Skip to main content
Compliance Areas

DPDP Grievance Redressal: Building the Mechanism the Act Requires

Section 8(10) requires a grievance mechanism, Section 13 makes it the mandatory first stop, and Rule 14 caps response at 90 days. What to build, step by step.

9 min read
On This Page

Every DPDP complaint is supposed to die inside your organisation. That is the design of the Act: Section 8(10) makes the grievance mechanism mandatory, and Section 13(3) makes it the mandatory first stop, so the Data Protection Board only ever sees the grievances a Data Fiduciary failed to resolve. The mechanism is either your containment layer or your paper trail of neglect.

This guide covers what to build. For the escalation view, what happens when a grievance is exhausted and moves to the Board, see how DPDP complaints reach the DPBI.

The Statutory Frame

Four provisions carry the obligation.

“A Data Fiduciary shall establish an effective mechanism to redress the grievances of Data Principals.” (Section 8(10))

“A Data Principal shall have the right to have readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager in respect of any act or omission of such Data Fiduciary or Consent Manager regarding the performance of its obligations in relation to the personal data of such Data Principal or the exercise of her rights under the provisions of this Act and the rules made thereunder.” (Section 13(1))

Section 13(2) requires the fiduciary to respond within the prescribed period, and Section 13(3) requires the Data Principal to exhaust this route before approaching the Board. Rule 14 of the DPDP Rules 2025 then operationalises it: publish the means of exercising rights and the particulars a requester must furnish (Rule 14(1)), establish the grievance system with a prominently published response timeline not exceeding ninety days, backed by technical and organisational measures to meet it (Rule 14(3)).

Note what Section 13(1) covers: not just data mishandling, but “any act or omission” concerning the fiduciary’s obligations or the individual’s rights. A delayed access request, an ignored correction, a withdrawal that did not propagate: each is grievance material.

The Timeline That Exists, and the One That Does Not

Two numbers circulate in DPDP grievance guidance. One is real.

The real one: your published period, capped at ninety days. Rule 14(3) does not hand every organisation a ninety-day allowance. It requires publishing a “reasonable period not exceeding ninety days” and building the measures to meet it. Publish thirty days and thirty days is your standard. Publish nothing and you have failed the rule before the first grievance arrives.

The invented one: the 48-hour acknowledgment. No provision of the DPDP Act or the DPDP Rules prescribes a 24-hour or 48-hour acknowledgment window for grievances. The figure migrates in from the IT (Intermediary Guidelines) Rules 2021, which require intermediaries to acknowledge complaints within 24 hours, a different statute governing a different function. Acknowledging fast is sound operational practice and builds the record that you engaged. It is not a DPDP mandate, and compliance copy that presents it as one is citing a law it has not read.

The enforcement date matters here too: Rule 14 sits in the tranche of Rules that becomes enforceable on 13 May 2027. The obligation in Section 8(10) is already law. The compliance timeline has the full sequence.

Grievance Officer vs Data Protection Officer

Section 8(9) requires publishing the business contact information of “a Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary” the Data Principal’s questions about processing.

The structure of that sentence settles a common confusion. A DPO is mandatory only for Significant Data Fiduciaries, under Section 10(2)(a): an individual based in India, responsible to the governing body, serving as the grievance contact. No class of entity has been notified as an SDF as of July 2026. Every other organisation satisfies Section 8(9) with a named grievance officer or authorised contact person, published where Data Principals can find it.

The appointment is the cheap part. The officer needs authority to pull records, instruct teams, and close grievances inside the published period. A named contact with no mandate is a compliance decoration.

Design the Period You Can Keep

The published response period is a commitment, not a disclosure. Three design rules follow:

  1. Choose from operational reality. Measure how long a rights request or complaint actually takes to resolve across your systems, add margin, publish that. An aspirational fourteen-day promise your team cannot keep converts every slow week into a rule breach.
  2. Publish it where Rule 14 says. Website or app, prominently, alongside the means of raising a grievance and the identifying particulars a requester must furnish. The notice under Rule 3 must separately carry the route for complaints, so the notice and the grievance page must agree.
  3. Build the measures behind it. Rule 14(3) pairs the published timeline with “appropriate technical and organisational measures” to meet it. A published number with no workflow behind it satisfies half the rule and fails the half that gets audited.

The Register Is the Defence

When a grievance escalates, the Board sees two artefacts: the complainant’s account, and whatever record the fiduciary can produce. A grievance the business cannot prove it handled is indistinguishable from one it ignored.

The register that protects you records, per grievance: receipt timestamp, acknowledgment, the owner it was routed to, actions taken, the resolution, and the date the Data Principal was informed. Rights requests belong in the same tracked system; under Section 13(1) a mishandled rights request is itself grievance material, so parallel inboxes multiply the failure surface.

Failure lands in the residual tier of the penalty Schedule, up to Rs 50 crore. Not the Rs 250 crore that headlines attach to everything, which belongs to Section 8(5) security safeguards alone. The residual tier is sufficient: an absent or unprovable grievance mechanism is among the easiest violations for the Board to establish, because the evidence is simply missing.

Section 13(1) names Consent Managers alongside Data Fiduciaries: the grievance right runs against a Consent Manager’s own acts and omissions, and Rule 14(3)‘s published-timeline standard binds them equally. Registered Consent Managers add the obligations of Rule 4 and the First Schedule, Part B of which imposes platform, independence, and record-keeping duties, including seven-year record retention. An entity planning Consent Manager registration should treat the grievance system as registration infrastructure, not an afterthought.

What to Build

The six steps in the checklist above compress to one sentence: appoint the contact, open the channel, publish a period you can keep, build the workflow, keep the register, and wire the notice and rights surfaces into the same system.

ConsentOS operates this layer: grievance and rights intake through the Rights Management Portal, each request routed to a responsible owner, with the timestamped resolution record that a Data Fiduciary produces if a matter ever reaches the Board.

Run the Gap Assessment to score your grievance and rights readiness against the Act.

Know where you stand on DPDP compliance

Run the free Compliance Vault Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.

Enforcement milestones, rule notifications, and deadline analysis.

One email when it matters, no more.