Zolvit
Zolvit

Our Legal Expertise

Your Rights Under the Digital Personal Data Protection Act, 2023

RightWhat It MeansSection
Notice and consent An organisation must give you notice and obtain consent before processing your personal data, unless the processing falls under a listed legitimate use Sections 5 to 7
Right to access information You can ask for a summary of the personal data being processed and the identities of parties it has been shared with Section 11
Right to correction and updating You can ask an organisation to correct, complete or update your personal data Section 12
Right to erasure You can ask for your data to be erased once the purpose of processing is served or where you withdraw consent Section 12
Right to grievance redressal You can raise a grievance with the organisation and expect a response within the prescribed time Section 13
Right to nominate You can nominate a person to exercise your rights on your death or incapacity Section 14

The Act also places duties on data principals, including not filing false or frivolous complaints and not impersonating another person while exercising these rights. These duties are relevant when a complaint is examined by the organisation or the Board, and we advise clients accordingly when preparing a grievance or complaint.

Where the Law Stands Today: The Phased Timeline

The DPDP Act, 2023 and the rules made under it are being brought into force in phases rather than all at once. Where you stand today, and which remedy is realistically available, depends on which phase is currently in effect. This is worth confirming before relying on any specific provision.

PhaseIn Force FromWhat It Means for You
Phase 1 13 November 2025 The Data Protection Board of India is constituted and the complaints mechanism is operational
Phase 2 November 2026 Consent managers are registered and operating, giving individuals a structured way to manage consent
Phase 3 May 2027 Provisions on notice, consent, security safeguards, breach reporting, rights enforcement and penalties become fully enforceable

Until Phase 3 is fully in force, individuals are not without recourse. Remedies for loss also continue to run under the Information Technology Act, 2000, including Section 43A (compensation for negligent handling of sensitive personal data), Section 72A (disclosure of information in breach of a lawful contract), and Section 66E (violation of privacy through capturing or publishing images), as well as under consumer law, where non-consensual disclosure of data may amount to an unfair trade practice under Section 2(47) of the Consumer Protection Act, 2019.

Note: Phase dates and the scope of what is enforceable at each stage should be verified against current notifications, as the government may revise timelines. See meity.gov.in for the latest official updates.

Privacy and Data Problems We Handle

Data misuse takes many forms, from a breach at a company you have dealt with to apps scraping your contacts without consent. Identifying the correct route, whether that is the grievance officer, the Board, the police, or a civil claim, depends on the specific problem.

  • Data Breach at a Company You Deal With

    Where a bank, e-commerce platform, or service provider has suffered a breach affecting your data, we help you understand what was disclosed and the steps available to you.

    • Route: Breach notice review, grievance officer complaint, and compensation claim where loss is established.
  • Personal Data Sold or Shared for Marketing and Spam

    Where your number or details have been shared without consent, resulting in unwanted calls or messages, we help you raise this with the organisation and, where appropriate, the Board.

    • Route: Grievance officer complaint and Board complaint under the DPDP Act.
  • Loan and Other Apps Scraping Contacts and Photos

    Where an app has accessed contacts, photos, or other data beyond what is necessary or consented to, we help you document the permissions granted and pursue the appropriate complaint.

    • Route: Evidence preservation, grievance officer complaint, and Board complaint or police complaint where harassment follows.
  • Refusal to Correct or Erase Data

    Where an organisation does not act on a correction or erasure request within the prescribed time, we help you escalate the matter.

    • Route: Written request followed by Board complaint on non-response.
  • Photos or Details Posted Without Consent

    Where your photos or personal details have been posted online without your consent, we assess whether civil, criminal, or injunctive remedies are appropriate.

    • Route: IT Act and Bharatiya Nyaya Sanhita provisions, and injunction where continuing harm is shown.
  • CCTV and Workplace Surveillance Beyond Purpose

    Where surveillance extends beyond its stated purpose, such as monitoring unrelated to safety or business need, we help you assess your position.

    • Route: Grievance to the data fiduciary and Board complaint, where applicable.
  • Children's Data Processed Without Verifiable Parental Consent

    Where a platform processes a child's data without verifiable parental consent, we help parents or guardians raise the issue with the organisation and, where required, the Board.

    • Route: Grievance officer complaint and Board complaint, given the enhanced obligations for children's data under the Act.
  • Identity Misuse from Leaked Data

    Where leaked data has been used for identity theft or fraud, we help you take the appropriate steps.

    • Route: Cybercrime complaint and coordinated action; see our [fraud and cybercrime legal services].

How to Complain: Grievance Officer, Data Protection Board, Court

The right route for a data protection complaint depends on what you are seeking, whether that is correction of your data, a direction against the organisation, or compensation for loss suffered. We help you identify the appropriate forum and prepare the complaint.

RouteWhenWhat It Gives
Grievance officer of the data fiduciary First step in most cases; a response is expected within the time prescribed under the Rules Correction, erasure, or resolution directly from the organisation
Data Protection Board of India After the grievance route has been exhausted or has failed Inquiry into the complaint, directions to the fiduciary, and penalties where a contravention is established; complaints are filed digitally, with appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT)
Civil court and IT Act Section 43A Where you have suffered quantifiable loss due to negligent handling of sensitive personal data Compensation, while Section 43A continues to operate
Consumer commission Where you are a consumer and the conduct amounts to a deficiency in service or unfair trade practice Compensation and other consumer remedies
Police and cybercrime portal Where the conduct involves an offence such as morphing, stalking, or extortion under the IT Act or Bharatiya Nyaya Sanhita Criminal investigation and proceedings

It is worth being clear about what the Board can and cannot do: the Board can direct the organisation to take corrective action and impose penalties for contraventions, but it does not award compensation to you. Where compensation is the objective, a parallel civil, IT Act, or consumer claim needs to be considered.

After a Data Breach: What You Are Entitled To

Where an organisation suffers a personal data breach, it is required to inform affected individuals and the Data Protection Board without delay, with a detailed report to the Board within 72 hours under the Rules. As an affected individual, you are entitled to know what data was compromised, what steps you should take, and, where you have suffered loss, to pursue compensation.

  • What a breach notice must tell you: the nature of the breach, the categories of data affected, and the likely consequences
  • Steps to protect your accounts and credit: changing passwords, enabling additional verification, and monitoring your credit report, see our [credit report and CIBIL dispute services]
  • Evidence to preserve: the breach notification, correspondence with the organisation, and any resulting misuse such as spam or fraudulent transactions
  • When to complain to the Board: where the organisation has not notified you appropriately or has not taken adequate remedial steps
  • When a civil or IT Act claim is worth pursuing: where you can show actual loss resulting from the breach, since compensation depends on establishing that loss

Data Breach or Misuse? Know Your Legal Options

  • Understand your privacy rights
  • Assess the data incident
  • Explore available remedies
  • Get support with complaints

Talk to a Expert Lawyer

Penalties Organisations Face

Under the Schedule to the DPDP Act, the Data Protection Board can impose penalties on an organisation for failing to take reasonable security safeguards, with a ceiling of up to ₹250 crore for such a contravention. Lower ceilings apply to failures such as inadequate breach notification, violations relating to children's data, and non-compliance with the additional obligations placed on Significant Data Fiduciaries. It is important to note that these penalties are paid to the government and do not go to the affected individual.

  • Factors the Board considers: the nature, gravity and duration of the breach, the type of data involved, and whether the organisation took timely remedial action
  • Voluntary undertakings: an organisation may offer a voluntary undertaking during proceedings, which the Board may accept in place of, or alongside, further action
  • Appeal: an order of the Board can be appealed before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT)
  • No automatic compensation: a penalty imposed on the organisation does not by itself result in payment to you; a separate claim is required for that

Note: Specific penalty amounts and the categories they attach to should be verified against the current Schedule at the time of filing, as these figures are set by the Act and Rules and may be clarified or revised.

If You Are a Business: Your Obligations in Brief

Every organisation that processes the digital personal data of individuals in India is a data fiduciary under the Act, with obligations relating to notice, consent, security safeguards, data retention, breach reporting, and handling of individual rights requests, to be fully in place by May 2027. Organisations classified as Significant Data Fiduciaries carry additional duties, including data protection impact assessments, periodic audits, and appointment of a Data Protection Officer.

  • Conducting a data inventory to identify what personal data is collected and why
  • Building compliant notice and consent flows for data collection
  • Appointing a grievance officer and setting up a redressal process
  • Preparing a breach response runbook, including the 72-hour reporting requirement
  • Reviewing vendor and processor contracts for data protection obligations

For structured support in preparing your organisation for these requirements, explore our [DPDP compliance advisory for businesses].

Step-by-Step: Enforcing Your Data Rights

Enforcing a data protection right typically moves from documenting what happened to raising it with the organisation, and, where necessary, escalating to the Board or another authority. We guide you through each stage based on your specific situation.

Step 1: Gather Evidence

Collect screenshots, notices, spam records, breach emails, and any other material showing what happened and when. You receive: Evidence File

    Step 2: Written Request or Grievance to the Fiduciary

    We help you prepare a formal request or grievance covering access, correction, erasure, or breach details, as relevant to your situation. You receive: Request Record

      Step 3: Board Complaint on Non-Response

      Where the organisation does not respond adequately within the prescribed time, we help you file a complaint with the Data Protection Board. You receive: Filed Complaint

        Step 4: Parallel Claim for Loss, Where Justified

        Where you have suffered demonstrable loss, we help you pursue a civil, IT Act, or consumer claim alongside the Board complaint. You receive: Filed Claim

          Step 5: Orders, Penalties, and Compensation

          We help you understand the Board's order or the court's decision and, where necessary, pursue an appeal before the TDSAT. You receive: Order Copy

            Documents and Evidence

            The documents that matter in a data protection complaint depend on the nature of the issue, but the following are commonly required:

            • The consent form or privacy notice you were shown at the time
            • Screenshots of account and app permissions granted
            • Evidence of misuse, such as spam calls, messages, or unauthorised transactions
            • The breach notification received from the organisation, if any
            • Correspondence with the grievance officer or the organisation
            • Evidence of loss suffered, such as financial records or account statements
            • Identity proof for verification purposes

            Cost and Time

            Filing a grievance with an organisation's grievance officer and a complaint with the Data Protection Board does not involve a filing fee. A civil claim for compensation, on the other hand, carries the applicable court fee based on the amount claimed. We offer a ₹99 online lawyer consultation to help you understand the right route before proceeding.

            On timelines, a grievance officer is expected to respond within the period prescribed under the Rules, while a Board inquiry can take several months depending on its workload and the complexity of the matter. These timelines are indicative and depend on the facts of each case, the forum involved, and the responsiveness of the other party.

            Mistakes to Avoid

            • Skipping the grievance officer step, approaching the Board directly without first raising the issue with the organisation may affect how your complaint is received
            • Expecting compensation from the Board, the Board penalises the organisation; it does not award compensation to you
            • Deleting the app before capturing permissions, this can remove important evidence of what data was accessed and how
            • Agreeing to "delete your account" as full resolution, this may not address the data already collected, shared, or misused
            • Not reporting identity misuse to 1930, the national cybercrime helpline can be important for time-sensitive financial fraud arising from a breach
            • Filing a false or exaggerated complaint, data principals have a duty under the Act not to file frivolous or false complaints, and doing so can weaken your position

            Why Choose Zolvit for Privacy and Data Protection: How Our Lawyers Help

            Zolvit Consumer Lawyer help individuals and businesses navigate the DPDP Act, the IT Act, and consumer law together, since a single data protection issue can often be pursued through more than one route depending on the facts.

            • Rights Assessment at ₹99
            • Grievance and Board Complaints
            • Erasure, Correction and Access Demands
            • Breach Response and Compensation Claims
            • Police and Injunction Where Content Is Posted
            • Business Compliance Advisory
            • Why Zolvit

              • DPDP, IT Act and consumer routes combined for the strongest available remedy
              • Complaints drafted to match the Rules, reducing the risk of rejection on technical grounds
              • Compensation pursued only where a claim genuinely exists, based on demonstrable loss
              • Businesses guided toward compliance ahead of the 2027 enforcement deadline

            Zolvit does not promise a particular outcome, a specific penalty on the organisation, or a guaranteed compensation figure. These depend on the facts, the evidence available, and the decision of the competent authority.

            FAQs

            The DPDP Act, 2023 is being implemented in phases. Full enforcement of key provisions is expected by May 2027, subject to the applicable implementation timeline.
            You generally have rights to notice, consent, access, correction, erasure, grievance redressal, and nomination. Their enforceability depends on the implementation phase.
            You generally need to raise the issue with the organisation first. If it remains unresolved, a complaint can be filed with the Data Protection Board. A lawyer can help prepare the complaint.
            The Data Protection Board imposes penalties on organisations, not compensation to individuals. Depending on the facts, you may pursue compensation through other available legal remedies.
            Yes. You can request erasure of your personal data where applicable, including when the purpose of processing is fulfilled or consent is withdrawn. Unresolved requests can be escalated.
            An organisation must notify affected individuals and the Data Protection Board about a personal data breach as required under the applicable Rules and provide relevant details within the prescribed timelines.
            Accessing contacts or photos without clear consent or beyond the stated purpose may raise legal concerns. The permissions, notice, and purpose of processing determine whether the access is lawful.
            The DPDP Act provides for penalties of up to ₹250 crore for certain contraventions, including failure to implement reasonable security safeguards. The applicable penalty depends on the nature of the violation.
            A consent manager helps individuals give, manage, review, and withdraw consent for data processing through a single interface under the DPDP framework.
            Employers may process personal data for legitimate employment-related purposes, but monitoring is not unlimited. Excessive or improper surveillance may raise legal concerns.
            The DPDP Act provides additional safeguards for children's data, including verifiable parental or guardian consent and restrictions on tracking and targeted advertising.
            Yes. Depending on the circumstances, you may have civil or criminal remedies under applicable data protection, information technology, and criminal laws.
            The DPDP Act primarily covers digital personal data, including data collected offline and later digitised. Purely offline, non-digitised records generally fall outside its scope.
            A small business should start with a data inventory, review its notice and consent practices, establish grievance handling, and prepare a data breach response plan.