The rights sit in Sections 11 to 14 of the Digital Personal Data Protection Act, 2023: a summary of the personal data being processed and the processing activities, including who else it has been shared with (Section 11); correction, completion, updating and erasure (Section 12); a readily available means of grievance redressal from the Data Fiduciary or Consent Manager, to be used before approaching the Data Protection Board (Section 13); and nominating another individual to exercise these rights in the event of death or incapacity (Section 14). Where processing relies on consent, the Data Principal can also withdraw it at any time, as easily as it was given (Section 6).
The Act also sets duties for Data Principals in Section 15, such as not impersonating another person, not suppressing material information when providing personal data for an official document, not registering a false or frivolous grievance, and giving only verifiably authentic information when asking for correction or erasure.
In practice, honouring these rights means receiving requests, verifying the person, finding the relevant data across systems, acting within the required time and keeping a record. ConsentX runs this as a DSAR and grievance workflow.
In ConsentX
Related terms
Under India's DPDPA, a Data Principal is the individual whose personal data is being processed, equivalent to a 'data subject' under the GDPR.
A DSAR is a request by an individual to access, correct, delete or port the personal data an organisation holds about them, which must be answered within a statutory deadline.
Under India's DPDPA, a Data Fiduciary is the entity that decides why and how personal data is processed, equivalent to a 'controller' under the GDPR.
Under India's DPDPA, a Consent Manager is a registered, interoperable platform through which a Data Principal can give, manage, review and withdraw consent across Data Fiduciaries.