Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

Section 13 of the Digital Personal Data Protection Act, 2023: Right of grievance redressal

The Data Principal has the right to readily available means of grievance redressal from a Data Fiduciary or Consent Manager for any act or omission regarding its obligations or...

Published
Updated
Reading time
8 min
Views
9
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Data Protection
Published
September 30, 2026
Last updated
Oct 9, 2026
Reading time
8 min
0:00
Last updated: October 2026Verified against: Government sources

Section 13 gives a Data Principal a right to readily available means of grievance redressal from a Data Fiduciary or Consent Manager, requires them to respond within a prescribed period, and requires the Data Principal to use that route before approaching the Board. A legal consultation can help you design the first-line mechanism that this section depends on.

Section 13 at a glance

Sub-sectionContent
13(1)Right to readily available means of grievance redressal from a Data Fiduciary or Consent Manager, for any act or omission regarding performance of its obligations relating to her personal data, or exercise of her rights under the Act and the rules
13(2)Response within such period as may be prescribed, for all or any class of Data Fiduciaries
13(3)Data Principal shall exhaust the opportunity of redressing her grievance under this section before approaching the Board

Section 13(1): what the right covers

The right is to "readily available means of grievance redressal". Three features:

  • "Readily available". The route has to be easy to find and use. A grievance process buried in a long privacy policy, or one needing a postal letter, is hard to call readily available. The Act does not define the phrase, so judge it by the ordinary test: can a typical Data Principal find and use it?
  • Two kinds of providers. The right runs against "a Data Fiduciary or Consent Manager". A Consent Manager under section 2(g) is a person registered with the Board who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent. See Consent Manager.
  • Two subjects. The grievance may be about "any act or omission" concerning (i) the performance of the provider's obligations in relation to her personal data, or (ii) the exercise of her rights under the Act and the rules. So it covers both a failure to protect her data and a failure to answer her access, correction or erasure request.

The fiduciary's matching duty is section 8(10): it must establish an effective mechanism to redress grievances of Data Principals, and under section 8(9) publish the contact information of a DPO, if applicable, or a person able to answer questions. Section 13 is the right; section 8(10) is the obligation that delivers it. See section 8(9) and (10).

Section 13(2): respond within the prescribed period

The fiduciary or Consent Manager "shall respond to any grievances ... within such period as may be prescribed from the date of its receipt for all or any class of Data Fiduciaries". Points to note:

  • The Act sets no number of days. It leaves the period to the rules, and allows the period to differ by class of Data Fiduciaries ("all or any class").
  • The clock runs "from the date of its receipt". Keep proof of when each grievance arrived.
  • "Respond" is the word used. The Act does not say the response must resolve the grievance, but the mechanism under section 8(10) must be effective. A response that only acknowledges and does nothing further invites escalation.

The DPDP Rules, 2025 (notified November 2025) prescribe the detail and different provisions commence on different dates; this article states no period from them. Check the Rules for the period applicable to you.

Section 13(3): exhaust first, then the Board

"The Data Principal shall exhaust the opportunity of redressing her grievance under this section before approaching the Board." This is a gatekeeping rule.

  • It sits alongside section 27(1)(b), under which the Board inquires on a complaint made by a Data Principal about a personal data breach, or a breach of a fiduciary's obligations or her rights. Section 13(3) is the stated pre-condition for such a complaint. See section 27.
  • The Act does not define "exhaust". It does not say how long she must wait or whether a rejection is needed. Read it with section 13(2): once the prescribed period has run without a proper response, or she has received a response and is dissatisfied, the opportunity has been used. The detail, if any, is for the Rules and the Board.
  • It does not bar the Board from acting on its own intimation under section 27(1)(a), for instance after a breach notice, or on a reference by the Government or a court under section 27(1)(b).
  • The Board may, under section 28(12), warn or impose costs on a complainant if it thinks the complaint is false or frivolous. Section 15(d) makes it a duty of the Data Principal not to register a false or frivolous grievance with a fiduciary or the Board. See section 15.

Why the first-line mechanism matters to a business

Because the Board expects the grievance route to have been used first, the complaint file you build at this stage is likely to be the first evidence in any later inquiry: what was asked, when, what was answered, who handled it. A business with no record has little to show. And an ineffective mechanism may itself be a breach of section 8(10) and of this section's aim.

Where section 13 may not apply

Section 17(1) says Chapter III does not apply in the listed situations. Section 17(3) notifications can relieve certain fiduciaries from named provisions, which do not include section 13 on the text. Section 17(5) allows the Central Government to declare, within five years of commencement, that any provision does not apply to specified Data Fiduciaries for a period. Check the notifications.

Consequence of breach

There is no specific Schedule entry for section 13. Item 7 covers breach of any other provision of the Act or rules: penalty up to fifty crore rupees, after an inquiry, a hearing and a finding that the breach is significant (section 33(1)). A Consent Manager's breach of its obligations can be taken up by the Board on a Data Principal's complaint under section 27(1)(c). See penalties.

Practical examples

Example 1: unanswered access request. A customer asked for her data summary and got no reply. She lodges a grievance through the company's mechanism. Only after the opportunity has been exhausted does she take it to the Board.

Example 2: Consent Manager grievance. A Data Principal complains to her Consent Manager that her withdrawal was not passed on. Section 13 covers the Consent Manager as well as the fiduciary.

Example 3: skipping the first step. A Data Principal files directly with the Board without using the company's grievance route. Section 13(3) says she must exhaust that route first.

Common mistakes

  • Having no record of when each grievance was received.
  • Treating an acknowledgement as a response.
  • Failing to give the Consent Manager's route the same attention.
  • Forgetting that the prescribed period may differ by class of fiduciary.

Need help with grievance handling?

A grievance process is only as good as its logging, ownership and timeliness. Through our legal consultation service we can help you set these up and align them with the Rules applicable to you.

Key takeaways

  • The Data Principal has a right to readily available grievance redressal from a Data Fiduciary or Consent Manager.
  • The response period is prescribed by rules and may differ by class.
  • She must exhaust this route before approaching the Board.
  • Keep dated records of every grievance and response.
  • No specific Schedule entry; Rs 50 crore is the ceiling for other provisions.

Read next

Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.

Quick recapKey facts & short answers

Key Facts About Section 13

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Who must provide grievance redressal?

A Data Fiduciary or Consent Manager (section 13(1)).

What is the time limit to respond?

Such period as may be prescribed. The Act states none. Check the DPDP Rules, 2025.

Settle the facts first; the right section and the right form follow from them.

— TaxClue Compliance Desk

Section 13: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

A Data Fiduciary or Consent Manager (section 13(1)).

Such period as may be prescribed. The Act states none. Check the DPDP Rules, 2025.

Section 13(3) requires her to exhaust the grievance opportunity first.

Any act or omission regarding the provider's obligations relating to her data or the exercise of her rights under the Act and rules.

No. Section 27(1) also lets it act on a breach intimation, a Government reference or court directions.

Section 28(12) lets the Board issue a warning or impose costs, and section 15(d) makes filing a false or frivolous grievance a duty breach.