The DPDP Act: What Rights Do You Actually Have Over Your Personal Data in India?
TL;DR: India's Digital Personal Data Protection Act gives you four specific, enforceable rights over your personal data — access, correction and erasure, grievance redressal, and nomination. Here's what each one actually lets you do, and how to use them.
Most people have heard the DPDP Act mentioned somewhere — in a privacy policy footer, a news headline, maybe a company email about "updated data practices." Few know what it actually hands them as an individual. It's worth knowing precisely, because these are real, usable rights, not just regulatory language aimed at companies.
What the DPDP Act actually is
The Digital Personal Data Protection Act, 2023 is India's primary law governing digital personal data, establishing a consent-based framework for how organizations — called Data Fiduciaries — can collect, process, and store your information. You, as the individual the data is about, are called a Data Principal. The Act's implementing rules were finalized in 2025, giving the framework practical, operational teeth rather than staying purely conceptual.
Right 1: Access
You can request a summary of what personal data a company holds about you, why they're processing it, and who else they've shared it with. This is the starting point for everything else — you can't correct or erase data you don't know exists, so this right is what makes the others usable in practice.
Right 2: Correction and erasure
You can ask a company to fix inaccurate or outdated data, complete missing fields, or delete data outright. There's an important limit worth understanding here: erasure isn't unconditional the way some people assume — it applies specifically where the data is no longer needed for the purpose it was originally collected for, not simply because you'd prefer it gone. Withdrawing consent stops further processing, but doesn't automatically trigger deletion if the company has a legitimate ongoing reason (a legal retention requirement, for instance) to keep it.
Right 3: Grievance redressal
Every Data Fiduciary is required to provide an accessible way for you to raise a complaint, typically through a designated Grievance Officer. If you're not satisfied with how it's handled, you can escalate to the Data Protection Board of India, the regulatory body set up specifically to adjudicate these disputes.
Right 4: Nomination
This one is less commonly known and somewhat distinctive to India's framework — you can nominate another person to exercise your data rights on your behalf in the event of your death or incapacity, similar in spirit to a nominee on a bank account, but for your digital data rights specifically.
How to actually exercise these rights, step by step
- Find the company's privacy policy or "Data Protection Policy" — it should list a Grievance Officer's contact details and the process for rights requests.
- Submit your request clearly — state which right you're exercising (access, correction, erasure) and what specifically you're asking for.
- Wait for a response within the prescribed timeframe — companies are required to respond within timelines set by the DPDP Rules, and exercising these rights should be free of charge unless your request is excessive or repetitive.
- If refused, ask for the specific reason — a company must provide a clear justification, usually citing a legal retention obligation, if it declines your request.
- Escalate to the Data Protection Board if the company's response is inadequate or the issue remains unresolved after going through their grievance process.
What the DPDP Act doesn't cover
It's worth being realistic about the limits. Compared to more expansive frameworks like GDPR, the DPDP Act doesn't include a right to data portability or a right to object to processing on grounds beyond consent. The central government can also exempt certain government agencies from parts of the Act on grounds like national security — a carve-out worth knowing exists, even if it doesn't affect most everyday consumer data requests.
Why this connects to your broader exposure
These rights give you a formal path to clean up your data at the source — with companies that are still holding information you've asked them to delete or correct. They don't, however, touch data that's already circulated beyond that company — copied into a breach dump, scraped by a data broker, or resold across markets outside any single company's direct control. Understanding your digital footprint as a whole means combining these formal legal rights with a direct check of what's actually out there. Scan My Shadow checks your phone number and email across 1,500+ sources, covering exactly the layer that DPDP rights requests, aimed at individual companies, can't reach on their own.
FAQs
Do I have to pay to exercise my DPDP rights?
No — exercising these rights is free unless your request is excessive or clearly repetitive, in which case a company may be permitted to push back.
Can a company simply ignore my erasure request?
No, but they can lawfully decline it with a valid reason — most commonly, a legal or regulatory retention requirement that overrides your erasure request for that specific data.
What happens if I escalate to the Data Protection Board and I'm still not satisfied?
The Board is designed to adjudicate these disputes directly, with the authority to impose penalties on non-compliant Data Fiduciaries — as the enforcement track record matures, this process is expected to become clearer and more predictable over time.
Curious what's already out there about you? Scan My Shadow checks your phone number and email across 1,500+ sources and sends you a clear report — no guesswork, just facts. Start your scan.

Comments
Post a Comment