Key point
Detailed clause-by-clause commentary on lawful exercise of rights, impersonation, suppression of material information, false or frivolous grievances, and verifiably authentic information
CHAPTER III - RIGHTS AND DUTIES OF DATA PRINCIPAL
Section 15 - Duties of Data Principal
Official text
A Data Principal shall perform the following duties, namely:—
(a)comply with the provisions of all applicable laws for the time being in force while exercising rights under the provisions of this Act;
(b)to ensure not to impersonate another person while providing her personal data for a specified purpose;
(c)to ensure not to suppress any material information while providing her personal data for any document, unique identifier, proof of identity or proof of address issued by the State or any of its instrumentalities;
(d)to ensure not to register a false or frivolous grievance or complaint with a Data Fiduciary or the Board; and
(e)to furnish only such information as is verifiably authentic, while exercising the right to correction or erasure under the provisions of this Act or the rules made thereunder.
Commentary
Statutory provision
1. Duties of Data Principal.
A Data Principal shall perform the following duties:
(a) comply with the provisions of all applicable laws for the time being in force while exercising rights under the provisions of this Act;
(b) ensure not to impersonate another person while providing her personal data for a specified purpose;
(c) ensure not to suppress any material information while providing her personal data for any document, unique identifier, proof of identity or proof of address issued by the State or any of its instrumentalities;
(d) ensure not to register a false or frivolous grievance or complaint with a Data Fiduciary or the Board; and
(e) furnish only such information as is verifiably authentic while exercising the right to correction or erasure under the Act or Rules.
2. Opening words: “A Data Principal shall perform the following duties”
Section 15 is structurally different from Sections 11 to 14.
Sections 11 to 14 confer rights on the Data Principal concerning:
-
access to information;
-
correction, completion, updating and erasure;
-
grievance redressal;
-
nomination.
Section 15 imposes corresponding statutory duties on the Data Principal.
The Act therefore does not treat the Data Principal only as the holder of rights. It requires honest and lawful conduct when:
-
personal data is provided for a specified purpose;
-
personal data is provided for State-issued documentation or identification;
-
grievances or complaints are registered;
-
correction or erasure rights are exercised;
-
other DPDPA rights are exercised.
The statutory structure may be represented as follows:
- DATA PRINCIPAL RIGHTS Access, correction, erasure, grievance and nomination
- DATA PRINCIPAL DUTIES Lawful, non-impersonating, non-suppressive, non-frivolous and authentic conduct ``
The duties are exhaustive only to the extent that Section 15 contains five express duties. A Data Fiduciary should not invent additional “Data Principal duties” and treat them as if they were statutory.
Example
For example, Section 15 does not expressly impose a general duty on the Data Principal to:
-
keep every item of personal data continuously updated without being asked;
-
read every privacy notice in full;
-
accept every verification method selected by the Data Fiduciary;
-
protect the Data Fiduciary from every loss;
-
report every suspected data breach;
-
indemnify the Data Fiduciary;
-
waive rights because incorrect information was previously supplied.
Those matters may arise under another law or contract, but they should not be attributed to Section 15 unless the statutory language supports them.
3. “Shall perform”
The word “shall” makes the duties mandatory.
They are not merely recommendations concerning responsible digital behaviour. A proven breach may give rise to proceedings and the monetary penalty provided in the Schedule.
However, Section 15 should not be interpreted as automatically penalising every:
-
typographical error;
-
misunderstanding;
-
unsuccessful grievance;
-
mistaken legal interpretation;
-
outdated record;
-
inability to produce a particular document.
Each paragraph contains its own elements. The alleged conduct must fall within the words of the relevant duty.
Example
For example:
-
paragraph (b) requires impersonation;
-
paragraph (c) requires suppression of material information in the specified State-document context;
-
paragraph (d) requires a false or frivolous grievance or complaint;
-
paragraph (e) concerns information furnished while exercising correction or erasure rights and requires verifiable authenticity.
The mere fact that a request is rejected does not establish breach of a Data Principal duty.
4. “The following duties”
The five duties are distinct. They apply to different contexts and should not be collapsed into a single general obligation to provide “correct data.”
| Duty | Relevant context | Conduct controlled |
|---|---|---|
| Section 15(a) | Exercise of rights under the Act | Non-compliance with applicable law |
| Section 15(b) | Providing personal data for a specified purpose | Impersonation |
| Section 15(c) | Providing data for State-issued documents, identifiers, identity or address proofs | Suppression of material information |
| Section 15(d) | Grievance to a Data Fiduciary or complaint to the Board | False or frivolous filing |
| Section 15(e) | Exercise of correction or erasure rights | Furnishing information that is not verifiably authentic |
The same conduct may raise more than one paragraph, but each element should be examined separately.
Example
For example, a person who submits forged identity information to change another individual’s account data may potentially engage:
-
paragraph (a), where another law is violated in exercising the right;
-
paragraph (b), where the person impersonates another;
-
paragraph (e), where the information furnished for correction is not verifiably authentic.
The existence of overlap does not remove the need to prove each duty relied upon.
5. Relationship between Section 15 and Data Fiduciary obligations
Section 15 does not reduce or transfer the Data Fiduciary’s statutory obligations.
Section 8(1) expressly provides that the Data Fiduciary remains responsible for compliance irrespective of:
-
any agreement to the contrary; or
-
failure of the Data Principal to perform her duties under the Act.
This relationship is essential.
A Data Principal’s wrongdoing or mistake does not permit the Data Fiduciary to disregard:
-
security safeguards;
-
processor governance;
-
breach notification;
-
retention;
-
grievance redressal;
-
child-data requirements;
-
data quality;
-
applicable rights.
6. Incorrect information and security
A customer provides an incorrect address.
The Data Fiduciary may require the customer to correct it and may be entitled to decline delivery until valid information is supplied. It must still protect the account and other personal data through reasonable security safeguards.
7. Impersonation and breach notification
An impersonator obtains access to another person’s account.
The impersonator may breach Section 15(b) and other laws. The Data Fiduciary must still examine:
-
whether safeguards were reasonable;
-
whether unauthorised processing occurred;
-
whether a personal data breach arose;
-
whether notification is required.
8. False grievance and grievance mechanism
A Data Principal submits a grievance that is later established to be false or frivolous.
The Data Fiduciary remains required to maintain a readily available and effective grievance mechanism. It cannot remove access to the mechanism for all Data Principals because one person misused it.
The principles are therefore separate:
DATA PRINCIPAL MAY BE RESPONSIBLE
FOR BREACH OF SECTION 15
BUT
DATA FIDUCIARY REMAINS RESPONSIBLE
FOR ITS OWN OBLIGATIONS
9. Section 15(a): “Comply with the provisions of all applicable laws”
The first duty requires the Data Principal to comply with all applicable laws while exercising rights under the DPDPA.
This provision prevents the exercise of a DPDPA right from being treated as authority to violate another law.
The right to access, correction, erasure, grievance or nomination must operate within the broader legal framework.
10. “Applicable laws”
The provision refers to laws that apply to:
-
the Data Principal;
-
the conduct;
-
the information;
-
the right being exercised;
-
the relevant sector or record.
Section 15(a) does not identify a closed list.
Potentially relevant laws may concern:
-
identity documents;
-
fraud;
-
forgery;
-
electronic records;
-
court proceedings;
-
confidentiality;
-
banking;
-
taxation;
-
medical records;
-
employment;
-
guardianship;
-
succession;
-
official secrets;
-
evidence.
The mere existence of another law is not enough. It must be applicable to the particular act of exercising the DPDPA right.
11. “While exercising rights”
The temporal and functional connection matters.
Section 15(a) applies where the Data Principal is exercising a right under the DPDPA and, in doing so, fails to comply with another applicable law.
Example
For example:
-
submitting a forged document to support correction;
-
unlawfully accessing another person’s account to submit an erasure request;
-
breaching a lawful confidentiality requirement while making a complaint;
-
falsely claiming guardianship to exercise another person’s rights.
The provision is not a general DPDPA penalty for every unrelated legal violation ever committed by a Data Principal.
If an individual violates an unrelated traffic law, that conduct has no connection with her exercise of a DPDPA right and does not become a Section 15(a) breach.
12. Section 15(a) and the lawful limits of rights
Section 15(a) confirms that Data Principal rights do not override other applicable laws.
13. Correction of regulated records
A Data Principal cannot insist that a regulated record be changed through an informal email where another law requires:
-
prescribed evidence;
-
a statutory form;
-
authentication;
-
approval by a competent authority.
Section 12(1) itself makes correction and erasure subject to requirements and procedures under applicable law. Section 15(a) places a corresponding duty on the Data Principal to comply with those requirements.
14. Erasure and legal retention
A Data Principal may request erasure, but Section 12(3) allows retention where necessary for compliance with law.
The Data Principal may challenge whether the law genuinely requires retention. She should not knowingly use false material or unlawful methods to force erasure of legally required records.
An unsuccessful erasure request is not itself a breach of Section 15(a). The breach would require non-compliance with an applicable law while exercising the right.
15. Access and third-party information
A Data Principal’s right under Section 11 is a right to a statutory summary. It is not authority to:
-
hack a system;
-
obtain another person’s credentials;
-
access another person’s account;
-
steal internal documents.
The Data Principal must use the rights mechanism lawfully.
16. Nomination
A person exercising nomination rights must comply with applicable law concerning:
-
identity;
-
capacity;
-
death;
-
guardianship;
-
representation.
Section 14 does not permit the nominee to falsify an incapacity or death record.
17. Section 15(a) does not create unlimited refusal power
A Data Fiduciary should not use paragraph (a) to refuse a right merely by stating that “other laws may apply.”
The Data Fiduciary should identify:
-
the applicable law;
-
the relevant requirement;
-
how the request conflicts with it;
-
whether the conflict affects the entire request or only part.
Example
For example, legal retention may justify refusal to erase certain transaction records. It does not automatically justify refusing to correct an inaccurate email address or erase an unrelated advertising profile.
The paragraph imposes a duty on the Data Principal. It is not a general exemption for the Data Fiduciary.
18. Section 15(b): “Ensure not to impersonate another person”
The second duty prohibits impersonation while providing personal data for a specified purpose.
The paragraph contains three elements:
-
the Data Principal provides personal data;
-
the personal data is provided for a specified purpose;
-
the Data Principal impersonates another person in doing so.
All three elements matter.
19. Meaning of impersonation
Impersonation involves presenting oneself as another person or providing personal data in a manner that falsely assumes another person’s identity.
Example
Examples may include:
-
creating an account in another person’s name;
-
using another person’s identity document as one’s own;
-
submitting another person’s phone number and identity details while claiming to be that person;
-
enrolling under another employee’s identity;
-
representing oneself as another customer;
-
falsely claiming to be a parent, guardian or nominee.
The provision does not require that the victim suffer financial loss before impersonation occurs.
Nor does it require that the impersonation successfully achieve its purpose.
An attempted impersonation may also engage other applicable laws. Section 15(b) does not replace those laws.
20. Similar names
Use of the same or a similar name does not automatically establish impersonation.
The relevant question is whether the person represented herself as another identifiable person.
21. Pseudonyms and usernames
Use of a pseudonym, screen name or fictional identity is not necessarily impersonation where:
-
the service permits it;
-
the person does not claim to be another real person;
-
no other fraud occurs.
Section 15(b) is directed at impersonating another person, not at every use of a name different from a legal name.
22. Shared contact details
Family members may lawfully share:
-
an address;
-
telephone number;
-
email account;
-
device.
The mere use of shared contact information does not establish impersonation. The context and representation made to the Data Fiduciary are decisive.
23. “While providing her personal data”
The wording should be read carefully.
The statutory concern is impersonation occurring while the individual provides personal data for a specified purpose.
The paragraph does not prohibit every form of impersonation occurring in every context. It addresses the integrity of personal-data provision within the DPDPA framework.
Example
For example, a person who creates a service account by using another individual’s identity details may breach the duty.
The expression “her personal data” should not be read to permit the use of another person’s data so long as the impersonator avoids submitting her own data. The core prohibition is against impersonation while personal data is supplied for the purpose.
24. “For a specified purpose”
A specified purpose is the purpose referred to in the notice under Section 5.
The paragraph therefore applies when personal data is provided to enable processing for that disclosed purpose.
Example
Examples include:
-
creation of an account;
-
provision of a service;
-
delivery;
-
employment application;
-
identity verification;
-
benefit administration;
-
age verification;
-
exercise of a right.
The person must not present herself as another person within that process.
25. False age declarations
A child who falsely declares herself to be an adult does not necessarily impersonate another person if she merely enters a false age without assuming another person’s identity.
That conduct may be dishonest and may involve another applicable issue, but Section 15(b) requires impersonation of another person.
If the child uses a parent’s identity details and presents herself as the parent, the conduct is much closer to impersonation under paragraph (b).
26. False parent claim
An adult presents herself as the parent of a child when she has no such relationship or authority.
The adult may be impersonating or falsely assuming another person’s parental identity, depending on the facts. The conduct may also affect the validity of verifiable parental consent under Section 9 and Rule 10.
The Data Fiduciary must still perform the due diligence required by Rule 10. It cannot rely solely on Section 15(b) to excuse an inadequate verification system.
27. Section 15(b) and Data Fiduciary verification
The Data Principal’s duty not to impersonate does not eliminate the Data Fiduciary’s obligation to use appropriate verification where the Act or risk requires it.
Example
For example:
-
Rule 10 requires due diligence concerning an adult identifying herself as a parent;
-
Rule 11 requires verification of lawful guardianship;
-
Rule 14 permits identification particulars for rights requests;
-
Section 8 requires reasonable security safeguards.
A Data Fiduciary cannot implement a knowingly ineffective authentication process and answer every impersonation incident by blaming the Data Principal.
The legal responsibilities coexist:
DATA PRINCIPAL
Must not impersonate another person
DATA FIDUCIARY
Must implement verification and security required by the Act, Rules and processing risk
28. Section 15(c): Suppression of material information
The third duty is narrower than a general obligation always to provide every fact to every Data Fiduciary.
It applies when the Data Principal provides personal data for:
-
a document issued by the State or its instrumentalities;
-
a unique identifier issued by the State or its instrumentalities;
-
proof of identity issued by the State or its instrumentalities;
-
proof of address issued by the State or its instrumentalities.
The Data Principal must not suppress material information in that context.
29. Meaning of “suppress”
Suppression involves withholding or concealing information that ought to be provided in the relevant process.
The concept differs from making an express false statement, although the same conduct may involve both.
Example
Examples may include knowingly omitting:
-
an existing identifier where disclosure is required;
-
a prior name where it is material to the application;
-
a fact affecting eligibility for the State-issued document;
-
an existing address record where the procedure requires disclosure;
-
a legally relevant disqualification.
A person does not suppress information merely because she fails to provide an immaterial detail that the process did not require.
30. “Material information”
Materiality is an essential limitation.
Information is material where it is relevant enough that its omission may affect:
-
issuance;
-
validity;
-
identity determination;
-
uniqueness;
-
eligibility;
-
reliability;
-
accuracy of the State-issued document or identifier.
The paragraph does not require disclosure of all information about the person.
31. Materiality depends on context
Information material to a passport application may differ from information material to:
-
a driving licence;
-
residence certificate;
-
tax identifier;
-
identity credential;
-
municipal certificate.
The relevant State process and applicable law help determine materiality.
32. Causation is not expressly required
The paragraph does not state that the suppression must successfully cause issuance of the document.
The duty concerns ensuring that material information is not suppressed while providing personal data for the identified purpose.
However, materiality should not be assumed merely because the issuing authority later asks for additional information. The information must be relevant to the issuance, integrity or reliability of the document or identifier.
33. State and its instrumentalities
Section 15(c) is confined to documents and identifiers issued by:
-
the State; or
-
its instrumentalities.
The provision does not expressly extend to every private-sector loyalty card, employee ID, customer number or private membership document.
34. State-issued documents
Potential examples may include documents, identifiers or proofs issued under governmental or statutory authority.
The exact coverage depends on:
-
issuing entity;
-
applicable legal framework;
-
nature of the document.
35. Private documents
A person may have contractual or other legal duties when applying for:
-
a private membership card;
-
employer ID;
-
private insurance policy;
-
commercial account.
Section 15(c), however, specifically refers to issuance by the State or its instrumentalities.
A Data Fiduciary should not expand paragraph (c) into a general prohibition on omitting information from every private form.
36. Instrumentality of the State
The Act does not separately define “instrumentalities” for Section 15(c).
Whether an entity is an instrumentality of the State depends on the applicable legal position and the nature of the issuing function.
A private contractor assisting a government body does not necessarily become the issuer. The relevant document may still be issued by the State or its instrumentality through the contractor’s technical platform.
37. “Document, unique identifier, proof of identity or proof of address”
These categories overlap but are not identical.
38. Document
This is the broadest term. It may cover an official record or certificate issued by the State or its instrumentalities.
39. Unique identifier
A unique identifier distinguishes the person within a particular system.
The provision does not list specific identifiers. Coverage depends on the nature of the State-issued identifier.
40. Proof of identity
This concerns an official document or credential used to establish identity.
41. Proof of address
This concerns an official document or credential used to establish an address.
The Data Principal’s duty relates to material information supplied for obtaining these items. It does not state that every State-issued document must contain every personal detail or remain permanently updated under Section 15(c).
42. Section 15(c) does not excuse State verification failures
The Data Principal must not suppress material information.
The issuing State body may still have duties concerning:
-
accuracy;
-
security;
-
lawful purpose;
-
technical and organisational measures;
-
grievance redressal;
-
applicable verification.
If the State issues an incorrect identifier because its system linked records improperly, it cannot automatically attribute the error to the Data Principal unless material suppression actually occurred.
Section 8(1) expressly preserves Data Fiduciary responsibility despite a Data Principal’s failure to perform duties.
43. Section 15(d): False or frivolous grievance or complaint
The fourth duty prohibits registration of a false or frivolous:
-
grievance with a Data Fiduciary; or
-
complaint with the Data Protection Board.
The distinction between grievance and complaint reflects the statutory sequence:
GRIEVANCE
Raised internally with the Data Fiduciary under Section 13
COMPLAINT
Approach to the Data Protection Board after internal exhaustion, where required
The provision protects grievance and regulatory mechanisms from deliberate misuse.
It must be interpreted carefully so that individuals are not deterred from raising genuine concerns.
44. Meaning of “false”
A grievance or complaint may be false where the filer knowingly presents materially untrue facts or fabricates the alleged event.
Example
Examples may include:
-
claiming a breach occurred when the filer knows it did not;
-
submitting fabricated communications;
-
claiming to be the affected Data Principal when she is not;
-
alleging that consent was never given while knowingly concealing the consent record she created;
-
falsely claiming that an erasure request was submitted.
An allegation later found unproved is not automatically false.
The Data Principal may genuinely believe that:
-
processing occurred without consent;
-
a recipient was unauthorised;
-
data was not erased;
-
an access response was incomplete.
If investigation shows otherwise, the grievance may be unsuccessful without being false.
The distinction is between:
-
honest but mistaken allegation; and
-
knowingly false allegation.
Section 15(d) should not be used to punish a person merely because the Data Fiduciary or Board disagrees with her interpretation.
45. Meaning of “frivolous”
The Act does not define frivolous.
In this context, a grievance or complaint may be frivolous where it lacks a serious basis, is manifestly without substance, or is filed for an improper or merely vexatious purpose rather than genuine redress.
Potential indicators may include:
-
repeated identical filings after the matter has been conclusively answered, without new facts;
-
a complaint wholly unrelated to the Data Principal’s personal data;
-
a filing made solely to harass;
-
invented allegations unsupported by any genuine belief;
-
misuse of the mechanism for an unrelated commercial dispute.
These are indicators, not a statutory test.
A grievance is not frivolous merely because:
-
it is legally unsuccessful;
-
the Data Principal lacks legal expertise;
-
it contains minor errors;
-
it is expressed emotionally;
-
it concerns a small amount of personal data;
-
the Data Fiduciary believes the harm is minor;
-
investigation is burdensome;
-
the Data Principal raises the matter more than once after ineffective remediation.
The classification should be made cautiously.
46. “False or frivolous”
The conjunction is or.
A filing may breach the duty if it is:
-
false; or
-
frivolous.
It need not necessarily be both.
However, the Data Fiduciary should not infer one from the other automatically.
A grievance may be:
-
factually incorrect but submitted in good faith;
-
factually accurate but frivolous in the sense that it is used abusively for no relevant redress;
-
repetitive because the underlying failure continues.
The context and the Data Principal’s conduct matter.
47. Registration of a grievance or complaint
The duty applies when a false or frivolous grievance or complaint is registered.
The provision is directed at formal use of the grievance or Board complaint mechanisms.
An informal question, criticism or expression of concern does not necessarily amount to registration of a statutory grievance or complaint.
The Data Fiduciary should distinguish:
-
a processing enquiry;
-
a rights request;
-
a grievance;
-
a Board complaint;
-
general customer feedback.
Example
For example:
“Can you explain why you require my location?”
is a question.
“You unlawfully retained my location after withdrawal, and I seek redress”
is a grievance.
Only the latter falls directly within the Section 15(d) filing context.
48. Grievance to the Data Fiduciary
The paragraph expressly names a grievance registered with a Data Fiduciary.
It does not name a grievance registered with a Consent Manager, even though Section 13 permits grievances against Consent Managers.
The omission should not be silently rewritten.
Section 15(a) may still require lawful conduct while exercising rights against a Consent Manager, and other laws may address false statements. But Section 15(d), as enacted, expressly refers to:
-
a Data Fiduciary; or
-
the Board.
A commentary should not state that Section 15(d) expressly covers Consent Manager grievances when the statutory words do not say so.
49. Complaint to the Board
A complaint to the Board may follow internal exhaustion under Section 13(3), where applicable.
Section 15(d) prevents deliberate misuse of the Board process.
The Board should distinguish between:
-
a complaint that fails on the merits;
-
a complaint filed prematurely;
-
a complaint lacking sufficient evidence;
-
a genuinely false or frivolous complaint.
Prematurity may lead to procedural rejection because internal redress was not exhausted. It does not automatically prove that the complaint is false or frivolous.
Similarly, inability to prove the allegation does not necessarily establish dishonest misuse.
50. Section 15(d) must not chill genuine grievances
Section 13 gives the Data Principal a statutory right to grievance redressal.
Section 15(d) should be interpreted consistently with that right.
A Data Fiduciary should not threaten a Section 15 penalty merely because a Data Principal:
-
disputes its response;
-
seeks escalation;
-
approaches the Board after exhaustion;
-
complains about a senior employee;
-
raises a security concern;
-
questions an algorithm;
-
alleges a systemic failure.
A broad or aggressive use of “frivolous” would undermine Section 13.
The Data Fiduciary may state that a grievance is unsupported or rejected. Formal determination of a statutory breach and monetary penalty falls within the Act’s enforcement framework. The Data Fiduciary does not itself impose the statutory Section 15 penalty.
51. Repeated grievances
Repeated filing requires careful analysis.
52. Potentially frivolous repetition
A Data Principal repeatedly submits the identical grievance:
-
no new facts;
-
no continuing issue;
-
full response already given;
-
sole apparent purpose is harassment.
The repetition may become relevant to frivolousness.
53. Legitimate repetition
A Data Principal repeats the grievance because:
-
processing continues;
-
the correction did not reach a processor;
-
marketing resumed;
-
the Data Fiduciary never provided a substantive response;
-
new evidence emerged;
-
the breach affected additional records.
The repetition is not frivolous merely because the subject resembles an earlier grievance.
The Data Fiduciary should examine whether its own incomplete remediation caused the renewed filing.
54. Section 15(e): “Furnish only such information as is verifiably authentic”
The fifth duty applies while the Data Principal exercises:
-
the right to correction; or
-
the right to erasure.
The Data Principal must furnish only information that is verifiably authentic.
This duty supports the integrity of rights processes that may alter or destroy personal data.
A Data Fiduciary may need reliable information to ensure that:
-
the requester is the correct individual;
-
the proposed correction is valid;
-
the record belongs to the requester;
-
the erasure request is genuine;
-
another person’s data is not altered or deleted.
55. “Furnish”
The duty applies to information the Data Principal provides in support of the request.
This may include:
-
identity particulars;
-
account identifiers;
-
supporting documents;
-
corrected data;
-
explanation;
-
evidence of authority;
-
proof relating to the requested change.
The paragraph does not require the Data Principal to furnish information that the Data Fiduciary does not reasonably need.
Nor does it authorise the Data Fiduciary to insist on unlimited supporting information.
The information furnished must be verifiably authentic. The amount and type of information required remain connected with:
-
the request;
-
applicable law;
-
the Data Fiduciary’s legitimate verification needs.
56. Meaning of “verifiably authentic”
The Act does not define the expression.
Two ideas are contained within it:
-
authenticity, meaning the information is genuine and what it purports to be; and
-
verifiability, meaning there is a reasonable means of checking that authenticity.
Example
Examples may include:
-
a valid identifier capable of being matched to the account;
-
a genuine document from an authoritative source;
-
a request through an authenticated account;
-
a reliable correction document;
-
a valid guardianship or nomination record where another person acts.
The phrase does not necessarily require a government-issued document for every request.
For a low-risk correction, verified account access and an OTP may provide sufficient confirmation. A high-consequence change may require stronger evidence.
The Act does not prescribe one verification method for all correction and erasure requests.
57. Authenticity of identity and authenticity of corrected data
Section 15(e) may involve two separate matters.
58. Authenticity of the requester
Is the person exercising the right genuinely the Data Principal, parent, guardian or nominee?
59. Authenticity of the substantive information
Is the information supplied to support the correction genuine?
Example
For example, changing a bank account may require verification that:
-
the request comes from the employee;
-
the bank information is genuine and belongs to the appropriate person, where relevant.
Changing a date of birth in a regulated record may require both:
-
identity verification;
-
authentic evidence of the correct date.
The Data Fiduciary should not treat authentication of the account login as conclusive proof that every proposed correction is accurate.
60. Correction requests
Section 12 requires the Data Fiduciary to:
-
correct inaccurate or misleading data;
-
complete incomplete data;
-
update personal data.
Section 15(e) requires the Data Principal to provide verifiably authentic information while exercising those rights.
The provisions are complementary.
61. Simple correction
A customer notices a spelling mistake in her name in an ordinary delivery profile.
The Data Fiduciary may be able to verify and make the correction through authenticated account access without requiring official documents.
62. High-consequence correction
A person requests alteration of:
-
date of birth in a regulated financial record;
-
bank account for salary;
-
identity number;
-
legal name;
-
eligibility information.
The Data Fiduciary may require stronger authentic evidence, particularly where another law prescribes a procedure.
63. Disputed evaluative information
A Data Principal cannot satisfy Section 15(e) merely by asserting that an unfavourable opinion is wrong.
She may provide verifiably authentic information showing that the opinion relied on false facts.
Example
For example:
-
authentic attendance records contradict an absenteeism score;
-
a completion certificate contradicts an “unqualified” label;
-
a final investigation outcome contradicts an unresolved allegation marker.
The Data Fiduciary must then assess correction or completion under Section 12.
64. Erasure requests
For erasure, verifiably authentic information primarily protects against unauthorised deletion.
A false erasure request may cause:
-
account loss;
-
destruction of records;
-
interruption of service;
-
loss of access;
-
prejudice to the genuine Data Principal.
The Data Fiduciary may require enough information to establish:
-
requester identity;
-
relevant account or record;
-
parent, guardian or nominee authority;
-
scope of the request.
Section 15(e) does not mean the Data Principal must prove that no retention exception applies. The Data Fiduciary must assess under Section 12(3) whether retention remains necessary:
-
for the specified purpose; or
-
for compliance with law.
The duties are divided:
DATA PRINCIPAL
Provides verifiably authentic information
DATA FIDUCIARY
Determines whether erasure is required or an exception permits retention
65. Does Section 15(e) apply to completion and updating?
Section 15(e) expressly refers to exercising the right to “correction or erasure.”
Section 12’s title and structure treat:
-
correction;
-
completion;
-
updating;
-
erasure as related rights.
A broad functional reading may treat information furnished for completion or updating as part of exercising the Section 12 correction framework.
However, the exact wording of Section 15(e) names correction and erasure, not completion and updating separately.
A cautious commentary should therefore state:
-
clearly, the duty applies to correction and erasure;
-
completion and updating may fall within the broader correction-right framework under Section 12, but the statutory wording should not be rewritten.
Irrespective of Section 15(e), Section 15(a) and other applicable laws may require lawful and truthful conduct in completion and updating requests.
66. Section 15(e) and Data Fiduciary over-collection
The Data Principal’s authenticity duty does not allow the Data Fiduciary to collect excessive personal data.
The Data Fiduciary should ask:
-
What fact must be verified?
-
What evidence is sufficient?
-
Is an existing authenticated account enough?
-
Can a token or reference number be used?
-
Is a complete identity document necessary?
-
Can unnecessary fields be masked?
A Data Fiduciary should not demand a full identity dossier for every low-risk correction merely because Section 15(e) uses “verifiably authentic.”
The verification information itself is personal data and must be:
-
processed for a lawful purpose;
-
protected;
-
retained only as necessary;
-
excluded from unrelated use.
67. Forged and altered evidence
A Data Principal who knowingly furnishes:
-
forged proof;
-
altered document;
-
false identifier;
-
fabricated death certificate;
-
false guardianship record;
-
false bank proof;
may breach Section 15(e), Section 15(a), and potentially other applicable laws.
The Data Fiduciary should not make that determination casually.
It should distinguish:
-
forged material;
-
outdated material;
-
poor-quality copy;
-
clerical inconsistency;
-
document not accepted under a particular procedure;
-
reasonable misunderstanding.
A document’s insufficiency for a requested correction does not necessarily mean it is inauthentic.
68. Nominees, parents and guardians under Section 15
Where another person exercises rights on behalf of the Data Principal, the Section 15 duties remain relevant.
69. Parent or lawful guardian
A parent or guardian should not:
-
impersonate another parent;
-
conceal material guardianship information;
-
submit false documents;
-
make a false grievance;
-
furnish inauthentic information for correction or erasure.
70. Section 14 nominee
A nominee should provide authentic information concerning:
-
nominee identity;
-
valid nomination;
-
death or incapacity;
-
Data Principal’s identifier;
-
requested right.
A person who falsely claims that the Data Principal is incapacitated may engage Section 15(a), paragraph (d) where a false grievance or complaint is filed, and paragraph (e) where inauthentic information supports correction or erasure.
71. Data Fiduciary duties remain
The existence of Section 15 does not permit the Data Fiduciary to accept every guardianship or nominee claim without verification.
The Data Fiduciary must still protect the Data Principal’s personal data against unauthorised access, alteration or erasure.
72. Data Principal errors versus statutory breaches
Not every incorrect submission is a Section 15 breach.
A meaningful distinction should be maintained among:
-
deliberate falsehood;
-
careless error;
-
outdated information;
-
misunderstanding;
-
inability to verify;
-
difference of opinion;
-
technical failure.
73. Typographical error
A customer accidentally enters one incorrect digit in a telephone number.
This is not automatically impersonation, suppression, a false grievance or furnishing of inauthentic correction information.
74. Outdated address
A customer forgets to update an old address.
Section 15 does not expressly impose a general duty to maintain every record continuously. The issue may be resolved through Section 12 updating.
75. Mistaken grievance
A customer believes that data was shared without authority. Investigation shows the disclosure was authorised.
The grievance is not automatically false or frivolous if the belief was genuine.
76. Fake identity document
A person knowingly submits a forged identity document to obtain another person’s account.
This is materially different and may engage multiple Section 15 duties and other laws.
77. Burden and enforcement
Section 15 creates duties, but the Data Fiduciary does not itself adjudicate and impose the statutory monetary penalty.
The relevant enforcement process under the Act must determine:
-
conduct alleged;
-
applicable duty;
-
evidence;
-
whether breach occurred;
-
appropriate penalty.
The Data Fiduciary may:
-
reject an invalid request;
-
investigate suspected impersonation;
-
secure an account;
-
preserve evidence;
-
raise the matter through lawful channels.
It should not present an internal allegation as a final statutory finding.
Likewise, the Board should distinguish an unsuccessful grievance from a breach of Section 15(d).
78. Penalty
The Schedule states that breach in observance of Section 15 duties may attract a monetary penalty extending to ₹10,000.
This amount is:
-
a maximum;
-
not an automatic fixed charge;
-
not a criminal fine imposed directly by the Data Fiduciary;
-
not compensation payable to the Data Fiduciary.
The penalty framework must operate through the processes under the Act.
The relatively lower maximum, compared with penalties applicable to Data Fiduciary failures, reflects the different nature and scale of the obligations. It does not make Section 15 optional.
79. Section 15 does not create contractual indemnity
A Data Fiduciary should not state in its terms that Section 15 automatically requires the Data Principal to indemnify it for:
-
every inaccurate field;
-
every unsuccessful grievance;
-
every account compromise;
-
every processor failure;
-
every regulatory penalty.
Section 15 creates statutory duties and a statutory penalty framework. It does not itself create a contractual indemnity in favour of the Data Fiduciary.
Any contractual term must separately comply with applicable law and cannot defeat Section 8(1), which preserves the Data Fiduciary’s responsibility despite the Data Principal’s failure to perform duties.
80. Section 15 and children
The Act’s definition of Data Principal includes the parent or lawful guardian in relation to a child.
Section 15 duties therefore require careful attribution where:
-
the child provided information;
-
the parent completed the process;
-
the lawful guardian exercised a right;
-
a child misrepresented age;
-
an adult impersonated a parent.
The Data Fiduciary should not automatically attribute every act of a child to a parent without examining:
-
who submitted the information;
-
who completed verification;
-
who made the grievance;
-
who furnished the correction evidence.
Section 15 does not remove the Data Fiduciary’s heightened obligations under Section 9.
A child’s false age declaration does not automatically excuse:
-
an ineffective Rule 10 parental-verification process;
-
prohibited tracking;
-
harmful processing;
-
targeted advertising.
81. Section 15 and persons with disabilities
A person with disability should not be presumed incapable of complying with Section 15 or exercising rights.
Where a lawful guardian acts on behalf of the person, the guardian’s own conduct in exercising the rights must comply with applicable duties.
The Data Fiduciary should distinguish:
-
genuine need for support;
-
lawful guardianship;
-
impersonation;
-
false claim of authority;
-
innocent misunderstanding.
A disability, communication difference or use of assisted technology does not make a grievance frivolous or information inauthentic.
82. Section 15 and AI-assisted submissions
A Data Principal may use technology to draft or organise a request or grievance.
Section 15 does not prohibit:
-
AI-assisted drafting;
-
translation tools;
-
automated form completion;
-
professional assistance.
The Data Principal remains responsible for the information she submits.
If an AI-generated grievance includes fabricated facts and the Data Principal knowingly registers those facts as true, Section 15(d) may become relevant.
If the Data Principal reasonably relies on the tool but promptly corrects an error when discovered, the situation should not automatically be treated as a deliberately false or frivolous filing.
The statutory analysis remains focused on the information and conduct, not merely the tool used.
83. Practical application matrix
| Situation | Potential Section 15 issue | Necessary qualification |
|---|---|---|
| Customer enters a typing error | Usually none automatically | Error is not necessarily impersonation or inauthenticity |
| Person creates account as another real person | Section 15(b) | Must involve impersonation |
| Applicant omits material fact for State-issued ID | Section 15(c) | Information must be material and issuance must be by State or instrumentality |
| Customer loses access and honestly suspects breach | Section 15(d) ordinarily not breached | Unproven grievance is not automatically false |
| Person repeatedly files invented complaints | Section 15(d) may apply | Falsity or frivolousness must be established |
| Data Principal supplies forged correction document | Sections 15(a) and 15(e) may apply | Must assess authenticity and applicable law |
| Employee disagrees with manager’s opinion | Not automatically Section 15 breach | Genuine disagreement is not false information |
| Nominee provides false death certificate | Sections 15(a) and 15(e), and possibly other law | Data Fiduciary must verify trigger |
| Child enters false age without assuming another identity | Not necessarily Section 15(b) | Impersonation requires another person |
| Child uses parent’s identity as her own | Section 15(b) may apply | Data Fiduciary still retains Rule 10 duties |
84. What Section 15 does not provide
Section 15 should not be expanded beyond its enacted words.
It does not expressly create:
-
a general duty to keep all personal data continuously updated;
-
strict liability for every accidental error;
-
a presumption that every rejected grievance is frivolous;
-
an adult-only right to make grievances;
-
a Data Fiduciary power to impose the ₹10,000 statutory penalty directly;
-
a contractual indemnity;
-
an exemption from Data Fiduciary obligations;
-
authority to demand Aadhaar for every correction request;
-
a duty to disclose all information in every private-sector form;
-
a prohibition on pseudonyms where another person is not impersonated;
-
a duty to prove legal entitlement before asking a genuine question;
-
a waiver of rights following a Data Principal’s breach;
-
a right for the Data Fiduciary to refuse all future requests from a person who once breached Section 15.
Each duty has a particular context and should be applied only within that context.
85. Consolidated interpretation
Section 15 introduces reciprocal responsibility into the DPDPA framework, but it does not place the Data Principal and Data Fiduciary on identical legal footing.
The Data Fiduciary determines the purposes and means of processing and remains responsible under Section 8(1), including where the Data Principal fails to perform a duty. Section 15 does not transfer the Data Fiduciary’s compliance obligations to the individual.
Paragraph (a) requires lawful conduct while exercising DPDPA rights. It does not make every unrelated violation of law a DPDPA breach.
Paragraph (b) prohibits impersonation while personal data is provided for a specified purpose. It does not prohibit every pseudonym, shared contact detail or innocent identification error. The individual must have represented herself as another person.
Paragraph (c) prohibits suppression of material information when personal data is supplied for obtaining a State-issued document, unique identifier, identity proof or address proof. It is not a general duty to disclose every fact in every private-sector transaction. The omitted information must be material.
Paragraph (d) protects grievance and Board processes from false or frivolous filings. It must be applied cautiously so that it does not deter genuine grievances. An unsuccessful, mistaken, repeated or poorly drafted grievance is not automatically false or frivolous.
Paragraph (e) requires verifiably authentic information when correction or erasure rights are exercised. It supports reliable identification and protects records against unauthorised alteration or deletion. It does not authorise excessive identity collection or a universal requirement to produce government documents.
The enforcement consequence is limited but real. A breach may attract a civil monetary penalty up to ₹10,000 through the statutory process. The Data Fiduciary cannot impose that statutory penalty itself or use Section 15 to avoid its own duties.
Key point
The controlling proposition is that Section 15 requires Data Principals to exercise DPDPA rights and participate in personal-data processing honestly and lawfully, without impersonation, material suppression, abusive complaints or inauthentic correction and erasure material, while preserving the Data Fiduciary’s independent and non-transferable responsibility for compliance with the Act.
Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.