THE RULES

Rule 9 - Contact information of person to answer questions about processing

Official text

Every Data Fiduciary shall prominently publish on its website or app, and mention in every response to a communication for the exercise of the rights of a Data Principal under the Act, the business contact information of the Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary the questions of the Data Principal about the processing of her personal data.

Cross-references

Rule 9

Commentary

Rule 9 creates a continuing point of accountability between every Data Fiduciary and the individuals whose personal data it processes. Its essential effect is simple: a Data Fiduciary must remain practically reachable through a competent and authorised privacy contact, and that contact must remain visible both generally and throughout every Data Principal rights interaction.

The Rule does not require every Data Fiduciary to appoint a Data Protection Officer. It recognises two possible arrangements:

  • where appointment of a DPO is legally required, the DPO’s business contact information must be provided; and

  • in every other case, the Data Fiduciary must designate a person capable of answering questions about personal-data processing on its behalf.

Rule 9 is scheduled to come into force on 13 May 2027, along with the principal substantive obligations and rights with which it operates.

The DPDPA cannot operate effectively if a Data Principal receives a privacy notice but has nobody to approach when the actual processing is unclear. Similarly, statutory rights have little practical value if an individual receives an automated response and cannot ask why her request was refused, partly fulfilled or made subject to further verification.

Rule 9 addresses this problem by imposing two connected requirements.

First, the Data Fiduciary must prominently publish the relevant business contact information on its website or application. This gives the Data Principal an accessible starting point for questions about processing.

Second, the Data Fiduciary must repeat that contact information in every response to a communication made for exercising a right under the DPDPA. This ensures that the interaction does not become a closed or unchallengeable automated process.

The Rule therefore supports both general transparency andcase-specific accountability. It ensures that the Data Principal can find the organisation before making a request and can continue communicating with it after receiving a response.

1.2 Relationship with the DPDPA

Rule 9 principally gives effect to Section 8(9), which requires publication of the business contact information of the Data Protection Officer, where applicable, or another person capable of answering questions raised by Data Principals about the processing of their personal data.

Its operation also supports:

  • Section 5, concerning notice;

  • Section 6, concerning consent and withdrawal;

  • Section 11, concerning access to information about processing;

  • Section 12, concerning correction, completion, updating and erasure;

  • Section 13, concerning grievance redressal;

  • Section 14, concerning nomination;

  • Section 8(6) and Rule 7, concerning breach intimation; and

  • Section 10, concerning the DPO of a Significant Data Fiduciary.

Rule 9 does not create a new substantive right to obtain every item of information requested from the contact person. Rather, it creates the communication infrastructure through which existing rights and questions about processing can be handled effectively.

The contact person is therefore not an informal customer-support convenience. That person or function forms part of the Data Fiduciary’s compliance architecture.

1.3 Who must provide the contact

The requirement applies to every Data Fiduciary, not only Significant Data Fiduciaries or large digital businesses.

A small employer, online retailer, hotel, hospital, educational institution, professional-services organisation or government body may not be required to appoint a statutory DPO. It must nevertheless identify an authorised person who can answer questions about its processing.

The scale of the mechanism may be proportionate to the organisation:

  • a small enterprise may use a monitored privacy email address administered by a trained compliance employee;

  • a medium-sized organisation may maintain a privacy team supported by a ticketing system;

  • a large platform may require a dedicated privacy portal, multilingual support, specialised rights teams and formal escalation procedures;

  • a Significant Data Fiduciary must publish the business contact information of its DPO.

What matters is not the size or title of the function. What matters is whether the contact is accessible, competent, authorised and capable of giving an accurate answer on behalf of the Data Fiduciary.

1.4 DPO and authorised privacy contact

For a Significant Data Fiduciary, the DPO occupies a distinct statutory position. The organisation should provide an official channel that reaches the DPO or DPO function. A general customer-service address will not be adequate where the support team cannot explain processing or coordinate the exercise of rights.

For other Data Fiduciaries, the authorised person could be a privacy officer, compliance officer, legal representative, grievance officer or another trained function. The Rule does not demand a particular designation.

However, merely naming an employee does not establish compliance. The designated person must be able to obtain reliable information concerning:

  • personal data collected or generated;

  • purposes of processing;

  • consent and other grounds relied upon;

  • relevant systems;

  • disclosures and Data Processors;

  • retention and erasure;

  • withdrawal of consent;

  • correction and access procedures;

  • grievances;

  • and breach-related questions.

The person does not need to know every technical detail immediately. The organisation must nevertheless give the contact sufficient authority, internal access and escalation support to obtain the answer and communicate it accurately.

Illustration

A customer asks an online retailer why her mobile number has been supplied to a delivery provider and whether the provider may send promotional messages.

The privacy contact should be able to determine:

  • why the number was originally shared;

  • whether the delivery provider acts as a Data Processor;

  • what contractual restrictions govern its use;

  • whether promotional use was authorised;

  • whether consent was obtained for marketing;

  • and what corrective step is required.

Telling the customer simply to contact the delivery provider would be inadequate if the retailer determined the original purpose and shared the data for processing on its behalf.

1.5 Business contact information

Rule 9 requires business contact information. It does not require the organisation to publish an employee’s private mobile number, residential address or personal email address.

A role-based business channel will often be more appropriate because it provides institutional continuity. Examples include:

  • a dedicated privacy email address;

  • a DPO email address;

  • a privacy portal;

  • an in-app rights or privacy channel;

  • an official telephone number; or

  • a business postal address where relevant.

A role-based address is useful only if it is actually monitored. An unattended mailbox or broken web form does not satisfy the practical object of the Rule.

The channel should also survive personnel changes. If the named privacy officer leaves, the Data Fiduciary must ensure that:

  • the published information remains correct;

  • messages continue to be received;

  • existing requests are preserved;

  • responsibility is reassigned;

  • and the website, application and response templates are updated.

1.6 Prominent publication

The contact must be easy to locate through ordinary use of the website or application.

A Data Fiduciary should not treat the requirement as satisfied merely because an email address appears near the end of a lengthy privacy policy or in a downloadable legal document. Prominence is concerned with practical visibility.

Depending on the service, the contact may appropriately appear in:

  • a clearly labelled privacy section;

  • account settings;

  • the rights centre;

  • the privacy notice;

  • the consent-management interface;

  • the grievance page; or

  • the principal help or support menu.

If the service operates through both a website and an application, publication through both channels is generally the more reliable approach. A user who interacts exclusively through an application should not be required to locate an unrelated corporate website to ask a privacy question.

Illustration

A mobile application contains a “Privacy and Personal Data” option in account settings. It identifies the responsible entity, supplies a direct contact link and explains that the channel may be used for questions concerning personal-data processing.

This is materially different from placing a privacy email address in small print within website terms that the app user is unlikely to see.

1.7 The contact must be capable of answering processing questions

Rule 9 is broader than a formal rights-request provision. Its contact mechanism should allow a Data Principal to ask ordinary but important questions such as:

  • Why is this information being collected?

  • Is this field necessary for the service?

  • Is my data used for marketing or profiling?

  • Which service provider has received it?

  • How long will it be retained?

  • What happens when I withdraw consent?

  • Why does an old address remain in your system?

  • Why was my erasure request only partly accepted?

  • Does your AI system use my information?

  • Which personal data remains after account deletion?

  • How do I raise a grievance?

The contact may answer a general question directly or identify that the communication should be treated as a formal access, correction, erasure or grievance request.

The organisation should focus on the substance of the individual’s communication rather than requiring precise statutory language. A Data Principal should not lose protection because she wrote “please tell me what information you have” rather than formally invoking Section 11.

1.8 Connection with Data Principal rights

The second part of Rule 9 requires the relevant contact information to appear in every response to a rights communication.

This is important because a rights request may involve several stages:

  1. acknowledgement;

  2. request for reasonable authentication;

  3. request for clarification;

  4. interim status update;

  5. substantive decision;

  6. explanation of partial fulfilment or refusal;

  7. grievance or escalation; and

  8. closure.

The language “every response” supports inclusion of the contact information throughout this chain, not merely in the final communication.

An automated acknowledgement should therefore not come from a closed “no-reply” address without identifying another functional privacy channel. Similarly, a refusal should not leave the Data Principal without a person capable of explaining the decision.

1.9 Illustration: Partial erasure

A former customer asks a financial institution to erase her account information. The institution erases optional marketing and profiling data but retains specified transaction and identification records because another law requires continued preservation.

The response should explain that distinction and provide the privacy contact so the former customer can ask:

  • precisely which data remains;

  • why retention is required;

  • how long it will continue;

  • who can access the retained records;

  • and whether the information remains available for ordinary commercial use.

The privacy contact should be able to explain that lawful retention does not necessarily permit continued marketing, profiling or unrelated analytics.

1.10 Interaction with notice under Rule 3

Rule 3 governs the notice accompanying or preceding a consent request. It requires information about the personal data, specified purpose, relevant goods or services, withdrawal, rights and complaints.

Rule 9 supplements that framework by ensuring that a person is available to explain the processing.

A compliant notice may state the required information but still leave the Data Principal with a legitimate question. For example, a notice may say that location data is used for delivery. The individual may wish to know whether the application collects precise location continuously or only the delivery address entered by her.

The Rule 9 contact gives her a route to obtain that explanation.

Rule 9 does not replace the need for a complete Rule 3 notice. A Data Fiduciary cannot provide a vague notice and expect the Data Principal to obtain all essential information separately through the contact person. The notice itself must satisfy the prescribed standard. The contact is supplementary.

The contact should support the Data Principal’s understanding of withdrawal, but it should not become a barrier to withdrawal.

If consent was given through a simple digital process, the Data Fiduciary should not require the Data Principal to contact an officer, justify her decision or complete an unnecessarily burdensome procedure before withdrawal is accepted.

The privacy contact should instead be able to explain:

  • which consent is being withdrawn;

  • the processing that will stop;

  • the time reasonably required to propagate the withdrawal;

  • the service consequences;

  • whether another legal ground supports limited continued processing;

  • which Data Processors must cease processing;

  • and what records must still be retained under law.

Illustration

A customer turns off personalised marketing in an application but continues receiving advertising messages.

The contact should investigate whether:

  • the preference was recorded;

  • the instruction reached the marketing system;

  • a Data Processor failed to update its suppression list;

  • the message had already been queued;

  • a different communication channel remained enabled;

  • or the message was transactional rather than promotional.

Sending the customer back to the same ineffective setting would not constitute meaningful accountability.

1.12 Interaction with grievance redressal

A question about processing is not always a grievance. But it can become one where the Data Fiduciary:

  • fails to respond;

  • provides an inaccurate answer;

  • does not fulfil a right;

  • continues withdrawn processing;

  • refuses correction;

  • retains data without proper justification;

  • or fails to control a Processor.

The privacy contact should therefore be connected to the grievance mechanism under Section 13.

A sensible system should allow the following progression:

  1. the Data Principal asks a processing question;

  2. the contact answers or routes it appropriately;

  3. if the issue concerns a statutory right, it enters the rights workflow;

  4. if the individual disputes the handling, it enters the grievance mechanism;

  5. the Data Fiduciary provides internal review; and

  6. the Data Principal may proceed to the Board after complying with the applicable exhaustion requirement.

The Data Fiduciary should not force the individual to begin again through an entirely separate channel merely because her question developed into a grievance.

1.13 Interaction with breach response

Rule 7 separately requires an intimation of a personal data breach to contain business contact information for a person capable of answering questions.

The Rule 9 contact may perform that role, but a significant breach may generate questions requiring specialised capability, such as:

  • whether a particular individual’s data was affected;

  • what categories of information were involved;

  • whether passwords should be changed;

  • whether a card should be blocked;

  • whether inaccurate information has been restored;

  • and what further support is available.

A large breach may justify a dedicated helpline or incident portal. That channel should remain coordinated with the ordinary privacy contact. The organisation should not publish several conflicting channels without explaining their purposes.

1.14 Contact does not transfer accountability

A Data Fiduciary may engage a customer-support provider or other Data Processor to operate the communication channel. But outsourcing the front-end service does not transfer legal responsibility.

The Data Fiduciary remains responsible for ensuring that the Processor:

  • follows documented instructions;

  • protects information received through inquiries;

  • authenticates requesters appropriately;

  • uses approved responses;

  • does not disclose information to the wrong person;

  • escalates complex questions;

  • maintains reliable records;

  • and does not independently use inquiry data.

The Processor should not be permitted to invent legal explanations or promise immediate deletion where statutory retention applies.

Similarly, a registered Consent Manager does not replace the Data Fiduciary’s Rule 9 contact. The Consent Manager may help the individual manage consent, but the Data Fiduciary remains responsible for explaining why it seeks the data, what it does with it and how long it retains it.

1.15 Group structures

A corporate group may maintain a central privacy office. Rule 9 does not prevent this arrangement, provided the central function can answer on behalf of the correct Data Fiduciary.

The Data Principal should not be required to determine complex corporate allocations before obtaining an answer.

A central privacy team should be able to identify:

  • the legal entity responsible for the service;

  • the processing operation concerned;

  • relevant Processors;

  • applicable retention;

  • and the entity responsible for acting on the request.

Where several group entities independently determine different processing purposes, those roles should be explained accurately. The existence of a common brand should not be used to obscure which entity is accountable.

1.16 Authentication and proportionality

The contact mechanism must balance accessibility with confidentiality.

A person asking a general question about the organisation’s retention policy should not ordinarily be required to provide an identity document.

By contrast, a person requesting account-specific personal data, correction of important records or erasure must be authenticated before the Data Fiduciary discloses or changes information.

Verification should be proportionate. The Data Fiduciary should not automatically demand additional identity documents where the Data Principal is already securely authenticated through her account and a lower-risk method is available.

The contact should be able to explain:

  • why verification is required;

  • what information is needed;

  • how it will be used;

  • how long it will be retained;

  • and whether an alternative verification method is available.

1.17 Internal capability required for meaningful answers

A privacy contact cannot answer accurately if the Data Fiduciary itself lacks basic governance information.

The function should have access to current:

  • personal-data inventories;

  • purpose maps;

  • notices and consent records;

  • systems and data-flow information;

  • Processor registers;

  • sharing arrangements;

  • retention schedules;

  • erasure procedures;

  • rights-handling standards;

  • grievance records;

  • and breach-response information.

This does not mean that every inquiry requires circulation across every department. It means that the organisation must know where authoritative information is held and how the contact can obtain it.

1.18 Illustration: AI processing question

An employee asks whether her performance data is used by an AI system to predict attrition.

The privacy contact should not respond based solely on the HR privacy notice if the organisation has activated a new analytics module. It should verify:

  • whether the system uses identifiable employee data;

  • the purpose of the analysis;

  • what data fields are involved;

  • who determines the processing;

  • whether a vendor uses the data;

  • what legal ground is relied upon;

  • how long outputs are retained;

  • and whether the result affects employment decisions.

Rule 9 therefore indirectly tests the quality of the Data Fiduciary’s internal records. An organisation that cannot explain its processing may have deeper problems concerning notice, purpose limitation, Processor management or accountability.

1.19 Quality and clarity of responses

The Rule does not prescribe the exact form of an answer, but the requirement that the contact be “able to answer” implies a meaningful response rather than a generic acknowledgement.

A good response should:

  • address the question actually asked;

  • use understandable language;

  • distinguish confirmed facts from matters under investigation;

  • avoid unsupported assurances;

  • explain any legal or operational limitation;

  • provide the next step;

  • and include the required contact information.

A response should not merely repeat the privacy policy if that does not resolve the question.

Example

For example, instead of saying:

“Your data is retained in accordance with applicable legal and operational requirements.”

the Data Fiduciary could explain:

“Your active customer profile has been erased. We continue to retain the invoice and payment-confirmation record because applicable tax and accounting law requires preservation of that transaction record. The retained record is restricted from marketing use and will be erased after the applicable legal period ends.”

The second answer gives the Data Principal a practical understanding of what remains, why it remains and how it may be used.

1.20 Security of the contact channel

The Rule 9 channel will itself process personal data. Data Principals may submit:

  • identity documents;

  • account information;

  • supporting records;

  • complaints;

  • medical information;

  • financial details;

  • correspondence;

  • or evidence of suspected misuse.

The channel must therefore be protected in accordance with Rule 6.

A privacy mailbox accessible to a large number of sales, marketing and customer-support employees may create unnecessary exposure. Access should be limited to personnel who need it, and sensitive requests should be transferred through secure systems.

The Data Fiduciary should also prevent:

  • disclosure to an impersonator;

  • insecure forwarding;

  • retention without a defined period;

  • use of inquiry information for marketing;

  • unauthorised downloads;

  • and excessive collection during verification.

1.21 Accessibility and practical usability

A contact is not genuinely available if the Data Principal cannot use it because of poor design.

The Data Fiduciary should account for:

  • app-only users;

  • persons using assistive technology;

  • users with limited digital literacy;

  • users who cannot use a voice-only channel;

  • elderly users;

  • and the language context of the service.

Rule 9 does not expressly prescribe an independent multilingual formula identical to Sections 5 and 6. Nevertheless, a Data Fiduciary serving individuals through Indian-language interfaces should ensure that privacy questions are not effectively restricted to technical English.

The organisation may use translation support, multilingual templates or language-capable personnel. The final answer should still be checked for accuracy, particularly where it concerns legal retention, consent withdrawal, breach consequences or refusal of a right.

1.22 Continuity and monitoring

Compliance is continuous. The contact must work after it is published.

The Data Fiduciary should periodically verify that:

  • the email address accepts messages;

  • the web form submits successfully;

  • the telephone number works;

  • requests receive acknowledgements;

  • rights-response templates reproduce the correct contact;

  • messages are assigned to responsible personnel;

  • absences and departures do not interrupt service;

  • escalations occur;

  • and unresolved requests remain visible.

A broken link or temporarily unavailable form may be a technical error. But repeated failure, failure to test or continued publication of obsolete information may show that the organisation has not maintained an effective contact mechanism.

1.23 Enforcement implications

Rule 9 does not have a separately named penalty entry. A significant breach may therefore fall within the residual Schedule entry for breach of another provision of the Act or Rules, which carries a maximum monetary penalty of up to ₹50 crore.

The ceiling is not automatic. The Board must follow the statutory inquiry process, determine that a significant breach occurred, provide an opportunity of hearing and apply the Section 33 factors.

The seriousness of non-compliance may be greater where:

  • no privacy contact exists;

  • the published channel is knowingly non-functional;

  • Data Principals are systematically unable to obtain answers;

  • rights responses repeatedly omit contact details;

  • the organisation uses the mechanism to frustrate withdrawal or erasure;

  • the defect continues after complaints;

  • inaccurate answers conceal unlawful processing;

  • or the absence of a functioning contact contributes to separate rights, grievance or breach-notification failures.

A short technical outage corrected promptly would ordinarily be different from a deliberate or systemic design that makes the Data Fiduciary practically unreachable.

1.24 Integrated interpretation

Rule 9 should be understood as a unified obligation of visibility, competence, continuity and answerability.

The Data Fiduciary must create a route through which a Data Principal can meaningfully connect with the person responsible for explaining personal-data processing. That route must be prominent in the service environment and must follow the Data Principal throughout every rights interaction.

The Rule does not require every organisation to build a large privacy department. It requires every Data Fiduciary to ensure that:

  • someone is authorised to answer;

  • that person can obtain accurate information;

  • the communication route is easy to find;

  • the route remains operational;

  • every rights response repeats the relevant contact;

  • questions can be escalated into rights or grievance procedures;

  • identity verification is proportionate;

  • the channel is secure;

  • and organisational changes do not break continuity.

Rule 9’s importance lies in the fact that it turns abstract statutory accountability into a practical relationship. A Data Fiduciary that determines why and how personal data is processed must remain capable of explaining those decisions to the individual concerned.

Key point

Rule 9 requires every Data Fiduciary to remain visibly and functionally answerable. The privacy contact is not merely an address published for formal compliance. It must be an authorised and supported point of accountability through which the Data Principal can understand the processing, clarify the handling of her rights, challenge an inadequate response and reach the organisation throughout the personal-data lifecycle.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.