📘 MODULE 3 OF 6

Data Principal Rights

Master the fundamental rights granted to individuals under Chapter III of DPDPA 2023 — from access and correction to grievance redressal and nomination, with practical implementation strategies.

5
Rights Covered
§11-15
DPDPA Sections
5
Lesson Parts
3.5
Hours Content
"

The right of an individual to exercise control over his personal data and to be able to control his/her own life would also encompass his right to control his existence on the Internet.

Justice D.Y. Chandrachud

K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1

⚖️

Landmark Precedent

Google Spain SL v. AEPD

Case C-131/12 (CJEU, 2014) — The "Right to be Forgotten" Case

The European Court of Justice established that individuals have the right to request removal of personal data from search engine results when the information is inadequate, irrelevant, or no longer relevant. This landmark ruling influenced India's inclusion of the erasure right under Section 12(3) of DPDPA. The court balanced individual privacy rights against public interest in access to information — a balancing test now embedded in India's framework.

Learning Objectives

What you'll master in this module

🎯

Right to Access

Understand data access requests, information disclosure requirements, and response mechanisms

✏️

Correction & Erasure

Master data rectification procedures and the conditions for lawful data deletion

📢

Grievance Redressal

Design compliant grievance mechanisms and understand the exhaustion requirement

👤

Nomination Rights

Implement nomination systems for death or incapacity scenarios

⚖️

Principal Duties

Understand the reciprocal obligations placed on data principals

🔧

Practical Implementation

Design rights management systems with templates and workflows

Module Content

5 comprehensive lessons covering all Data Principal rights

1

Right to Access Information

DPDPA Section 11 | Rule 13

Learn how data principals can obtain summaries of their personal data, understand processing activities, and identify all entities with whom their data has been shared.

§11(1)(a) Data Summary §11(1)(b) Third-Party Sharing §11(1)(c) Additional Information Request Procedures Response Timelines
⏱️ 45 mins 📖 12 topics
Start →
2

Right to Correction and Erasure

DPDPA Section 12 | Rule 8

Master the correction, completion, and updating obligations, plus understand when erasure is mandatory and when retention exceptions apply under law.

§12(1) Correction Right §12(2) Fiduciary Obligations §12(3) Erasure Request Retention Exceptions Rule 8 Timelines
⏱️ 50 mins 📖 14 topics
Start →
3

Right to Grievance Redressal

DPDPA Section 13 | Rule 13(3)

Design compliant grievance mechanisms, understand response obligations, and learn the mandatory exhaustion requirement before approaching the Board.

§13(1) Grievance Right §13(2) Response Period §13(3) Exhaustion Rule Mechanism Design Consent Managers
⏱️ 40 mins 📖 10 topics
Start →
4

Right to Nominate

DPDPA Section 14

Understand nomination rights for death and incapacity scenarios, implement nomination mechanisms, and handle posthumous data management complexities.

§14(1) Nomination Right §14(2) Incapacity Definition Death Scenarios Digital Estate Implementation
⏱️ 35 mins 📖 8 topics
Start →
5

Duties of Data Principal

DPDPA Section 15

Learn the reciprocal duties imposed on data principals — from compliance obligations to prohibitions against impersonation, false information, and frivolous complaints.

§15(a) Legal Compliance §15(b) No Impersonation §15(c) No Suppression §15(d) No False Complaints §15(e) Authentic Information
⏱️ 30 mins 📖 8 topics
Start →
📝

Module 3 Assessment

Test your understanding of Data Principal rights with scenario-based questions covering all five sections.

25
Questions
45
Minutes
70%
Pass Score
Take Module Quiz