How to File a DPDP Complaint With the Data Protection Board of India
The path a DPDP complaint follows: grievance to the Data Fiduciary first, then escalation to the Data Protection Board of India, plus the ninety-day response rule.
On This Page
- Every Complaint Ends at the Same Place
- The Grievance Mechanism a Data Fiduciary Must Run
- The Exhaustion Rule Under Section 13
- The Ninety-Day Response Window
- What Escalation to the Board Looks Like
- How a Data Principal Files and Escalates a Complaint
- The Penalty for Getting It Wrong
- What the Board Expects a Data Fiduciary to Produce
- Build the Mechanism Before the Complaint
Every Complaint Ends at the Same Place
Under the DPDP Act 2023, a Data Principal who believes a business has mishandled their personal data has a defined route to challenge it. That route ends at the Data Protection Board of India, the adjudicatory body the Act creates to hear complaints and impose penalties.
It does not start there. The Act builds a two-step path. A Data Principal must first raise the grievance with the Data Fiduciary that holds the data. Only when that internal mechanism has been exhausted does the complaint move to the Board. Most businesses have never operated a mechanism capable of receiving such a grievance in the first place, which is where the exposure begins.
The Grievance Mechanism a Data Fiduciary Must Run
Section 8(10) of the DPDP Act requires every Data Fiduciary to establish an effective mechanism to redress the grievances of Data Principals. This is not a suggestion to add a contact form. It is a statutory obligation to receive, track, and resolve grievances within a defined period. The grievance redressal build guide covers standing that mechanism up, component by component.
Section 8(9) requires the business to publish the business contact information of a person who can answer questions about the processing of personal data. For a Significant Data Fiduciary, Section 10(2)(a) makes this a Data Protection Officer, an individual based in India who is the point of contact for grievance redressal and is responsible to the governing body. No class of business has been notified as a Significant Data Fiduciary as of July 2026, so most organisations do not need a formal DPO. They still must appoint a grievance officer or authorised contact person and publish that contact.
The obligation to surface this route is written into the notice itself. Rule 3 requires the notice a business gives at collection to include the means by which a Data Principal can exercise their rights and make a complaint to the Board. A business that hides its grievance contact, or routes it to an unmonitored inbox, has not met the obligation.
The Exhaustion Rule Under Section 13
Section 13 gives every Data Principal the right of grievance redressal and requires that right to be exhausted before approaching the Board. This is the pivot the entire process turns on.
A Data Principal cannot take a first complaint straight to the Data Protection Board. They must first use the Data Fiduciary’s grievance mechanism and give it a reasonable period to respond. The Board is an escalation forum for grievances the business has failed to resolve, not a helpdesk of first resort. For a business, this rule is an advantage and a trap at once. It provides a window to resolve a matter before a regulator is ever involved. It also means the quality of the internal mechanism decides whether a grievance is contained or escalated.
The Ninety-Day Response Window
Rule 14(3) of the DPDP Rules sets the outer limit. Every Data Fiduciary and Consent Manager must prominently publish, on its website or app, the response period of its grievance redressal system, and that period cannot exceed ninety days. The business must also implement the technical and organisational measures needed to meet it.
This is a forward obligation. The substantive DPDP Rules, including Rule 14(3), become enforceable on 13 May 2027. That does not make the requirement optional until then. A business that sets a realistic period and publishes it now has a documented standard to operate against. A business that waits inherits a ninety-day ceiling with no system built to honour it.
What Escalation to the Board Looks Like
When a grievance is exhausted and unresolved, the complaint reaches the Data Protection Board of India. The Board can investigate the matter, direct the Data Fiduciary to remediate, and impose financial penalties where non-compliance is established.
The institution is being assembled now. As of July 2026 the Board has been established as a body corporate, its leadership appointments are in progress, and it has taken no enforcement actions yet. This is preparation time, not a reprieve. The compliance deadline that governs the substantive obligations is 13 May 2027, and the record a business will be asked to produce is built long before a complaint is ever filed.
How a Data Principal Files and Escalates a Complaint
The statutory sequence is fixed. A complaint follows these steps in order.
-
Raise the grievance with the Data Fiduciary. The Data Principal uses the grievance mechanism the business is required to operate under Section 8(10), through the contact it publishes under Section 8(9). The request identifies the person, describes the personal data at issue, and states the outcome sought.
-
Allow the published response period to run. The Data Fiduciary has its published grievance response period to resolve the matter. Under Rule 14(3) that period cannot exceed ninety days.
-
Escalate to the Data Protection Board of India. If the internal mechanism has been exhausted and the matter is still unresolved, the Data Principal escalates the complaint to the Board. Section 13 makes exhausting the internal mechanism a precondition to approaching it.
-
The Board investigates and may direct remediation. The Board can investigate, direct the business to remediate, and impose penalties where non-compliance is established.
The Penalty for Getting It Wrong
Failure to operate a grievance mechanism, or to respond to a Data Principal who exercises a right, falls under the Act’s residual penalty tier, up to Rs 50 crore. This is the category the Schedule assigns to non-compliance with any provision the higher tiers do not name, and it is where grievance and rights failures land.
The Rs 250 crore figure that anchors most DPDP coverage is a different tier. It applies only to a failure of reasonable security safeguards under Section 8(5). Attaching it to a grievance or rights failure overstates the exposure and misreads the Schedule. The accurate number for an ignored complaint is the residual tier, and it is large enough on its own.
What the Board Expects a Data Fiduciary to Produce
A grievance mechanism that satisfies Section 8(10) is an operational system, not a page. When a complaint reaches the Board, the fiduciary’s defence rests on one artefact: a timestamped resolution record showing when the grievance was received, acknowledged, and resolved. For the full build, the intake channel, the named officer, the published response period, and the record itself, see the grievance redressal build guide.
A grievance the business cannot prove it handled is indistinguishable, to the Board, from one it ignored. ConsentOS operates the grievance intake, routes each complaint to the responsible owner, and produces the timestamped resolution record a Data Fiduciary needs if a matter ever reaches the Board.
Build the Mechanism Before the Complaint
The DPDP compliance checklist covers grievance readiness among its obligation items. To see where your grievance and rights workflows currently stand, take the free DPDP Gap Assessment. You will receive a report identifying which obligations your organisation has not yet met. ConsentOS operates the grievance and consent workflows behind each of these duties. Compare plans, from ₹2,999 per month.
Frequently asked questions
How do I file a complaint with the Data Protection Board of India?
The DPDP Act sets a two-step path. First, raise the grievance with the Data Fiduciary that holds your data, through the grievance mechanism it is required to operate under Section 8(10). Only after that mechanism has been exhausted, and the Fiduciary has failed to resolve the matter within its published response period, can you escalate the complaint to the Data Protection Board of India. Section 13 makes exhausting the internal mechanism a precondition to approaching the Board.
What is the exhaustion rule under Section 13 of the DPDP Act?
Section 13 gives every Data Principal the right of grievance redressal and requires that right to be exhausted before approaching the Data Protection Board. In practice this means a complainant must first use the Data Fiduciary's grievance mechanism and allow it a reasonable period to respond. The Board is an escalation forum, not the first point of contact.
How long does a Data Fiduciary have to respond to a grievance?
Rule 14(3) of the DPDP Rules requires every Data Fiduciary and Consent Manager to prominently publish, on its website or app, the response period of its grievance redressal system, which cannot exceed ninety days. This is a forward obligation that becomes enforceable on 13 May 2027, alongside the other substantive Rules. Businesses should set and publish a period now as preparation.
What happens after a complaint reaches the Data Protection Board?
The Data Protection Board of India can investigate the complaint, direct the Data Fiduciary to remediate, and impose financial penalties where non-compliance is established. As of July 2026 the Board has been established as a body corporate and its leadership appointments are in progress, with no enforcement actions taken yet. The compliance deadline that matters is 13 May 2027.
What penalty does a business face for ignoring a grievance?
Failure to operate a grievance mechanism or respond to a Data Principal falls under the Act's residual penalty tier, up to Rs 50 crore. This is the category for non-compliance with any provision the higher tiers do not name. It is not the Rs 250 crore tier, which applies only to a failure of reasonable security safeguards under Section 8(5).
Does a small business need a Data Protection Officer to handle complaints?
No. A Data Protection Officer based in India is mandatory only for a Significant Data Fiduciary under Section 10(2)(a). Every other Data Fiduciary must still publish a contact under Section 8(9) and run a grievance mechanism under Section 8(10), but it appoints a grievance officer or authorised contact person rather than a formal DPO.
Know where you stand on DPDP compliance
Run the free DPDP Gap Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.
Enforcement milestones, rule notifications, and deadline analysis.
One email when it matters, no more.
Resources
Continue Reading
Related DPDP Act 2023 guidance from the ConsentOS knowledge base.
DPDP Act 2023: All 8 Data Principal Rights with Templates (India)
Access, correction, erasure, grievance, and nominee rights under the DPDP Act 2023: the response deadlines a Data Fiduciary must meet, with ready-to-use request templates.
7 min read
Regulatory UpdatesDPDP Penalties: ₹250 Crore Risk and Enforcement Tiers in India
A breakdown of every penalty provision in the DPDP Act 2023. Understand the financial exposure, the enforcement mechanism, and what triggers each penalty tier.
7 min read
Consent ManagementDPDP Consent Management: Technical Systems for Indian Businesses
The DPDP Act 2023 makes consent the legal foundation for data processing. This is what valid consent requires, how withdrawal works, and what your systems must support.
7 min read