Know your rights as an Indian citizen under India's Digital Personal Data Protection (DPDP) Act.
If any business — anywhere in the world — collects your personal data (name, phone, address, payments) and either operates in India or offers goods or services to people in India, India's Digital Personal Data Protection Act 2023 gives you real, enforceable rights over that data: the right to see it, correct it, delete it, and complain when it's mishandled. The law follows your data, not the company's postal address. This guide explains those rights in plain language, how to actually use them, and the few responsibilities the law asks of you in return. (In the law's own terms, you are the "Data Principal" — see the plain-English box below.)
In plain English
- You (the user / customer) = a "Data Principal"
- The business holding your data = a "Data Fiduciary"
- Which businesses this covers = any business processing your data in India, or based anywhere in the world if it offers goods or services to people in India (Section 3(a)–(b))
- Your rights over your data = Sections 11–14 of the DPDP Act
- Your duties as a user = Section 15 of the DPDP Act
- The complaints regulator = the Data Protection Board (DPB)
Does This Apply to Foreign Companies Too?
Yes. Under Section 3(b) of the Act, the DPDP Act applies to processing of your personal data outside India if that processing is "in connection with any activity related to offering of goods or services to Data Principals within the territory of India." In practice: a US SaaS product, a UK retailer, or a Singapore app that sells to or serves people in India is covered by the same rights described in this guide, alongside every India-based business (Section 3(a)). Where the company is registered has no bearing on whether you can exercise these rights against it.
This Isn't Just for Big Companies
The Act defines "Data Fiduciary" broadly: "any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data" (Section 2(i)), and "person" is itself defined to include an individual, a Hindu undivided family, a company, a firm, or an association of persons — whether incorporated or not (Section 2(s)). There's no size or formality threshold.
That means the same rights in this guide apply against a local apparel shop tracking your number for a rewards programme, an Instagram or Facebook seller taking orders over DM, or any WhatsApp Business account digitising your name, number, or address for their business — not just registered companies with a website. The obligation applies once the data is "in digital form, or in non-digital form and digitised subsequently" (Section 3(a)). The one real carve-out is Section 3(c)(i): personal data an individual processes purely for their own personal or domestic purposes, not while running a business, falls outside the Act entirely.
A website is not mandatory to be covered by these obligations — but a Data Fiduciary must still publish, somewhere, the means for you to exercise your rights (Rule 14(1) says "on its website or app, or both, as the case may be"). For a seller with no website, that in practice means an Instagram bio, a WhatsApp catalogue note, or a printed notice at the counter — the specific channel isn't prescribed, but going without any published channel isn't compliant.
Order Updates vs. Marketing: Two Different Kinds of Consent
Not every message a business sends you needs the same permission behind it. The Act draws a real distinction between the two:
Order updates, delivery notifications, and similar service communications can generally rely on Section 7(a), the "legitimate uses" ground — where you've voluntarily given your data and a purpose for it (placing an order), the business can process it for that purpose, and any purpose "necessary for" or "incidental to" it, without needing to collect a fresh, separate consent for each such message.
Marketing and promotional messages are a different matter. These aren't necessary to fulfil the transaction you asked for, so they need their own basis: specific, informed, unconditional consent under Section 6(1), which requires consent to be "free, specific, informed, unconditional and unambiguous," limited to the personal data "necessary for such specified purpose." A business can't bundle a marketing opt-in into the checkbox you tick to place an order — it has to be its own, clearly separate ask, and you can withdraw it at any time with the same ease you gave it.
In short: if a shop texts you that your order has shipped, that's covered by the transaction. If the same shop texts you a festive-season discount code, that needs your separate, specific yes — and you can say no to the second without losing the first.
Quick Answer: What Rights Do You Have as a User?
As a user, you have four rights under the DPDP Act 2023: the right to access information about your personal data (Section 11), the right to correction and erasure (Section 12), the right to grievance redressal (Section 13), and the right to nominate someone to exercise these rights on your behalf (Section 14). Separately, you can withdraw consent at any time under Section 6(4). In return, Section 15 places five duties on you — including not impersonating others and giving authentic information.
Your Four Rights as a User (Sections 11–14)
| Right | Section | What it lets you do |
|---|---|---|
| Access information | Section 11 | Ask a business for a summary of the personal data it holds about you and how it's being processed, plus the identities of every other Data Fiduciary and Data Processor it has shared your data with |
| Correction & erasure | Section 12 | Have your data corrected, completed, updated, or erased |
| Grievance redressal | Section 13 | Use the business's or Consent Manager's complaint mechanism — which must respond within a published period capped at 90 days (Rule 14(3)) — before escalating to the Data Protection Board |
| Nominate | Section 14 | Name one or more people to exercise your rights if you die or become incapacitated |
Right 1 — Right to Access Information (Section 11)
On request, a Data Fiduciary must give you: a summary of the personal data it is processing and the processing activities it has undertaken; and the identities of all other Data Fiduciaries and Data Processors with whom your data has been shared, along with a description of what was shared. This right applies to data processed on the basis of your consent (and certain legitimate uses). It's the foundation of transparency — you can't correct or delete what you don't know a business holds.
Right 2 — Right to Correction and Erasure (Section 12)
Section 12 gives you the right to correction, completion, updating and erasure of the personal data you previously consented to a business processing. If a business is holding an old address, a misspelt name, or data it no longer needs, you can require it to fix or delete that data — subject to any legal obligation the business has to retain certain records (for example, tax records).
Right 3 — Right of Grievance Redressal (Section 13)
You have the right to a readily available means of grievance redressal provided by the Data Fiduciary or its Consent Manager. The Act states they "shall respond to any grievances… within such period as may be prescribed." Rule 14(3) of the DPDP Rules 2025 fills in that number: Data Fiduciaries and Consent Managers must publish, and meet, a response period not exceeding 90 days. Importantly, Section 13(3) requires you to exhaust this grievance mechanism before approaching the Data Protection Board — so always raise it with the business first and keep a record.
Right 4 — Right to Nominate (Section 14)
Section 14 lets you nominate one or more individuals to exercise your rights under the Act in the event of your death or incapacity. This is especially relevant for accounts holding sensitive financial or health data — it ensures someone you trust can access, correct, or close them.
What About Withdrawing Consent?
Withdrawing consent is often mistaken for a "fifth right," but it actually sits in the consent provisions, not Chapter III. Under Section 6(4), you may withdraw your consent at any time, and the Act requires that withdrawing be "comparable to the ease with which such consent was given" (Section 6(5) makes clear that withdrawal doesn't undo processing already carried out lawfully). So if you opted in with one tap, the business must let you opt out just as easily.
How to Exercise Your Rights (The Practical Steps)
The DPDP Rules 2025 (Rule 14, "Rights of Data Principals") set out how this works in practice. A business must prominently publish on its website or app the means for you to make a request, and the identifier it needs to recognise you (for example, your registered email, mobile number, or a customer/enrolment number). It must also publish, and stick to, the period within which it will respond.
- Find the request channel. Look for a "Privacy", "Your Data", or "Data Request" link on the website, app, or privacy notice.
- Identify yourself. Provide the identifier the business specifies so it can locate your records.
- State the right you're exercising. Access, correction, erasure, or a grievance — be specific.
- Keep a record. Note the date you submitted the request; the business must respond within its published timeline.
- Escalate only after exhausting the grievance route. If unresolved, you can then approach the Data Protection Board (Section 13(3)).
Run a business and need to handle these requests from the other side? See our guide for businesses on customer rights and building a DSR process.
Your Duties as a Data Principal (Section 15)
Rights come with responsibilities. Section 15 lists five duties every Data Principal must perform:
| # | Duty (Section 15) |
|---|---|
| 15(a) | Comply with all applicable laws while exercising your rights under the Act |
| 15(b) | Do not impersonate another person while providing your personal data for a specified purpose |
| 15(c) | Do not suppress any material information while providing personal data for any document, unique identifier, proof of identity, or proof of address issued by the State |
| 15(d) | Do not register a false or frivolous grievance or complaint with a Data Fiduciary or the Board |
| 15(e) | Furnish only information that is verifiably authentic when exercising the right to correction or erasure |
In short: give correct, genuine information, don't pretend to be someone else, and don't abuse the complaint system.
Is There a Penalty If a Data Principal Breaks These Duties?
Yes — but it's modest. The Schedule to the Act (referenced in Section 33) sets a penalty of up to ₹10,000 for a Data Principal who breaches the duties in Section 15. This is the lowest tier in the entire penalty schedule (business-side penalties run from ₹50 Crore to ₹250 Crore), reflecting that the Act's weight falls overwhelmingly on businesses, not individuals.
Why These Rights Matter
The DPDP Act reframes your personal data as something that belongs to you and is merely entrusted to a business — which is exactly why the word "fiduciary" is used for the business that holds it. Knowing your four rights (and how to exercise them) turns the Act from an abstract law into a practical tool you can use whenever a company mishandles your data.
If you run a business rather than just use one, the mirror image of this guide is our explainer on your responsibilities as a business — what the law requires of the organisations (the "Data Fiduciaries") holding all this data.
⬇ Download this guide as a shareable PDF — a 13-page plain-English walkthrough of your rights, with the exact Act and Rules sections behind each one. Free, no signup.
References & Sources
- Ministry of Electronics & IT, Government of India — The Digital Personal Data Protection Act, 2023 (Chapter III, Sections 11–15; Section 6; the Schedule).
- The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 14, "Rights of Data Principals."
- India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text.
This article is general information about the DPDP Act 2023 and DPDP Rules 2025, not legal advice. Section and rule references are cited from the official text; always confirm against the current notified version for your specific situation.