Section 13 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 13 gives a Data Principal a right to readily available means of grievance redressal from a Data Fiduciary or Consent Manager, requires them to respond within a prescribed period, and requires the Data Principal to use that route before approaching the Board. A legal consultation can help you design the first-line mechanism that this section depends on.
The Data Principal has the right to readily available means of grievance redressal from a Data Fiduciary or Consent Manager for any act or omission regarding its obligations or her rights (section 13(1)). The fiduciary or Consent Manager must respond within a prescribed period (section 13(2)). The Data Principal must exhaust this opportunity before approaching the Board (section 13(3)). No specific Schedule entry applies; the ceiling for other provisions is Rs 50 crore.
Section 13 at a glance
| Sub-section | Content |
|---|---|
| 13(1) | Right to readily available means of grievance redressal from a Data Fiduciary or Consent Manager, for any act or omission regarding performance of its obligations relating to her personal data, or exercise of her rights under the Act and the rules |
| 13(2) | Response within such period as may be prescribed, for all or any class of Data Fiduciaries |
| 13(3) | Data Principal shall exhaust the opportunity of redressing her grievance under this section before approaching the Board |
Section 13(1): what the right covers
The right is to "readily available means of grievance redressal". Three features:
- "Readily available". The route has to be easy to find and use. A grievance process buried in a long privacy policy, or one needing a postal letter, is hard to call readily available. The Act does not define the phrase, so judge it by the ordinary test: can a typical Data Principal find and use it?
- Two kinds of providers. The right runs against "a Data Fiduciary or Consent Manager". A Consent Manager under section 2(g) is a person registered with the Board who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent. See Consent Manager.
- Two subjects. The grievance may be about "any act or omission" concerning (i) the performance of the provider's obligations in relation to her personal data, or (ii) the exercise of her rights under the Act and the rules. So it covers both a failure to protect her data and a failure to answer her access, correction or erasure request.
The fiduciary's matching duty is section 8(10): it must establish an effective mechanism to redress grievances of Data Principals, and under section 8(9) publish the contact information of a DPO, if applicable, or a person able to answer questions. Section 13 is the right; section 8(10) is the obligation that delivers it. See section 8(9) and (10).
Section 13(2): respond within the prescribed period
The fiduciary or Consent Manager "shall respond to any grievances ... within such period as may be prescribed from the date of its receipt for all or any class of Data Fiduciaries". Points to note:
- The Act sets no number of days. It leaves the period to the rules, and allows the period to differ by class of Data Fiduciaries ("all or any class").
- The clock runs "from the date of its receipt". Keep proof of when each grievance arrived.
- "Respond" is the word used. The Act does not say the response must resolve the grievance, but the mechanism under section 8(10) must be effective. A response that only acknowledges and does nothing further invites escalation.
The DPDP Rules, 2025 (notified November 2025) prescribe the detail and different provisions commence on different dates; this article states no period from them. Check the Rules for the period applicable to you.
Section 13(3): exhaust first, then the Board
"The Data Principal shall exhaust the opportunity of redressing her grievance under this section before approaching the Board." This is a gatekeeping rule.
- It sits alongside section 27(1)(b), under which the Board inquires on a complaint made by a Data Principal about a personal data breach, or a breach of a fiduciary's obligations or her rights. Section 13(3) is the stated pre-condition for such a complaint. See section 27.
- The Act does not define "exhaust". It does not say how long she must wait or whether a rejection is needed. Read it with section 13(2): once the prescribed period has run without a proper response, or she has received a response and is dissatisfied, the opportunity has been used. The detail, if any, is for the Rules and the Board.
- It does not bar the Board from acting on its own intimation under section 27(1)(a), for instance after a breach notice, or on a reference by the Government or a court under section 27(1)(b).
- The Board may, under section 28(12), warn or impose costs on a complainant if it thinks the complaint is false or frivolous. Section 15(d) makes it a duty of the Data Principal not to register a false or frivolous grievance with a fiduciary or the Board. See section 15.
Why the first-line mechanism matters to a business
Because the Board expects the grievance route to have been used first, the complaint file you build at this stage is likely to be the first evidence in any later inquiry: what was asked, when, what was answered, who handled it. A business with no record has little to show. And an ineffective mechanism may itself be a breach of section 8(10) and of this section's aim.
Where section 13 may not apply
Section 17(1) says Chapter III does not apply in the listed situations. Section 17(3) notifications can relieve certain fiduciaries from named provisions, which do not include section 13 on the text. Section 17(5) allows the Central Government to declare, within five years of commencement, that any provision does not apply to specified Data Fiduciaries for a period. Check the notifications.
Consequence of breach
There is no specific Schedule entry for section 13. Item 7 covers breach of any other provision of the Act or rules: penalty up to fifty crore rupees, after an inquiry, a hearing and a finding that the breach is significant (section 33(1)). A Consent Manager's breach of its obligations can be taken up by the Board on a Data Principal's complaint under section 27(1)(c). See penalties.
Practical examples
Example 1: unanswered access request. A customer asked for her data summary and got no reply. She lodges a grievance through the company's mechanism. Only after the opportunity has been exhausted does she take it to the Board.
Example 2: Consent Manager grievance. A Data Principal complains to her Consent Manager that her withdrawal was not passed on. Section 13 covers the Consent Manager as well as the fiduciary.
Example 3: skipping the first step. A Data Principal files directly with the Board without using the company's grievance route. Section 13(3) says she must exhaust that route first.
Common mistakes
- Having no record of when each grievance was received.
- Treating an acknowledgement as a response.
- Failing to give the Consent Manager's route the same attention.
- Forgetting that the prescribed period may differ by class of fiduciary.
Need help with grievance handling?
A grievance process is only as good as its logging, ownership and timeliness. Through our legal consultation service we can help you set these up and align them with the Rules applicable to you.
Key takeaways
- The Data Principal has a right to readily available grievance redressal from a Data Fiduciary or Consent Manager.
- The response period is prescribed by rules and may differ by class.
- She must exhaust this route before approaching the Board.
- Keep dated records of every grievance and response.
- No specific Schedule entry; Rs 50 crore is the ceiling for other provisions.
Read next
- Section 8 of the DPDP Act, 2023: contact information and grievance redressal
- Section 11 of the DPDP Act, 2023: right to access information
- Section 27 of the DPDP Act, 2023: powers and functions of the Board
- Rights of the Data Principal under sections 11 to 14
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
