Readiness assessment
Share this section

Chapter III · Rights and Duties of Data Principal

Section 15: Duties of the Data Principal

Section 15 is the one provision in Chapter III that imposes duties rather than rights: five obligations on individuals to act honestly and authentically when they share data or exercise their DPDP rights.

Official text
Section 15Duties of Data Principal
Chapter
Chapter III · Rights and Duties of Data Principal
Status
Enacted · phased commencement
Full compliance
13 May 2027
Applies to
Data Principals
Official citation
DPDP Act, 2023, s.15
Reading time
6 min
Updated
August 2026

At a glance

Section 15 is the only provision in Chapter III that imposes duties rather than rights. A Data Principal must comply with all applicable laws while exercising DPDP rights [15(a)]; not impersonate another person when providing personal data [15(b)]; not suppress material information when providing data for a State-issued document, identifier, or proof of identity or address [15(c)]; not register a false or frivolous grievance with a Data Fiduciary or the Board [15(d)]; and furnish only verifiably authentic information when exercising the right to correction or erasure [15(e)]. Breach can attract a penalty of up to Rs 10,000 under the Schedule, imposed by the Data Protection Board and not by the company. It is scheduled to take effect on 13 May 2027.

Applies to Data PrincipalsChapter Chapter IIIEffective 13 May 2027Read time 6 min

Key takeaways

  • Section 15 is the only duty-imposing provision in Chapter III: five obligations, not a right.
  • The duties: comply with law [15(a)], do not impersonate [15(b)], do not suppress material information for State documents [15(c)], no false or frivolous grievances [15(d)], and give verifiably authentic data for correction or erasure [15(e)].
  • For a company it is a safeguard, not a shield: it justifies proportionate verification and rejecting clearly false or abusive requests, never dismissing a genuine request as inconvenient.
  • Breach can draw a penalty of up to Rs 10,000 under the Schedule, and only the Board imposes it, not you.
  • "Frivolous" must be applied carefully: a poorly written, repeated, or ultimately unsuccessful complaint is not automatically frivolous.
  • Section 15 does not shift your obligations: notice, consent, security, breach reporting and rights fulfilment under Section 8 still stand in full.

Who should read this

Read this if you run rights-request, grievance, KYC or account-recovery workflows, because Section 15 defines when you can insist on authentic data and turn away abuse, and where you still cannot.

FoundersLegal / DPOCompliance leadsProduct / engineering

In plain language

Chapter III is almost all about rights. Section 15 is the exception: it puts five duties on the individual. The point is integrity, stopping people from using privacy rights to commit identity fraud, falsify official records, or abuse grievance channels.

For a business this is a safeguard, not a blanket defence. It lets you require truthful, authentic information and turn away demonstrably false or abusive requests. It does not let you ignore a genuine access, correction, erasure or grievance request just because it is inconvenient, repeated, complex or commercially awkward.

The balance cuts both ways: individuals must act honestly, and you must still meet every obligation you already have. Section 15 can never be used as a pretext to avoid compliance.

The text of the law

Section 15: Duties of the Data Principal

15(a) A Data Principal shall comply with the provisions of all applicable laws in force while exercising rights under the Act.

15(b) A Data Principal shall not impersonate another person while providing her personal data for a specified purpose.

15(c) A Data Principal shall not suppress any material information while providing personal data for any document, unique identifier, proof of identity or proof of address issued by the State or its instrumentalities.

15(d) A Data Principal shall not register a false or frivolous grievance or complaint with a Data Fiduciary or the Board.

15(e) A Data Principal shall furnish only verifiably authentic information while exercising the right to correction or erasure.

Wording summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.

What this means for you

  • Set a risk-based verification standard for rights requests: light checks for low-risk changes, step-up verification for erasure, account recovery, identity fields, payment details, and nominee or guardian requests.
  • Do not weaponise verification: do not demand documents for a low-risk change that account authentication already covers, and do not keep verification copies longer than needed.
  • Apply a documented, careful standard before calling any grievance false or frivolous, and get privacy or legal sign-off on high-risk dismissals, because a weak "frivolous" label is itself a risk.
  • For correction and erasure, require verifiably authentic data and confirm the requester really is the Data Principal or an authorised nominee or guardian before anything irreversible.
  • Keep case logs: identity check, systems reviewed, decision reason, reviewer, response and escalation route.
  • Remember the limits: you cannot fine anyone under the Act (only the Board can), and Section 15 never removes your own Section 8 duties. Not sure your process holds up? Take the readiness assessment.

Frequently asked questions

What does Section 15 of the DPDP Act require?
It imposes five duties on the Data Principal: comply with applicable law, do not impersonate another person, do not suppress material information for State-issued documents, do not file a false or frivolous grievance, and give only verifiably authentic information when exercising correction or erasure.
Can a company reject a request under Section 15?
It can require proportionate verification and refuse a clearly false, impersonated or abusive request, but it cannot dismiss a genuine rights request just because it is inconvenient, repeated or complex.
What is the penalty for breaching Section 15?
Up to Rs 10,000 under the Schedule to the Act. It is imposed by the Data Protection Board through its process, not a fine the company can levy itself.
Does Section 15 reduce a company's obligations?
No. Notice, consent, security, breach reporting and rights fulfilment under the Act still apply in full. Section 15 is not a pretext to avoid compliance.
When does Section 15 take effect?
It is scheduled to come into force on 13 May 2027 under the phased commencement of the DPDP Act.

Sources

This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.

Start readiness assessment