DPDPA Data Principal Rights: How to Handle Access, Correction and Erasure Requests
October 1, 2026
October 1, 2026
Most DPDPA readiness conversations start with consent banners. The harder operational work sits on the other side: what happens when a customer, employee or student writes in and asks, "What data do you hold on me, and can you delete it?" Under the Digital Personal Data Protection Act, 2023, that request is a legal right, and the DPDP Rules, 2025 put a clock on your response.
This guide covers the four rights your organisation must be ready to honour, what the Rules require, and a practical workflow for handling requests at scale.
The DPDP Rules were notified on 13 November 2025 with a phased start. The Rules that operationalise Data Principal rights, including Rule 14, take effect on 13 May 2027. MeitY has floated a proposal to compress the timeline to 12 months, which would pull the deadline forward to November 2026, but as of this writing it has not been notified. Either way, a rights-handling process takes months to design, staff and test, so the time to build it is now. See our DPDPA compliance timeline for the full phase-by-phase breakdown.
Rule 14 expects every Data Fiduciary to publish, prominently on its website or app, the means by which a Data Principal can make a request, along with any identifier you need to verify them (a customer ID, registered mobile number or employee code, for example). If you are a Significant Data Fiduciary, you must also publish your Data Protection Officer's contact details; everyone else must publish contact details of a person who can answer questions about processing.
Create a single intake channel, typically a web form plus a dedicated email address, and route every request there. Requests that arrive through sales reps, WhatsApp or branch staff should be logged into the same system the same day. Scattered intake is the most common reason organisations miss deadlines.
Confirm the requester is who they claim to be, using identifiers you already hold. An OTP to the registered mobile number is usually enough. Do not demand more personal data than you need to verify; asking for an Aadhaar copy to process a newsletter unsubscribe creates a new privacy problem.
You cannot answer an access request without a data map. List every system holding personal data: CRM, ERP, HRMS, marketing automation, support desk, spreadsheets on shared drives, and every vendor you pass data to. For each, record the owner and how to search by individual.
Each verified request becomes a ticket with sub-tasks for every system owner. Track due dates against the 90-day ceiling, but set an internal target of 30 days so escalations have room.
Erasure is not absolute. Tax, labour and sector-specific laws may require you to keep certain records. Document why any data is retained, restrict access to it, and erase everything else, including copies held by your processors.
An access response should be understandable by a non-lawyer: what you hold, why, who you shared it with. Avoid raw database dumps.
Log the request, verification method, actions taken, dates and the final response. If a Data Principal escalates to the Data Protection Board, this record is your defence.
DAPro (Data Adhikaar), Qodequay's DPDPA compliance platform, brings consent, rights handling and compliance evidence into one system. Its Evidence Vault keeps tamper-evident records of what was requested and what you did, it supports 22 languages for notices and communication, and 25+ connectors link it to the systems where personal data actually lives. Book a 30-minute walkthrough to see it against your own data map.
This article is for general information and is not legal advice. Always confirm obligations against the official text of the DPDP Act and Rules and consult qualified counsel for your situation.
Monthly insights on AI, VR and DPDPA compliance — straight from our team to your inbox.
Free 30-minute consultation with our team — or see our products in action.