DPDP Grievance Redressal: Building the Mechanism the Act Requires
Section 8(10) requires a grievance mechanism, Section 13 makes it the mandatory first stop, and Rule 14 caps response at 90 days. What to build, step by step.
On This Page
Every DPDP complaint is supposed to die inside your organisation. That is the design of the Act: Section 8(10) makes the grievance mechanism mandatory, and Section 13(3) makes it the mandatory first stop, so the Data Protection Board only ever sees the grievances a Data Fiduciary failed to resolve. The mechanism is either your containment layer or your paper trail of neglect.
This guide covers what to build. For the escalation view, what happens when a grievance is exhausted and moves to the Board, see how DPDP complaints reach the DPBI.
The Statutory Frame
Four provisions carry the obligation.
“A Data Fiduciary shall establish an effective mechanism to redress the grievances of Data Principals.” (Section 8(10))
“A Data Principal shall have the right to have readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager in respect of any act or omission of such Data Fiduciary or Consent Manager regarding the performance of its obligations in relation to the personal data of such Data Principal or the exercise of her rights under the provisions of this Act and the rules made thereunder.” (Section 13(1))
Section 13(2) requires the fiduciary to respond within the prescribed period, and Section 13(3) requires the Data Principal to exhaust this route before approaching the Board. Rule 14 of the DPDP Rules 2025 then operationalises it: publish the means of exercising rights and the particulars a requester must furnish (Rule 14(1)), establish the grievance system with a prominently published response timeline not exceeding ninety days, backed by technical and organisational measures to meet it (Rule 14(3)).
Note what Section 13(1) covers: not just data mishandling, but “any act or omission” concerning the fiduciary’s obligations or the individual’s rights. A delayed access request, an ignored correction, a withdrawal that did not propagate: each is grievance material.
The Timeline That Exists, and the One That Does Not
Two numbers circulate in DPDP grievance guidance. One is real.
The real one: your published period, capped at ninety days. Rule 14(3) does not hand every organisation a ninety-day allowance. It requires publishing a “reasonable period not exceeding ninety days” and building the measures to meet it. Publish thirty days and thirty days is your standard. Publish nothing and you have failed the rule before the first grievance arrives.
The invented one: the 48-hour acknowledgment. No provision of the DPDP Act or the DPDP Rules prescribes a 24-hour or 48-hour acknowledgment window for grievances. The figure migrates in from the IT (Intermediary Guidelines) Rules 2021, which require intermediaries to acknowledge complaints within 24 hours, a different statute governing a different function. Acknowledging fast is sound operational practice and builds the record that you engaged. It is not a DPDP mandate, and compliance copy that presents it as one is citing a law it has not read.
The enforcement date matters here too: Rule 14 sits in the tranche of Rules that becomes enforceable on 13 May 2027. The obligation in Section 8(10) is already law. The compliance timeline has the full sequence.
Grievance Officer vs Data Protection Officer
Section 8(9) requires publishing the business contact information of “a Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary” the Data Principal’s questions about processing.
The structure of that sentence settles a common confusion. A DPO is mandatory only for Significant Data Fiduciaries, under Section 10(2)(a): an individual based in India, responsible to the governing body, serving as the grievance contact. No class of entity has been notified as an SDF as of July 2026. Every other organisation satisfies Section 8(9) with a named grievance officer or authorised contact person, published where Data Principals can find it.
The appointment is the cheap part. The officer needs authority to pull records, instruct teams, and close grievances inside the published period. A named contact with no mandate is a compliance decoration.
Design the Period You Can Keep
The published response period is a commitment, not a disclosure. Three design rules follow:
- Choose from operational reality. Measure how long a rights request or complaint actually takes to resolve across your systems, add margin, publish that. An aspirational fourteen-day promise your team cannot keep converts every slow week into a rule breach.
- Publish it where Rule 14 says. Website or app, prominently, alongside the means of raising a grievance and the identifying particulars a requester must furnish. The notice under Rule 3 must separately carry the route for complaints, so the notice and the grievance page must agree.
- Build the measures behind it. Rule 14(3) pairs the published timeline with “appropriate technical and organisational measures” to meet it. A published number with no workflow behind it satisfies half the rule and fails the half that gets audited.
The Register Is the Defence
When a grievance escalates, the Board sees two artefacts: the complainant’s account, and whatever record the fiduciary can produce. A grievance the business cannot prove it handled is indistinguishable from one it ignored.
The register that protects you records, per grievance: receipt timestamp, acknowledgment, the owner it was routed to, actions taken, the resolution, and the date the Data Principal was informed. Rights requests belong in the same tracked system; under Section 13(1) a mishandled rights request is itself grievance material, so parallel inboxes multiply the failure surface.
Failure lands in the residual tier of the penalty Schedule, up to Rs 50 crore. Not the Rs 250 crore that headlines attach to everything, which belongs to Section 8(5) security safeguards alone. The residual tier is sufficient: an absent or unprovable grievance mechanism is among the easiest violations for the Board to establish, because the evidence is simply missing.
Consent Managers Carry Their Own Duties
Section 13(1) names Consent Managers alongside Data Fiduciaries: the grievance right runs against a Consent Manager’s own acts and omissions, and Rule 14(3)‘s published-timeline standard binds them equally. Registered Consent Managers add the obligations of Rule 4 and the First Schedule, Part B of which imposes platform, independence, and record-keeping duties, including seven-year record retention. An entity planning Consent Manager registration should treat the grievance system as registration infrastructure, not an afterthought.
What to Build
The six steps in the checklist above compress to one sentence: appoint the contact, open the channel, publish a period you can keep, build the workflow, keep the register, and wire the notice and rights surfaces into the same system.
ConsentOS operates this layer: grievance and rights intake through the Rights Management Portal, each request routed to a responsible owner, with the timestamped resolution record that a Data Fiduciary produces if a matter ever reaches the Board.
Run the Gap Assessment to score your grievance and rights readiness against the Act.
Know where you stand on DPDP compliance
Run the free Compliance Vault Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.
Enforcement milestones, rule notifications, and deadline analysis.
One email when it matters, no more.
Resources
Continue Reading
Related DPDP Act 2023 guidance from the ConsentOS knowledge base.
How to File a DPDP Complaint With the Data Protection Board of India
The path a DPDP complaint follows: grievance to the Data Fiduciary first, then escalation to the Data Protection Board of India, plus the ninety-day response rule.
8 min read
Data Principal RightsDPDP Act 2023: All 8 Data Principal Rights with Templates (India)
Access, correction, erasure, grievance, and nominee rights under the DPDP Act 2023: the response deadlines a Data Fiduciary must meet, with ready-to-use request templates.
7 min read
Compliance AreasDPDP Notice Requirements: What Section 5 and Rule 3 Demand
What a DPDP notice must contain under Section 5 and Rule 3: itemised data, specific purposes, rights links, and the retrospective notice owed to existing users.
9 min read
Consent ManagementDPDP Consent Manager Registration: Who Needs It and How to Apply
Most companies do not need to register. Who does, the 13 November 2026 deadline, the Rs 2 crore net worth test, and what Sections 6(7) to 6(9) require.
12 min read