🛡 Today's alert: fake "electricity bill overdue" SMS scam is trending — never click payment links in SMS.
Online Privacy

India's Data Protection Law Is Finally Live — 7 Privacy Rights You Should Start Using

For years, "data protection" in India was a promise on paper. That changed on 14 November 2025, when the government notified the Digital Personal Data Protection (DPDP) Rules, 2025 — operationalising the DPDP Act, 2023. Companies, apps and websites that process your personal data now have enforceable legal duties, being phased in through 2026 and 2027, with penalties running up to ₹250 crore per violation.

Most Indians haven't noticed yet. Here's what the law actually gives you, and how to use it.

The 7 rights you now have

Companies ("data fiduciaries" in the law) must ask for your consent through a clear notice — what data, for what purpose — available in English or any of the 22 scheduled Indian languages. Bundled, buried, take-it-or-leave-it consent is exactly what the law targets.

Withdrawing consent must be as simple as granting it was. Once withdrawn, the company must stop processing and delete the data unless another law requires keeping it.

3. You can ask what a company holds about you

You have a right to a summary of the personal data being processed, the purposes, and every entity it has been shared with.

4. You can demand correction and erasure

Wrong phone number, stale address, an account you closed years ago — you can require correction, updating and erasure of data no longer needed for the purpose you consented to.

5. Grievances must be answered — on a clock

Every data fiduciary must publish a grievance officer contact and respond within defined timelines. If they don't, you can escalate to the Data Protection Board of India — the adjudicating body under the Act.

6. Children get special protection

Processing a child's data requires verifiable parental consent, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited.

7. You can nominate someone

You may nominate a person to exercise these rights for you in case of death or incapacity — a small clause with real consequences for digital inheritance.

What companies must now do

DutyWhat it means for you
Purpose limitationData collected for delivery can't quietly become marketing fodder
Breach notificationYou must be informed of data breaches affecting you, without delay
Data minimisation and erasureCompanies can't hoard your data forever "just in case"
Security safeguardsEncryption, access control and logging are legal duties, not best practices
Consent managersRegistered platforms will let you view and manage consents in one place

The honest caveats

  • Phased rollout. Core obligations take effect in stages — some duties apply from late 2026 into 2027. Companies are adapting now; full enforcement builds over time.
  • The Board is still being set up. As of mid-2026 the Data Protection Board is not yet fully operational, so escalation paths are still settling.
  • Government exemptions are broad, and the Act's amendment to the RTI Act is under challenge — in February 2026 the Supreme Court issued notice in petitions questioning parts of the DPDP framework. The law will keep evolving.
Start a paper trail anyway

Rights get real when people use them. Email a company's grievance officer requesting your data summary or erasure — even an ignored request builds the record that matters when the Board takes up complaints.

How to make a request that actually works

A vague email gets a vague reply. A request that names the right, states a deadline and creates a record is much harder to ignore — and if it is ignored, it becomes the evidence for your escalation.

Send it to the company's published grievance officer address, from the email or number registered with them, and keep it short:

Subject: Data principal request under the DPDP Act, 2023 — [your account/customer ID] I am a data principal whose personal data you process as a data fiduciary. Under the Digital Personal Data Protection Act, 2023, I request: 1. A summary of the personal data you hold about me and the purposes for which it is processed; 2. The identities of all data fiduciaries and processors with whom it has been shared; 3. [Choose: correction of the following inaccurate data — … / erasure of my personal data, as it is no longer necessary for the purpose for which it was collected / withdrawal of my consent for … ] Please confirm receipt and provide a substantive response within your published grievance timeline. Kindly note the reference number for this request. [Name, registered mobile/email, date]

Four things make the difference:

  • Send it to the grievance officer, not general support — that address carries a published response obligation.
  • Ask for a reference number. It converts "we never received it" into a documented failure.
  • Pick one clear ask. Erasure and a data summary in one email is fine; a page of grievances is not.
  • Diarise the deadline and follow up in writing the day it passes.

When they ignore you

Companies are still adjusting to this law, and the first request often goes nowhere. Escalate in order, keeping every reply:

  1. Follow up in writing once the published timeline lapses, referencing your original date and reference number.
  2. Escalate within the company — most publish a nodal or appellate officer above the grievance officer.
  3. Use the sector regulator, which is often faster. For a bank or NBFC, the RBI Ombudsman at cms.rbi.org.in; for telecom, the operator's appellate authority and the DoT route; for insurance, IRDAI's grievance system. These bodies are fully operational today, whereas the Data Protection Board is still being stood up.
  4. Complain to the Data Protection Board as its processes come online, with your documented trail ready.
  5. Consider the consumer route where the failure caused you actual loss — deficiency in service is separately actionable through e-Daakhil.
The five-rung escalation ladder for an ignored data request: the company's grievance officer, its nodal or appellate officer, your sector regulator such as the RBI Ombudsman or IRDAI which is fully operational today, the Data Protection Board of India which is still being established, and the consumer route where the failure caused actual loss.
Where a data request actually goes when it is ignored. Diagram by Awareness360.

The awkward but useful thing about that ladder is the mismatch between rungs 3 and 4. The body created specifically to enforce your data rights is the one still being built; the bodies that will actually move a company today were built for something else entirely and happen to cover you.

Sequence it accordingly. Use the sector regulator as your working escalation, and treat the Data Protection Board as the destination your paper trail is heading towards. A request refused in 2026 — with a date, a reference number and a documented silence — will be worth considerably more once the Board is hearing complaints than a stronger grievance you never put in writing.

5 practical moves this week

  1. Audit app permissions (Settings → Privacy): revoke location, contacts, microphone and SMS access from apps that don't need them.
  2. Use "delete account", not just "uninstall" — under the DPDP regime, deletion requests now carry legal weight.
  3. Find the grievance officer page of your bank, telecom and most-used apps — bookmark them.
  4. Check what Google and Meta hold on you (Google Takeout, Meta's "Download your information") — informed consent starts with knowing.
  5. Lock your Aadhaar biometrics in the mAadhaar app, and share masked Aadhaar wherever full details aren't required.

Frequently asked questions

Can I really force a company to delete my data?

You can require it, with limits. Erasure applies to personal data no longer necessary for the purpose you consented to — but a company may retain what another law requires it to keep. Banks, insurers and telecom operators have statutory record-retention obligations, so "delete everything" will not fully succeed there. Expect partial compliance in regulated sectors and full deletion from an app that had no reason to keep you on file.

Does the DPDP Act cover data collected before it came into force?

The obligations attach to processing, so data a company continues to hold and use falls within the regime — and companies were required to give notice to existing users about data already collected. In practice this is exactly why an access request is useful: it forces a company to account for what it is still holding from years ago.

What does it cost to complain?

Nothing. Writing to a grievance officer is free, and the regulator and ombudsman routes above cost nothing either. Be wary of anyone offering to pursue a data-protection claim for an upfront fee — the mechanisms here are designed to be used directly.

Is the Data Protection Board actually working yet?

Not fully. The Act's obligations are being phased in through 2026 and 2027, and the Board is still being established, so escalation paths are genuinely unsettled today. This is the honest gap in the law right now — which is why the sector regulators above are the more practical route for the moment. Build your paper trail anyway; it is what you will need once the Board is live.

Do these rights apply to government bodies?

Only partly. The Act contains broad exemptions for the State, including for national security, law enforcement and certain public functions. It also amended the RTI Act's personal-information exemption, which is under challenge before the Supreme Court. Rights against private companies are much stronger than rights against government processing.

An app won't work unless I accept everything. Is that allowed?

It depends on necessity. Consent is supposed to be specific and purpose-linked, and bundled take-it-or-leave-it consent is precisely what the law targets — but an app may legitimately require data genuinely necessary to provide its service. A ride app needs your location; a torch app does not need your contacts. Where the demand is plainly unnecessary, that is worth a grievance complaint.

What happens if my data is breached?

You are entitled to be informed of a breach affecting you. On learning of one, change that password and any password reused elsewhere, enable two-factor authentication, and watch for targeted phishing — breach data is what makes scam calls sound convincingly well-informed. If money is involved, treat it as fraud and call 1930 immediately.

A registered platform that will let you view, give and withdraw consents across services from one place, rather than hunting through dozens of apps. It is one of the more genuinely useful ideas in the framework, and it is still being operationalised — worth knowing about, not yet something you can rely on.

The bottom line

India now has an enforceable privacy law with real penalties — but a law only protects people who invoke it. Learn the seven rights, use the grievance channels, and treat every consent screen as a decision rather than an obstacle. Your data has always been valuable; from November 2025, it finally has legal armour.

How this guide is made

Written and fact-checked by the Awareness360 editorial team from primary sources — RBI, SEBI, IRDAI, the Income Tax Department and Government of India portals — with links to the originals in the text above. Last reviewed on 12 Aug 2026. This is general educational information for Indian readers, not professional financial, legal or tax advice.

Spotted something out of date? Tell us and we'll correct it — see our editorial policy.

← Previous
Refund Stuck? File a Consumer Complaint Online with e-Daakhil — No Lawyer Needed