AMLEGALS — Strategic Lawyering
DPDPA rights · Grievance

Grievance redressal under the DPDPA: the right, the officer and the timeline

Before a dispute reaches the Data Protection Board, the Act expects it to be dealt with by the organisation that holds the data. Grievance redressal is the Data Principal’s first, enforceable right of response, and the Data Fiduciary’s duty to answer.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 4 min read

A gold flow of dots moving through stages into a resolution node on a dark navy background
Short answer

Section 13 of the Digital Personal Data Protection Act, 2023 gives every Data Principal the right to a readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager, in respect of any act or omission regarding the performance of its obligations. The Data Fiduciary must respond within the period prescribed by the DPDP Rules, 2025. Separately, Section 8(10) requires a Data Fiduciary to publish the business contact information of a Data Protection Officer, where one is appointed, or of a person able to answer questions about the processing on its behalf. The grievance route must be exhausted before a Data Principal approaches the Board: Section 14 preserves the right to approach the Board, and Rules 17 to 21 set out how. Grievance redressal is therefore a required internal mechanism, not an optional contact form.

  • Grievance redressal
  • Grievance officer
  • Section 13
  • Section 8(10)
  • Data Principal
  • Complaint
  • DPDP Rules 2025
The right
Section 13: readily available grievance redressal
Contact duty
Section 8(10): publish DPO or contact person details
Timeline
Respond within the period prescribed by the DPDP Rules, 2025
Escalation
Board under Section 14 and Rules 17 to 21 after the route is used

The right to grievance redressal

Section 13(1) gives a Data Principal the right to a readily available means of grievance redressal provided by the Data Fiduciary or Consent Manager, for any act or omission relating to its obligations under the Act. Section 13(2) requires the Data Fiduciary or Consent Manager to respond within the period prescribed by the Rules.

Section 13(3) is important: a Data Principal must exhaust the opportunity of redressing the grievance under this section before approaching the Board. The internal mechanism is a precondition, not a courtesy.

The grievance officer and contact duty

The Act does not use a single fixed title for every organisation. Section 8(10) requires a Data Fiduciary to publish the business contact information of a Data Protection Officer, if one is appointed, or of a person who is able to answer, on behalf of the Data Fiduciary, questions raised by a Data Principal about the processing of personal data.

A Significant Data Fiduciary must appoint a Data Protection Officer based in India under Section 10(2)(a), and that officer is the point of contact and the person responsible to the board. Other Data Fiduciaries name a contact person under Section 8(10). Either way, the contact must be genuinely reachable.

Building a compliant grievance mechanism

A grievance mechanism that meets Section 13 shares a few practical features.

  • Publish the contact details required by Section 8(10) in the privacy notice and on the website.
  • Give the Data Principal a clear channel to raise a grievance and an acknowledgement when they do.
  • Set an internal service level that meets the response period prescribed by the Rules.
  • Keep a record of each grievance, the response and the outcome, as part of the compliance file.
  • Route unresolved matters to the Data Protection Officer or contact person before they reach the Board.

What happens if the grievance is not resolved

If the grievance is not resolved, the Data Principal may approach the Data Protection Board. Section 14 preserves the right to approach the Board, and the procedure is set out in Rules 17 to 21 of the DPDP Rules, 2025.

A documented, timely grievance process is the best protection for a Data Fiduciary: it resolves most matters early and, where a complaint does reach the Board, it shows the organisation met its Section 13 duty.

How AMLEGALS sets up grievance redressal

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance.

The team designs the grievance mechanism, the contact disclosures under Section 8(10), the response workflow and the record, so the organisation meets Section 13 and is ready if a matter escalates to the Board.

Questions and answers

Grievance Redressal Under DPDPA: common questions

Does the DPDPA require a grievance officer?

Section 13 requires a readily available grievance redressal mechanism, and Section 8(10) requires the Data Fiduciary to publish the contact details of a Data Protection Officer or a person able to answer questions. A Significant Data Fiduciary must appoint an India-based DPO under Section 10(2)(a).

How quickly must a grievance be answered?

Within the period prescribed by the DPDP Rules, 2025 under Section 13(2). The Data Fiduciary should set an internal service level that meets this period.

Can a Data Principal go straight to the Board?

No. Section 13(3) requires the Data Principal to exhaust the grievance redressal opportunity with the Data Fiduciary or Consent Manager before approaching the Board.

What should a grievance mechanism include?

A published contact under Section 8(10), a clear channel to raise a grievance, acknowledgement, a response within the prescribed period, and a record of the grievance and its outcome.

Where does a grievance go if the organisation does not resolve it?

The Data Principal may approach the Data Protection Board under Section 14, following the procedure in Rules 17 to 21.

Contact

Set up a compliant grievance mechanism

Share how you currently handle data privacy queries. The AMLEGALS data privacy team will design a mechanism that meets Section 13 and Section 8(10).

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

Grievance Redressal Under DPDPA: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Grievance Redressal Under DPDPA?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Grievance Redressal Under DPDPA under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Grievance Redressal Under DPDPA under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Grievance Redressal Under DPDPA?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Grievance Redressal Under DPDPA rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Grievance Redressal Under DPDPA?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Grievance Redressal Under DPDPA · DPDPA Exposure Assessment