Readiness assessment
Share this section

Chapter III · Rights and Duties of Data Principal

Section 11: Right to access information about personal data

Section 11 gives a Data Principal the right to ask a Data Fiduciary for a summary of the personal data it processes about them, what it does with that data, and every other party the data has been shared with.

Official text
Section 11Right to access
Chapter
Chapter III · Rights and Duties of Data Principal
Status
Enacted · phased commencement
Full compliance
13 May 2027
Applies to
Data Principals & Data Fiduciaries
Official citation
DPDP Act, 2023, s.11
Reading time
6 min
Updated
August 2026

At a glance

Section 11 gives a Data Principal the right to obtain, from a Data Fiduciary she has given consent to (including data voluntarily provided under Section 7(a)), a summary of the personal data being processed and the processing activities carried out, the identities of every other Data Fiduciary and Data Processor the data has been shared with along with a description of what was shared, and any further information that may be prescribed. A narrow exception lets a Data Fiduciary withhold recipient details where the data was shared with a body legally authorised to obtain it, pursuant to a written request for investigating offences or cyber incidents. The right is operationalised by Rule 14 of the DPDP Rules, 2025 and is scheduled to take effect on 13 May 2027.

Applies to Data PrincipalsChapter Chapter IIIEffective 13 May 2027Read time 6 min

Key takeaways

  • On request, a Data Fiduciary must give a person a summary of the personal data it processes about them and the processing activities it carries out [11(1)(a)].
  • The person can also demand the identities of every other Data Fiduciary and Data Processor the data was shared with, plus a description of what was shared [11(1)(b)].
  • The right applies where processing rests on consent, including data voluntarily provided under Section 7(a).
  • A narrow carve-out lets you withhold recipient details only where data went to a legally authorised body investigating offences or cyber incidents [11(2)]. It does not hide ordinary vendors.
  • This is not data portability and not an automated-decision explanation right; the Act contains neither.
  • Requests run through Rule 14 of the DPDP Rules, 2025: publish your request channel and the identifier you need. Scheduled effective 13 May 2027.

Who should read this

Read this if you process personal data on the basis of consent, because Section 11 is the moment your data map, vendor register and request workflow are tested by a real person.

FoundersLegal / DPOCompliance leadsProduct / engineering

In plain language

Section 11 turns a simple question into a legal obligation: for this exact person, what data do we hold, why and how do we use it, and which outside parties received which parts of it? If you cannot answer that quickly and accurately, you have a data-governance problem, not just a privacy gap.

The obligation sits with you, the Data Fiduciary, even when the data lives inside your vendors. If a customer's data is spread across your cloud host, CRM, analytics, support desk and payment provider, you must be able to name those recipients and describe what each one received. "Our vendor list is somewhere" is not a Section 11 answer.

A general record of processing helps, but Section 11 is triggered by one individual. You have to turn a high-level inventory into a person-specific response, reconciling every identifier that person has (email, phone, customer ID, device ID) without exposing anyone else's data.

The text of the law

Section 11: Right to access information about personal data

11(1) A Data Principal has the right to obtain from a Data Fiduciary to whom she has previously given consent (including consent as referred to in Section 7(a)), on making a request in the prescribed manner: (a) a summary of the personal data being processed and the processing activities undertaken; (b) the identities of all other Data Fiduciaries and Data Processors with whom the data has been shared, along with a description of the data so shared; and (c) any other prescribed information related to the personal data and its processing.

11(2) Clauses (b) and (c) do not apply to the sharing of personal data with another Data Fiduciary authorised by law to obtain it, where the sharing is pursuant to a written request for the prevention, detection or investigation of offences or cyber incidents, or for prosecution or punishment of offences.

Wording summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.

What this means for you

  • Build a data map that links identity to fields, systems, purposes, recipients and retention status, so one lookup answers the whole question.
  • Keep a recipient and processor register that names each vendor and the exact data categories shared with them, and distinguishes processors from other Data Fiduciaries.
  • Stand up a request workflow: log the request, verify identity proportionately, search authoritative systems, compile a plain-language summary, apply only narrowly tailored exceptions, deliver securely, and keep an audit trail.
  • Treat the 11(2) carve-out and the Section 17 exemptions as documented, case-specific decisions reviewed by counsel, not a default reason to refuse.
  • Note the timing nuance: Rule 14 requires you to publish a grievance-redressal period within a reasonable time not exceeding 90 days; that 90-day figure governs grievances, not a standalone Section 11 response deadline, so set a faster access SLA.
  • Neighbouring rights follow this one: correction and erasure and grievance redressal.

Frequently asked questions

What is the right to access under Section 11?
It lets a Data Principal ask a Data Fiduciary for a summary of the personal data it processes about them, the processing activities involved, and the identities of every other Data Fiduciary and Data Processor the data was shared with, along with a description of what was shared.
Does Section 11 give me a downloadable copy of all my data?
No. Section 11 requires a summary and a description of sharing, not a raw database export. The DPDP Act does not create a GDPR-style data-portability right.
Can a company refuse to tell me who it shared my data with?
Only in one narrow case: where the data was shared with a body legally authorised to obtain it, pursuant to a written request for investigating offences or cyber incidents, or for prosecution. It cannot be used to hide ordinary vendors, analytics providers or affiliates.
When does Section 11 take effect?
It is scheduled to come into force on 13 May 2027 under the phased commencement, with Rule 14 of the DPDP Rules, 2025 setting out how people make requests.
Does Section 11 apply to startups?
The Central Government may notify certain Data Fiduciaries, including startups, to whom Section 11 does not apply (Section 17(3)). Treat any exemption as a documented, case-specific decision, not a default.

Sources

This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.

Start readiness assessment