top of page

How to Set Up a Data Principal Rights Request Process Under the DPDP Rules 2025

Writer: Kaustav Chowdhury
Kaustav Chowdhury
15 hours ago
6 min read

A data principal rights request process is the operational answer to sections 11 to 14 of the Digital Personal Data Protection Act, 2023 and to rule 14 of the Digital Personal Data Protection Rules, 2025. The provisions are short, and the work they generate is almost entirely about plumbing: who receives the request, how the person is identified, what has to be returned and within what period.

Step 1: Note When the Obligations Commence

By G.S.R. 843(E) dated November 13, 2025, issued under section 1(2) of the Act, sections 11 to 17 come into force eighteen months after publication, as do sections 3 to 5 and sections 7 to 10. Rule 14 of the Rules, notified by G.S.R. 846(E) of the same date, is in the matching tranche with rules 3, 5 to 16, 22 and 23.

Only section 6(9) and section 27(1)(d) of the Act, and rule 4 of the Rules, commence at the one year point. The rights machinery therefore commences in May 2027 rather than November 2026, and an advisory that puts the whole framework on the earlier date is wrong about which obligations arrive when.

Step 2: Publish the Means, the Particulars and the Contact Point

Rule 14(1) requires a data fiduciary and a consent manager to publish prominently on its website or app the details of the means by which a data principal may make a request for the exercise of her rights, and the particulars of any information she must furnish so that the request can be serviced.

Rule 9 is the companion obligation and is easy to miss. It requires the fiduciary to publish prominently on its website or app, and to mention in every response to a communication for the exercise of rights, the business contact information of the data protection officer if applicable, or of a person able to answer the data principal's questions about the processing of her personal data. Section 8(9) is the enabling provision. Two obligations, two places, and the second one applies to every outbound reply.

Step 3: Build the Access Response Around What Section 11 Asks For

Section 11 entitles the data principal, on a request made in the prescribed manner, to a summary of the personal data being processed and of the processing activities undertaken with respect to it, and to the identities of all other data fiduciaries and data processors with whom the personal data has been shared, along with a description of the personal data so shared.

The sharing list is the part that cannot be assembled on demand. It has to be maintained as a record, keyed to the categories of personal data, and kept current as vendors change. A response that gives a data export and no sharing list does not answer the section.

Step 4: Handle Correction and Erasure as Separate Duties

Section 12(1) gives the right to correction, completion, updating and erasure of personal data for the processing of which consent was previously given. Section 12(2) then states what the fiduciary shall do on receiving a request for correction, completion or updating: correct the inaccurate or misleading data, complete the incomplete data, and update the data. There is no discretion in that limb.

Erasure is different. Under section 12(3) the fiduciary must erase on request unless retention is necessary for the specified purpose or for compliance with any law in force. So the workflow needs two branches, with the erasure branch recording which limb of the carve out is relied on and why.

Step 5: Run Grievance Redressal Against the Ninety Day Limit

Section 13(1) gives the data principal the right to readily available means of grievance redressal in respect of any act or omission of the fiduciary or consent manager regarding its obligations or her rights, and section 13(2) requires a response within the prescribed period. Rule 14(3) sets that period at a reasonable period not exceeding ninety days from receipt.

Ninety days is an outer limit, not a service standard, and it is measured from receipt rather than from triage. Section 13(3) requires the data principal to exhaust this remedy before approaching the Board, which makes the grievance record the document the Board will read first. Timestamp receipt, log every step, and keep the file capable of being produced.

Step 6: Provide for Nomination Under Section 14

Section 14(1) gives the data principal the right to nominate another individual to exercise her rights in the event of her death or incapacity, and section 14(2) defines incapacity as inability to exercise those rights due to unsoundness of mind or infirmity of body. Rule 14(4) provides that she may nominate one or more individuals using the means and furnishing the particulars the fiduciary requires.

This is the limb most often left out of a build. It needs a place to record the nominee, a route by which the nominee can establish the triggering event, and a rule about what the nominee may do. Decide those questions in advance rather than at the point of a bereavement.

Step 7: Identify the Requester Without Collecting New Data

Rule 14(2) allows the data principal to make a request using the means and furnishing the particulars the fiduciary requires, and rule 14(5) explains that an identifier means any sequence of characters issued by the fiduciary by which the data principal may be identified, which includes a customer identification number, an email address, a mobile number or a licence number.

The design consequence is that verification should run off something the fiduciary already issued. Demanding a government identity document in order to answer a request about data the fiduciary already holds enlarges the data set and invites a grievance of its own.

Common Pitfalls to Avoid

  • Dating the obligation to November 2026: Sections 11 to 17 and rule 14 commence with the eighteen month tranche. Only the consent manager provisions commence a year after publication.

  • Treating ninety days as the target: Rule 14(3) sets a reasonable period not exceeding ninety days, measured from receipt. A process that routinely uses the whole period is not meeting it.

  • Omitting the sharing list: Section 11 requires the identities of other fiduciaries and processors with whom the data was shared and a description of what was shared.

  • Running correction and erasure through one branch: Section 12(2) is mandatory on a correction request. Section 12(3) allows retention where the specified purpose or a law requires it.

  • Forgetting rule 9 in outbound replies: The contact information has to be published and also mentioned in every response to a communication for the exercise of rights.

  • Leaving nomination unbuilt: Section 14 and rule 14(4) require a working route for one or more nominees, including proof of death or incapacity.

  • Over verifying the requester: Rule 14(5) treats an identifier issued by the fiduciary as sufficient to identify the data principal.

Key Statutory Provisions

  • Section 8 of the Digital Personal Data Protection Act, 2023: Sub-section (9) requires the business contact information of the data protection officer, or of a person able to answer questions about the processing, to be published in the prescribed manner.

  • Section 11 of the Act: The right to a summary of the personal data processed and of the processing activities, and to the identities of other data fiduciaries and data processors with whom the data was shared with a description of what was shared.

  • Section 12 of the Act: The right to correction, completion, updating and erasure, with the mandatory duties on a correction request in sub-section (2) and the qualified erasure duty in sub-section (3).

  • Section 13 of the Act: The right to readily available means of grievance redressal, the duty to respond within the prescribed period, and the requirement to exhaust the remedy before approaching the Board.

  • Section 14 of the Act: The right to nominate an individual to exercise the data principal's rights in the event of death or incapacity, with incapacity defined as unsoundness of mind or infirmity of body.

  • Rule 9 of the Digital Personal Data Protection Rules, 2025: Publication of the business contact information on the website or app and its inclusion in every response to a communication for the exercise of rights.

  • Rule 14 of the Rules: Publication of the means and particulars for requests, the ninety day outer limit for grievance redressal, nomination of one or more individuals, and the meaning of an identifier issued by the data fiduciary.

Sources and References


Disclaimer: This article is for informational purposes only and does not constitute legal advice. Readers should consult a qualified legal professional for advice specific to their circumstances.

Comments


bottom of page