Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

Rules 9 and 14(3) of the Digital Personal Data Protection Rules, 2025: business contact information and the ninety-day grievance system

Rules 9 and 14 are in the group that, under rule 1(4), comes into force eighteen months after the date of publication of the Gazette. Rule 9: prominently publish on the website or...

Published
Updated
Reading time
8 min
Views
8
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Data Protection
Published
October 2, 2026
Last updated
Oct 8, 2026
Reading time
8 min
0:00
Last updated: October 2026Verified against: Government sources

Rule 9 makes every Data Fiduciary publish, and repeat in its replies, the business contact information of a person who can answer questions about processing. Rule 14(3) adds a duty to publish the period within which grievances are answered, not exceeding ninety days, and to back it with technical and organisational measures.

The Act behind these rules

Section 8(9) and (10) of the Act require a Data Fiduciary to publish the business contact information of a Data Protection Officer, or of a person who can answer questions, and to have a grievance redressal system. The Act's text is covered in Section 8 of the DPDP Act: contact information and grievance redressal. The Data Protection Officer is an obligation of a Significant Data Fiduciary under section 10. The Data Principal's right to grievance redressal is in section 13.

Rule 1(4) places rules 9 and 14 in the group that comes into force "eighteen months after the date of publication of this Gazette". Counting from the Gazette date of 13 November 2025, eighteen months end in mid-May 2027; confirm the exact date of publication before relying on a date. See rules 1 and 2. The rest of rule 14 is in our article on how Data Principals exercise their rights.

If your team is setting up a contact and grievance route for the first time, a legal consultation can help you decide who answers and how fast.

Rule 9: the contact point

"Every Data Fiduciary shall prominently publish on its website or app, and mention in every response to a communication for the exercise of the rights of a Data Principal under the Act, the business contact information of the Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary the questions of the Data Principal about the processing of her personal data."

ElementWhat the text says
Who"Every Data Fiduciary"
What"business contact information" of (a) the Data Protection Officer, if applicable, or (b) a person able to answer the Data Principal's questions about processing of her personal data
Where"prominently publish on its website or app"; and "mention in every response to a communication for the exercise of the rights of a Data Principal"

Three practical points follow from the text. First, the duty is for every Data Fiduciary, large or small. Second, "if applicable" ties the Data Protection Officer to those Data Fiduciaries that have one; the Rules do not say who must appoint one in this rule, and section 10 of the Act deals with Significant Data Fiduciaries. Where there is no Data Protection Officer, a person who can answer takes the place. Third, publication is not enough: the details must also appear in every response to a rights communication, so a reply to an access request or an erasure request should carry the contact.

"Business contact information" is not defined in the Rules. The same words appear in rule 7(1)(e) (breach) and in the Second Schedule item (g); see rule 7(1).

Example (invented): FinLeaf, a loan app, publishes in its app footer the name of its compliance officer, a business email address and a phone number. Every reply to a customer's data request, such as a request to see what data FinLeaf holds, ends with the same details.

Rule 14(3): the ninety-day grievance system

As printed: "Every Data Fiduciary and Consent Manager shall prominently publish on its website or app, or both, as the case may be, within a reasonable period not exceeding ninety days under its grievance redressal system for responding to the grievances of Data Principals and shall, for ensuring the effectiveness of the system in responding within such period, implement appropriate technical and organisational measures."

Drafting slip: the sentence is incomplete. After "prominently publish ... within a reasonable period not exceeding ninety days under its grievance redressal system for responding to the grievances of Data Principals", the object of "publish" is missing. Read as a whole, it reads as a duty to publish the period, not exceeding ninety days, within which grievances are responded to, and to implement measures to meet that period. The wording is incomplete and is quoted as printed.

What can safely be taken from the text:

  1. The duty applies to "every Data Fiduciary and Consent Manager".
  2. The place is the website or app, or both.
  3. The period must be "a reasonable period not exceeding ninety days". Ninety days is the outer limit, not a standard period; a Data Fiduciary may publish a shorter one, and "reasonable" is the test. It is not a promise that ninety days is always reasonable.
  4. The duty to implement "appropriate technical and organisational measures" is for "ensuring the effectiveness of the system in responding within such period". A published period that is not backed by staff, tooling or tracking does not meet it.

The text does not say from which event the period runs, for example receipt of the grievance. It is silent on that point. It also does not say what happens when the period is missed; the Data Principal's recourse to the Board is a matter for the Act and for the notice under rule 3, which must tell her how to complain to the Board.

Example (invented): HealthBridge, an online clinic booking site, publishes "We respond to every privacy grievance within thirty days" on its grievance page, and sets up a ticketing queue that flags any item at day twenty-five. The thirty-day period is within the ninety-day limit and the queue is the measure that makes the period effective.

How the two rules fit together

A Data Principal who has a question writes to the contact in rule 9. If she is not satisfied, she uses the grievance system in rule 14(3). Both are public and both sit on the website or app. The site's older post on a DPDP-compliant privacy policy is a starting point for placing both on a policy page, though it predates the Rules.

Rules 9 and 14(3) state no penalty. Check later amendments and notifications.

Need help setting up your contact and grievance route?

Naming the right person, writing the public notice and building a tracked grievance queue are small tasks that a regulator will look at. Speak to our legal team to set them up and align them with your notice and privacy policy.

Key takeaways

  • Rules 9 and 14 start eighteen months after the date of publication of the Gazette (rule 1(4)).
  • Rule 9: publish prominently, and mention in every response to a rights communication, the business contact information of the Data Protection Officer if applicable, or another person who can answer.
  • Rule 14(3): every Data Fiduciary and Consent Manager publishes a grievance response period of a reasonable period not exceeding ninety days and implements measures to make it work.
  • Rule 14(3) is incompletely worded; it is quoted as printed.
  • Ninety days is the outer limit printed in the Rule.
  • Later amendments and notifications should be checked.

Read next

Disclaimer: Based on the Digital Personal Data Protection Rules, 2025 as notified in the Gazette of India on 13 November 2025 (G.S.R. 846(E)), as consulted on 2 October 2026. The Rules come into force in three stages under rule 1; later amendments, notifications and anything published by the Data Protection Board of India should be checked. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About Rules 9 and 14

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Who must publish contact information under rule 9?

Every Data Fiduciary, on its website or app, and in every response to a rights communication.

Do I need a Data Protection Officer?

Rule 9 refers to the Data Protection Officer "if applicable". Where none applies, name a person who can answer questions on behalf of the Data Fiduciary.

A breach is handled well or badly in the first few hours — have the plan before the incident.

— TaxClue Data Protection Desk

Rules 9 and 14: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

Every Data Fiduciary, on its website or app, and in every response to a rights communication.

Rule 9 refers to the Data Protection Officer "if applicable". Where none applies, name a person who can answer questions on behalf of the Data Fiduciary.

No. Rule 14(3) says "a reasonable period not exceeding ninety days". Ninety days is the outer limit.

Yes. It says "Every Data Fiduciary and Consent Manager".

Words appear to be missing after "prominently publish", so the sentence has no clear object. It is read as a duty to publish the response period.

Rule 9 asks for the "business contact information" of a person; the Rules do not define the term.