DPDP Act User Rights: A Practical Guide for Indian Websites
Map DPDP Act Sections 11 to 14 into website workflows for access, correction, erasure, grievance, and nomination. Detailed Rules were still awaited; prepare from the Act text now.
- Timing: Sections 11 to 17 commence on once Rules and commencement are notified under forthcoming MeitY commencement notifications.
- Access (Section 11): Summary of data and activities, plus sharing lists where the section applies, not only a raw file dump.
- Correction and erasure (Section 12): Fix, complete, update; erase unless retention is needed for the specified purpose or for law.
- Grievance (Section 13 / Rule 14): Publish a response period of at most 90 days and staff to meet it before Board complaints.
- Build: Rights page, identity checks, system inventory, processor contracts, and tabletop tests before Rules commence.
Indian websites that collect digital personal data need a clear plan for data principal rights. The Digital Personal Data Protection Act, 2023 (DPDP Act) sets those rights in Sections 11 to 14. The forthcoming DPDP Rules from MeitY (DPDP Rules) add the operational detail in Rule 14. the rights text is law, but the commencement schedule means Sections 11 to 17 become operative on once Rules and commencement are notified under forthcoming MeitY commencement notifications.
This guide maps each right to practical website work: notices, request channels, identity checks, response packs, and grievance handling. It also notes where GDPR Articles 15 to 17 cover similar ground for teams that already run EU programs.
What the DPDP Act covers for websites
The DPDP Act applies to processing of digital personal data in India, and to processing outside India when it relates to offering goods or services to data principals in India (Section 3). A data fiduciary decides the purpose and means of processing. A data principal is the individual whose personal data is processed.
Rights in Chapter III mainly attach where the data principal previously gave consent for processing, including consent under Section 7(a) for certain voluntary uses. Build your workflows around consent-backed processing first, then review legitimate uses and exemptions with counsel.
Commencement timing you should plan for
MeitY had not yet notified commencement or detailed Rules as of this writing stages commencement:
- Board and rule-making related provisions began on publication in the eventual Rules notification.
- Consent Manager registration (Section 6(9)) and related Board powers begin one year after publication (a future Consent Manager registration date once notified).
- Core obligations and data principal rights in Sections 3 to 5, much of Section 6, Sections 7 to 10, and Sections 11 to 17 begin eighteen months after publication: once Rules and commencement are notified.
Use the runway to publish request channels, train staff, inventory systems, and test response packs before rights become enforceable.
Section 11: Right to access information about personal data
Under Section 11(1), a data principal who previously gave consent may request:
- A summary of personal data being processed and the processing activities for that data.
- Identities of other data fiduciaries and data processors with whom the data was shared, plus a description of what was shared.
- Any other information related to the personal data and its processing, as may be prescribed.
Section 11(2) limits sharing disclosures when data was shared with another fiduciary authorised by law for prevention, detection, investigation of offences or cyber incidents, or for prosecution or punishment, on a written request.
Website checklist for access
- Publish how to submit an access request (web form, email, or in-app path) and which identifiers you need (Rule 14(1)).
- Map systems that hold account, billing, support, analytics, and marketing records for each request type.
- Prepare a standard access pack: data summary, purposes, processors or vendors involved, and sharing list where Section 11 requires it.
- Log request receipt, identity check steps, systems searched, and what you released or withheld.
- Route law-enforcement-related sharing questions to legal before you disclose recipient lists.
Section 12: Correction, completion, updating, and erasure
Section 12(1) gives rights to correction, completion, updating, and erasure for personal data processed on prior consent (including Section 7(a) consent), subject to other law.
On a correction, completion, or update request, Section 12(2) requires the fiduciary to:
- Correct inaccurate or misleading personal data.
- Complete incomplete personal data.
- Update the personal data.
For erasure, Section 12(3) says the fiduciary must erase on a valid request unless retention is necessary for the specified purpose or for compliance with any law in force.
Separately, Section 8(7) requires erasure when consent is withdrawn or when it is reasonable to assume the specified purpose is no longer served, unless law requires retention, and to cause processors to erase data you shared with them for processing.
Website checklist for correction and erasure
- Let users fix profile fields where you can (name, contact, preferences) without opening a formal ticket when risk is low.
- For formal correction tickets, verify identity, capture what is wrong, update source systems, and push changes to processors under contract.
- For erasure, check retention triggers: tax, KYC, dispute, fraud, or other legal holds. Document why you keep or delete each category.
- When you erase, stop downstream uses and instruct processors under Section 8(7)(b).
- Confirm completion to the requester and keep an audit trail.
Section 13: Grievance redressal
Section 13 requires readily available grievance redressal for acts or omissions about obligations or rights. The fiduciary or Consent Manager must respond within the prescribed period. The data principal must exhaust that process before approaching the Data Protection Board.
Rule 14(3) requires you to publish, on your website or app, a response period under your grievance system that is reasonable and not more than ninety days, and to put technical and organisational measures in place so you can meet that period.
Website checklist for grievances
- Publish a privacy contact or grievance officer path and the target response time (at most 90 days under Rule 14(3)).
- Separate product support tickets from privacy grievances so privacy SLAs are visible.
- Acknowledge receipt quickly, even if full resolution takes longer.
- Record outcomes so you can show exhaustion of the Section 13 path if a Board complaint follows.
Section 14: Right to nominate
Section 14 lets a data principal nominate another individual to exercise rights on death or incapacity (unsoundness of mind or infirmity of body). Rule 14(4) says nomination may cover one or more individuals, using your published means and particulars, and subject to your terms of service and applicable law.
Website checklist for nomination
- Add a nomination option to the privacy rights page once your product and legal teams agree the form fields and proof rules.
- Store nominee details securely and define who can act, and on what events.
- Train support so nominee requests are not rejected as “not the account holder” without checking nomination records.
Rule 14: How requests must be enabled
Rule 14 of the forthcoming DPDP Rules is the operational layer for rights:
- Publish means and identifiers (Rule 14(1)): how to make a request, and particulars such as username or other identifier needed under your terms of service.
- Request routing (Rule 14(2)): the principal requests the fiduciary that received consent, using your published means and particulars.
- Grievance timeline (Rule 14(3)): publish a response period not exceeding ninety days and implement measures to meet it.
- Nomination (Rule 14(4)): allow nomination through your published process.
- Identifier meaning (Rule 14(5)): includes customer IDs, enrolment IDs, email, mobile number, licence number, and similar sequences you issue for identification.
Data principal duties (Section 15)
Section 15 requires principals not to impersonate others, not to suppress material information for State-issued identity documents, not to file false or frivolous grievances, and to furnish verifiably authentic information when seeking correction or erasure. Your forms can ask for authentic identifiers, but keep identity checks proportionate and document your process.
Comparison with GDPR Articles 15 to 17
If you already fulfil GDPR rights, reuse tooling carefully. The scopes differ.
| Topic | DPDP Act | GDPR (EUR-Lex) |
|---|---|---|
| Access | Section 11: summary of data and activities; identities of fiduciaries and processors with whom data was shared; other prescribed information | Article 15: confirmation of processing, access to personal data, and listed information (purposes, recipients, retention, rights, and more) |
| Correction | Section 12(2): correct, complete, update | Article 16: rectification without undue delay; complete incomplete data |
| Erasure | Section 12(3): erase unless retention needed for specified purpose or law | Article 17: erasure without undue delay where listed grounds apply, with listed exceptions |
| Response clock | Grievance response period prescribed; Rule 14(3) caps published grievance period at 90 days | Article 12(3): generally one month, extendable under conditions |
Do not assume a GDPR access export automatically meets Section 11. Build an India-specific summary and sharing list where consent-based processing applies.
Practical build plan for an Indian website
1. Rights page and notice links
Section 5 notices must tell people how to exercise rights under Section 6(4) (consent withdrawal) and Section 13 (grievance). Link the privacy policy and cookie notice to one rights page that covers access, correction, erasure, grievance, and nomination, with the identifiers you require under Rule 14.
2. Intake and identity
Use one branded form or verified email channel. Collect the minimum identifiers needed to find the person (email, account ID, mobile). Match intensity of verification to risk: account login may suffice for low-risk profile updates; erasure of payment or identity data may need stronger checks.
3. System inventory
List where personal data lives: CMS, CRM, email ESP, analytics, payment, support desk, backups, and processors. Without this map, access and erasure stall.
4. Response templates
Draft templates for: acknowledgment, identity needed, access pack delivered, correction completed, erasure completed, partial refusal with legal retention reason, and grievance closure. Keep timestamps.
5. Processor contracts
Section 8(2) requires a valid contract when you use a processor. Ensure contracts let you pull data for access packs and force erasure when Section 8(7) or Section 12(3) applies.
6. Train and test before Rules commence
Run tabletop exercises: access for a logged-in user, correction of a wrong phone number, erasure with a tax retention hold, and a grievance that escalates after a slow first reply. Fix gaps while Sections 11 to 14 are still in the commencement runway.
Related in this series: GDPR vs DPDP: User Rights and Consent Compared, How to Handle DSARs with OneTrust, Data Privacy Compliance Checklist for Indian Businesses, and Consent Withdrawal Under DPDP and GDPR.
Sources
- Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Sections 3, 5, 6, 8, 11 to 15: MeitY PDF; also India Code.
- MeitY commencement notification forthcoming MeitY commencement notifications, a future MeitY notification date (eighteen-month commencement for Sections 11 to 17 on once Rules and commencement are notified).
- forthcoming DPDP Rules from MeitY, Rule 14 (rights of data principals); MeitY publication page: DPDP forthcoming Rules.
- Regulation (EU) 2016/679, Articles 15, 16, and 17: EUR-Lex.
Disclaimer
This article was prepared by Imran using publicly available information. It is for general education only and is not legal advice. Do not rely on it alone when implementing cookie compliance, DSAR handling, consent flows, privacy policies, or other privacy and data-protection controls. Consult your own legal counsel for advice that fits your business, jurisdictions, and systems.
Last updated on 4 September 2026
