The right to grievance redressal
Section 13(1) gives a Data Principal the right to a readily available means of grievance redressal provided by the Data Fiduciary or Consent Manager, for any act or omission relating to its obligations under the Act. Section 13(2) requires the Data Fiduciary or Consent Manager to respond within the period prescribed by the Rules.
Section 13(3) is important: a Data Principal must exhaust the opportunity of redressing the grievance under this section before approaching the Board. The internal mechanism is a precondition, not a courtesy.
The grievance officer and contact duty
The Act does not use a single fixed title for every organisation. Section 8(10) requires a Data Fiduciary to publish the business contact information of a Data Protection Officer, if one is appointed, or of a person who is able to answer, on behalf of the Data Fiduciary, questions raised by a Data Principal about the processing of personal data.
A Significant Data Fiduciary must appoint a Data Protection Officer based in India under Section 10(2)(a), and that officer is the point of contact and the person responsible to the board. Other Data Fiduciaries name a contact person under Section 8(10). Either way, the contact must be genuinely reachable.
Building a compliant grievance mechanism
A grievance mechanism that meets Section 13 shares a few practical features.
- Publish the contact details required by Section 8(10) in the privacy notice and on the website.
- Give the Data Principal a clear channel to raise a grievance and an acknowledgement when they do.
- Set an internal service level that meets the response period prescribed by the Rules.
- Keep a record of each grievance, the response and the outcome, as part of the compliance file.
- Route unresolved matters to the Data Protection Officer or contact person before they reach the Board.
What happens if the grievance is not resolved
If the grievance is not resolved, the Data Principal may approach the Data Protection Board. Section 14 preserves the right to approach the Board, and the procedure is set out in Rules 17 to 21 of the DPDP Rules, 2025.
A documented, timely grievance process is the best protection for a Data Fiduciary: it resolves most matters early and, where a complaint does reach the Board, it shows the organisation met its Section 13 duty.
How AMLEGALS sets up grievance redressal
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance.
The team designs the grievance mechanism, the contact disclosures under Section 8(10), the response workflow and the record, so the organisation meets Section 13 and is ready if a matter escalates to the Board.

