Pricoris

Data Subject Rights under DPDP Act Access Correction Erasure and Grievance Handling in India

Data Subject Rights are a core obligation under DPDP compliance in India. Organisations must enable individuals to exercise control over their personal data through structured, time-bound processes. These rights are enforceable and require operational readiness across systems and teams

Data Subject Rights

What are Data Subject Rights under DPDP 

DPDP grants individuals the right to
• Access information about their personal data
• Request correction and updating
• Request erasure of personal data
• Raise grievances
• Nominate another individual (as applicable)

These rights require organisations to move from policy statements to executable workflows

Why Data Subject Rights are a High-Risk Area 

Common challenges
• Data spread across multiple systems
• No central tracking of requests
• Manual handling leading to delays
• Inability to verify identity

Risk scenarios

SituationRisk
Incomplete responseRegulatory exposure
Delayed responseComplaint escalation
Data not foundLoss of trust
Inconsistent handlingAudit failure

Data Subject Rights Lifecycle 

StageKey ActionsEvidence
Request intakeCapture request through defined channelRequest logs
Identity verificationValidate requester identityVerification records
Data discoveryLocate data across systemsData mapping output
ActionCorrect / delete / provide accessExecution logs
ResponseCommunicate outcomeResponse records
ClosureRecord completion and timelineAudit trail

Request Handling Framework 

Organisations must define
• Channels for request submission (portal, email, support)
• Identity verification process
• Classification of request type
• SLA and response timelines
• Escalation and grievance handling

Automation is recommended for scale

Linkage with Consent and Retention 

Consent
• Withdrawal of consent may trigger deletion

Refer: Consent Management under DPDP

Retention
• Erasure may be denied if retention is legally required

Refer: Data Retention under DPD

This creates a dependency between rights, consent and retention controls

Technology and System Requirements 

Required capabilities
• Central request tracking system
• Data discovery and mapping integration
• Workflow automation
• Audit logs

Advanced
• API-based data retrieval
• Unified privacy dashboard

Common Failures Observed 

• No defined workflow
• Identity verification not implemented
• Requests handled outside system
• No linkage to data inventory
• No audit trail

These gaps weaken DPDP compliance defensibility

Executive View 

Data Subject Rights are a direct interface between organisation and individual

They impact
• Regulatory compliance
• Customer trust
• Operational efficiency

Failure in rights management often leads to complaints and enforcement action

FAQs

What are Data Subject Rights under DPDP
Rights provided to individuals to access, correct, erase and control their personal data

Can erasure be denied
Yes if retention is required under law

How should requests be handled
Through defined workflows with tracking and audit trail

Are timelines defined
Timelines are expected to be reasonable and prescribed as applicable

Also Read

https://pricoris.com/blog/dpdp-vs-gdpr/
https://pricoris.com/blog/dpdp-act-compliance-guide/
https://pricoris.com/blog/dpdp-retention-erasure-guide/
https://pricoris.com/blog/notice-and-consent-under-the-dpdp-act/
https://pricoris.com/blog/how-iso-27701-2025-redefines-privacy-risk/
https://pricoris.com/blog/ai-guardrail-assessment/
https://pricoris.com/blog/ai-shared-responsibility-and-contractual-clauses-for-saas/
https://pricoris.com/blog/ai-risk-assessment/
https://pricoris.com/blog/consent-management-udner-dpdp-act/
https://pricoris.com/blog/data-retention-under-dpdp-act/
https://pricoris.com/blog/dpdp-compliance-in-india/
https://pricoris.com/blog/dpdp-certification-in-india/
https://pricoris.com/blog/data-subject-rights-under-dpdp-act/
https://pricoris.com/blog/data-breach-management-under-dpdp-act/

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top