Readiness assessment
Share this section

Chapter III · Rights and Duties of Data Principal

Section 13: Right of grievance redressal

Section 13 gives a person a readily available way to complain to a Data Fiduciary or Consent Manager about how their data was handled, and makes internal redressal the first step before the Data Protection Board.

Official text
Section 13Grievance redressal
Chapter
Chapter III · Rights and Duties of Data Principal
Status
Enacted · phased commencement
Full compliance
13 May 2027
Applies to
Data Principals & Data Fiduciaries
Official citation
DPDP Act, 2023, s.13
Reading time
6 min
Updated
August 2026

At a glance

Section 13 gives a Data Principal the right to a readily available means of grievance redressal from a Data Fiduciary or Consent Manager, for any act or omission relating to its obligations or to the exercise of her rights [13(1)]. The Data Fiduciary or Consent Manager must respond within the prescribed period, which the DPDP Rules, 2025 set as a reasonable period not exceeding 90 days [13(2)]. The Data Principal must exhaust this internal redressal before approaching the Data Protection Board [13(3)]. The right is broad, covering notice, consent, access, correction, erasure, security, processors and children's data, and is scheduled to take effect on 13 May 2027.

Applies to Data PrincipalsChapter Chapter IIIEffective 13 May 2027Read time 6 min

Key takeaways

  • You must offer a readily available complaint route and, under Rule 14, publish it plus the identifier needed to find the person [13(1)].
  • It covers any act or omission about your data obligations or a person's rights, so the scope is deliberately broad.
  • You must respond within a reasonable period not exceeding 90 days, that is the outer limit, not the target.
  • A person must exhaust internal redressal before the Board [13(3)], but a broken or unanswered channel strengthens their case to escalate.
  • Both Data Fiduciaries and Consent Managers must provide it, each for their own acts or omissions.
  • A Significant Data Fiduciary must route this through its India-based DPO; everyone else should still name an accountable owner, not a shared inbox.

Who should read this

Read this if you handle personal data, because Section 13 is where every other obligation, notice, consent, access, deletion, security, is tested by a real complaint with a clock on it.

FoundersLegal / DPOCompliance leadsProduct / engineering

In plain language

Section 13 is the enforcement bridge for the whole chapter. When something goes wrong, marketing after a withdrawal, an ignored access request, a missed breach notice, this is the channel a person uses, and the one the Board expects them to try first.

"Readily available" is a real bar. The route should be easy to find from your notice or footer, usable by people who have closed their account or cannot log in, mobile-friendly, in plain language, and tracked. "Contact us for concerns" with no ownership or SLA is a weak design.

Responding is not the same as fully granting. A good response states the finding, the action taken, the reason for any refusal, what was retained and why, and the escalation route, not a holding reply on day 89.

The text of the law

Section 13: Right of grievance redressal

13(1) A Data Principal has the right to readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager in respect of any act or omission regarding its obligations or the exercise of her rights under the Act and Rules.

13(2) The Data Fiduciary or Consent Manager shall respond to grievances within such period as may be prescribed from the date of receipt.

13(3) The Data Principal shall exhaust the opportunity of redressing her grievance under this section before approaching the Board.

Wording summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.

What this means for you

  • Publish the grievance route and the identifier a person needs (username, customer ID, email or mobile), and keep it usable for logged-out and former users.
  • Run it like case management: unique case ID, SLA clock, named owner, evidence capture, routing and an audit trail.
  • Set internal targets well inside the 90-day limit: acknowledge in a few business days, resolve simple requests in 15 to 30 days.
  • Give a reasoned outcome: the finding, the corrective action, any retained-data rationale, and how to escalate.
  • Name an accountable privacy owner or DPO; treat recurring grievances as signals of a deeper control gap in access, deletion or consent.
  • Want a working grievance workflow and DPO contact in place before 2027? Take the readiness assessment or find a specialist.

Frequently asked questions

What can I raise as a grievance under Section 13?
Any act or omission by a Data Fiduciary or Consent Manager about your personal data or your rights: a missing notice, ignored consent withdrawal, an incomplete access response, a refused correction or erasure, a breach you were not told about, or a vendor still using your data.
How long does a company have to respond?
The DPDP Rules, 2025 require the grievance system to respond within a reasonable period not exceeding 90 days, and to publish that period. Ninety days is the outer limit, not a target.
Do I have to complain to the company before the Data Protection Board?
Yes. Section 13(3) requires you to exhaust the internal grievance route first. But a channel that does not work or does not respond in time strengthens your basis to escalate to the Board.
Who has to provide a grievance mechanism?
Both Data Fiduciaries and Consent Managers, each for their own acts or omissions. A company cannot simply redirect you to its cloud or support vendor.
When does Section 13 take effect?
It is scheduled to come into force on 13 May 2027 under the phased commencement, alongside Rule 14 of the DPDP Rules, 2025.

Sources

This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.

Start readiness assessment