July 28, 2026 · Alastor InfoSec Team
DPDPA Data Principal Rights: What Indian Businesses Must Build Before November 2026
India's Digital Personal Data Protection Act (DPDPA) is not just a compliance exercise in data mapping and breach notification. At its core, the law creates a set of enforceable rights for every Indian resident whose personal data you process — rights that your technology, processes, and legal agreements must be able to honour on demand. With Phase 2 enforcement beginning November 13, 2026, the clock is running out for Data Fiduciaries who have been treating these rights as a future problem.
This post breaks down each right, what it requires you to build, and how to make your organisation operationally ready before November.
The Six Rights Every Data Principal Now Has
The DPDP Act grants Data Principals — the individuals whose personal data you collect — six primary rights. None of these are optional, and each carries enforcement teeth through the Data Protection Board of India (DPBI).
Right to Information (Section 11): A Data Principal can, at any time, request a summary of the personal data you are processing, the purposes for which it is being used, and the names of third parties (Data Processors, Consent Managers) with whom it has been shared. You must respond within a defined timeframe. This means you need a complete, queryable record of every data element you hold on every individual — not just aggregate compliance documentation, but individual-level data inventories.
Right to Correction and Erasure (Section 12): On request, you must update inaccurate personal data, complete incomplete records, and erase data that is no longer necessary for the purpose for which it was collected or for which consent was given. The erasure obligation is particularly demanding: it must cascade to your Data Processors and any consent-sharing arrangements. A deletion request that removes data from your production database but leaves it sitting in your analytics warehouse or your vendor's CRM is non-compliant.
Right to Grievance Redressal (Section 13): Every Data Fiduciary must appoint a Data Protection Officer (for Significant Data Fiduciaries) or an equivalent grievance officer and publish clear contact information. A Data Principal who believes their rights are being violated can file a complaint with your grievance officer first, and then escalate to the DPBI. The law expects a response — not a holding email, but an actual decision — within a reasonable time.
Right to Nominate (Section 14): Data Principals can nominate another individual to exercise their rights on their behalf in the event of death or incapacity. Most organisations have not considered this provision at all. It requires a nomination flow in your consent management system and a verification process for nominees.
What You Need to Build, System by System
Consent and Data Inventory Layer
The rights framework is only as strong as your data inventory. If you cannot answer the question "what personal data do we hold on User X and where does it live?", you cannot honour any of the rights above. Alastor Shield's compliance automation maps data processing activities to data flows and individual-level records, giving you the queryable inventory that Section 11 requests require.
Most organisations discover during this exercise that personal data is scattered across at least a dozen systems — a CRM, a marketing automation platform, a customer support tool, a cloud data warehouse, a BI tool, and multiple third-party SaaS products. Every one of those systems must be included in your rights-fulfilment workflow.
Rights Request Portal
You need a mechanism through which Data Principals can submit requests — for information, correction, erasure, or nomination. This can be a dedicated portal, a support workflow, or an integrated product feature, but it must be discoverable, accessible, and functional. The request must be acknowledged and actioned, not silently queued.
The portal also needs to verify identity before fulfilling requests. Returning all personal data about a user to an impostor is itself a data breach. Your verification mechanism must strike a balance between friction and security — especially for erasure requests, where an attacker who can spoof a request could delete records maliciously.
Downstream Deletion Propagation
Erasure under DPDPA does not mean only your database. Under Rule 7 of the DPDP Rules (notified November 2025), Data Fiduciaries must contractually require their Data Processors to delete or return personal data on instruction. That means your DPA (Data Processing Agreement) with every vendor, cloud provider, and SaaS tool must include a deletion instruction clause — and you must have a workflow to actually send that instruction and receive confirmation.
If you do not have updated DPAs with your processors, you are both non-compliant with the DPDP Rules and practically unable to honour erasure requests. This is one of the most commonly missed gaps we see when assessing DPDPA readiness.
Grievance Officer Registration and Response SLA
From November 13, 2026, the DPBI will be open to receive complaints from Data Principals who have not received satisfactory responses from Data Fiduciaries. If your grievance officer is not appointed, not discoverable on your website, or not actually responsive, complaints will go directly to the Board — with penalties of up to INR 250 crore (approximately USD 30 million) for failure to take reasonable security safeguards and up to INR 50 crore for failure to fulfil Data Principal rights obligations.
Appoint a named individual or team, publish the contact information in your Privacy Notice, define an internal SLA for acknowledgement and resolution, and log every request and response.
The Cascade Effect: Consent Manager Integration
Beginning in the June-August 2026 window, the central government is operationalising the Consent Manager framework under Rule 4. This changes the rights landscape materially. Once a Data Principal is using a Consent Manager — an interoperable platform through which they manage consent across multiple services — their withdrawal of consent must propagate to every Data Fiduciary using that Consent Manager.
For organisations that onboard Consent Managers as an approved channel for collecting consent, this means your systems must be able to receive and process a consent withdrawal signal from an external platform in near-real time. The technical integration requirement is non-trivial: you need an API endpoint that accepts the withdrawal signal, a process to stop all processing immediately, and a documented timeline for cascading the withdrawal to downstream processors.
Consent Manager registration under Rule 4 begins November 13, 2026. If you plan to integrate with registered Consent Managers, your API integration must be ready before that date.
A Practical Prioritisation for the Next 16 Weeks
Organisations that have not yet started on Data Principal rights should prioritise in this order: first, complete the data inventory (you cannot fulfil rights without it); second, stand up the grievance officer and publish contact information (this reduces DPBI exposure immediately); third, audit and update processor DPAs to include deletion obligations; fourth, build or procure the rights request portal; fifth, begin technical integration planning for the Consent Manager framework.
The November 2026 deadline is firm. Phase 3 in May 2027 will bring stricter notice requirements and the full 72-hour breach notification obligation, but the rights framework — grievance officer, data inventory, and erasure capability — is a Phase 2 obligation.
How Alastor InfoSec Can Help
Alastor Shield provides the compliance automation layer that makes Data Principal rights manageable at scale. It maps your data flows to individual-level records, tracks consent status, automates control monitoring for DPDPA obligations, and generates the evidence your grievance officer and future DPBI auditors will need. For organisations that need a full readiness assessment — data inventory, DPA audit, processor review, and rights portal gap analysis — our team can complete the engagement in four weeks.
Reach us at [email protected] or visit Alastor Shield to start your DPDPA readiness assessment.
Data Principal rights are not a box-checking exercise — they are enforceable obligations with penalties attached, and building the underlying infrastructure takes time that most organisations do not have left before November 13, 2026.