CHAPTER III - RIGHTS AND DUTIES OF DATA PRINCIPAL

Section 13 - Right of grievance redressal

Official text

(1)A Data Principal shall have the right to have readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager in respect of any act or omission of such Data Fiduciary or Consent Manager regarding the performance of its obligations in relation to the personal data of such Data Principal or the exercise of her rights under the provisions of this Act and the rules made thereunder.

(2)The Data Fiduciary or Consent Manager shall respond to any grievances referred to in sub-section (1) within such period as may be prescribed from the date of its receipt for all or any class of Data Fiduciaries.

(3)The Data Principal shall exhaust the opportunity of redressing her grievance under this section before approaching the Board.

Cross-references

Section 13

Commentary

Key point

Detailed clause-by-clause commentary on scope, accessibility, acts and omissions, Consent Managers, response periods, internal exhaustion, contact information and recourse to the Data Protection Board

Statutory provision

1. Right of grievance redressal.

(1) A Data Principal shall have the right to have readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager in respect of any act or omission of such Data Fiduciary or Consent Manager regarding the performance of its obligations in relation to the personal data of such Data Principal or the exercise of her rights under the provisions of this Act and the rules made thereunder.

(2) The Data Fiduciary or Consent Manager shall respond to any grievances referred to in sub-section (1) within such period as may be prescribed from the date of its receipt for all or any class of Data Fiduciaries.

(3) The Data Principal shall exhaust the opportunity of redressing her grievance under this section before approaching the Board.

2. Opening structure of Section 13

Section 13 creates a statutory internal-redress mechanism for disputes concerning personal-data processing.

Its structure contains three connected rights and obligations.

First, the Data Principal must have a readily available means through which a grievance can be raised against a Data Fiduciary or Consent Manager.

Second, the Data Fiduciary or Consent Manager must respond within the period prescribed under the Rules.

Third, the Data Principal must use and exhaust this internal opportunity before approaching the Data Protection Board of India.

The statutory sequence is:

  1. ACT OR OMISSION CONCERNING PERSONAL DATA OR EXERCISE OF A DATA PRINCIPAL RIGHT
  2. GRIEVANCE TO THE RELEVANT DATA FIDUCIARY OR CONSENT MANAGER
  3. RESPONSE WITHIN THE PUBLISHED REASONABLE PERIOD, WHICH CANNOT EXCEED NINETY DAYS
  4. GRIEVANCE RESOLVED OR INTERNAL OPPORTUNITY EXHAUSTED
  5. DATA PRINCIPAL MAY APPROACH THE DATA PROTECTION BOARD OF INDIA

Section 13 is therefore more than a requirement to publish an email address. It establishes a complete procedural stage between the occurrence of an alleged privacy failure and regulatory recourse before the Board.

At the same time, Section 13 does not itself create every remedy a Data Principal may demand. It creates the right to raise a grievance and receive a response concerning obligations and rights that arise elsewhere under the Act and Rules.

3. “A Data Principal shall have the right”

The opening words establish that grievance redressal is a statutory right of the Data Principal.

The mechanism is not merely:

  • a voluntary customer-support facility;

  • a contractual complaint route;

  • an internal corporate courtesy;

  • an informal communication channel.

The Data Fiduciary or Consent Manager must make the mechanism available because the Data Principal has a statutory entitlement to use it.

The Data Principal does not need to prove in advance that:

  • the Data Fiduciary has violated the Act;

  • the Consent Manager acted unlawfully;

  • a personal data breach occurred;

  • she suffered financial loss;

  • she suffered physical or emotional injury;

  • the act or omission was intentional.

The function of the grievance mechanism is to enable the Data Principal to present the issue so that the relevant entity can determine:

  1. what act or omission is alleged;

  2. which obligation or right is involved;

  3. whether the alleged failure occurred;

  4. what response or remedial action is appropriate.

A Data Principal may therefore raise a grievance about a procedural failure even where no separate loss has been demonstrated.

Example

For example, the Data Principal may complain that:

  • the rights-request mechanism does not work;

  • the Data Fiduciary failed to identify Data Processors in a Section 11 response;

  • inaccurate information remains active after a Section 12 request;

  • the Consent Manager did not transmit consent withdrawal;

  • the Data Fiduciary has not explained why personal data remains retained.

Each grievance concerns the performance of an obligation or exercise of a right, even if no monetary loss has resulted.

4. Who is entitled to raise a grievance?

A Data Principal is ordinarily the individual to whom the personal data relates.

The statutory definition also includes:

  • the parent or lawful guardian of a child; and

  • the lawful guardian of a person with disability acting on her behalf in the legally applicable circumstances.

A nominee may exercise rights following the Data Principal’s death or incapacity in accordance with Section 14, Rule 14(4), the terms of service and applicable law. Rule 14 permits nomination of one or more individuals using the means and particulars required by the Data Fiduciary.

The grievance mechanism may therefore be used by:

  • the adult Data Principal directly;

  • a verified parent or lawful guardian acting for a child;

  • a lawful guardian acting for a qualifying person with disability;

  • a valid nominee in the circumstances contemplated by Section 14.

A family relationship alone does not automatically authorise one person to access or alter another person’s personal data.

The Data Fiduciary or Consent Manager may need to verify:

  • identity of the requester;

  • account or record concerned;

  • parental or guardianship authority;

  • nomination;

  • circumstances activating a nomination;

  • connection between the grievance and the Data Principal’s personal data.

The verification process must be sufficient to prevent impersonation, but it should not be used to make grievance submission unnecessarily difficult.

Section 13 differs materially from Sections 11 and 12.

Section 11 expressly applies to the Data Fiduciary:

“to whom she has previously given consent, including consent as referred to in clause (a) of section 7.”

Section 12 applies to personal data:

“for the processing of which she has previously given consent, including consent as referred to in clause (a) of section 7.”

Section 13 contains neither limitation.

It refers instead to:

  • any act or omission;

  • of a Data Fiduciary or Consent Manager;

  • regarding performance of its obligations;

  • in relation to the Data Principal’s personal data;

  • or exercise of her rights.

This difference must be given legal effect.

A Data Principal may use Section 13 concerning an applicable obligation even where the personal data is processed under another ground in Section 7.

Potentially relevant processing includes:

  • employment processing under Section 7(i);

  • medical-emergency processing;

  • public-health processing;

  • disaster-related processing;

  • State processing;

  • compliance with legal disclosure requirements;

  • compliance with judgments or orders.

The grievance will succeed or fail according to the obligation alleged, the processing ground, any applicable exemption and the facts. It cannot be rejected solely because the Data Principal did not consent to the original processing.

7. Employment example

An employer processes employee payroll and attendance information under Section 7(i).

The employee discovers that payroll information was disclosed through an insecure vendor system.

The employer cannot reject the employee’s grievance on the ground that payroll processing did not depend on consent. The grievance concerns:

  • Section 8(1) responsibility for processor activity;

  • Section 8(5) security safeguards;

  • potentially Section 8(6) breach notification.

Section 13 contains no prior-consent condition that excludes the grievance.

8. Medical-emergency example

A hospital processes an unconscious patient’s personal data under the medical-emergency ground.

The patient later alleges that the hospital used the emergency information for an unrelated commercial purpose.

The patient may raise a grievance about the alleged misuse. The absence of prior consent does not remove the hospital’s generally applicable obligations.

9. State processing

Where a government authority acts as a Data Fiduciary under Section 7, a Data Principal may raise a grievance concerning an applicable obligation, subject to Section 17, other statutory exemptions and the law authorising the processing.

Section 13 is not a general freedom-of-information provision and does not allow the Data Principal to challenge every administrative decision as a privacy grievance. The issue must concern:

  • the Data Principal’s personal data;

  • an applicable DPDPA obligation; or

  • a right available under the Act and Rules.

10. Section 13 does not enlarge Sections 11 and 12

The broader grievance right does not eliminate the express conditions attached to Sections 11 and 12.

A distinction must be maintained between:

  1. the right to raise a grievance; and

  2. entitlement to the particular substantive remedy requested.

11. Section 11 example

An employee seeks the full Section 11 information package concerning personal data processed solely under Section 7(i).

The employer takes the position that Section 11’s express prior-consent condition is not satisfied.

The employee may raise a Section 13 grievance challenging that interpretation. The employer must examine and respond to the grievance.

However, Section 13 does not automatically grant the employee the Section 11 information if Section 11 does not legally apply.

12. Section 12 example

A bank customer requests erasure of records that banking law requires the bank to retain.

The customer may raise a grievance against the refusal.

The bank must respond, but Section 13 does not override the legal-retention exception in Section 12(3).

The appropriate response may explain:

  • the personal data retained;

  • the applicable legal requirement;

  • the retention period;

  • the restrictions placed on use;

  • the personal data erased because no exception applied.

The legal position is therefore:

BROAD RIGHT TO RAISE A GRIEVANCE

DOES NOT MEAN

AUTOMATIC ENTITLEMENT TO EVERY REMEDY REQUESTED

Section 13 requires examination and response. The substantive outcome continues to depend on the provision being invoked.

13. Two independent limbs within Section 13(1)

Section 13(1) contains two separate grounds for grievance.

A grievance may concern:

  1. performance of the Data Fiduciary’s or Consent Manager’s obligations in relation to the Data Principal’s personal data; or

  2. exercise of the Data Principal’s rights under the Act and Rules.

These two limbs overlap but are not identical.

14. First limb: Performance of obligations

This limb covers alleged failure to comply with duties under the Act or Rules.

Example

Examples include:

  • failure to provide valid notice;

  • invalid consent;

  • processing beyond a Section 7 purpose;

  • failure to use a valid processor contract;

  • failure to protect personal data;

  • failure to notify a breach;

  • failure to erase personal data after the purpose ends;

  • unlawful child-data processing;

  • failure to publish contact information;

  • failure to operate an effective grievance mechanism.

The Data Principal does not need to identify a separately titled right in Chapter III. It is sufficient that the grievance concerns an applicable obligation relating to her personal data.

14.1 Example: Security

Section 8(5) imposes a security obligation on the Data Fiduciary. Chapter III does not separately create a right titled “right to security.”

Section 13 nevertheless permits a grievance concerning the Data Fiduciary’s alleged failure to protect the Data Principal’s personal data.

14.2 Example: Processor conduct

A cloud, payroll or marketing provider acts as a Data Processor on behalf of the Data Fiduciary.

If the processor misuses or exposes the Data Principal’s personal data, the Data Principal may raise a grievance with the Data Fiduciary concerning its Section 8 responsibility.

15. Second limb: Exercise of rights

This limb concerns the operation of the rights mechanisms themselves.

It includes grievances concerning:

  • access under Section 11;

  • correction, completion, updating or erasure under Section 12;

  • grievance redressal under Section 13;

  • nomination under Section 14;

  • consent withdrawal under Section 6.

15.1 Example: Access response

The Data Fiduciary responds to a Section 11 request but identifies only categories of service providers instead of their identities.

The Data Principal may raise a grievance that the response does not satisfy Section 11(1)(b).

15.2 Example: Correction

The Data Principal supplies reliable evidence of her corrected bank details, but the old details remain active in the processor’s system.

The grievance concerns both:

  • exercise of the Section 12 right; and

  • the Data Fiduciary’s responsibility for processing undertaken on its behalf.

16. “Readily available means”

The right is not merely to grievance redressal in the abstract. The means must be readily available.

This introduces an accessibility requirement.

A Data Fiduciary or Consent Manager does not satisfy Section 13 merely by technically maintaining an internal grievance mailbox known only to employees.

The Data Principal should be able to determine without unreasonable difficulty:

  • where to raise a grievance;

  • how to submit it;

  • what identification particulars are required;

  • how the grievance will be acknowledged or tracked;

  • the applicable response period.

17. What “readily available” does not prescribe

Section 13 does not require every Data Fiduciary to provide:

  • a toll-free number;

  • postal and electronic channels simultaneously;

  • twenty-four-hour staffed support;

  • a dedicated mobile application;

  • a particular button or webpage;

  • an in-person grievance desk.

The Data Fiduciary may select a mechanism appropriate to its processing and relationship with Data Principals.

The mechanism must nevertheless be practically usable.

18. Hidden mechanisms

A grievance means may not be readily available where it is:

  • buried in lengthy terms;

  • located behind unrelated menu options;

  • labelled only as general technical support;

  • available solely after login;

  • inaccessible after account closure;

  • available only by first contacting sales personnel;

  • dependent on an obsolete email address;

  • operated through a chatbot incapable of recording a privacy grievance.

19. Data Principals without user accounts

Not every Data Principal will hold an account.

The Data Fiduciary may process personal data concerning:

  • CCTV subjects;

  • visitors;

  • former employees;

  • rejected applicants;

  • former customers;

  • vendor personnel;

  • emergency patients;

  • persons whose data was indirectly received.

A grievance mechanism available only through an authenticated customer account may not be readily available to those persons.

The Data Fiduciary should provide a route that corresponds with the categories of individuals whose personal data it processes.

20. Accessibility

A mechanism may also need to account for:

  • assistive technologies;

  • visual or hearing impairment;

  • limited digital access;

  • language;

  • guardians and nominees.

Section 13 and Rule 14 do not prescribe a universal accessibility format. The mechanism must nevertheless be capable of practical use by the relevant Data Principal.

21. Rule 14(1): Publication of the rights mechanism

Rule 14 requires the Data Fiduciary and, where applicable, the Consent Manager to prominently publish on its website, application or both:

  • the details of the means using which a Data Principal may make a request;

  • the particulars required to identify her under the terms of service.

The publication requirement operationalises the general concept of ready availability.

22. “Prominently publish”

The Rule does not prescribe:

  • font size;

  • page position;

  • colour;

  • mandatory footer placement;

  • a fixed label.

The information must be reasonably visible and discoverable.

A privacy mechanism may not be prominent where the Data Principal must search through multiple unrelated documents or screens to locate it.

23. Initial requests and grievances

The Data Fiduciary should distinguish between:

  • an initial request to exercise a right; and

  • a grievance concerning the handling of that request or another act or omission.

Example

For example:

“Please erase my optional marketing profile.”

This is an initial Section 12 request.

“You refused to erase my marketing profile and did not identify any continuing purpose or legal requirement.”

This is a Section 13 grievance.

The same portal may receive both, but the entity should classify and process them correctly.

24. Identification particulars under Rule 14

Rule 14 allows the Data Fiduciary to require particulars such as a username or other identifier to identify the Data Principal.

An identifier includes a sequence of characters issued by the Data Fiduciary, including:

  • customer identification file number;

  • customer acquisition form number;

  • application reference number;

  • enrolment ID;

  • email address;

  • mobile number;

  • licence number.

The list is inclusive rather than exhaustive.

25. Purpose of identification

Identification helps the Data Fiduciary or Consent Manager:

  • associate the grievance with the correct personal data;

  • investigate the relevant processing;

  • prevent impersonation;

  • protect another person’s information;

  • communicate securely.

26. Proportionate identification

The Rules do not authorise unlimited identity collection.

The required particulars should correspond with what is reasonably needed to identify the Data Principal and investigate the grievance.

Where an authenticated account holder raises a grievance from within the account, demanding an additional complete identity document may be unnecessary unless the risk justifies it.

Where a former account holder seeks access to highly consequential data, stronger verification may be appropriate.

The grievance mechanism should not require Aadhaar or other high-detail identity information merely for administrative convenience unless another law or genuine risk justifies it.

27. Grievance clock and identification

Section 13(2) measures the response period from receipt of the grievance.

Neither Section 13 nor Rule 14 expressly states that the period begins only after identity verification is completed.

Where additional particulars are genuinely required, the entity should request them promptly.

It should not leave the grievance unregistered or indefinitely suspend the statutory period merely because its own initial form failed to request adequate information.

Section 13 expressly applies to two categories of regulated persons.

29. Data Fiduciary

The grievance may concern the Data Fiduciary’s decisions concerning:

  • purpose;

  • means;

  • consent;

  • legitimate use;

  • processors;

  • sharing;

  • retention;

  • security;

  • rights;

  • child-data processing.

A grievance against a Consent Manager may concern its own obligations in facilitating:

  • giving consent;

  • management of consent;

  • review of consent;

  • withdrawal of consent;

  • operation of the interoperable platform.

Example

For example, the Data Principal may allege that the Consent Manager:

  • recorded a consent she did not give;

  • failed to display an existing consent;

  • did not transmit withdrawal;

  • connected the wrong Data Fiduciary;

  • prevented access to her consent dashboard.

31. Determining the correct respondent

The grievance should be directed to the entity whose act or omission is alleged.

31.1 Example: Withdrawal correctly transmitted

The Consent Manager correctly transmits withdrawal, but the Data Fiduciary continues processing.

The grievance concerns the Data Fiduciary.

31.2 Example: Withdrawal not transmitted

The Data Principal submits withdrawal through the Consent Manager, but the Consent Manager fails to communicate it.

The grievance concerns the Consent Manager’s omission.

31.3 Example: Multiple failures

The Consent Manager transmits an incorrect instruction, and the Data Fiduciary fails to investigate a clear inconsistency.

Both entities may need to examine their respective conduct.

Section 13 does not permit either entity simply to redirect the Data Principal without determining whether its own act or omission contributed to the issue.

32. Why Data Processors are not named in Section 13

Section 13 does not expressly grant a grievance right against a Data Processor.

This reflects the accountability arrangement in Section 8.

The Data Fiduciary remains responsible for processing:

  • undertaken by it; and

  • undertaken on its behalf by a Data Processor.

A grievance concerning a processor should therefore ordinarily be addressed through the Data Fiduciary.

Example

Examples include:

  • payroll vendor uses the wrong bank details;

  • cloud provider exposes customer information;

  • marketing vendor continues after withdrawal;

  • AI vendor retains prompts contrary to instructions;

  • recruitment vendor fails to erase applicant data.

The Data Fiduciary may involve the processor in investigation and remediation. It cannot answer the Data Principal merely by saying:

“Please contact our vendor. We are not responsible for its system.”

A processor may independently become a Data Fiduciary for an operation where it determines its own purpose. A grievance concerning that independent processing would then be directed to it in its capacity as Data Fiduciary, not merely processor.

33. “In respect of any act or omission”

The phrase covers positive conduct and failures to act.

34. Acts

Potential acts include:

  • collection of personal data;

  • unauthorised disclosure;

  • processing for another purpose;

  • refusal of a rights request;

  • publication of personal data;

  • tracking;

  • continued marketing;

  • use of inaccurate information.

35. Omissions

Potential omissions include:

  • failure to give notice;

  • failure to stop after withdrawal;

  • failure to correct data;

  • failure to erase data;

  • failure to secure personal data;

  • failure to notify a breach;

  • failure to provide processor identities;

  • failure to establish a grievance mechanism;

  • failure to respond within the published period.

The inclusion of omissions is important because privacy harm frequently results from organisational inaction.

36. “Any” remains connected to the Act

The word “any” gives breadth, but the grievance must still relate to:

  • performance of an obligation concerning the Data Principal’s personal data; or

  • exercise of a statutory right.

An unrelated commercial complaint does not become a Section 13 grievance merely because the organisation holds the complainant’s personal data.

36.1 Not ordinarily a Section 13 grievance

“The product delivered was the wrong colour.”

36.2 Potentially a Section 13 grievance

“You sent my delivery address and purchase history to an unrelated seller without authority.”

The first concerns product performance. The second concerns personal-data processing.

A single communication may contain both consumer and privacy issues. The Data Fiduciary should separate and route each component appropriately.

37. “Regarding the performance of its obligations”

The grievance mechanism extends across the obligations applicable to the particular Data Fiduciary or Consent Manager.

For a Data Fiduciary, potential obligations include:

  • processing only for lawful purposes and valid grounds;

  • providing notice;

  • obtaining valid consent;

  • remaining within the Section 7 ground;

  • maintaining processor contracts;

  • taking responsibility for processor processing;

  • ensuring data quality where required;

  • implementing technical and organisational measures;

  • maintaining reasonable security safeguards;

  • notifying breaches;

  • erasing personal data;

  • publishing contact information;

  • establishing an effective grievance mechanism;

  • protecting children;

  • complying with SDF duties where applicable;

  • responding to rights.

For a Consent Manager, the grievance concerns the obligations applicable to its registered consent-management role.

The grievance mechanism is not limited to obligations contained in Chapter III. It extends to obligations throughout the Act and Rules where they relate to the Data Principal’s personal data.

38. “In relation to the personal data of such Data Principal”

The grievance must relate to the requester’s personal data.

The right is not a general public-interest complaint mechanism for persons who are unaffected by the processing.

A person may act for another Data Principal only where she has lawful authority, such as:

  • parent or lawful guardian;

  • lawful guardian of a qualifying person with disability;

  • valid nominee under Section 14.

39. Systemic issues

A grievance concerning one Data Principal may expose a broader control failure.

Example

For example, a user shows that the consent-withdrawal toggle does not stop marketing for any account.

The grievance remains linked with her personal data. However, the Data Fiduciary should examine whether the same omission affects other Data Principals.

Section 13 does not establish a class-action mechanism, but effective observance under Section 8(4) may require systemic remediation rather than correction of one account alone.

40. “Or the exercise of her rights”

This phrase makes the grievance mechanism an internal review route for failures concerning Data Principal rights.

It may cover:

  • inability to submit a request;

  • excessive identification requirements;

  • incomplete access response;

  • refusal to correct data;

  • refusal to erase;

  • inability to nominate;

  • non-functional consent withdrawal;

  • non-responsive grievance process.

The Data Fiduciary should examine both:

  1. whether the substantive right applied; and

  2. whether the procedure used to exercise it functioned correctly.

A request may fail because:

  • the right does not apply;

  • the request lacks necessary particulars;

  • an exception applies;

  • the Data Fiduciary’s system is defective;

  • the entity misinterpreted the law.

Section 13 gives the entity an opportunity to review that conclusion before the matter reaches the Board.

Rule 14(2) states that, to exercise Data Principal rights, she may make a request to the Data Fiduciary to whom she previously gave consent, using the published means and particulars.

This wording should not be interpreted as inserting into Section 13 the prior-consent limitation that Parliament expressly included in Sections 11 and 12 but omitted from Section 13.

A coherent reading is:

  • Rule 14(2) provides the request procedure for consent-connected rights, particularly Sections 11 and 12;

  • Rule 14(3) separately governs grievance redressal by every Data Fiduciary and Consent Manager;

  • Section 13 remains available for acts or omissions concerning any applicable statutory obligation or right.

Rules are subordinate to the Act and should not be read to narrow the express statutory right beyond the language enacted by Parliament.

The omission of consent and Section 7(a) from Section 13 is therefore legally meaningful.

42. Section 13(2): “Shall respond”

The Data Fiduciary or Consent Manager has a mandatory obligation to respond.

A response is more than:

  • receipt;

  • reference-number generation;

  • automated acknowledgement;

  • notification that the grievance was forwarded.

A substantive response should communicate the entity’s position.

It may:

  • accept the grievance;

  • partially accept it;

  • reject it;

  • explain necessary further information;

  • explain a statutory exception;

  • identify remedial action;

  • identify that the grievance concerns another entity while addressing its own role.

43. Acceptance

Where the grievance is valid, the response should explain:

  • what failure occurred;

  • what action has been taken;

  • whether processors were instructed;

  • whether data was corrected or erased;

  • whether processing stopped;

  • whether additional action remains pending.

Section 13 does not require an admission of legal liability in every response. It requires meaningful redress and an intelligible outcome.

44. Partial acceptance

A grievance may contain several claims.

Example

For example:

  • marketing after withdrawal is accepted;

  • a demand to erase a legally retained invoice is refused.

The response should treat each component separately.

45. Rejection

A grievance may be rejected where:

  • the alleged processing did not occur;

  • the requested right does not apply;

  • the requester cannot be identified;

  • the grievance concerns another person;

  • legal retention applies;

  • the demand exceeds the statute.

A rejection should ordinarily include reasons sufficient to enable the Data Principal to understand the conclusion and decide whether to approach the Board.

46. Rule 14(3): Reasonable period not exceeding ninety days

Rule 14 requires every Data Fiduciary and Consent Manager to publish a reasonable grievance-response period. That period cannot exceed ninety days.

47. Ninety days is the maximum

The Rule does not grant every entity an automatic ninety-day period.

It requires the published period to satisfy two conditions:

  1. it must be reasonable;

  2. it must not exceed ninety days.

A straightforward grievance may reasonably be resolved much faster.

Example

For example:

  • updating an incorrectly recorded withdrawal;

  • restoring a disabled rights link;

  • correcting a processor identity omitted from a response.

A complex grievance involving:

  • archived systems;

  • multiple processors;

  • disputed identity;

  • legal-retention analysis;

  • security investigation;

may reasonably require more time, subject to the published period and ninety-day ceiling.

48. The period must be published

The entity must state the period prominently.

An assurance such as:

“We respond as soon as possible”

does not specify a period.

A clear formulation would be:

“We will respond to privacy grievances within thirty days from receipt.”

The chosen period should reflect the entity’s actual capability and should be supported by technical and organisational measures.

49. From receipt

Section 13(2) measures the period from receipt of the grievance.

The entity should record:

  • date received;

  • channel;

  • reference number;

  • identity particulars;

  • assignment;

  • response date.

A grievance clearly submitted through a general support channel should not be treated as legally nonexistent merely because it was not filed through the preferred privacy form. The entity may redirect it internally and ask the Data Principal to supply any missing particulars.

50. Interim responses

An interim update may be appropriate where investigation continues.

However, an automated or interim update should not be treated as the final statutory response if it does not address the grievance.

Rule 14 does not expressly provide for extension beyond ninety days.

51. Appropriate technical and organisational measures

Rule 14(3) requires more than publication of a timeline. The Data Fiduciary and Consent Manager must implement appropriate technical and organisational measures to ensure that the grievance system responds within that period.

52. Technical measures

Depending on the operation, these may include:

  • intake forms;

  • unique case references;

  • secure document upload;

  • deadline calculation;

  • escalation alerts;

  • account matching;

  • case histories;

  • processor task assignment;

  • response records.

The Rule does not prescribe specific grievance software.

53. Organisational measures

These may include:

  • identified responsibility;

  • staff training;

  • legal and privacy escalation;

  • DPO oversight where applicable;

  • processor cooperation;

  • decision authority;

  • quality review;

  • recurring-issue analysis.

The published period is not meaningful unless the organisation has systems and personnel capable of meeting it.

54. Processor dependence

The Data Fiduciary must structure processor contracts and workflows so that a processor can assist within the Data Fiduciary’s response period.

The Data Fiduciary cannot justify a late response merely by saying:

“Our vendor has not replied.”

Section 8(1) keeps responsibility with the Data Fiduciary for processing undertaken on its behalf.

55. Relationship with Section 8(10)

Section 8(10) requires every Data Fiduciary to establish an effective mechanism to redress Data Principal grievances.

Section 13 creates the corresponding individual right.

Rule 14(3) supplies the response-period and operational requirements.

The provisions work together as follows:

SECTION 8(10)

The Data Fiduciary must establish an effective mechanism

SECTION 13(1)

The Data Principal has the right to readily available means

SECTION 13(2) AND RULE 14(3)

The entity must respond within a published reasonable period not exceeding ninety days

SECTION 13(3)

The Data Principal must exhaust the internal opportunity before approaching the Data Protection Board

A mechanism may be ineffective where:

  • it cannot receive grievances;

  • it only generates acknowledgements;

  • no investigation occurs;

  • departments do not cooperate;

  • processors cannot be queried;

  • responses routinely exceed the period;

  • the Data Principal cannot understand the outcome;

  • no corrective action is possible.

56. Published contact information under Section 8(9) and Rule 9

The Data Fiduciary must prominently publish the business contact information of:

  • its DPO, where applicable; or

  • another person able to answer questions on its behalf.

That information must also appear in every response to a communication concerning exercise of Data Principal rights.

This requirement supports Section 13 but is not identical to it.

57. Processing enquiries versus grievances

A processing enquiry asks for information.

“Why is my location being collected?”

A grievance alleges or challenges an act or omission.

“You continued collecting my location after I withdrew consent.”

The same contact person or channel may handle both, but the legal functions are different.

58. Significant Data Fiduciaries

For an SDF, the DPO must be the grievance point of contact under Section 10(2)(a)(iv).

The DPO may rely on a supporting team, but the grievance framework should remain connected with the DPO’s statutory role.

59. Other Data Fiduciaries

A non-SDF need not appoint a DPO solely for Section 13.

It must identify a person who can answer on behalf of the Data Fiduciary.

That person should have enough authority and access to:

  • understand the question;

  • obtain relevant facts;

  • coordinate investigation;

  • provide an authorised response;

  • escalate a grievance.

60. Business contact information

Appropriate business contact information may include:

  • official email;

  • official telephone number;

  • office address;

  • privacy portal.

The requirement does not compel publication of:

  • residential address;

  • private mobile number;

  • personal email.

A role-based contact may provide continuity when personnel change.

61. Section 13(3): Exhaustion before approaching the Board

Section 13(3) requires the Data Principal to exhaust the internal grievance opportunity before approaching the Data Protection Board of India.

This is a mandatory sequencing rule.

The Data Principal should ordinarily:

  1. submit the grievance to the relevant Data Fiduciary or Consent Manager;

  2. allow it the published period to respond;

  3. consider the response;

  4. approach the Board if the matter remains unresolved.

62. Purpose of exhaustion

The requirement allows the regulated entity to:

  • investigate;

  • correct an error;

  • explain an exception;

  • remedy processor failure;

  • stop unlawful processing;

  • avoid unnecessary Board proceedings.

It also gives the Board a record of:

  • the original grievance;

  • the entity’s response;

  • action taken;

  • unresolved issue.

63. Exhaustion does not require satisfaction

The Data Principal need not accept an unsatisfactory response.

The opportunity is exhausted where:

  • a substantive final response is given and the Data Principal remains dissatisfied; or

  • the published response period expires without an effective response.

The Data Principal should not be required to wait indefinitely because the entity leaves the grievance open.

64. No endless internal process

Section 13 does not expressly require multiple internal appeals.

A Data Fiduciary may voluntarily provide:

  • first-level review;

  • escalation;

  • DPO review;

  • internal appeal.

Those stages should not be used to postpone Board access beyond the statutory grievance opportunity.

An organisation should clearly identify what constitutes its final internal response.

65. Automated closure

An automated message that closes a grievance without considering its substance may not provide a meaningful redress opportunity.

The Data Principal should retain evidence of:

  • submission;

  • acknowledgement;

  • response;

  • closure;

  • elapsed time.

That record may be relevant before the Board.

66. Grievance against the correct respondent

Where the issue concerns the Data Fiduciary, the internal opportunity should be exhausted with that Data Fiduciary.

Where it concerns the Consent Manager, the opportunity should be exhausted with the Consent Manager.

Where both entities contributed, separate or coordinated grievances may be necessary.

The entities should not send the Data Principal in a loop.

Example

For example:

  • Consent Manager says the Data Fiduciary is responsible.

  • Data Fiduciary says the Consent Manager is responsible.

  • Neither investigates its own systems.

That would undermine the purpose of readily available and effective redressal.

Each entity should determine:

  • what it did;

  • what it failed to do;

  • which information it controls;

  • what remediation it can perform.

67. Approaching the Data Protection Board

Section 13 does not prescribe the procedure for a complaint before the Board.

It also does not determine:

  • evidentiary requirements;

  • form;

  • relief;

  • hearing procedure;

  • appeal.

Those matters arise under the Board and procedural provisions of the Act and Rules.

The internal grievance decision does not bind the Board.

A Data Fiduciary cannot make its own response final or immune from regulatory consideration by stating in its terms of service that:

“All privacy grievance decisions are final.”

Section 13(3) expressly contemplates subsequent approach to the Board after internal exhaustion.

68. No express compensation right

Section 13 does not itself create a right to compensation or damages.

A valid grievance may result in:

  • correction;

  • erasure;

  • cessation of processing;

  • provision of information;

  • improved safeguards;

  • processor instruction;

  • account remediation;

  • revised procedure.

Financial compensation may depend on another legal or contractual basis.

Similarly, a monetary penalty imposed by the Board under the DPDPA is regulatory. It is not automatically payable to the Data Principal as compensation.

69. Security grievances and breach obligations

A grievance may alert the Data Fiduciary to a previously unknown breach.

Example

For example, a Data Principal reports:

  • another person’s information appears in her account;

  • her profile is accessible through a public link;

  • a processor emailed information to the wrong recipient;

  • an unauthorised person accessed her account.

The grievance team must route the issue immediately to the incident-response function.

The grievance response period does not postpone:

  • Section 8(6) breach intimation;

  • Rule 7 notification obligations;

  • other applicable cyber-incident reporting.

The Data Fiduciary cannot wait up to ninety days to decide whether an incident is a reportable breach merely because the information arrived as a grievance.

Where a Data Principal alleges continued processing after withdrawal, the Data Fiduciary should examine:

  • whether valid consent existed;

  • when withdrawal was made;

  • the channel used;

  • whether the Consent Manager was involved;

  • systems receiving the signal;

  • processor instructions;

  • continuing processing;

  • any independent lawful ground;

  • retention.

The response should distinguish:

  • processing stopped;

  • personal data erased;

  • restricted retention under law;

  • another valid purpose;

  • processor action.

A generic response stating “your preferences were updated” may be inadequate where personalised marketing or another consent-based function continues.

71. Grievances concerning Section 11

A Data Principal may allege that an access response:

  • omitted personal-data categories;

  • inadequately described processing activities;

  • failed to identify processors;

  • identified only recipient classes;

  • omitted descriptions of data shared;

  • relied incorrectly on Section 11(2);

  • was delivered insecurely.

The grievance reviewer must apply Section 11’s actual scope.

The Data Principal has a right to a summary, not necessarily a complete copy of every record or source code.

Accordingly:

  • a request for omitted processor identities may be valid;

  • a demand for complete algorithmic source code may exceed Section 11.

Section 13 requires a reasoned review, not automatic acceptance of the Data Principal’s legal interpretation.

72. Grievances concerning Section 12

A Data Principal may complain that:

  • inaccurate data was not corrected;

  • misleading data was not qualified;

  • incomplete personal data remains incomplete;

  • an update did not reach active systems;

  • a processor still holds outdated data;

  • erasure was refused without identifying necessity or law;

  • legally retained information continues to be used commercially.

The response should identify:

  • data concerned;

  • action taken;

  • data retained;

  • specified purpose;

  • legal requirement;

  • processor action;

  • unresolved issue.

The grievance mechanism does not override Section 12’s exceptions. It should test whether those exceptions were applied correctly.

73. Employment grievances

Because Section 13 is not consent-limited, employees may use it concerning applicable obligations even where the employer relies on Section 7(i).

Potential grievances include:

  • insecure payroll handling;

  • disclosure to an unauthorised vendor;

  • inaccurate data used in promotion;

  • excessive retention after exit;

  • biometric-data security;

  • undisclosed monitoring;

  • processor failure;

  • breach notification.

The grievance mechanism does not automatically grant the employee full access to every confidential employment investigation or a right to erase legally required employment records.

The substantive remedy depends on:

  • the relevant statutory obligation;

  • Section 7(i);

  • Section 8;

  • Section 12 where applicable;

  • employment law;

  • legal retention.

74. Grievances involving children

A parent or lawful guardian may raise grievances concerning:

  • failure to obtain verifiable consent;

  • detrimental processing;

  • prohibited tracking;

  • behavioural monitoring;

  • targeted advertising;

  • misuse of an exemption;

  • insecure child accounts;

  • failure to erase child data.

The Data Fiduciary should verify the adult’s authority consistently with the child-data framework.

Where the complaint reveals an urgent child-safety issue, protective action should not be delayed until the expiry of the ordinary grievance period.

A child may also directly report a safety problem. Formal exercise of the statutory right may require the parental or guardianship arrangement, but the organisation should not ignore an urgent concern merely because it was first communicated by the child.

75. Persons with disabilities

The grievance mechanism should remain available directly to a person with disability where she can exercise the right, including with appropriate support.

The Data Fiduciary should not require guardian involvement merely because the individual has a disability.

Where a lawful guardian acts on behalf of the person, the guardian’s authority should be verified under Rule 11 and applicable law.

The means of redress may need to support:

  • assistive technology;

  • clear language;

  • accessible authentication;

  • assisted communication;

  • alternative formats.

The Act does not prescribe one universal accessible format. The mechanism must still be readily available in substance.

76. AI and automated processing grievances

Section 13 does not create:

  • a general right to source code;

  • a universal right to an explanation;

  • a universal right to human intervention;

  • a prohibition on automated decisions.

A grievance may nevertheless concern an AI-supported process where the allegation involves an existing DPDPA obligation, such as:

  • inaccurate personal data;

  • misleading classification;

  • processing beyond consent;

  • unauthorised sharing;

  • security failure;

  • inability to correct;

  • unlawful retention;

  • child behavioural monitoring;

  • ineffective grievance review.

The Data Fiduciary must be able to investigate sufficiently to answer the grievance.

A response stating:

“The decision was made by an algorithm, so it cannot be reviewed”

does not address whether the personal-data processing complied with the Act.

For an SDF, Rule 13(3) separately requires due diligence concerning technical measures and algorithmic software.

77. Grievance records and evidence

Section 13 and Rule 14 do not prescribe a formal grievance-register template.

The entity should nevertheless keep sufficient records to demonstrate:

  • date of receipt;

  • Data Principal identification;

  • issue raised;

  • assignment;

  • investigation;

  • processor involvement;

  • response;

  • date of response;

  • remedial action;

  • closure;

  • escalation.

Those records support:

  • compliance with the published period;

  • Section 8(10) effectiveness;

  • Rule 14 technical and organisational measures;

  • proof of exhaustion;

  • regulatory inquiry;

  • recurring-issue analysis.

The grievance record is itself personal data and should be protected and retained only as long as justified.

78. Third-party information and confidentiality

A grievance investigation may involve information relating to:

  • employees;

  • witnesses;

  • other customers;

  • family members;

  • security personnel;

  • processors;

  • internal systems.

Section 13 does not give the Data Principal an express right to the entire investigation file.

The response should provide sufficient information to explain:

  • what was investigated;

  • conclusion;

  • action taken;

  • continuing position.

The Data Fiduciary should avoid unnecessary disclosure of another person’s personal data, confidential security information or legally protected material.

Confidentiality should not be used as a reason to provide no meaningful response at all.

79. False or frivolous grievances

Section 15 requires Data Principals not to register false or frivolous grievances or complaints.

That duty does not permit the entity to label every difficult, unsuccessful or repeated complaint as frivolous.

A grievance is not frivolous merely because:

  • it lacks legal terminology;

  • it is technically complex;

  • the entity disagrees;

  • the alleged breach is ultimately unproved;

  • investigation requires significant effort.

A false or frivolous conclusion should follow actual consideration.

Even where a grievance is found to be frivolous, the entity should provide a response explaining that conclusion sufficiently to close the internal process.

80. Repeated grievances

Section 13 does not prescribe a separate rule for repeated grievances.

The entity may refer to an earlier response where:

  • the issue is identical;

  • no new facts exist;

  • no continuing failure is alleged.

It should not treat a grievance as a duplicate where:

  • processing continues;

  • remediation failed;

  • new personal data is involved;

  • new evidence is supplied;

  • the earlier response did not address the substance.

A repeated grievance may indicate that the original remedy was ineffective.

A single event may engage:

  • consumer law;

  • banking regulation;

  • insurance regulation;

  • employment procedures;

  • telecommunications regulation;

  • disability law;

  • contractual dispute mechanisms.

Section 13 does not expressly replace those mechanisms.

Example

For example, a bank customer may complain about:

  1. an incorrect financial charge; and

  2. inaccurate personal data used to impose the charge.

The first may involve banking redress. The second may involve the DPDPA grievance mechanism.

The Data Fiduciary should identify and address the privacy component without necessarily deciding the entire sectoral dispute.

82. What Section 13 does not provide

Section 13 should not be expanded beyond its enacted content.

It does not expressly create:

  • a consent requirement for grievances;

  • an automatic ninety-day period for every complaint;

  • a ninety-day period for every initial Section 11 or Section 12 request;

  • automatic acceptance of grievances;

  • compensation;

  • a class-action procedure;

  • a right to the complete investigation file;

  • a right to source code;

  • a universal human-review right;

  • a requirement for every Data Fiduciary to appoint a DPO;

  • a right to bypass internal redress;

  • a mandatory two-level appeal;

  • a requirement for a toll-free telephone service;

  • a grievance right concerning matters wholly unrelated to personal data or DPDPA obligations.

Any such entitlement would require another legal basis.

Section 13 is broader than Sections 11 and 12 in one important respect: it is not confined to processing for which the Data Principal previously gave consent or to the Section 7(a) relationship.

Its coverage follows the Data Fiduciary’s or Consent Manager’s applicable statutory obligations and the rights available to the Data Principal.

A Data Principal may therefore raise a grievance concerning employment, emergency, State, public-health or other non-consensual processing where an applicable DPDPA obligation is alleged to have been breached.

That broader grievance right does not erase the limitations of the substantive right being invoked. A grievance about Section 11 remains subject to Section 11’s conditions. A grievance about erasure remains subject to Section 12’s conditions and exceptions. Section 13 creates the internal review route; it does not automatically grant every requested outcome.

The grievance means must be readily available. Rule 14 reinforces that requirement through prominent publication of the rights mechanism and identification particulars. Data Principals without active accounts, including former customers, employees, applicants and CCTV subjects, must not be excluded merely because the organisation designed its mechanism only for current account holders.

The response must be substantive. Acknowledgement alone is not ordinarily sufficient. The Data Fiduciary or Consent Manager may accept, partially accept or reject the grievance, but should communicate an intelligible conclusion and any remedial action.

The published response period must be reasonable and cannot exceed ninety days. Ninety days is the statutory ceiling, not a default entitlement to delay every grievance. The entity must operate technical and organisational measures capable of meeting its published period.

The DPO or other published business contact provides an accessible point for processing questions and rights communications. For an SDF, the DPO is the statutory grievance contact. For other Data Fiduciaries, an authorised person must be able to answer on the organisation’s behalf.

Finally, the Data Principal must exhaust the internal opportunity before approaching the Data Protection Board. Exhaustion requires a genuine opportunity for the relevant entity to consider and respond. It does not require the Data Principal to accept an unsatisfactory answer or to remain trapped in an endless internal appeal process.

Key point

The controlling proposition is that Section 13 creates a general, ground-neutral and mandatory internal grievance right covering any act or omission concerning an applicable DPDPA obligation or the exercise of a statutory right, while preserving the substantive conditions and exceptions contained in the particular provisions on which the grievance is based.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.