Quick take: India’s Digital Personal Data Protection (DPDP) Act gives you — the Data Principal — practical rights when apps, banks, hospitals, edtech firms, or other organisations process your personal data. This is a citizen “what you can ask” checklist in plain English — not a lawyer’s brief, not an SIR policy timeline, and not ONORC.


Who is who (tiny glossary)


Today is Saturday, 26 September 2026. As DPDP rules and organisational compliance mature through 2025–26, citizens who keep written trails will fare better than citizens who only rant on social media.

Rights you should actually use

1) Right to notice / to know

You can expect clear notice: what data, purpose, how to withdraw consent, how to complain. If an app buries this in nonsense legalese, ask for a plain summary of what they hold about you and why.

2) Right to correction and updating

Wrong address, old mobile, misspelled name in a hospital or bank file? Ask for correction / completion / update. Attach proof. Keep ticket numbers.

3) Right to erasure (with limits)

For data processed on consent, you can often ask for erasure when the purpose is over or consent is withdrawn — subject to lawful retention (tax, medical, court, regulatory holds). “Delete everything forever including what the law makes them keep” is not a realistic ask.

Where processing was consent-based, withdrawal should be as easy as giving consent — not a maze. Withdrawal doesn’t always erase past lawful processing.

5) Grievance redressal

Fiduciaries should publish a grievance path and respond in defined timelines (rules have pointed to windows measured in weeks, not years — check the latest published timeline on their privacy page). Exhaust their grievance process before you escalate to the Data Protection Board routes the Act creates.

Practical “what you can ask” checklist

Copy-paste style requests (adapt to email / in-app forms):


Send from an email you control. Save PDFs of their replies.

Where citizens usually need this


DPDP sits beside sector rules (RBI, telemedicine, IRDAI, etc.). Use both when needed.

What DPDP is not


Sensible sequence when something feels wrong


Citizen habits that help year-round


NetaSampark angle

Data rights are civic rights in a digital republic. When a public-facing hospital, municipal app, or state portal mishandles citizen data repeatedly, representation still matters. Find the right office on NetaSampark while you also use the fiduciary’s grievance form.

Official anchors: Digital Personal Data Protection Act, 2023 · MeitY / published DPDP rules & explanatory notes · Organisation privacy / grievance pages

Nomination and the 90-day grievance habit

DPDP also contemplates nomination — someone who can exercise rights on your behalf in situations the Act allows (think incapacity). If a bank or insurer offers a nominee / authorised representative field for data rights, fill it thoughtfully.

On grievances: many compliance explainers and rule discussions point to fiduciaries needing to resolve complaints on the order of about 90 days max. Use that as a calendar habit — diary a follow-up — while checking the organisation’s published timeline. Board escalation comes after you give their grievance channel a fair, documented chance.

Draft for human approval. Not legal advice. Board procedures and rule timelines evolve — follow the latest official text for escalation.