KYCKART
KYCKART Guide · September 2026Guide

What Is a Data Principal Under the DPDP Act? Rights, Requests, and the Fulfilment Duties Coming for BFSI Institutions

A data principal is the individual whose personal data is processed under India’s DPDP Act. The four Chapter III rights, and what a bank or NBFC will have to do when a request arrives once the Rule 14 rights provisions commence.

calendar_monthSeptember 9, 2026
schedule~14 min read
library_books27 Cited Sources
What Is a Data Principal Under the DPDP Act? Rights, Requests, and the Fulfilment Duties Coming for BFSI Institutions

A data principal under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) is the individual to whom the personal data relates, which for a bank, NBFC or insurer normally means the customer, borrower or policyholder whose data it holds. The same Section 2 definition extends the term in two directions: where the individual is a child, it includes the parents or lawful guardian of that child, and where she is a person with disability, it includes her lawful guardian acting on her behalf. Section 2 defines a child as an individual who has not completed the age of eighteen years, and personal data as any data about an individual who is identifiable by or in relation to such data.

This piece is about the side of that definition a BFSI institution has to operate: what the four statutory rights oblige it to do, how a request will reach it once the DPDP Rules, 2025 commence, and which requests it may lawfully decline.

01KYCKART Regulatory Analysis

The Third Role in the Act's Structure

How data principals interact with fiduciaries, processors, and consent managers

The DPDP Act’s compliance architecture runs across three roles. The data principal holds the rights set out in Chapter III. The data fiduciary carries the obligations, including the duty to establish an effective grievance-redressal mechanism and the rights-fulfilment publication duties that Rule 14 of the DPDP Rules, 2025 will impose once it commences. The data processor sits behind the fiduciary, processing on its behalf.

Both of the other two roles have their own treatment. For the fiduciary side, including the full Section 8 obligation list, Significant Data Fiduciary designation and cross-border transfer, see KYCKART’s What Is a Data Fiduciary Under India’s DPDP Act? For the processor side, the contract mechanism and vendor evaluation, see What Is a Data Processor Under the DPDP Act? For the Act’s history and phased rollout, see What Is the DPDP Act?

A fourth actor sits between the principal and the fiduciary on consent. Section 2 defines a Consent Manager as a person registered with the Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform. Registration and obligations of a Consent Manager sit in Rule 4 of the DPDP Rules, 2025, which commences one year after publication of the Rules.

02KYCKART Regulatory Analysis

The Four Rights, Sections 11 to 14

Statutory boundaries, exceptions, and the consent attachment rule

Chapter III of the DPDP Act, headed “Rights and Duties of Data Principal”, confers four rights. Each carries a limit written into the Act itself.

Section 11: Access to Information About Personal Data

Section 11(1) entitles a Data Principal, on making a request in the prescribed manner to a Data Fiduciary to whom she has previously given consent, to obtain a summary of the personal data being processed and the processing activities undertaken with respect to it; the identities of all other Data Fiduciaries and Data Processors with whom that data has been shared, along with a description of the data shared; and any other information related to her personal data and its processing as may be prescribed.

Answering the clause (b) limb means the institution can name every downstream fiduciary and processor a given customer’s data went to, and describe what was shared with each.

Section 11(2)writes an exception into the right itself. Clauses (b) and (c) of Section 11(1) do not apply in respect of sharing personal data with another Data Fiduciary authorised by law to obtain it, where the sharing is pursuant to a written request from that other fiduciary for the purpose of prevention, detection or investigation of offences or cyber incidents, or for prosecution or punishment of offences. On this piece’s reading of that sub-section, an access response does not have to disclose that the bank shared the customer’s data with a law-enforcement or investigative body under a written request of that kind.

Section 12: Correction, Completion, Updating and Erasure

Section 12 has three sub-sections. Section 12(1) gives the Data Principal the right to correction, completion, updating and erasure of personal data for the processing of which she has previously given consent, in accordance with any requirement or procedure under any law for the time being in force. Section 12(2)sets the fiduciary’s response duty on the first three limbs: on receiving a request for correction, completion or updating, it shall correct inaccurate or misleading personal data, complete incomplete personal data, and update personal data.

The erasure limb is separate and carries its own condition. Section 12(3) requires the principal to make a request in the prescribed manner, and on receipt the fiduciary shall erase her personal data unless retention of it is necessary for the specified purpose or for compliance with any law for the time being in force. The three-sub-section structure and the wording of that carve-out are reproduced identically in an independent bare-act reproduction.

For a bank, the Section 12(2) duty attaches to the personal data itself. On receiving a correction, completion or updating request, the fiduciary must correct the inaccurate or misleading personal data, complete the incomplete personal data, and update the personal data.

Section 13: Grievance Redressal

Section 13(1) gives the Data Principal the right to readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager, in respect of any act or omission regarding the performance of its obligations in relation to her personal data or the exercise of her rights under the Act and its rules. Section 13(2) requires the fiduciary or Consent Manager to respond to such grievances within such period as may be prescribed from the date of receipt. Section 13(3) requires the Data Principal to exhaust the opportunity of redressing her grievance under this section before approaching the Board.

Section 14: Nomination

Section 14(1) gives the Data Principal the right to nominate, in the prescribed manner, another individual who will exercise her rights under the Act in the event of her death or incapacity. Section 14(2) defines incapacity as inability to exercise those rights due to unsoundness of mind or infirmity of body.

How Sections 11 and 12 Attach the Right to Consent

Both the access right and the correction and erasure right open by attaching themselves to a Data Fiduciary “to whom she has previously given consent, including consent as referred to in clause (a) of section 7”. Section 7(a)is the “voluntarily provided” legitimate use: processing for the specified purpose for which the Data Principal has voluntarily provided her personal data, and in respect of which she has not indicated that she does not consent to its use. Section 7’s other clauses, including (d) fulfilling a legal disclosure obligation to a State instrumentality, (e) compliance with a court order or judgment, and (i) employment purposes, are not referenced in the opening of Sections 11 or 12.

03KYCKART Regulatory Analysis

The Duties Side, and the ₹10,000 Entry in the Schedule

The only penalty tier directed at individuals rather than institutions

Chapter III’s heading covers duties as well as rights. Section 15 sets five duties on the Data Principal: comply with the provisions of all applicable laws while exercising rights under the Act; do not impersonate another person while providing personal data for a specified purpose; do not suppress any material information while providing personal data for any document, unique identifier, proof of identity or proof of address issued by the State or its instrumentalities; do not register a false or frivolous grievance or complaint with a Data Fiduciary or the Board; and furnish only such information as is verifiably authentic while exercising the right to correction or erasure.

The DPDP Act’s penalty Schedule, referenced in Section 33(1), carries a distinct entry for breach of the Section 15 duties, with a maximum penalty of ₹10,000. It is the only entry in the Schedule directed at the individual rather than at a Data Fiduciary or Consent Manager. The Schedule’s other tiers sit several orders of magnitude above it: up to ₹250 crore for a Section 8(5) security-safeguards breach, ₹200 crore for a Section 8(6) breach-notification failure, ₹200 crore for Section 9 children’s-data breaches, ₹150 crore for Significant Data Fiduciary obligations under Section 10, and ₹50 crore for breach of any other provision of the Act or Rules.

04KYCKART Regulatory Analysis

How a Request Actually Arrives: Rule 14 of the DPDP Rules, 2025

The intake mechanics, published particulars, and commencement timeline

Rule 14 of the DPDP Rules, 2025 is titled “Rights of Data Principals” and is the rule that will operationalise Sections 11 to 14 once it commences. Its five sub-rules matter directly to how a BFSI institution builds intake:

  • Published intake particulars: Rule 14(1) will require the Data Fiduciary, and where applicable the Consent Manager, to prominently publish on its website or app, or both, the details of the means by which a Data Principal may make a request to exercise those rights, and the particulars, if any, such as the username or other identifier which may be required to identify her under its terms of service.
  • Principal’s obligation to use defined channels: Rule 14(2) will put the corresponding step on the principal. To exercise her rights she may make a request to the Data Fiduciary to whom she has previously given consent, using the means and furnishing the particulars required by that fiduciary.
  • Grievance response ceiling: Rule 14(3) is the only sub-rule carrying a time period. Once it commences, every Data Fiduciary and Consent Manager will have to prominently publish, on its website or app, the period within which it will respond under its grievance redressal system, described as a reasonable period not exceeding ninety days.
  • Nomination workflow: Rule 14(4)covers nomination. When it comes into force, the Data Principal may, in accordance with the fiduciary’s terms of service and applicable law, nominate one or more individuals, again using the means and particulars the fiduciary requires.
  • Permitted identifiers: As drafted, Rule 14(5)defines “identifier” as any sequence of characters issued by the Data Fiduciary to identify the Data Principal, and includes a customer identification file (CIF) number, customer acquisition form number, application reference number, enrolment ID, email address, mobile number or licence number.

On timelines, Rule 14 sets one period and no more. The ninety-day figure is a ceiling on a period the fiduciary itself sets and publishes, and it applies to grievance redressal. Rule 14, verified against a second independent reproduction of its text, contains no other numeric period. No separate statutory deadline for responding to an access, correction or erasure request is prescribed by Rule 14.

Commencement Status: Rule 14 Is Not Yet in Force

Rule 1 of the DPDP Rules, 2025 phases commencement. Rules 1, 2 and 17 to 21 came into force on publication (13 November 2025). Rule 4 comes into force one year after publication (13 November 2026). Rules 3, 5 to 16, 22 and 23 come into force eighteen months after publication (computed as 13 May 2027). Rule 14 therefore sits in the eighteen-month tranche, as commonly reported across legal commentaries.

05KYCKART Regulatory Analysis

Fulfilment Operations for a BFSI Institution

Four core operational building blocks before intake goes live

Once the rights provisions commence, four things will have to exist before a rights request can be answered at all: a published intake channel, a way to verify the requester, a way to carry out a correction, and a record of what was done.

1. Intake Channel and Published Particulars

Rule 14(1) will put the channel and the identifying particulars on the fiduciary’s own website or app as published content, and Rule 14(5) supplies the vocabulary a bank would use to define them.

2. Verifying the Requester & Impersonation Risk

Rule 14(1)(b) will require the fiduciary to publish the particulars “if any” required to identify the principal under its terms of service, and Rule 14(5) defines identifier by example. The Rules prescribe no identity-assurance level, no document standard and no step-up authentication requirement for a rights request.

Roughly a quarter of organisations accepted an email address and phone number alone as proof of identity and handed over sensitive personal data, including Social Security numbers and account credentials.

: Black Hat USA 2019 / Dark Reading

What the absence of a prescribed verification standard can cost was demonstrated at Black Hat USA 2019, where researcher James Pavur presented “GDPArrrrr: Using Privacy Laws To Steal Identities”. Submitting access requests impersonating his fiancée to more than 150 companies, roughly a quarter surrendered sensitive personal data on email or phone alone, and some deleted her account unverified. A practitioner review framed this as a live liability risk inside access request handling. While that is a GDPR finding from another jurisdiction, it illustrates the critical need for strong verification.

3. Carrying Out a Correction

On receiving a correction, completion or updating request, Section 12(2) requires the fiduciary to correct the inaccurate or misleading personal data, complete the incomplete personal data, and update the personal data. This belongs on the build list alongside intake and record-keeping, since the sub-section sets the duty without prescribing internal workflow.

4. Record-Keeping & RBI Advisory No. 3/2026

RBI’s Department of Supervision issued Advisory No. 3/2026, dated 25 March 2026, on customer data protection best practices. Secondary summaries in Mondaq and Consent.in report its recommendations include board-approved data retention policies across live systems, test environments and backups; audit trails for deletion and modification capturing user identity, timestamps and system details; certified destruction methods; and centralized consent management. The advisory is illustrative guidance and does not substitute for applicable law.

06KYCKART Regulatory Analysis

When a Request Can Lawfully Be Refused

Statutory retention carve-outs, PMLA interactions, and Section 17(1) exemptions

Four provisions carry the refusal grounds, and each names its own condition.

ProvisionWhat It Permits to WithholdStatutory Condition
Section 11(2)The clause (b) and (c) limbs of an access response: identities of other fiduciaries and processors the data was shared with, and prescribed further informationThe sharing was with another Data Fiduciary authorised by law to obtain the data, pursuant to a written request for prevention, detection or investigation of offences or cyber incidents, or for prosecution or punishment of offences
Section 12(3)Erasure of personal dataRetention is necessary for the specified purpose or for compliance with any law for the time being in force
Section 8(7)Erasure on consent withdrawal or on the specified purpose ceasing, which is the fiduciary's own duty independent of any requestRetention is necessary for compliance with any law for the time being in force
Section 17(1)The whole of Chapter III, Sections 11 to 15, for the processing concernedOne of the Section 17(1) grounds applies to that processing (e.g. legal right enforcement, judicial/regulatory functions, offence prevention/prosecution, or default recovery under Section 17(1)(f))

Section 17(1) is the widest of the four. It provides that Chapter II (except Section 8(1) and (5)) and Chapter III (Rights and Duties, Sections 11 to 15) shall not apply where one of its grounds is met. The grounds include enforcing legal rights, court or regulatory functions, offence prevention/investigation, foreign contract data processing, and crucially for BFSI, Section 17(1)(f): ascertaining the financial information and assets and liabilities of a loan defaulter.

Worked Example: KYC Records Against an Erasure Request

RBI’s Master Direction on KYC requires Regulated Entities to maintain all transaction records for at least five years from the transaction date, and customer identification and address records for at least five years after the business relationship ends.

The statutory obligation underneath sits in PMLA. Under Section 12(1)(a) and 12(1)(e) of the Prevention of Money-Laundering Act, 2002, transaction and client identification records carry the same five-year retention mandates.

Because Section 12(3) carves out retention necessary for compliance with any law in force, an erasure request does not require a bank to purge statutory KYC or AML records during those running periods. However, non-mandated retention (marketing lists, enriched analytics, test environments) does not share the same protection.

Note that Section 8(8) and the Third Schedule read with Rule 8 prescribe deeming periods for when a purpose ceases to exist for three specific classes: large e-commerce entities, online gaming intermediaries, and social media intermediaries (each at three years). Banks and NBFCs are not among the classes named in that schedule.

07KYCKART Regulatory Analysis

Data Principal, Data Fiduciary, Data Processor

The structural triad of India's personal data protection architecture

DimensionData PrincipalData FiduciaryData Processor
Who it isThe individual to whom the personal data relates, including a child’s parents or lawful guardian and a person with disability’s lawful guardian acting on her behalfThe party the Act places the obligations on. Covered in KYCKART’s data fiduciary explainerProcesses personal data on behalf of the fiduciary. Covered in KYCKART’s data processor checklist
RightsFour statutory rights under Chapter III: access (S.11), correction and erasure (S.12), grievance redressal (S.13), nomination (S.14)Receives and fulfils requests through published channels and particulars once Rule 14(1) and 14(2) commence in the eighteen-month trancheActs only on instructions under contract with the fiduciary. See the data processor explainer
DutiesFive duties under Section 15, including not registering false grievances and furnishing only authentic information on correction/erasure requestsErasure under Section 8(7), published DPO/contact under Section 8(9), grievance system under Section 8(10), plus Rule 14 once commencedMaintains contractual security safeguards and assists the fiduciary under DPA terms. See the data processor explainer
Penalty exposureUp to ₹10,000 for breach of Section 15 duties, the only entry directed at the individualUp to ₹250 crore (S.8(5)), ₹200 crore (S.8(6)), ₹200 crore (S.9), ₹150 crore (S.10), and ₹50 crore for any other breachOutside this piece’s scope. Contractual indemnity and secondary exposure through the fiduciary
08KYCKART Regulatory Analysis

Escalation to the Data Protection Board

Exhaustion requirement, inquiry powers, and the enforcement split

The Act puts the fiduciary’s internal mechanism first. Section 13(3) requires the Data Principal to exhaust the opportunity of redressing her grievance under Section 13 before approaching the Board. Matching duties require the fiduciary to establish an effective grievance mechanism under Section 8(10) and publish DPO or contact details under Section 8(9).

Once a complaint reaches the Board, Section 27 sets its powers: inquiring into breaches, directing remedial mitigation, and imposing penalties under the Schedule. The Board has civil-court powers regarding summons, document discovery, and receiving evidence on affidavit.

Importantly, the commencement schedule treats the two halves differently: the Board rules (17 to 21) commenced on publication, while Rule 14 (rights requests) sits in the eighteen-month tranche.

09KYCKART Regulatory Analysis

What This Means for a Bank's Rights-Request Build

Practical implications, architectural sequencing, and open legal questions

Read together, Section 12(3) and Section 8(7) point to a narrower erasure exposure than generic “right to be forgotten” headlines suggest. Both provisions condition erasure on retention not being necessary for compliance with any law for the time being in force. RBI’s KYC Master Direction and PMLA Section 12 supply exactly that law for identification records, transaction records, account files and business correspondence inside the five-year windows described above. This suggests that an erasure request from a bank customer does not clear the KYC and transaction record set while those statutory clocks run.

The practical implication is that personal data held for secondary purposes (marketing pools, behavioral scoring copies, analytics enrichments, unmanaged test backups) does not enjoy that statutory safe harbor. That explains why RBI’s Advisory No. 3/2026 emphasizes applying board-approved data retention policies consistently across both live and backup environments.

A second insight concerns build sequencing. Because the Board and grievance obligations sit in the Act and early tranches, but Rule 14 rights requests commence at eighteen months (May 2027), institutions should sequence their builds accordingly: establish robust internal grievance mechanisms and published contact points first, while engineering the deeper rights-intake and verification layer against the May 2027 milestone.

Finally, an open textual question remains: Sections 11(1) and 12(1) specifically attach rights to data processed on consent (including Section 7(a) voluntary provision). Whether personal data processed under other Section 7 legitimate uses (e.g. legal disclosure, court orders, employment) attracts identical Section 11/12 rights is an unresolved textual question worth reviewing with counsel.

KYCKART Regulatory Analysis

Frequently Asked Questions

Direct answers on data principal rights, response timelines, and exceptions

This piece is KYCKART’s informational interpretation of publicly available regulatory sources on the DPDP Act, 2023, the DPDP Rules, 2025, RBI’s KYC Master Direction and RBI Advisory No. 3/2026. Regulatory positions stated here are as at 9 September 2026. It is not legal, tax or compliance advice. Organisations should verify specific obligations against the primary statutory text and consult qualified counsel before acting on any interpretation here, including before deciding how to answer or decline any specific data-principal request.

BC

Bhanujeet Choudhary

Head of Compliance, KYCKART

DPDP Act & BFSI Architecture

Prepare your DPDP compliance roadmap

KYCKART helps banks and NBFCs align customer onboarding and identity workflows with India’s evolving data protection framework.

Talk to our compliance teamarrow_forward