Rules 9 and 14 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Rule 9 makes every Data Fiduciary publish, and repeat in its replies, the business contact information of a person who can answer questions about processing. Rule 14(3) adds a duty to publish the period within which grievances are answered, not exceeding ninety days, and to back it with technical and organisational measures.
Rules 9 and 14 are in the group that, under rule 1(4), comes into force eighteen months after the date of publication of the Gazette. Rule 9: prominently publish on the website or app, and mention in every response to a rights communication, the business contact information of the Data Protection Officer, if applicable, or another person who can answer. Rule 14(3): every Data Fiduciary and Consent Manager publishes a grievance period of a reasonable period not exceeding ninety days and implements measures to meet it.
The Act behind these rules
Section 8(9) and (10) of the Act require a Data Fiduciary to publish the business contact information of a Data Protection Officer, or of a person who can answer questions, and to have a grievance redressal system. The Act's text is covered in Section 8 of the DPDP Act: contact information and grievance redressal. The Data Protection Officer is an obligation of a Significant Data Fiduciary under section 10. The Data Principal's right to grievance redressal is in section 13.
Rule 1(4) places rules 9 and 14 in the group that comes into force "eighteen months after the date of publication of this Gazette". Counting from the Gazette date of 13 November 2025, eighteen months end in mid-May 2027; confirm the exact date of publication before relying on a date. See rules 1 and 2. The rest of rule 14 is in our article on how Data Principals exercise their rights.
If your team is setting up a contact and grievance route for the first time, a legal consultation can help you decide who answers and how fast.
Rule 9: the contact point
"Every Data Fiduciary shall prominently publish on its website or app, and mention in every response to a communication for the exercise of the rights of a Data Principal under the Act, the business contact information of the Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary the questions of the Data Principal about the processing of her personal data."
| Element | What the text says |
|---|---|
| Who | "Every Data Fiduciary" |
| What | "business contact information" of (a) the Data Protection Officer, if applicable, or (b) a person able to answer the Data Principal's questions about processing of her personal data |
| Where | "prominently publish on its website or app"; and "mention in every response to a communication for the exercise of the rights of a Data Principal" |
Three practical points follow from the text. First, the duty is for every Data Fiduciary, large or small. Second, "if applicable" ties the Data Protection Officer to those Data Fiduciaries that have one; the Rules do not say who must appoint one in this rule, and section 10 of the Act deals with Significant Data Fiduciaries. Where there is no Data Protection Officer, a person who can answer takes the place. Third, publication is not enough: the details must also appear in every response to a rights communication, so a reply to an access request or an erasure request should carry the contact.
"Business contact information" is not defined in the Rules. The same words appear in rule 7(1)(e) (breach) and in the Second Schedule item (g); see rule 7(1).
Example (invented): FinLeaf, a loan app, publishes in its app footer the name of its compliance officer, a business email address and a phone number. Every reply to a customer's data request, such as a request to see what data FinLeaf holds, ends with the same details.
Rule 14(3): the ninety-day grievance system
As printed: "Every Data Fiduciary and Consent Manager shall prominently publish on its website or app, or both, as the case may be, within a reasonable period not exceeding ninety days under its grievance redressal system for responding to the grievances of Data Principals and shall, for ensuring the effectiveness of the system in responding within such period, implement appropriate technical and organisational measures."
Drafting slip: the sentence is incomplete. After "prominently publish ... within a reasonable period not exceeding ninety days under its grievance redressal system for responding to the grievances of Data Principals", the object of "publish" is missing. Read as a whole, it reads as a duty to publish the period, not exceeding ninety days, within which grievances are responded to, and to implement measures to meet that period. The wording is incomplete and is quoted as printed.
What can safely be taken from the text:
- The duty applies to "every Data Fiduciary and Consent Manager".
- The place is the website or app, or both.
- The period must be "a reasonable period not exceeding ninety days". Ninety days is the outer limit, not a standard period; a Data Fiduciary may publish a shorter one, and "reasonable" is the test. It is not a promise that ninety days is always reasonable.
- The duty to implement "appropriate technical and organisational measures" is for "ensuring the effectiveness of the system in responding within such period". A published period that is not backed by staff, tooling or tracking does not meet it.
The text does not say from which event the period runs, for example receipt of the grievance. It is silent on that point. It also does not say what happens when the period is missed; the Data Principal's recourse to the Board is a matter for the Act and for the notice under rule 3, which must tell her how to complain to the Board.
Example (invented): HealthBridge, an online clinic booking site, publishes "We respond to every privacy grievance within thirty days" on its grievance page, and sets up a ticketing queue that flags any item at day twenty-five. The thirty-day period is within the ninety-day limit and the queue is the measure that makes the period effective.
How the two rules fit together
A Data Principal who has a question writes to the contact in rule 9. If she is not satisfied, she uses the grievance system in rule 14(3). Both are public and both sit on the website or app. The site's older post on a DPDP-compliant privacy policy is a starting point for placing both on a policy page, though it predates the Rules.
Rules 9 and 14(3) state no penalty. Check later amendments and notifications.
Need help setting up your contact and grievance route?
Naming the right person, writing the public notice and building a tracked grievance queue are small tasks that a regulator will look at. Speak to our legal team to set them up and align them with your notice and privacy policy.
Key takeaways
- Rules 9 and 14 start eighteen months after the date of publication of the Gazette (rule 1(4)).
- Rule 9: publish prominently, and mention in every response to a rights communication, the business contact information of the Data Protection Officer if applicable, or another person who can answer.
- Rule 14(3): every Data Fiduciary and Consent Manager publishes a grievance response period of a reasonable period not exceeding ninety days and implements measures to make it work.
- Rule 14(3) is incompletely worded; it is quoted as printed.
- Ninety days is the outer limit printed in the Rule.
- Later amendments and notifications should be checked.
Read next
- Rule 14: how Data Principals exercise their rights, identifier and nomination
- Rule 3: notice by a Data Fiduciary to a Data Principal
- Section 8 of the DPDP Act: contact information and grievance redressal
- Rights of a Data Principal under sections 11 to 14
Disclaimer: Based on the Digital Personal Data Protection Rules, 2025 as notified in the Gazette of India on 13 November 2025 (G.S.R. 846(E)), as consulted on 2 October 2026. The Rules come into force in three stages under rule 1; later amendments, notifications and anything published by the Data Protection Board of India should be checked. This article is general information, not legal advice; check the official text before acting.
