Skip to content
Coverage

Data rights

India Digital Personal Data Protection Act 2023

NationalINDerived or secondary source

India

Rule id
data.in-dpdp
Version
1.0.0
In force from
November 13, 2025
Last read against its sources
August 5, 2026
Countries bound
India

In plain language

What this regime says.

India's DPDP Act 2023 is enacted and its Rules were notified in November 2025, but the obligations that let an individual actually exercise access and erasure rights do not commence until 13 May 2027. Until then, use sector regulators.

Who is covered

Data principals whose digital personal data is processed within India, and processing outside India connected with offering goods or services to data principals in India.

What you get

A summary of your data and the recipients, correction, and erasure — from 13 May 2027. No compensation, ever: the Act gives the individual no private right of action.

Where claims go wrong

  • Assuming the Act is fully in force. The rights machinery commences on 13 May 2027.
  • Going to the Data Protection Board without exhausting the data fiduciary's grievance mechanism first. Section 13 requires it.
  • Expecting compensation. The Act provides none, and it repealed the s. 43A route that used to exist.

Authority

Every citation,
with its pinpoint.

A claim that cites “EU law” gets filed. A claim that cites Article 7(1)(c) gets answered. These are the exact coordinates this entry rests on.
  1. Digital Personal Data Protection Act, 2023 (No. 22 of 2023), ss. 11–14The Digital Personal Data Protection Act, 2023URL verified 2026-08-05ss. 11 (access), 12 (correction and erasure), 13 (grievance redressal), 14 (nomination)

Sources

Where a figure is indexed, converted or published by a regulator rather than fixed in the instrument, the provenance is recorded separately. Anything marked as a modelled estimate is exactly that — a model, not a statutory number.

What it imposes

Clocks, defences and the ladder.

A rule module builds these while it evaluates, because a limitation period depends on which forum is open to you. What follows is the structure this regime produces — deliberately with no dates and no figures, because those belong to your facts rather than to the law.

The clocks it starts

  • India Digital Personal Data Protection Act 2023: deadline for the controller to respondThe DPDP Act itself sets no response period for a s. 11 request; the periods are prescribed by the Rules. The figure shown here is an outer working assumption for planning only and is NOT a statutory deadline — see the commencement warning. Section 13 requires the data fiduciary to publish a grievance-redressal mechanism and to respond within the prescribed period.Digital Personal Data Protection Act, 2023 (No. 22 of 2023), ss. 11–14 — ss. 11 (access), 12 (correction and erasure), 13 (grievance redressal), 14 (nomination)Response due

What it entitles you to, beyond money

  • Compliance with your access requestA data principal has the right to obtain a summary of the personal data being processed, the processing activities undertaken, and the identities of other data fiduciaries and processors with whom the data has been shared together with a description of what was shared. NOTE THE COMMENCEMENT POSITION BELOW: this right is enacted but its enforcement machinery does not commence until 13 May 2027.s. 11

What the other side will say

Each of these is a refusal this regime lets a counterparty attempt, paired with the answer to it. Reading them before you write is worth more than any amount of polish on the letter itself.

Endless identity verification

high likelihood

We cannot action your request until you verify your identity. Please send a copy of your passport, a utility bill, and a selfie holding your ID.

What answers it

A controller may use reasonable measures to verify identity, but it may only ask for information it actually needs and already holds a basis to check. Demanding a passport scan from someone whose account you identify by email address is disproportionate and is itself a data-minimisation problem. Offer to verify through the same channel you already use to log in, state that you consider the demand excessive, and note that the response clock is running.

"We hold no personal data about you"

high likelihood

A search of our systems returned no personal data relating to you.

What answers it

Ask for that in writing, signed, together with a description of the systems searched and the search terms used. A nil return is a substantive answer that the controller must stand behind, and it is frequently wrong: it usually means one production database was searched and backups, CRM, marketing, support tickets, call recordings, and third-party processors were not. Name the systems you believe hold your data, including any you have interacted with.

Blanket confidentiality or trade-secret refusal

medium likelihood

The information you have requested is commercially confidential / contains our trade secrets / is proprietary.

What answers it

Confidentiality and intellectual-property carve-outs are narrow and must be applied item by item, not as a blanket. The correct response is redaction of the protected element and disclosure of the rest, with a schedule explaining what was withheld and why. Ask for that schedule.

Refusal because the data mentions someone else

medium likelihood

We cannot disclose these records because they contain the personal data of other individuals.

What answers it

The presence of third-party data is a reason to redact, not to refuse. The controller must consider whether it can disclose with the third party removed, whether the third party has consented, and whether it is reasonable to disclose without consent. A blanket refusal on this ground is not a lawful answer.

"Your request is manifestly excessive"

medium likelihood

Your request is manifestly unfounded or excessive, so we are refusing it / charging a fee.

What answers it

The burden of showing that a request is manifestly unfounded or excessive is on the controller, and it is a high bar — the regulator guidance treats it as exceptional, not as a routine response to a broad request. Ask the controller to state, in writing, the specific grounds and the evidence for them. If you have made only one request, say so. A single, first, ordinary request is not excessive.

Where to take it next

  1. Written request to Sample ControllerSend it to the named data-protection contact or privacy team, in writing, and keep proof of the date. If the organisation has a designated Data Protection Officer, address it to them by title. Use the word "request" and name the right you are exercising.Claim directtypically 90 days
  2. Internal appeal / complaint to the controllerSection 13 requires you to exhaust the data fiduciary's own grievance redressal mechanism BEFORE approaching the Data Protection Board. This is a hard precondition, not a courtesy.Internal appealtypically 45 days
  3. Complain to the Data Protection Board of Indiathe Data Protection Board of India takes complaints from individuals about a specific organisation's handling of a specific request. It is free. Attach your original request, proof of the date you sent it, and anything the organisation sent back.Regulatortypically 180 daysofficial page

Documents

What this regime can produce.

Every one of these is a document you send yourself, in your own name. Duesday never writes to anybody on your behalf and is never anyone’s agent.

The same claim type elsewhere

Other rights in the same countries

India — DGCA Civil Aviation Requirements, Section 3 Series M Part IVINNationalIndiaDGCA CAR Section 3, Series M, Part IV, Paras 1.2, 1.3 and 1.7Confidence: highIndia — India PostINNationalIndiaPost Office Act 2023 and the Department of Posts rules and compensation scheduleConfidence: lowIndia — IRCTC Ticket Deposit Receipt (TDR) refunds for cancelled and substantially delayed trainsINNationalIndiaRailway Passengers (Cancellation of Tickets and Refund of Fare) RulesConfidence: lowIndia — RBI e-mandate framework for recurring paymentsINNationalIndiaRBI circular DPSS.CO.PD.No.447/02.14.003/2019-20 (21 August 2019) — Processing of e-mandate on cards for recurring transactionsConfidence: mediumIndia — RBI limited liability for unauthorised electronic banking transactionsINNationalIndiaRBI/2017-18/15 — Customer Protection: Limiting Liability of Customers in Unauthorised Electronic Banking Transactions (6 July 2017)Confidence: highIndia — representative consumer complaints and s.245 Companies Act class actionsINNationalIndiaConsumer Protection Act 2019, s.35(1)(c) and s.2(5)Confidence: lowIndia — security deposit (Model Tenancy Act 2021 where adopted, otherwise State Rent Acts)INNationalIndiaModel Tenancy Act, 2021Confidence: lowIndia — the Clinical Establishments Act rate-display duty and the consumer forum routeINNationalIndiaClinical Establishments (Registration and Regulation) Act, 2010Confidence: low

Does this one reach your facts?

The engine runs every regime that could apply at once and reconciles them, rather than making you guess which page to read.

Not a law firm. Not legal advice. You send it yourself. This page describes a law; it is not advice about your situation and no outcome is promised.