Section 11 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 11 gives a Data Principal the right to obtain from a Data Fiduciary a summary of her personal data being processed, the identities of all other Data Fiduciaries and Data Processors with whom it has been shared, and any other prescribed information. A legal consultation can help you build a response process that is ready before the first request arrives.
A Data Principal who has previously given consent, including consent under section 7(a), may request from that Data Fiduciary: (a) a summary of the personal data processed and the processing activities; (b) the identities of all other Data Fiduciaries and Data Processors with whom the data has been shared, with a description of the data shared; and (c) any other prescribed information (section 11(1)). Sharing with an authorised law-enforcement recipient on a written request is carved out of (b) and (c) (section 11(2)).
Section 11 at a glance
| Provision | Content |
|---|---|
| 11(1) opening | Right against the Data Fiduciary to whom she previously gave consent, including consent under section 7(a); request in the manner prescribed |
| 11(1)(a) | Summary of personal data being processed and processing activities |
| 11(1)(b) | Identities of all other Data Fiduciaries and Data Processors with whom data has been shared, with a description of the data shared |
| 11(1)(c) | Any other information related to the personal data and its processing, as may be prescribed |
| 11(2) | Clauses (b) and (c) do not apply to sharing with a Data Fiduciary authorised by law, on a written request, for prevention, detection or investigation of offences or cyber incidents, or prosecution or punishment of offences |
Who can use it, and against whom
The right is given to "the Data Principal", who under section 2(j) includes the parent or lawful guardian of a child and the lawful guardian of a person with disability, acting on her behalf. After death or incapacity, a nominee may exercise rights under section 14. See section 14.
It lies against "the Data Fiduciary to whom she has previously given consent, including consent as referred to in clause (a) of section 7". The text has two parts.
- Previously given consent. The right is tied to consent having been given. On a plain reading, it does not extend to a fiduciary that processes her data only under a section 7 use other than clause (a), for example a legal obligation or a State function.
- Including section 7(a). Section 7(a) is the use where the Data Principal has voluntarily provided her data for a specified purpose and has not indicated that she does not consent. The Act treats that as covered for this right even though no separate consent was sought. See section 7(a) and (b).
The request is to be made "in such manner as may be prescribed". The Act does not state a form, a fee, a time for reply or a mode of delivery for the response. The DPDP Rules, 2025 (notified November 2025) prescribe the detail and different provisions commence on different dates; check the Rules for how the request is made and answered.
What the Data Principal can obtain
(a) Summary of data and processing activities
A summary "of personal data which is being processed" and "the processing activities undertaken" with respect to it. The text asks for a summary, not a copy of every record and not raw files. The summary should tell her what categories and items of data the fiduciary holds and what is done with them, using the actions in section 2(x) such as collection, storage, use and sharing. Note "which is being processed": the wording points to data currently processed.
(b) Identities of other Data Fiduciaries and Data Processors
This is the provision with operational impact. The fiduciary must be able to say who it has shared the data with, including Data Processors, and describe what data was shared. A business needs a live register of recipients: group companies, vendors, payment and logistics partners, cloud and analytics providers. If the register does not exist, this request cannot be answered from memory.
(c) Any other information
Anything related to the personal data and its processing "as may be prescribed". The Act adds nothing itself, so this category only has content to the extent the Rules supply it.
The law-enforcement carve-out: section 11(2)
Clauses (b) and (c) of sub-section (1) do not apply to "the sharing of any personal data by the said Data Fiduciary with any other Data Fiduciary authorised by law to obtain such personal data", where the sharing is:
- pursuant to a request made in writing by that other Data Fiduciary, and
- for the purpose of prevention or detection or investigation of offences or cyber incidents, or prosecution or punishment of offences.
All the elements are needed: authorised by law, written request, and the listed purposes. If so, the fiduciary need not disclose that recipient's identity. Note that the carve-out is from clauses (b) and (c) only. Clause (a), the summary of data and processing, still applies. Section 11(2) does not exempt a Data Processor from disclosure, and it does not remove other duties. A business that shares under an oral request, or with someone not authorised by law, cannot rely on it.
Where the right may not apply
- Section 17(1): Chapter III, which contains section 11, does not apply in the situations listed there, such as enforcing a legal claim or processing by a court. See section 17(1).
- Section 17(3): the Central Government may notify Data Fiduciaries or classes, including startups, to whom section 11 does not apply. Check for a notification.
- Section 17(2): the Act does not apply at all to the processing it lists, for example by notified State instrumentalities for security purposes.
Section 11 and the other rights
Section 11 is the first of four rights in Chapter III: access (11), correction and erasure (12), grievance redressal (13) and nomination (14). They are covered together in the overview on rights of the Data Principal. Access is often the first step: a Data Principal checks what is held and then uses section 12 to correct or erase it. See section 12.
Consequence of breach
The Schedule has no separate entry for section 11. Item 7 covers breach of any other provision of the Act or the rules, with a ceiling of fifty crore rupees. A Data Principal who does not get a response can use the grievance mechanism under section 8(10) and section 13, and only after that approach the Board (section 13(3)). The Board acts after an inquiry, a hearing and a finding that the breach is significant (section 33(1)). See penalties.
Practical examples
Example 1: e-commerce customer. A customer asks an online store what it holds. The store gives a summary of the data categories and uses, and lists the payment gateway, courier and analytics vendors to which it disclosed data, describing what each received.
Example 2: police request. An authority authorised by law asks in writing for a customer's transaction data for investigating an offence. The store need not name that authority in response to the customer's access request, by section 11(2). It still gives the summary under clause (a).
Example 3: no recipient list. A company shares data with many tools but has no register. It cannot answer clause (b), which is a process gap to fix before requests arrive.
Common mistakes
- Treating access as only a copy of one's data, and ignoring the list of recipients.
- Omitting Data Processors from the answer.
- Relying on section 11(2) without a written request or legal authority.
- Not checking whether the processing rests on consent or on another section 7 use.
Need help setting up access request handling?
A workable access process needs a data map, a recipient register and a named owner. Get in touch through our legal consultation service and we can help you design it around your systems.
Key takeaways
- The right lies against a fiduciary to whom she previously gave consent, including consent under section 7(a).
- She can obtain a summary of data and processing, and the identities of other Data Fiduciaries and Data Processors with the data shared.
- Other information is available only as prescribed.
- Sharing with an authorised recipient on a written law-enforcement request is carved out of (b) and (c).
- The manner of request and reply is left to the Rules.
Read next
- Section 12 of the DPDP Act, 2023: right to correction and erasure
- Section 13 of the DPDP Act, 2023: right of grievance redressal
- Section 14 of the DPDP Act, 2023: right to nominate
- Rights of the Data Principal under sections 11 to 14
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
