As a Data Principal, the Act gives you four specific rights over your own data. Here’s what each one actually lets you do.
1. Right to access — see a summary of what data an organisation holds about you, and who else it’s been shared with.
2. Right to correction and erasure — fix data that’s wrong or outdated, and ask for it to be deleted once it’s no longer needed.
3. Right to grievance redressal — complain to the organisation, and escalate to the Data Protection Board if you’re not satisfied.
4. Right to nominate — name someone who can exercise these rights on your behalf if you die or become incapacitated.
2. Right to correction and erasure — fix data that’s wrong or outdated, and ask for it to be deleted once it’s no longer needed.
3. Right to grievance redressal — complain to the organisation, and escalate to the Data Protection Board if you’re not satisfied.
4. Right to nominate — name someone who can exercise these rights on your behalf if you die or become incapacitated.
One notable absence: unlike GDPR, the DPDP Act doesn’t include a right to data portability — there’s no statutory right to take your data from one service and hand it to a competitor in a ready-to-use format. India’s four rights focus on knowing, fixing, complaining and delegating, not on moving data between platforms..
Common misconception — That India’s law mirrors GDPR’s rights one-for-one. It doesn’t — data portability, in particular, simply isn’t part of the DPDP Act.
Four rights, precisely defined: access, correct-and-erase, complain, and nominate.
SOURCES The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdfÂ