Data Principal Rights Fulfilment Checklist
Sections 11 to 14 of the DPDP Act grant data principals the rights to access, correct, update, erase, file grievance, withdraw consent, and nominate a representative. Rule 14 of the DPDP Rules 2025 sets out the operational form: the data fiduciary must publish the mechanism, accept requests, verify identity, respond within 7 days for a valid request, and resolve grievances within 90 days. Each right is operationally distinct — access produces a summary, correction touches live records, erasure triggers downstream processor notification, grievance requires escalation, nomination requires proof of identity. For a retail bank with 5–25 million customers, a published rights mechanism generates anywhere from 50 to 5,000 requests a month depending on awareness; every one carries a 7-day clock, every refusal needs a documented lawful basis, every grievance is a 90-day hard limit. The checklist below covers the pre-receipt setup, the per-right execution, and the evidence retention that makes the rights pipeline defensible under audit.