Chapter III · Rights and Duties of Data Principal
Section 15: Duties of the Data Principal
Section 15 is the one provision in Chapter III that imposes duties rather than rights: five obligations on individuals to act honestly and authentically when they share data or exercise their DPDP rights.
- Chapter
- Chapter III · Rights and Duties of Data Principal
- Status
- Enacted · phased commencement
- Full compliance
- 13 May 2027
- Applies to
- Data Principals
- Official citation
- DPDP Act, 2023, s.15
- Reading time
- 6 min
- Updated
- August 2026
At a glance
Section 15 is the only provision in Chapter III that imposes duties rather than rights. A Data Principal must comply with all applicable laws while exercising DPDP rights [15(a)]; not impersonate another person when providing personal data [15(b)]; not suppress material information when providing data for a State-issued document, identifier, or proof of identity or address [15(c)]; not register a false or frivolous grievance with a Data Fiduciary or the Board [15(d)]; and furnish only verifiably authentic information when exercising the right to correction or erasure [15(e)]. Breach can attract a penalty of up to Rs 10,000 under the Schedule, imposed by the Data Protection Board and not by the company. It is scheduled to take effect on 13 May 2027.
Key takeaways
- Section 15 is the only duty-imposing provision in Chapter III: five obligations, not a right.
- The duties: comply with law [15(a)], do not impersonate [15(b)], do not suppress material information for State documents [15(c)], no false or frivolous grievances [15(d)], and give verifiably authentic data for correction or erasure [15(e)].
- For a company it is a safeguard, not a shield: it justifies proportionate verification and rejecting clearly false or abusive requests, never dismissing a genuine request as inconvenient.
- Breach can draw a penalty of up to Rs 10,000 under the Schedule, and only the Board imposes it, not you.
- "Frivolous" must be applied carefully: a poorly written, repeated, or ultimately unsuccessful complaint is not automatically frivolous.
- Section 15 does not shift your obligations: notice, consent, security, breach reporting and rights fulfilment under Section 8 still stand in full.
Who should read this
Read this if you run rights-request, grievance, KYC or account-recovery workflows, because Section 15 defines when you can insist on authentic data and turn away abuse, and where you still cannot.
In plain language
Chapter III is almost all about rights. Section 15 is the exception: it puts five duties on the individual. The point is integrity, stopping people from using privacy rights to commit identity fraud, falsify official records, or abuse grievance channels.
For a business this is a safeguard, not a blanket defence. It lets you require truthful, authentic information and turn away demonstrably false or abusive requests. It does not let you ignore a genuine access, correction, erasure or grievance request just because it is inconvenient, repeated, complex or commercially awkward.
The balance cuts both ways: individuals must act honestly, and you must still meet every obligation you already have. Section 15 can never be used as a pretext to avoid compliance.
The text of the law
Section 15: Duties of the Data Principal
15(a) A Data Principal shall comply with the provisions of all applicable laws in force while exercising rights under the Act.
15(b) A Data Principal shall not impersonate another person while providing her personal data for a specified purpose.
15(c) A Data Principal shall not suppress any material information while providing personal data for any document, unique identifier, proof of identity or proof of address issued by the State or its instrumentalities.
15(d) A Data Principal shall not register a false or frivolous grievance or complaint with a Data Fiduciary or the Board.
15(e) A Data Principal shall furnish only verifiably authentic information while exercising the right to correction or erasure.
Wording summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.
What this means for you
- Set a risk-based verification standard for rights requests: light checks for low-risk changes, step-up verification for erasure, account recovery, identity fields, payment details, and nominee or guardian requests.
- Do not weaponise verification: do not demand documents for a low-risk change that account authentication already covers, and do not keep verification copies longer than needed.
- Apply a documented, careful standard before calling any grievance false or frivolous, and get privacy or legal sign-off on high-risk dismissals, because a weak "frivolous" label is itself a risk.
- For correction and erasure, require verifiably authentic data and confirm the requester really is the Data Principal or an authorised nominee or guardian before anything irreversible.
- Keep case logs: identity check, systems reviewed, decision reason, reviewer, response and escalation route.
- Remember the limits: you cannot fine anyone under the Act (only the Board can), and Section 15 never removes your own Section 8 duties. Not sure your process holds up? Take the readiness assessment.
Frequently asked questions
What does Section 15 of the DPDP Act require?
Can a company reject a request under Section 15?
What is the penalty for breaching Section 15?
Does Section 15 reduce a company's obligations?
When does Section 15 take effect?
Sources
- Digital Personal Data Protection Act, 2023Ministry of Electronics and IT (MeitY)
- DPDP Rules, 2025Notified 13–14 November 2025
This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.