Chapter 4 — Data Principal Rights and Organisational Accountability
1. A right that exists on paper and nowhere else
There is a particular kind of failure that privacy statutes make easy, and it is worth naming at the start because everything in this chapter is built against it. An enterprise reads the rights provisions — the principal may request access, correction, erasure, grievance redressal, nomination — and responds by writing a policy. The policy says the rights exist. It may even enumerate them accurately, citing sections. And then nothing happens, because a policy is a description of services that do not exist: no intake channel that routes a request to an owner, no identity check that protects the principal’s data from the next stranger who asks for it, no aggregation machinery that can actually assemble a summary of what the enterprise holds, no propagation that reaches the processors, no evidence that any of it happened within any deadline.
When a real principal eventually invokes the right — and eventually one does — the policy is tested against reality, and reality fails. The request lands in a support inbox, is treated as a ticket, is answered by a well-meaning agent with no authority and no machinery, and the organisation may have failed the applicable duty despite its policy. The legal conclusion depends on scope, commencement and the actual response, not on the ticket label alone.
This chapter’s central idea is the antidote, and it is deliberately operational:
A right is not satisfied because it appears in the Act or in a policy. A right is satisfied because the organisation runs a named, funded, evidenced service that delivers it — a service with an owner, an intake, an identity-assurance step, an SLA, an execution path that reaches processors, and an evidence trail. And accountability is not “a DPO exists” — it is a set of named owners with decision rights for each service, answerable for the service actually working. The rights-to-service matrix is the instrument that makes this concrete enough to build and to audit.
2. The rights and duties, read carefully
The Act grants the Data Principal four rights (Sections 11 to 14) and imposes five duties (Section 15). Reading them precisely matters, because each one carries an operational consequence the service design must honour.
The right to access information (Section 11). A principal who has previously given consent, including the Section 7(a) case, may request from the fiduciary: (a) a summary of the personal data being processed and the processing activities undertaken; (b) the identities of all other Data Fiduciaries and Data Processors with whom her personal data has been shared, along with a description of the data so shared; and (c) any other prescribed information. Two design consequences follow immediately. First, the service is not “send the principal her record” — it is a summary of processing plus a sharing disclosure, which presumes the inventory (Chapter 7) and the processor map (Chapter 17) exist. Second, Section 11(2) excludes (1)(b)/(c) in respect of sharing with another fiduciary authorised by law to obtain the data, on its written request for prevention/detection/investigation of offences or cyber incidents, or prosecution/punishment of offences. It does not remove the (1)(a) summary. The record must prove recipient authority, written request and qualifying purpose, not merely say “law enforcement” (ACT:441–462[3]).
The right to correction, completion, updating and erasure (Section 12). This also concerns prior-consent processing, including Section 7(a), in accordance with applicable legal requirements/procedure (ACT:463–476[3]). On a correction request, the fiduciary must correct inaccurate or misleading data, complete incomplete data, and update it (Section 12(2)) — three distinct operations a service must be able to distinguish. On an erasure request, the fiduciary shall erase — the duty is expressed strongly — unless retention is necessary for the specified purpose or for compliance with any law (Section 12(3)). That “unless” is the lawful-retention assessment of Chapter 14, and it means the erasure service must be able to make and document a per-request retention judgement, not a global one.
The right to grievance redressal (Section 13). The principal is entitled to “readily available means of grievance redressal” from the fiduciary or its Consent Manager (Section 13(1)). Rule 14(3) requires a prominently published reasonable grievance-response period not exceeding ninety days and measures to make the system effective. This is a grievance period, not a uniform deadline for access, correction or erasure (ACT:477–487[3]; RULES:1308–1311[4]). And then the provision that changes the geometry of the whole chapter: the principal must exhaust this grievance route before approaching the Board (Section 13(3)).
The right to nominate (Section 14). The principal may nominate another individual to exercise her rights in the event of death or incapacity. Section 14(2) defines incapacity as inability to exercise those rights due to unsoundness of mind or infirmity of body. Rule 14(4) permits one or more nominees in accordance with terms of service and applicable law, using the specified means/particulars; there is no nomination schedule (ACT:489–495[3]; RULES:1312–1318[4]). Operationally, this is two services, not one — intake of a nomination during the principal’s life, and activation at the hardest possible moment, when the requester arrives with a death certificate or a capacity question, and the service must verify and act without over-collecting.
The duties of the Data Principal (Section 15). The principal must comply with law while exercising rights, must not impersonate, must not suppress material information in State-issued documents, must not register false or frivolous grievances or complaints with the fiduciary or Board, and must furnish only verifiably authentic information when exercising correction or erasure. These duties matter to the service design — they justify the identity-assurance and validation steps — but the boundary must be held: Section 8(1) makes the fiduciary responsible irrespective of a principal’s failure to perform her duties, so the duties power the service’s checks and never excuse its failures.
3. The tension: the exhaustion screen cuts both ways
Of everything in this chapter, Section 13(3) deserves the closest strategic reading, because it creates a tension that runs in both directions at once.
The provision looks, at first, like pure protection. The principal cannot run to the Board without first coming to the enterprise; the grievance service is a mandatory first door; the Board’s docket is screened by the enterprise’s own redressal. Read that way, a cynical enterprise sees an opportunity: make the grievance channel technically existent but practically dismal — buried in a terms page, answered slowly, resolved never — and the principal is trapped behind the screen.
The trap catches the enterprise, not the principal. Section 13(1) does not merely require a channel; it requires “readily available” means, and Section 13(2) requires a response within the applicable published reasonable grievance period. A buried or non-responsive channel may breach Section 13, and the principal who was blocked at the enterprise’s door arrives at the Board with a documented failure as her exhibit. Meanwhile the enterprise that built the service properly gets the protection the provision actually offers: grievances resolved early and cheaply, a defensible record that it responded within the period, and a record of exhaustion genuinely attempted before escalation. It cannot guarantee that a principal will not complain or dictate the Board’s outcome. Do not force a principal with a qualifying final rejection to wait an invented universal ninety-day moratorium; exhaustion is assessed against the actual grievance opportunity (ACT:477–487[3]).
The exhaustion screen protects only the enterprise that deserves it. The grievance service is either a real service — available, responsive, evidenced — or it is a liability manufacturing Board complaints out of frustrated principals. The rights-to-service matrix below therefore treats the grievance service not as the least-important right but as the strategic one: it is the enterprise’s front door to the principal and its first line before the regulator, and it is run, staffed, and measured accordingly.
4. The rights-to-service ownership matrix
The recommended matrix names a service, a Responsible owner, an Accountable owner, an identity-assurance approach, and an service target. The Act does not prescribe these five management fields, and the target is not substituted for the applicable statutory obligation.
| Right | Scope / legal output | Recommended owners (R / A) | Identity / exception gate | External clock versus internal target |
|---|---|---|---|---|
| Access, Section 11 | Prior consent including Section 7(a); data/activity summary, recipient identities and shared-data description, any prescribed further information | DataOps / privacy service owner | Verify subject and actor; documented Section 11(2) exception only for (1)(b)/(c) | No universal numerical response SLA stated by these provisions; illustrative internal target: ten calendar days |
| Correction/completion/update, Section 12(2) | Same prior-consent scope; correct misleading/inaccurate data, complete and update | DataOps / privacy service owner | Verify subject, request and disputed-data evidence; propagate relevant corrections as recommended implementation, not Section 8(7)(b) quotation | Illustrative internal target: ten calendar days; not statutory |
| Erasure, Section 12(3), Section 8(7) | Scope each retained category; distinguish specified-purpose/law retention from unrestricted reuse | DataOps and engineering / privacy service owner | Verify request; apply Rule 8(3), Rule 6(1)(e) and evidenced other-law needs; no wholesale refusal | Illustrative internal target: ten calendar days for component decision/response; not permission to postpone legally required action |
| Grievance, Section 13 / Rule 14(3) | Readily available means; respond within reasonable published period, at most ninety days | GrievanceOps / privacy service owner | Proportionate identity/communication checks; do not reject complaints merely because disputed | Scenario policy: published thirty-calendar-day response period from receipt, reviewed for reasonableness; statutory maximum is not a target |
| Nomination, Section 14 / Rule 14(4) | Nominee(s) exercise original subject’s rights on death/incapacity under applicable terms/law | IdentityOps / privacy service owner | Subject, acting nominee, authority, scope and activation remain separate; conflict/recovery paths | Illustrative internal target: ten calendar days for intake/authority decision, not a statutory nomination SLA |
| Principal duties, Section 15 | Legal duties while exercising rights/providing data; do not excuse fiduciary failures | IdentityOps / privacy service owner | Validate authenticity without punitive automated blocking | No separate invented service clock |
These owners and targets are author recommendations for the fictional Company. It is not_designated, so its privacy owner is not falsely represented as a mandatory statutory SDF DPO. An actual SDF must appoint the Section 10 DPO; Rule 9 otherwise permits a person able to answer processing questions. Publish business contact information on the site/app and in every rights response (ACT:376–381,418–426[3]; RULES:1168–1172[4]).
The service must publish means and identifying particulars under Rule 14(1), while Rule 14(2)‘s prior-consent wording is read with the parent Act. Mixed-ground employee requests need component assessment; the conservative service design keeps grievance and nomination intake open rather than using employment Section 7(i) to remove every channel. A voluntary access extension is labelled as such, not misstated as a statutory Section 11 entitlement (QL-010).
Two rows deserve comment beyond their cells. The erasure row carries Chapter 14’s lawful-retention assessment inside it — the service is never a bare delete button, and the documented judgement is part of the response’s defensibility. And the duties row is deliberately a row: Section 15’s duties belong in the matrix as the design input for every identity-assurance cell, not as a free-standing policy statement.
The recommended matrix also extends downstream because applicable outputs may depend on processor-held data. An access response that cannot describe sharing (Section 11(1)(b)) because the processor map is incomplete is a failed response; an erasure that stops at the primary database cannot be called complete while an applicable processor-erasure action is unresolved. Lawful retained copies are distinguished from failed erasure; a processor acknowledgement is evidence of its assertion, not proof of physical disposal. The services depend on the inventory (Chapter 7), the purpose matrix (Chapter 8), and the processor contracts (Chapter 17) — which is why rights arrive where the design joins to those foundations. Intake, grievance ownership and urgent incident response must still be established in parallel rather than withheld until discovery is complete.
5. Accountability: named owners, decision rights, evidence
The matrix names owners; accountability gives them authority, and three practices make it real rather than nominal.
Decision rights are written down. Each service has a defined authority for its judgement calls: who may apply the Section 11(2) carve-out, who signs the Section 12(3) lawful-retention decision, who may deny a request and on what documented basis. A denial with no named decision-maker is not a decision; it is a liability. The exception authority of Chapter 1 applies here in miniature.
Counsel is consulted at the boundaries, not after the failures. The carve-outs and retention judgements are exactly the places Chapter 1’s residual discipline flags; the service design routes them to counsel as decision gates — with the facts, the provision, and the principal’s request — rather than discovering them as complaints.
The evidence belongs to the enterprise, not the tool. Whatever platform or ticketing runs the service (Chapters 28, 30), the case record — requester, identity-assurance result, validation, action, proof, response, timing — is the enterprise’s own evidence, landing in the Chapter 22 grid. An unprovable SLA claim should be reported as unverified, not silently changed into either a demonstrated success or a proved timing failure.
6. The control-test-evidence set
The author recommends testing these services with the Chapter 22 fixture families — and rights services have a specific shape of test that deserves spelling out:
- Positive: a valid access, correction, erasure, and grievance each completes within SLA with the correct result and a reconstructible case record.
- Negative: an unauthorised requester receives no personal-data disclosure. A valid nominee is not denied merely for being a different actor: check authority separately from subject identity.
- Race: an erasure request racing an access request on the same record produces a consistent outcome, not a half-deleted disclosure.
- Processor: a required scoped action reaches the processor; absent acknowledgement remains failed/unconfirmed, not completed. Test both authorised retention and eligible disposal, and obtain evidence beyond a generic receipt where deletion is asserted.
- Adversarial: reject forged authority for data release, preserve the complaint record, and route disputed authenticity or alleged frivolousness to a human. Section 15 is not a licence to silence a genuine grievance; Section 28(12) separately gives the Board warning/cost powers.
- Restore: load the older SNAP-001 into SYS-014 quarantine, replay later WITHDRAW-001 restrictions, and deny marketing before access. Retained bytes and permitted use are separate; this tests the restriction path, not universal erasure.
- Exhaustion: a grievance is answered within the Section 13(2) period, with the response evidenced — the test that makes the Section 13(3) screen defensible.
7. A compound rights case with an unresolved processor branch
CASE-001 / RIGHTS-001 is a synthetic specimen at EVT-009, 2 June 2027 12:00 +05:30, assuming the retained core provisions commence unchanged. SUB-001 is both subject and acting requester at intake; the authenticated account assertion is stipulated for teaching, not a deployed identity check. The request asks for access, correction and erasure. CONSENT-001/PUR-001 and the earlier CONSENT-002/PUR-002 establish the scenario’s prior-consent scope. WITHDRAW-001 has already revoked marketing, and ACK-001 from ENT-004 is absent at the illustrative five-minute target. That target is not Section 6(6)‘s statutory “reasonable time”.
The privacy service owner records DEC-006 component by component. A source-backed Rule 8(3) minimum applies to processing-related personal data/traffic/logs; Rule 6(1)(e) separately applies to the relevant security evidence. The author recommends restricted archive access, no marketing use and an eligibility-review event, not a fabricated definitive disposal date. HOLD-001 is only a proposed narrow hold on disputed DS-002; its other-law authority is not yet established and is not claimed as an additional legal retention justification. The verified Rule 8(3) layer already prevents promising immediate total destruction. QL-001 preserves reset/copy/overlap interpretation; no ten-year bank illustration is substituted for a real NBFC retention instrument.
Specimen access response — illustrative, not sent
“Case RIGHTS-001 concerns SUB-001. We process borrower contact/profile information in DS-001 for requested loan-application handling PUR-001; loan application and transaction information in DS-002; and consent/notice events in DS-004. Optional marketing PUR-002 is withdrawn. For this specimen, sharing is stipulated with ENT-003 for hosting of borrower/application records and ENT-004 for the optional marketing contact/preference projection DS-003. No insurer referral has occurred for this subject, so ENT-002 is not invented as a recipient. We have not established a Section 11(2) exception in your case. Processing and sharing verification with ENT-004 remains open; this response is an interim description, not a claim that our recipient inventory is complete. Your correction and erasure components are answered separately. Contact: the Company’s privacy service owner through the authenticated case reply channel.”
This specimen shows why unknown sharing must be stated rather than filled with a plausible supplier list. For an actual final statutory response, establish the complete required summary and sharing information; an interim response does not erase that obligation. The recommended case record binds each recipient and data category to evidence, not just to a vendor catalogue. The Rule 9 business contact must be populated with the real responsible person’s published business channel before use; the role label here is synthetic, not a ready-to-send client address.
Specimen correction and partial-erasure decision — illustrative, not sent
“Your contact correction has been accepted for action in DS-001; completion will be confirmed only after the authoritative record and relevant downstream uses are checked. Marketing authorisation PUR-002 is withdrawn. We have blocked new Company marketing decisions in the scenario, but ENT-004’s acknowledgement is missing; processor cessation remains unconfirmed and escalated. We are not claiming your data is deleted everywhere. Relevant processing records remain restricted for the Rule 8(3) minimum one-year retention requirement, and applicable security evidence for Rule 6(1)(e). This retained evidence cannot be used to restart marketing. We will separately track disposal eligibility and any substantiated legal hold; the proposed loan hold does not cover marketing data and has not been treated as proved legal authority.”
This is a reasoned partial response recommended by the author, not a claim that Section 12(3) specifies this wording or a particular receipt schema. It distinguishes accepted request, intended correction, locally restricted use, unresolved supplier execution and legally required retained evidence. The statutory component is the correction/erasure/retention analysis; the split statuses and explanatory text are operating design. Neither an internal ten-day target nor closing a correspondence ticket proves erasure.
Specimen grievance reply — illustrative, not sent
“Your complaint that marketing continued after withdrawal is registered against RIGHTS-001. The missing ENT-004 acknowledgement and potential stale audience path remain under investigation. The supplier feed is restricted in the proposed response plan; we will not report confirmed end-to-end cessation until evidence supports it. Your next case update is targeted for 3 June 2027, and our hypothetical published grievance-response period is thirty calendar days from receipt, subject to providing a reasonable response rather than waiting unnecessarily. You may continue to use this case channel. Section 13 requires exhaustion of the grievance opportunity before approaching the Board; this reply does not waive your right to complain or impose an additional waiting period after a qualifying final decision.”
No notification or message was transmitted, no fix was observed, and no principal’s decision not to complain is asserted. Chapter 12 owns the detailed rights workflow, Chapter 10 the cessation interface and Chapter 14 disposal/restore. This chapter supplies the accountable communication pattern they must support, including the failed branch rather than a guaranteed inquiry-proof ending.
Nominee dispute without changing the subject
At EVT-012, NOM-001 and NOM-002 name SUB-006 and SUB-007 for SUB-001. EVT-013 stipulates a substantiated incapacity and conflicting instructions. DEC-008 pauses disputed execution while authority and scope are resolved; subject_id remains SUB-001 and actor_id names the requesting nominee. EVT-014’s recovery revokes activated representative authority in the recommended design. It does not erase the subject’s history or transfer ownership of her identifier. The actual evidential standard and dispute handling need legal/operational review; neither the Seventh Schedule nor a convenient database re-key supplies them.
8. What remains for the reader and the reviewer
The retained English Rule 14 mechanism and grievance period are no longer unread residuals. The remaining questions are application-level: granularity and completeness of the Section 11 summary, a proved Section 11(2) disclosure exception, retention/reset/copy interaction under QL-001, mixed-ground handling under QL-010, and proportionate nominee authority/activation evidence. The Company must establish real service channels, published targets, reviewer authority and supplier evidence before deployment.
A practical acceptance review should try to make the service lie: ask for a total-erasure receipt while a minimum or failed processor remains; submit two conflicting nominee requests; restore a pre-withdrawal snapshot; or try to close access with an unknown recipient set. The required answer is an honest component status and a named action, not a green dashboard. These are proposed test specifications; local arithmetic checks in the remediation packet do not implement or validate a production rights service.
Bridge to the next chapter
With the rights mapped to services and their accountability named, one obligation remains that no single enterprise can satisfy alone: the principal’s data flows through regulators, sector rules, and jurisdictions that overlap and sometimes conflict — RBI directives and DPDP duties, CERT-In clocks and Board notifications, foreign contracts and Indian principals. Chapter 5 takes up Sector Regulation and Multinational Obligations — the discipline of reconciling DPDP with every other law it touches, without flattening a single conflict.
References (sources retained)
- DPDP Act 2023 — research/legal/evidence/01_dpdp_act_2023_gazette.txt (Sections 8, 11–15).
- DPDP Rules 2025 (GSR 846(E)) — research/legal/evidence/05_gsr_846e_dpdp_rules_2025.txt (Rule 14).
- Research, re-anchored not reused: right_to_erasure_gdpr.md and the rights-workflow note (research/operations/notes/) — pattern seeds only.
- Chapters 7, 8, 10, 14, 17 — the foundations the services depend on; Chapter 22 — the grid the evidence lands in.
Source key and provenance legend
Physical references use newline-based line numbers in the following retained source paths; each numbered reference resolves to its original source URL. Review date: 15 September 2026. Full calculated hashes and source versions: out/remediation/Q02/source-manifest.json. The Q01 baseline and its bounded official-update limitations remain controlling; no later-law absence or entity certification is asserted.
- ACT:
research/legal/evidence/01_dpdp_act_2023_gazette.txt— Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023).[3] - RULES:
research/legal/evidence/05_gsr_846e_dpdp_rules_2025.txt— Digital Personal Data Protection Rules, 2025, G.S.R. 846(E).[4] - COMM:
research/legal/evidence/02_gsr_843e_commencement.txt— G.S.R. 843(E), DPDP Act commencement notification.[5] - EST:
research/legal/evidence/03_gsr_844e_board_establishment.txt— G.S.R. 844(E), establishment of Data Protection Board of India.[6] - MEMBERS:
research/legal/evidence/04_gsr_845e_board_members.txt— G.S.R. 845(E), number of members of Data Protection Board of India.[7] - CORR:
research/legal/evidence/06_gsr_892e_corrigendum.txt— Corrigenda to G.S.R. 846(E), G.S.R. 892(E).[8] - RECRUIT:
research/legal/evidence/07_board_recruitment_notice_2026.txt— Filling up the post of Chairman & Members in the Data Protection Board of India.[9]
Sources
[3] https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf [4] https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf [5] https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf [6] https://www.meity.gov.in/static/uploads/2025/11/cc217843dc3bcb37b2b05bcc3b4e031f.pdf [7] https://www.meity.gov.in/static/uploads/2025/11/f6c0837972422cf79d890bfe84cc04d6.pdf [8] https://www.meity.gov.in/static/uploads/2025/12/3c7ebbae0e5456f493f486e6845df86b.pdf [9] https://www.meity.gov.in/static/uploads/2026/05/53b1bcf01cab9a0adde463e73fbc3417.pdf
Contents · Reader guide and citation conventions · Artifact index