Chapter III · Rights and Duties of Data Principal
Section 13: Right of grievance redressal
Section 13 gives a person a readily available way to complain to a Data Fiduciary or Consent Manager about how their data was handled, and makes internal redressal the first step before the Data Protection Board.
- Chapter
- Chapter III · Rights and Duties of Data Principal
- Status
- Enacted · phased commencement
- Full compliance
- 13 May 2027
- Applies to
- Data Principals & Data Fiduciaries
- Official citation
- DPDP Act, 2023, s.13
- Reading time
- 6 min
- Updated
- August 2026
At a glance
Section 13 gives a Data Principal the right to a readily available means of grievance redressal from a Data Fiduciary or Consent Manager, for any act or omission relating to its obligations or to the exercise of her rights [13(1)]. The Data Fiduciary or Consent Manager must respond within the prescribed period, which the DPDP Rules, 2025 set as a reasonable period not exceeding 90 days [13(2)]. The Data Principal must exhaust this internal redressal before approaching the Data Protection Board [13(3)]. The right is broad, covering notice, consent, access, correction, erasure, security, processors and children's data, and is scheduled to take effect on 13 May 2027.
Key takeaways
- You must offer a readily available complaint route and, under Rule 14, publish it plus the identifier needed to find the person [13(1)].
- It covers any act or omission about your data obligations or a person's rights, so the scope is deliberately broad.
- You must respond within a reasonable period not exceeding 90 days, that is the outer limit, not the target.
- A person must exhaust internal redressal before the Board [13(3)], but a broken or unanswered channel strengthens their case to escalate.
- Both Data Fiduciaries and Consent Managers must provide it, each for their own acts or omissions.
- A Significant Data Fiduciary must route this through its India-based DPO; everyone else should still name an accountable owner, not a shared inbox.
Who should read this
Read this if you handle personal data, because Section 13 is where every other obligation, notice, consent, access, deletion, security, is tested by a real complaint with a clock on it.
In plain language
Section 13 is the enforcement bridge for the whole chapter. When something goes wrong, marketing after a withdrawal, an ignored access request, a missed breach notice, this is the channel a person uses, and the one the Board expects them to try first.
"Readily available" is a real bar. The route should be easy to find from your notice or footer, usable by people who have closed their account or cannot log in, mobile-friendly, in plain language, and tracked. "Contact us for concerns" with no ownership or SLA is a weak design.
Responding is not the same as fully granting. A good response states the finding, the action taken, the reason for any refusal, what was retained and why, and the escalation route, not a holding reply on day 89.
The text of the law
Section 13: Right of grievance redressal
13(1) A Data Principal has the right to readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager in respect of any act or omission regarding its obligations or the exercise of her rights under the Act and Rules.
13(2) The Data Fiduciary or Consent Manager shall respond to grievances within such period as may be prescribed from the date of receipt.
13(3) The Data Principal shall exhaust the opportunity of redressing her grievance under this section before approaching the Board.
Wording summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.
What this means for you
- Publish the grievance route and the identifier a person needs (username, customer ID, email or mobile), and keep it usable for logged-out and former users.
- Run it like case management: unique case ID, SLA clock, named owner, evidence capture, routing and an audit trail.
- Set internal targets well inside the 90-day limit: acknowledge in a few business days, resolve simple requests in 15 to 30 days.
- Give a reasoned outcome: the finding, the corrective action, any retained-data rationale, and how to escalate.
- Name an accountable privacy owner or DPO; treat recurring grievances as signals of a deeper control gap in access, deletion or consent.
- Want a working grievance workflow and DPO contact in place before 2027? Take the readiness assessment or find a specialist.
Frequently asked questions
What can I raise as a grievance under Section 13?
How long does a company have to respond?
Do I have to complain to the company before the Data Protection Board?
Who has to provide a grievance mechanism?
When does Section 13 take effect?
Sources
- Digital Personal Data Protection Act, 2023Ministry of Electronics and IT (MeitY)
- DPDP Rules, 2025Notified 13–14 November 2025
This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.