A data principal is the individual to whom personal data relates. That is the definition in Section 2(j) of the DPDP Act. Where the individual is a child, the term includes their parents or lawful guardian, and where the individual is a person with a disability, it includes a lawful guardian acting on their behalf. The data principal is the Indian law’s counterpart to the GDPR’s data subject, with one difference that surprises most organisations: the Act gives data principals duties as well as rights.
Every obligation a data fiduciary carries is owed to data principals. Knowing who they are, what they can ask for and what they owe in return is what turns a privacy policy into a working process.
Who counts as a data principal
Only individuals. A company is never a data principal, although the people who work for it are. In practice, an organisation’s data principals usually include:
- customers and prospective customers;
- employees, former employees and job applicants;
- patients, students or members, depending on the sector;
- website and app users;
- the named contacts at suppliers and business customers.
Two groups act through someone else. A child, meaning anyone under eighteen, is represented by a parent or lawful guardian, and a data fiduciary must obtain verifiable parental consent before processing a child’s data under Section 9 and Rule 10. A person with a disability who has a lawful guardian acts through that guardian.
The rights of a data principal
| Right | Section | What the organisation must do |
|---|---|---|
| Information about how their data is processed | Section 11 | Provide a summary of the personal data held and how it is processed, and the identities of other fiduciaries and processors it has been shared with |
| Correction, completion, updating and erasure | Section 12 | Act on the request, and erase data no longer needed unless the law requires it to be kept |
| Grievance redressal | Section 13 | Run a readily available grievance route and respond within the prescribed time; Rule 14 sets an outer limit of 90 days |
| Nomination | Section 14 | Let the individual nominate someone to exercise their rights in the event of death or incapacity |
| Withdrawal of consent | Section 6 | Make withdrawal as easy as giving consent, and stop processing, including by processors, within a reasonable time |
One detail matters for employers and for any organisation relying on legitimate uses. The information right in Section 11 and the correction and erasure right in Section 12 attach to data the individual consented to, including data given voluntarily under Section 7(a). Where processing rests on another legitimate use, such as employment, those two rights do not apply in the same way, although grievance redressal does.
A data principal must use the organisation’s own grievance process before complaining to the Data Protection Board, under Section 13(3). A clear, working grievance route is therefore an organisation’s first line of defence.
The duties of a data principal
Section 15 places five duties on data principals. They must:
- comply with the law when exercising their rights;
- not impersonate another person when providing personal data;
- not suppress material information when providing personal data for any document, unique identifier, proof of identity or proof of address issued by the State;
- not register a false or frivolous grievance or complaint;
- provide only verifiably authentic information when exercising the right to correction or erasure.
Breach of these duties carries a penalty of up to INR 10,000. The duties are narrow, and organisations should not use them to discourage requests. Their practical value lies in handling requests made in bad faith, such as repeated frivolous complaints.
What this means for your organisation
Organisations that handle data principals well do four simple things. They publish one clear route for requests and grievances. They name one person who owns it. They use standard templates for each type of request, with a way to verify identity. And they keep a register of every request and its outcome, which becomes their evidence of compliance. Our guide to DPDP compliance on a startup budget explains why this is usually enough without rights management software, and our consent notice guide covers the notice that tells data principals about these rights in the first place.
These duties take effect on 13 May 2027, eighteen months after the DPDP Rules were notified. For help building the process, see our DPDP consulting page. Large organisations should also check whether they may be notified as a significant data fiduciary.
Frequently asked questions
Broadly, yes: both are the individual the personal data is about. The DPDP Act differs in giving data principals duties as well as rights, and in tying some rights to data given with consent.
No. Only individuals are data principals. The employees and business contacts of a company are data principals in their own right.
The definition includes the child’s parents or lawful guardian, and verifiable parental consent is required before a child’s data is processed.
Rule 14 sets an outer limit of 90 days for grievances. Most organisations should set shorter internal targets so that the limit is never tested.
Only after using the organisation’s own grievance process, under Section 13(3) of the Act.
Five, under Section 15, including not impersonating others, not suppressing material information in documents issued by the State, and not filing false or frivolous complaints. Breach carries a penalty of up to INR 10,000.
Sandhya Khamesra is Founder and CEO of Pricoris LLP, a Noida-based data privacy and governance consultancy that provides DPDP consulting. She is a Chartered Accountant with more than 35 years across information security, privacy and risk management. This article is general commentary on the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as in force on 22 September 2026. It is not legal advice. Last reviewed 22 September 2026.