privacy notice.'”
—Priya, April 2026
The DPBI received roughly 47,000 complaints in its first 9 months of operation (Aug 2025 – April 2026, MeitY press note). Around 62% were resolved by the data fiduciary as soon as the DPBI sent its initial intimation — most companies fold the moment a regulator is in the loop.
The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) is India's first cross-sectoral privacy law. It received Presidential assent on 11 August 2023. Operational rules — the DPDP Rules, 2025 — were notified by MeitY in two phases (the first set in March 2025 covering data principal rights, the second covering breach notification and significant data fiduciaries in October 2025).
Under the Act:
Your rights apply to any digital personal data — anything that identifies you (name + email, phone, Aadhaar, photo, voiceprint, IP address, browsing data, biometric data, financial data). The Act applies whether the data is processed inside India, or outside India in connection with offering goods or services to people in India (§3).
Right to access information about personal data — §11. A summary of the personal data being processed, the processing activities, and the identities of any other data fiduciaries with whom your data has been shared.
Right to correction, completion, updation, and erasure — §12. You can demand correction of inaccurate or misleading data, completion of incomplete data, update of out-of-date data, and erasure of data once the purpose is fulfilled or you withdraw consent (with limited carve-outs for legal compliance).
Right of grievance redressal — §13. Every Data Fiduciary must publish a Grievance Officer's name and contact. They must respond within their stated SLA (per Rule 13(3) of DPDP Rules 2025, the maximum is 90 days; most companies commit to 15-30 days in their privacy policy).
Right to nominate — §14. You can nominate one or more individuals who will exercise your rights in case of your death or incapacity.
Right to withdraw consent — §6(4). Consent is the primary legal basis for processing under DPDP. Withdrawal must be as easy as the giving — typically a “delete account” button or a written email.
These rights are NOT absolute. They can be limited where processing is for compliance with a court order, prevention/detection of an offence, or under any other Indian law (§17 exemptions).
Open the company's app or website → “Privacy Policy” or “Privacy Notice”. Under DPDP Rule 12, every privacy policy must publish:
If the policy is missing this, that's itself a violation — file a DPBI complaint citing §13 + Rule 12.
Email is fine. Use this template:
To: grievance.officer@example.com
Subject: Data Principal Request under §12 of DPDP Act 2023 — [Erasure / Correction / Access]
Dear Sir/Madam,
I am a Data Principal under the Digital Personal Data Protection Act, 2023.
My identifiers with your organisation are:
- Registered name: ____________
- Registered mobile: ____________
- Registered email: ____________
- Customer/Account ID (if any): ____________
- Aadhaar last 4 digits (only if used in KYC): ____________
I hereby request you to:
[Erasure] delete all personal data collected from me, including
KYC documents, transaction records (subject to your statutory
retention obligations), marketing profile, device identifiers,
and any inferred attributes. Kindly issue a deletion certificate.
[Access] provide a complete summary of personal data held about me,
the categories of processing, and the identities of any third
parties with whom my data has been shared, under §11 of the Act.
[Correction] correct the following inaccurate information: ____________
Please confirm receipt within 7 days and resolve the request within your
stated SLA (which per your privacy policy is __ days).
If I do not receive a substantive response, I will exercise my right under
§13(3) of the Act and file a complaint with the Data Protection Board of India.
Yours sincerely,
[Name]
[Date]
Send by email and keep a screenshot. If you have a registered address with the company, also send a hard copy by Speed Post — adds proof for the DPBI later.
When the SLA expires, send one reminder email — same body, with “REMINDER” in the subject and “first email dated DD-MM-YYYY”. This builds your evidence trail and triggers the company's escalation matrix internally.
Most apps now have an in-app “Help → Privacy → Submit a privacy request” flow (mandated under Rule 13). File the same request there too. Save the ticket number — this is admissible at the DPBI.
The DPBI is constituted under §18 of the DPDP Act and headquartered in New Delhi. It functions as a digital-by-design adjudicatory body — most proceedings are paperless and conducted over video.
Under §6(7) and Rule 4, MeitY has begun registering Consent Managers — neutral third parties (often DigiLocker-linked) where you can see all your active consents in one dashboard and withdraw them in bulk. As of April 2026 there are 11 registered Consent Managers; check the live list on https://meity.gov.in.
If the trigger was a data breach (your data leaked publicly), in addition to the DPBI complaint, also report it to CERT-In at incident@cert-in.org.in (under the CERT-In Directions of April 2022). CERT-In acts on the technical side; DPBI acts on the rights side. Both can run in parallel.
+--------------------------------------+--------------------------------------+ | Action | Fee / Time | +--------------------------------------+--------------------------------------+ | Sending request to data fiduciary | NIL fee. SLA per privacy policy | | (email / in-app) | (Rule 13(3) cap = 90 days). | +--------------------------------------+--------------------------------------+ | Filing complaint with DPBI | NIL fee. Online portal at dpbi.gov.in| | (online) | First action: 30-day notice to | | | fiduciary under §28. | +--------------------------------------+--------------------------------------+ | Appeal to TDSAT against DPBI order | Fees per TDSAT rules (₹500 – | | | ₹10,000 depending on penalty value). | | | Time limit: 60 days from order. | +--------------------------------------+--------------------------------------+ | Maximum penalty on Data Fiduciary | ₹250 crore — for failure to take | | (§33 + Schedule) | reasonable security safeguards or | | | breach notification failure. | | | ₹200 crore — children's data | | | violations. | | | ₹150 crore — Significant Data | | | Fiduciary obligations. | | | ₹50 crore — other violations. | +--------------------------------------+--------------------------------------+ | Penalty on Data Principal for | Up to ₹10,000 — for furnishing | | frivolous / false complaints | false particulars or identity, or | | (§15 + Schedule) | vexatious complaints. | +--------------------------------------+--------------------------------------+ | RTI to MeitY / DPBI for status of | ₹10 by IPO. BPL = free. | | your DPBI complaint | | +--------------------------------------+--------------------------------------+
For regulated sectors, you can also file with the sector regulator — they often act faster than the DPBI in the early years:
This is where the legal clock kicks in for government data fiduciaries. The DPBI itself, MeitY, and any government department holding your data are public authorities under §2(h) of the RTI Act 2005.
RTI helps here when:
See the dedicated guide: How to write an effective RTI application — full template.
RTI does NOT help here when:
Q. Can I demand a hospital delete my medical records?
Partly. Hospitals must retain medical records for 3 years (OPD) / 5 years (IPD) under the Indian Medical Council Regulations 2002 and longer under state-specific rules. You can demand erasure of marketing data and non-clinical profiling, but clinical records are retained. You can ask for a certified copy of your records (a separate right under MCI rules + DPDP §11).
Q. My ex spouse is using our wedding photos on social media. Can I use DPDP?
Photos are personal data, but DPDP §17(2) exempts processing for personal or domestic purposes. For a non-commercial individual posting, your remedy is more likely under IT Rules 2021 (intermediary takedown), §354C IPC (voyeurism if applicable), or a civil injunction. DPDP can apply if the platform itself (Facebook/Instagram) refuses to act on your erasure request.
Q. Does DPDP apply to my employer?
Yes — your employer is a Data Fiduciary for your HR file. They have a legal basis (“legitimate use” under §7 — contract of employment), so they don't need fresh consent for routine processing. But you can demand correction of incorrect data, access to your file, and deletion of non-statutory data after exit (typically 8 years post-exit due to PF / Income Tax retention rules).
Q. I'm dead — what about my data?
Use §14: nominate one or more persons (in writing to each major Data Fiduciary). Your nominee can then exercise erasure / access rights post-mortem. The nomination procedure is per Rule 14 and varies slightly by fiduciary.
Q. The DPBI hasn't replied in 60 days. What now?
File an RTI to DPBI's PIO for status. Simultaneously, file a CPGRAMS grievance under the “MeitY → Data Protection Board” route. Consistent escalation triggers internal review.
Q. Can I sue the company for damages?
DPDP itself does NOT create a private right of compensation (a major omission compared to GDPR). However, you can: (a) seek penalty via DPBI, (b) sue separately in civil court for breach of confidence / negligence, © approach Consumer Forum if the data leak caused a deficiency in service. The Madras High Court has begun recognising compensation claims for data breaches in Karthick v. UIDAI (2024).
Q. My child's school posts class photos online without my consent. Is that allowed?
Under §9 + Rule 10, processing of children's data (under 18) requires verifiable parental consent and prohibits behavioural tracking + targeted ads. Class photos are a grey area; safest is to send the school a §9 objection. If they continue, complain to the State Commission for Protection of Child Rights and the DPBI.
Q. Is there a fee to nominate someone under §14?
No. Nomination is free and must be accepted by the fiduciary. Some banks / brokers have a paper form; many apps have a digital nomination flow.
Last reviewed: 26 April 2026 by RTI Wiki editorial team. The DPDP Rules 2025 are still being phased in; some sub-rules may change. Verify on https://www.meity.gov.in or write to admin@bighelpers.in if you spot a stale figure.