Compliance Guide

Data Principal Rights Under DPDP Act 2023

Every Indian citizen has rights over their personal data under DPDP. Start your compliance journey.

Discuss this page with an LLM

DPDP Action Sheet

Use this before your next workflow goes live. It keeps the useful parts visible and turns DPDP into checks your team can actually answer.

For Data Principal Rights Under DPDP Act 2023, the DPDP question is how personal data enters the workflow, where it is stored, which tools touch it, what purpose was explained, and how deletion or withdrawal will work.

1. Lead Forms

Check:

  • What data are you collecting?
  • Is the purpose clear at the point of collection?
  • Is marketing consent separate from service communication?
  • Can the user withdraw consent later?

Common mistake: one checkbox that silently covers newsletters, sales calls, partner sharing and remarketing.

2. Email and WhatsApp

Check:

  • Who is on the list?
  • Where did consent come from?
  • Is the list imported from a vendor, event, webinar, scrape or old CRM?
  • Can you prove the source of consent?

Common mistake: treating every lead as permanently marketable.

3. Ads and Retargeting

Check:

  • Are pixels or ad platforms receiving identifiable user behavior?
  • Are audiences built from customer lists?
  • Are lookalike or remarketing audiences using personal data?

Common mistake: assuming "the ad platform handles it" means your company has no DPDP responsibility.

4. Website Analytics

Check:

  • Which tools run on the site?
  • Are IP address, device identifiers, session IDs or form fields being captured?
  • Is analytics used only for measurement, or also for profiling and targeting?

Common mistake: installing tools first and asking privacy questions later.

5. Vendor List

Make a quick list:

  • CRM
  • Email platform
  • WhatsApp provider
  • Analytics
  • Ad pixels
  • Form tool
  • Landing page builder
  • Webinar tool

For each vendor, answer: what data goes there, why, who can access it and how deletion works.

6. This Week's Action

Map one campaign from first click to final follow-up. Mark every place personal data is collected, enriched, shared, uploaded or used for targeting.

If your team cannot answer where the data came from and where it goes next, start with a data flow map before rewriting policy copy.

Book a DPDP clarity call

Want all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.

Managing Identity Verification

Organizations must verify a person’s identity before acting on a correction or erasure request. Collecting a full Aadhaar copy for a simple email change creates excessive data risk. Use “view-only” verification or OTP-based authentication to confirm the Data Principal’s identity without storing new sensitive documents.

The Retention Conflict

The right to erasure often conflicts with Indian tax laws that require keeping transaction records for seven years. You must categorize your database so that personal identifiers can be deleted while keeping the financial values required for audits. Tagging every data point with a “legal hold” status prevents accidental deletion of records required by other regulators.

Handling Nominees

The DPDP Act allows individuals to nominate someone to exercise their rights in case of death or incapacity. Your systems must store the nominee’s contact details separately from the primary user. You must ensure the nominee’s data is only used for rights management and is deleted once the primary account is closed or the nomination is revoked.

WorkflowPersonal Data HandledDPDP Compliance Risk
Grievance RedressalComplaint history, Phone, EmailStoring dispute logs after the legal limitation period
Right to CorrectionUpdated Address, New ID detailsFailing to sync updated data with third-party cloud vendors
Right to ErasureTransaction logs, User ProfileDeleting data that is currently part of an active tax investigation
NominationNominee Name, RelationshipProcessing nominee data without a specific “Nomination” consent notice

This week

Draft a standard response template for “Right to Erasure” requests. The template must list which data you will delete immediately and which data you are legally required to keep for tax or regulatory reasons.

Now think about your work. Where does personal data enter your workflows? Where does it sit? Who else touches it?

Frequently asked questions

Can we ignore a correction request if we believe our current data is accurate?

No, you must investigate the request. If you decide not to change the data, you must provide the individual with a written explanation of why their information is considered accurate.

How long do we have to respond to a grievance regarding data rights?

While the Act does not set a specific hourly deadline, you must respond within the timelines specified in your internal grievance policy. Most Indian consumer standards suggest a 7 to 30-day window for resolution.

Do we need to delete backup tapes if a user requests erasure?

You must ensure the data is "put beyond use." If immediate deletion from offline backups is technically impossible, you must ensure that data is not restored back into production systems.

Book clarity call