Grievance Redressal Under DPDP Act 2023
Learn how DPDP grievance redressal works, from internal handling to escalation before the Data Protection Board.
Discuss this page with an LLM
DPDP Action Sheet
Use this before your next workflow goes live. It keeps the useful parts visible and turns DPDP into checks your team can actually answer.
For Grievance Redressal Under DPDP Act 2023, the DPDP question is how personal data enters the workflow, where it is stored, which tools touch it, what purpose was explained, and how deletion or withdrawal will work.
1. Lead Forms
Check:
- What data are you collecting?
- Is the purpose clear at the point of collection?
- Is marketing consent separate from service communication?
- Can the user withdraw consent later?
Common mistake: one checkbox that silently covers newsletters, sales calls, partner sharing and remarketing.
2. Email and WhatsApp
Check:
- Who is on the list?
- Where did consent come from?
- Is the list imported from a vendor, event, webinar, scrape or old CRM?
- Can you prove the source of consent?
Common mistake: treating every lead as permanently marketable.
3. Ads and Retargeting
Check:
- Are pixels or ad platforms receiving identifiable user behavior?
- Are audiences built from customer lists?
- Are lookalike or remarketing audiences using personal data?
Common mistake: assuming "the ad platform handles it" means your company has no DPDP responsibility.
4. Website Analytics
Check:
- Which tools run on the site?
- Are IP address, device identifiers, session IDs or form fields being captured?
- Is analytics used only for measurement, or also for profiling and targeting?
Common mistake: installing tools first and asking privacy questions later.
5. Vendor List
Make a quick list:
- CRM
- Email platform
- WhatsApp provider
- Analytics
- Ad pixels
- Form tool
- Landing page builder
- Webinar tool
For each vendor, answer: what data goes there, why, who can access it and how deletion works.
6. This Week's Action
Map one campaign from first click to final follow-up. Mark every place personal data is collected, enriched, shared, uploaded or used for targeting.
If your team cannot answer where the data came from and where it goes next, start with a data flow map before rewriting policy copy.
Book a DPDP clarity callWant all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.
The Grievance Officer Mandate
Every data fiduciary must appoint a Grievance Officer and publish their contact details on their website footer. This person is the legal bridge between your company, the user, and the Data Protection Board. They must manage specific requests like data porting or consent withdrawal that standard customer support teams are not trained to handle.
Identity Verification vs. Data Minimization
When a user asks to see what data you hold, you must verify their identity. However, you cannot demand a physical copy of a government ID if a digital OTP or an existing login can confirm their identity. Collecting excessive identification documents to process a simple grievance creates a new, unnecessary data liability for your firm.
| Workflow | Personal Data Involved | DPDP Risk |
|---|---|---|
| Identity Verification | Aadhaar numbers, OTPs, or photo IDs | Storing ID copies after the ticket is closed |
| Complaint Logging | Transaction history and chat logs | Keeping detailed logs longer than the resolution period |
| Escalation to Vendors | User email and specific complaint details | Sharing PII with outsourced support without a contract |
| Board Reporting | Summary of grievances and resolution times | Including specific user names in reports to the Board |
This week
Check your website footer. Ensure the name, email address, and phone number of your Grievance Officer are clearly visible and that the email inbox is monitored daily.
Now think about your work. Where does personal data enter your workflows? Where does it sit? Who else touches it?
Frequently asked questions
Can we charge a fee for processing a data access request?
No. The DPDP Act requires that users be able to exercise their rights and file grievances without any financial cost.
How long do we have to resolve a grievance before the user can go to the Board?
Users must exhaust your internal grievance process first. You must resolve the issue within the specific period set by the government rules to prevent the user from escalating the matter to the Data Protection Board.
Can our existing customer support head serve as the Grievance Officer?
Yes, provided their contact information is publicly listed and they have the authority to pull data records or delete entries across all your company's databases.