Section 8 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 8(9) requires a Data Fiduciary to publish business contact information of a Data Protection Officer, if applicable, or of a person who can answer the Data Principal's questions about processing. Section 8(10) requires an effective mechanism to redress grievances. A legal consultation can help you set up both in a way that holds together with your notice.
A Data Fiduciary must publish, in the prescribed manner, business contact information of a Data Protection Officer, if applicable, or of a person able to answer questions raised by Data Principals about processing of their personal data (section 8(9)). It must also establish an effective mechanism to redress grievances of Data Principals (section 8(10)). These are not limited to Significant Data Fiduciaries. Breach falls under the fifty crore rupee ceiling for other provisions.
Sub-sections (9) and (10) at a glance
| Sub-section | Duty | Key words |
|---|---|---|
| 8(9) | Publish business contact information, in such manner as may be prescribed | DPO "if applicable", or a person able to answer questions |
| 8(10) | Establish an effective mechanism to redress grievances | "Effective"; Data Principals |
Section 8(9): who is the contact person
The section offers two options, depending on the business.
- A Data Protection Officer, "if applicable". Section 2(l) defines the Data Protection Officer as an individual appointed by a Significant Data Fiduciary under section 10(2)(a). So a DPO in the Act's sense exists only for Significant Data Fiduciaries. Under section 10(2)(a) the DPO must represent the fiduciary, be based in India, be an individual responsible to the Board of Directors or similar governing body, and be the point of contact for the grievance redressal mechanism. See duties of a Significant Data Fiduciary.
- "A person who is able to answer on behalf of the Data Fiduciary" the questions raised by the Data Principal about processing of her personal data. This is the option for every other Data Fiduciary.
Some things the text leaves open:
- It says "business contact information", so a work email, phone number or postal address, not a personal mobile of an employee.
- It does not say the person must be an employee, a director or based in India, except in the case of a DPO under section 10. A senior employee, the company secretary or a designated officer are all possibilities in practice.
- "Able to answer" is a capability test. A contact who cannot say what data is held or why fails the purpose of the section, even if a name is published.
- The manner of publication is "as may be prescribed", so the Rules cover where and how. The DPDP Rules, 2025 (notified November 2025) prescribe the detail and different provisions commence on different dates; check the Rules.
This links to the notice. Section 5(1)(ii) already requires the notice to tell the Data Principal how to exercise her rights and make a complaint to the Board. The contact in section 8(9) is where she can put questions before she escalates. See section 5.
Section 8(10): an "effective" mechanism
Section 8(10) is one line: a Data Fiduciary "shall establish an effective mechanism to redress the grievances of Data Principals". Note the following:
- It applies to every Data Fiduciary, unlike the DPO requirement.
- "Effective" is the test. A mailbox that nobody reads, or a form with no follow-up, will not meet it. The Act gives no definition, so look at practical things: is there a way to lodge a grievance, is it acknowledged, is someone responsible, is it resolved, is the record kept.
- It works with section 13. Section 13(1) gives the Data Principal the right to readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager. Section 13(2) requires a response within a prescribed period. Section 13(3) requires her to exhaust that route before approaching the Board. Section 8(10) is the fiduciary's side of the same arrangement. See section 13.
Because the Board expects a Data Principal to use the fiduciary's mechanism first, a weak mechanism has real consequences. If it does not work, complaints will reach the Board sooner, where the fiduciary will have to explain its processes in an inquiry under section 28.
Who this applies to
- All Data Fiduciaries, within the limits of section 17.
- Section 17(1) says Chapter II, except sub-sections (1) and (5) of section 8, does not apply in the listed situations, so sub-sections (9) and (10) fall away there.
- Section 17(3) notifications for startups and others name section 5, sub-sections (3) and (7) of section 8, and sections 10 and 11. They do not name sub-sections (9) and (10). Whether they change, in future, is for the Central Government's notifications; check them.
- A Consent Manager also has to provide grievance redressal under section 13, even though section 8 is about Data Fiduciaries.
Consequence of breach
There is no separate Schedule entry for section 8(9) or 8(10). Item 7 of the Schedule covers breach of any other provision of the Act or the rules: penalty may extend to fifty crore rupees. The Board can impose it only after an inquiry and a hearing, where the breach is significant (section 33(1)), considering section 33(2). See penalties.
Practical examples
Example 1: small online retailer. The retailer is not a Significant Data Fiduciary. It publishes a named privacy contact with a business email on its site and is able to state what data it holds. That meets the "person able to answer" option in section 8(9).
Example 2: dead mailbox. A company publishes a privacy email address that bounces. The mechanism exists on paper but is not effective under section 8(10).
Example 3: Significant Data Fiduciary. It must publish the business contact information of the DPO, who under section 10(2)(a)(iv) is also the point of contact for the grievance mechanism.
Common mistakes
- Publishing a generic "contact us" page with no link to data queries.
- Naming a person who cannot answer on the company's behalf.
- Using a staff member's personal number.
- Not keeping a log of grievances and outcomes.
- Forgetting that the mechanism must exist before the Data Principal needs it.
Need help with your grievance and contact set-up?
Many businesses have a policy page but no working process behind it. Through our legal consultation service, we can help you choose a contact person, draft the published details and build a simple grievance routine.
Key takeaways
- Publish business contact information of a DPO (if applicable) or a person able to answer queries.
- Every Data Fiduciary must have an effective grievance redressal mechanism.
- The manner of publication and response periods are left to the Rules.
- The Data Principal must use the fiduciary's grievance route before going to the Board (section 13(3)).
- Breach falls under Schedule item 7, up to fifty crore rupees.
Read next
- Section 13 of the DPDP Act, 2023: right of grievance redressal
- Section 10 of the DPDP Act, 2023: duties of a Significant Data Fiduciary
- Section 8 of the DPDP Act, 2023: erasure and retention of personal data
- Privacy policy draft for DPDP compliance
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
