How to File a DPDP Complaint With the Data Protection Board of India
The path a DPDP complaint follows: grievance to the Data Fiduciary first, then escalation to the Data Protection Board of India, plus the ninety-day response rule.
On This Page
- Every Complaint Ends at the Same Place
- The Grievance Mechanism a Data Fiduciary Must Run
- The Exhaustion Rule Under Section 13
- The Ninety-Day Response Window
- What Escalation to the Board Looks Like
- How a Data Principal Files and Escalates a Complaint
- The Penalty for Getting It Wrong
- What the Board Expects a Data Fiduciary to Produce
- Build the Mechanism Before the Complaint
Every Complaint Ends at the Same Place
Under the DPDP Act 2023, a Data Principal who believes a business has mishandled their personal data has a defined route to challenge it. That route ends at the Data Protection Board of India, the adjudicatory body the Act creates to hear complaints and impose penalties.
It does not start there. The Act builds a two-step path. A Data Principal must first raise the grievance with the Data Fiduciary that holds the data. Only when that internal mechanism has been exhausted does the complaint move to the Board. Most businesses have never operated a mechanism capable of receiving such a grievance in the first place, which is where the exposure begins.
The Grievance Mechanism a Data Fiduciary Must Run
Section 8(10) of the DPDP Act requires every Data Fiduciary to establish an effective mechanism to redress the grievances of Data Principals. This is not a suggestion to add a contact form. It is a statutory obligation to receive, track, and resolve grievances within a defined period. The grievance redressal build guide covers standing that mechanism up, component by component.
Section 8(9) requires the business to publish the business contact information of a person who can answer questions about the processing of personal data. For a Significant Data Fiduciary, Section 10(2)(a) makes this a Data Protection Officer, an individual based in India who is the point of contact for grievance redressal and is responsible to the governing body. No class of business has been notified as a Significant Data Fiduciary as of July 2026, so most organisations do not need a formal DPO. They still must appoint a grievance officer or authorised contact person and publish that contact.
The obligation to surface this route is written into the notice itself. Rule 3 requires the notice a business gives at collection to include the means by which a Data Principal can exercise their rights and make a complaint to the Board. A business that hides its grievance contact, or routes it to an unmonitored inbox, has not met the obligation.
The Exhaustion Rule Under Section 13
Section 13 gives every Data Principal the right of grievance redressal and requires that right to be exhausted before approaching the Board. This is the pivot the entire process turns on.
A Data Principal cannot take a first complaint straight to the Data Protection Board. They must first use the Data Fiduciary’s grievance mechanism and give it a reasonable period to respond. The Board is an escalation forum for grievances the business has failed to resolve, not a helpdesk of first resort. For a business, this rule is an advantage and a trap at once. It provides a window to resolve a matter before a regulator is ever involved. It also means the quality of the internal mechanism decides whether a grievance is contained or escalated.
The Ninety-Day Response Window
Rule 14(3) of the DPDP Rules sets the outer limit. Every Data Fiduciary and Consent Manager must prominently publish, on its website or app, the response period of its grievance redressal system, and that period cannot exceed ninety days. The business must also implement the technical and organisational measures needed to meet it.
This is a forward obligation. The substantive DPDP Rules, including Rule 14(3), become enforceable on 13 May 2027. That does not make the requirement optional until then. A business that sets a realistic period and publishes it now has a documented standard to operate against. A business that waits inherits a ninety-day ceiling with no system built to honour it.
What Escalation to the Board Looks Like
When a grievance is exhausted and unresolved, the complaint reaches the Data Protection Board of India. The Board can investigate the matter, direct the Data Fiduciary to remediate, and impose financial penalties where non-compliance is established.
The institution is being assembled now. As of July 2026 the Board has been established as a body corporate, its leadership appointments are in progress, and it has taken no enforcement actions yet. This is preparation time, not a reprieve. The compliance deadline that governs the substantive obligations is 13 May 2027, and the record a business will be asked to produce is built long before a complaint is ever filed.
How a Data Principal Files and Escalates a Complaint
The statutory sequence is fixed. A complaint follows these steps in order.
-
Raise the grievance with the Data Fiduciary. The Data Principal uses the grievance mechanism the business is required to operate under Section 8(10), through the contact it publishes under Section 8(9). The request identifies the person, describes the personal data at issue, and states the outcome sought.
-
Allow the published response period to run. The Data Fiduciary has its published grievance response period to resolve the matter. Under Rule 14(3) that period cannot exceed ninety days.
-
Escalate to the Data Protection Board of India. If the internal mechanism has been exhausted and the matter is still unresolved, the Data Principal escalates the complaint to the Board. Section 13 makes exhausting the internal mechanism a precondition to approaching it.
-
The Board investigates and may direct remediation. The Board can investigate, direct the business to remediate, and impose penalties where non-compliance is established.
The Penalty for Getting It Wrong
Failure to operate a grievance mechanism, or to respond to a Data Principal who exercises a right, falls under the Act’s residual penalty tier, up to Rs 50 crore. This is the category the Schedule assigns to non-compliance with any provision the higher tiers do not name, and it is where grievance and rights failures land.
The Rs 250 crore figure that anchors most DPDP coverage is a different tier. It applies only to a failure of reasonable security safeguards under Section 8(5). Attaching it to a grievance or rights failure overstates the exposure and misreads the Schedule. The accurate number for an ignored complaint is the residual tier, and it is large enough on its own.
What the Board Expects a Data Fiduciary to Produce
A grievance mechanism that satisfies Section 8(10) is an operational system, not a page. When a complaint reaches the Board, the fiduciary’s defence rests on one artefact: a timestamped resolution record showing when the grievance was received, acknowledged, and resolved. For the full build, the intake channel, the named officer, the published response period, and the record itself, see the grievance redressal build guide.
A grievance the business cannot prove it handled is indistinguishable, to the Board, from one it ignored. ConsentOS operates the grievance intake, routes each complaint to the responsible owner, and produces the timestamped resolution record a Data Fiduciary needs if a matter ever reaches the Board.
Build the Mechanism Before the Complaint
The DPDP compliance checklist covers grievance readiness among its obligation items. To see where your grievance and rights workflows currently stand, take the free Compliance Vault Assessment. You will receive a report identifying which obligations your organisation has not yet met. ConsentOS operates the grievance and consent workflows behind each of these duties. Compare plans, from ₹2,999 per month.
Know where you stand on DPDP compliance
Run the free Compliance Vault Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.
Enforcement milestones, rule notifications, and deadline analysis.
One email when it matters, no more.
Resources
Continue Reading
Related DPDP Act 2023 guidance from the ConsentOS knowledge base.
DPDP Act 2023: All 8 Data Principal Rights with Templates (India)
Access, correction, erasure, grievance, and nominee rights under the DPDP Act 2023: the response deadlines a Data Fiduciary must meet, with ready-to-use request templates.
7 min read
Regulatory UpdatesDPDP Penalties: ₹250 Crore Risk and Enforcement Tiers in India
A breakdown of every penalty provision in the DPDP Act 2023. Understand the financial exposure, the enforcement mechanism, and what triggers each penalty tier.
7 min read
Consent ManagementDPDP Consent Management: Technical Systems for Indian Businesses
The DPDP Act 2023 makes consent the legal foundation for data processing. This is what valid consent requires, how withdrawal works, and what your systems must support.
7 min read