Pricoris

Who Is a Data Principal Under the DPDP Act? Rights, Duties and Examples

A data principal is the individual to whom personal data relates. That is the definition in Section 2(j) of the DPDP Act. Where the individual is a child, the term includes their parents or lawful guardian, and where the individual is a person with a disability, it includes a lawful guardian acting on their behalf. The data principal is the Indian law’s counterpart to the GDPR’s data subject, with one difference that surprises most organisations: the Act gives data principals duties as well as rights.

Every obligation a data fiduciary carries is owed to data principals. Knowing who they are, what they can ask for and what they owe in return is what turns a privacy policy into a working process.

Who counts as a data principal

Only individuals. A company is never a data principal, although the people who work for it are. In practice, an organisation’s data principals usually include:

  • customers and prospective customers;
  • employees, former employees and job applicants;
  • patients, students or members, depending on the sector;
  • website and app users;
  • the named contacts at suppliers and business customers.

Two groups act through someone else. A child, meaning anyone under eighteen, is represented by a parent or lawful guardian, and a data fiduciary must obtain verifiable parental consent before processing a child’s data under Section 9 and Rule 10. A person with a disability who has a lawful guardian acts through that guardian.

The rights of a data principal

RightSectionWhat the organisation must do
Information about how their data is processedSection 11Provide a summary of the personal data held and how it is processed, and the identities of other fiduciaries and processors it has been shared with
Correction, completion, updating and erasureSection 12Act on the request, and erase data no longer needed unless the law requires it to be kept
Grievance redressalSection 13Run a readily available grievance route and respond within the prescribed time; Rule 14 sets an outer limit of 90 days
NominationSection 14Let the individual nominate someone to exercise their rights in the event of death or incapacity
Withdrawal of consentSection 6Make withdrawal as easy as giving consent, and stop processing, including by processors, within a reasonable time

One detail matters for employers and for any organisation relying on legitimate uses. The information right in Section 11 and the correction and erasure right in Section 12 attach to data the individual consented to, including data given voluntarily under Section 7(a). Where processing rests on another legitimate use, such as employment, those two rights do not apply in the same way, although grievance redressal does.

A data principal must use the organisation’s own grievance process before complaining to the Data Protection Board, under Section 13(3). A clear, working grievance route is therefore an organisation’s first line of defence.

The duties of a data principal

Section 15 places five duties on data principals. They must:

  • comply with the law when exercising their rights;
  • not impersonate another person when providing personal data;
  • not suppress material information when providing personal data for any document, unique identifier, proof of identity or proof of address issued by the State;
  • not register a false or frivolous grievance or complaint;
  • provide only verifiably authentic information when exercising the right to correction or erasure.

Breach of these duties carries a penalty of up to INR 10,000. The duties are narrow, and organisations should not use them to discourage requests. Their practical value lies in handling requests made in bad faith, such as repeated frivolous complaints.

What this means for your organisation

Organisations that handle data principals well do four simple things. They publish one clear route for requests and grievances. They name one person who owns it. They use standard templates for each type of request, with a way to verify identity. And they keep a register of every request and its outcome, which becomes their evidence of compliance. Our guide to DPDP compliance on a startup budget explains why this is usually enough without rights management software, and our consent notice guide covers the notice that tells data principals about these rights in the first place.

These duties take effect on 13 May 2027, eighteen months after the DPDP Rules were notified. For help building the process, see our DPDP consulting page. Large organisations should also check whether they may be notified as a significant data fiduciary.

Frequently asked questions

Is a data principal the same as a data subject under the GDPR?

Broadly, yes: both are the individual the personal data is about. The DPDP Act differs in giving data principals duties as well as rights, and in tying some rights to data given with consent.

Can a company be a data principal?

No. Only individuals are data principals. The employees and business contacts of a company are data principals in their own right.

Who is the data principal when the data is about a child?

The definition includes the child’s parents or lawful guardian, and verifiable parental consent is required before a child’s data is processed.

How quickly must an organisation respond to a data principal?

Rule 14 sets an outer limit of 90 days for grievances. Most organisations should set shorter internal targets so that the limit is never tested.

Can a data principal complain directly to the Data Protection Board?

Only after using the organisation’s own grievance process, under Section 13(3) of the Act.

What duties does a data principal have?

Five, under Section 15, including not impersonating others, not suppressing material information in documents issued by the State, and not filing false or frivolous complaints. Breach carries a penalty of up to INR 10,000.


Sandhya Khamesra is Founder and CEO of Pricoris LLP, a Noida-based data privacy and governance consultancy that provides DPDP consulting. She is a Chartered Accountant with more than 35 years across information security, privacy and risk management. This article is general commentary on the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as in force on 22 September 2026. It is not legal advice. Last reviewed 22 September 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top