Consult an Expert
Business Setup
Trademarks & IP
Accounting & Tax
Licenses & Registrations
| Right | What It Means | Section |
|---|---|---|
| Notice and consent An organisation must give you notice and obtain consent | before processing your personal data, unless the processing falls under a listed legitimate use | Sections 5 to 7 |
| Right to access information | You can ask for a summary of the personal data being processed and the identities of parties it has been shared with | Section 11 |
| Right to correction and updating | You can ask an organisation to correct, complete or update your personal data | Section 12 |
| Right to erasure | You can ask for your data to be erased once the purpose of processing is served or where you withdraw consent | Section 12 |
| Right to grievance redressal | You can raise a grievance with the organisation and expect a response within the prescribed time | Section 13 |
| Right to nominate | You can nominate a person to exercise your rights on your death or incapacity | Section 14 |
The Act also places duties on data principals, including not filing false or frivolous complaints and not impersonating another person while exercising these rights. These duties are relevant when a complaint is examined by the organisation or the Board, and we advise clients accordingly when preparing a grievance or complaint.
The DPDP Act, 2023 and the rules made under it are being brought into force in phases rather than all at once. Where you stand today, and which remedy is realistically available, depends on which phase is currently in effect. This is worth confirming before relying on any specific provision.
| Phase | In Force From | What It Means for You |
|---|---|---|
| Phase 1 | 13 November 2025 | The Data Protection Board of India is constituted and the complaints mechanism is operational |
| Phase 2 | November 2026 | Consent managers are registered and operating, giving individuals a structured way to manage consent |
| Phase 3 | May 2027 | Provisions on notice, consent, security safeguards, breach reporting, rights enforcement and penalties become fully enforceable |
Until Phase 3 is fully in force, individuals are not without recourse. Remedies for loss also continue to run under the Information Technology Act, 2000, including Section 43A (compensation for negligent handling of sensitive personal data), Section 72A (disclosure of information in breach of a lawful contract), and Section 66E (violation of privacy through capturing or publishing images), as well as under consumer law, where non-consensual disclosure of data may amount to an unfair trade practice under Section 2(47) of the Consumer Protection Act, 2019.
Note: Phase dates and the scope of what is enforceable at each stage should be verified against current notifications, as the government may revise timelines. See meity.gov.in for the latest official updates.
Data misuse takes many forms, from a breach at a company you have dealt with to apps scraping your contacts without consent. Identifying the correct route, whether that is the grievance officer, the Board, the police, or a civil claim, depends on the specific problem.
Data Breach at a Company You Deal With
Where a bank, e-commerce platform, or service provider has suffered a breach affecting your data, we help you understand what was disclosed and the steps available to you.
Personal Data Sold or Shared for Marketing and Spam
Where your number or details have been shared without consent, resulting in unwanted calls or messages, we help you raise this with the organisation and, where appropriate, the Board.
Loan and Other Apps Scraping Contacts and Photos
Where an app has accessed contacts, photos, or other data beyond what is necessary or consented to, we help you document the permissions granted and pursue the appropriate complaint.
Refusal to Correct or Erase Data
Where an organisation does not act on a correction or erasure request within the prescribed time, we help you escalate the matter.
Photos or Details Posted Without Consent
Where your photos or personal details have been posted online without your consent, we assess whether civil, criminal, or injunctive remedies are appropriate.
CCTV and Workplace Surveillance Beyond Purpose
Where surveillance extends beyond its stated purpose, such as monitoring unrelated to safety or business need, we help you assess your position.
Children's Data Processed Without Verifiable Parental Consent
Where a platform processes a child's data without verifiable parental consent, we help parents or guardians raise the issue with the organisation and, where required, the Board.
Identity Misuse from Leaked Data
Where leaked data has been used for identity theft or fraud, we help you take the appropriate steps.
The right route for a data protection complaint depends on what you are seeking, whether that is correction of your data, a direction against the organisation, or compensation for loss suffered. We help you identify the appropriate forum and prepare the complaint.
| Route | When | What It Gives |
|---|---|---|
| Grievance officer of the data fiduciary | First step in most cases; a response is expected within the time prescribed under the Rules | Correction, erasure, or resolution directly from the organisation |
| Data Protection Board of India | After the grievance route has been exhausted or has failed | Inquiry into the complaint, directions to the fiduciary, and penalties where a contravention is established; complaints are filed digitally, with appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) |
| Civil court and IT Act Section 43A | Where you have suffered quantifiable loss due to negligent handling of sensitive personal data | Compensation, while Section 43A continues to operate |
| Consumer commission | Where you are a consumer and the conduct amounts to a deficiency in service or unfair trade practice | Compensation and other consumer remedies |
| Police and cybercrime portal | Where the conduct involves an offence such as morphing, stalking, or extortion under the IT Act or Bharatiya Nyaya Sanhita | Criminal investigation and proceedings |
It is worth being clear about what the Board can and cannot do: the Board can direct the organisation to take corrective action and impose penalties for contraventions, but it does not award compensation to you. Where compensation is the objective, a parallel civil, IT Act, or consumer claim needs to be considered.
Where an organisation suffers a personal data breach, it is required to inform affected individuals and the Data Protection Board without delay, with a detailed report to the Board within 72 hours under the Rules. As an affected individual, you are entitled to know what data was compromised, what steps you should take, and, where you have suffered loss, to pursue compensation.
Talk to a Expert Lawyer
Under the Schedule to the DPDP Act, the Data Protection Board can impose penalties on an organisation for failing to take reasonable security safeguards, with a ceiling of up to ₹250 crore for such a contravention. Lower ceilings apply to failures such as inadequate breach notification, violations relating to children's data, and non-compliance with the additional obligations placed on Significant Data Fiduciaries. It is important to note that these penalties are paid to the government and do not go to the affected individual.
Note: Specific penalty amounts and the categories they attach to should be verified against the current Schedule at the time of filing, as these figures are set by the Act and Rules and may be clarified or revised.
Every organisation that processes the digital personal data of individuals in India is a data fiduciary under the Act, with obligations relating to notice, consent, security safeguards, data retention, breach reporting, and handling of individual rights requests, to be fully in place by May 2027. Organisations classified as Significant Data Fiduciaries carry additional duties, including data protection impact assessments, periodic audits, and appointment of a Data Protection Officer.
For structured support in preparing your organisation for these requirements, explore our [DPDP compliance advisory for businesses].
Enforcing a data protection right typically moves from documenting what happened to raising it with the organisation, and, where necessary, escalating to the Board or another authority. We guide you through each stage based on your specific situation.
Collect screenshots, notices, spam records, breach emails, and any other material showing what happened and when. You receive: Evidence File
We help you prepare a formal request or grievance covering access, correction, erasure, or breach details, as relevant to your situation. You receive: Request Record
Where the organisation does not respond adequately within the prescribed time, we help you file a complaint with the Data Protection Board. You receive: Filed Complaint
Where you have suffered demonstrable loss, we help you pursue a civil, IT Act, or consumer claim alongside the Board complaint. You receive: Filed Claim
We help you understand the Board's order or the court's decision and, where necessary, pursue an appeal before the TDSAT. You receive: Order Copy
The documents that matter in a data protection complaint depend on the nature of the issue, but the following are commonly required:
Filing a grievance with an organisation's grievance officer and a complaint with the Data Protection Board does not involve a filing fee. A civil claim for compensation, on the other hand, carries the applicable court fee based on the amount claimed. We offer a ₹99 online lawyer consultation to help you understand the right route before proceeding.
On timelines, a grievance officer is expected to respond within the period prescribed under the Rules, while a Board inquiry can take several months depending on its workload and the complexity of the matter. These timelines are indicative and depend on the facts of each case, the forum involved, and the responsiveness of the other party.
Zolvit Consumer Lawyer help individuals and businesses navigate the DPDP Act, the IT Act, and consumer law together, since a single data protection issue can often be pursued through more than one route depending on the facts.
Why Zolvit
Zolvit does not promise a particular outcome, a specific penalty on the organisation, or a guaranteed compensation figure. These depend on the facts, the evidence available, and the decision of the competent authority.