What is DPDPA Chapter III (Rights of Data Principal)?
Chapter III of India's DPDPA establishes the rights of Data Principals including the right to information, correction, erasure, grievance redressal, and nomination, forming the core of individual data protection under Indian law.
Chapter III of the Digital Personal Data Protection Act (DPDPA) outlines the fundamental rights granted to Data Principals (individuals whose data is processed). These rights form the backbone of individual data protection under Indian law and place corresponding obligations on Data Fiduciaries. The rights include the right to information about processing activities, the right to correction and erasure of personal data, the right to grievance redressal, and the right to nominate another person to exercise these rights in case of death or incapacity.
The right to information under Section 11 requires Data Fiduciaries to provide Data Principals with a summary of the personal data being processed and the processing activities. The right to correction and erasure under Section 12 allows Data Principals to request correction of inaccurate or misleading data, completion of incomplete data, updating of outdated data, and erasure of data that is no longer necessary for the purpose for which it was collected. The right to grievance redressal under Section 13 requires Data Fiduciaries to establish accessible mechanisms for addressing Data Principal complaints. Section 14 establishes the right of nomination, allowing Data Principals to designate someone to exercise their rights posthumously.
Organizations operating as Data Fiduciaries in India must implement processes to receive and respond to Data Principal requests efficiently. IQWorks facilitates this through SearchIQ for locating a Data Principal's information across systems, DiscoverIQ for maintaining comprehensive data inventories, and automated workflows through ComplyIQ for processing rights requests within regulatory timeframes.
Relevant Regulations
How IQWorks Helps
Related Terms
DPDPA (Digital Personal Data Protection Act)
The Digital Personal Data Protection Act is India's comprehensive data privacy law enacted in 2023, governing the processing of digital personal data with an emphasis on consent, data fiduciary obligations, and the rights of data principals.
Data Fiduciary
A Data Fiduciary under India's DPDPA is any person or entity that alone or in conjunction with others determines the purpose and means of processing digital personal data, analogous to a data controller under the GDPR.
Data Principal / Data Subject
A Data Principal (under India's DPDPA) or Data Subject (under the GDPR) is the individual whose personal data is being collected, processed, or stored by an organization.
Data Subject Rights (DSR)
Data Subject Rights are the legal rights granted to individuals under data protection laws, enabling them to control how their personal data is collected, used, stored, and shared by organizations.
Right to Erasure (Right to Be Forgotten)
The right to erasure, also known as the right to be forgotten, allows individuals to request that organizations delete their personal data when it is no longer necessary, consent is withdrawn, or processing is unlawful.