Next dueCompany / ROC
14 OCTADT-1 · Auditor appointment (after AGM)in 4 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 31 OCTMSME-1 · Dues to MSMEs · Apr–Sep 2026in 21 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days 30 JUNDPT-3 · Return of deposits · FY 2026-27in 263 days 11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days
All due dates

Section 8 of the Digital Personal Data Protection Act, 2023: Contact information and grievance redressal

A Data Fiduciary must publish, in the prescribed manner, business contact information of a Data Protection Officer, if applicable, or of a person able to answer questions raised...

Published
Updated
Reading time
7 min
Views
8
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
Topic
Data Protection
Published
September 30, 2026
Last updated
Oct 7, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Section 8(9) requires a Data Fiduciary to publish business contact information of a Data Protection Officer, if applicable, or of a person who can answer the Data Principal's questions about processing. Section 8(10) requires an effective mechanism to redress grievances. A legal consultation can help you set up both in a way that holds together with your notice.

Sub-sections (9) and (10) at a glance

Sub-sectionDutyKey words
8(9)Publish business contact information, in such manner as may be prescribedDPO "if applicable", or a person able to answer questions
8(10)Establish an effective mechanism to redress grievances"Effective"; Data Principals

Section 8(9): who is the contact person

The section offers two options, depending on the business.

  1. A Data Protection Officer, "if applicable". Section 2(l) defines the Data Protection Officer as an individual appointed by a Significant Data Fiduciary under section 10(2)(a). So a DPO in the Act's sense exists only for Significant Data Fiduciaries. Under section 10(2)(a) the DPO must represent the fiduciary, be based in India, be an individual responsible to the Board of Directors or similar governing body, and be the point of contact for the grievance redressal mechanism. See duties of a Significant Data Fiduciary.
  2. "A person who is able to answer on behalf of the Data Fiduciary" the questions raised by the Data Principal about processing of her personal data. This is the option for every other Data Fiduciary.

Some things the text leaves open:

  • It says "business contact information", so a work email, phone number or postal address, not a personal mobile of an employee.
  • It does not say the person must be an employee, a director or based in India, except in the case of a DPO under section 10. A senior employee, the company secretary or a designated officer are all possibilities in practice.
  • "Able to answer" is a capability test. A contact who cannot say what data is held or why fails the purpose of the section, even if a name is published.
  • The manner of publication is "as may be prescribed", so the Rules cover where and how. The DPDP Rules, 2025 (notified November 2025) prescribe the detail and different provisions commence on different dates; check the Rules.

This links to the notice. Section 5(1)(ii) already requires the notice to tell the Data Principal how to exercise her rights and make a complaint to the Board. The contact in section 8(9) is where she can put questions before she escalates. See section 5.

Section 8(10): an "effective" mechanism

Section 8(10) is one line: a Data Fiduciary "shall establish an effective mechanism to redress the grievances of Data Principals". Note the following:

  • It applies to every Data Fiduciary, unlike the DPO requirement.
  • "Effective" is the test. A mailbox that nobody reads, or a form with no follow-up, will not meet it. The Act gives no definition, so look at practical things: is there a way to lodge a grievance, is it acknowledged, is someone responsible, is it resolved, is the record kept.
  • It works with section 13. Section 13(1) gives the Data Principal the right to readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager. Section 13(2) requires a response within a prescribed period. Section 13(3) requires her to exhaust that route before approaching the Board. Section 8(10) is the fiduciary's side of the same arrangement. See section 13.

Because the Board expects a Data Principal to use the fiduciary's mechanism first, a weak mechanism has real consequences. If it does not work, complaints will reach the Board sooner, where the fiduciary will have to explain its processes in an inquiry under section 28.

Who this applies to

  • All Data Fiduciaries, within the limits of section 17.
  • Section 17(1) says Chapter II, except sub-sections (1) and (5) of section 8, does not apply in the listed situations, so sub-sections (9) and (10) fall away there.
  • Section 17(3) notifications for startups and others name section 5, sub-sections (3) and (7) of section 8, and sections 10 and 11. They do not name sub-sections (9) and (10). Whether they change, in future, is for the Central Government's notifications; check them.
  • A Consent Manager also has to provide grievance redressal under section 13, even though section 8 is about Data Fiduciaries.

Consequence of breach

There is no separate Schedule entry for section 8(9) or 8(10). Item 7 of the Schedule covers breach of any other provision of the Act or the rules: penalty may extend to fifty crore rupees. The Board can impose it only after an inquiry and a hearing, where the breach is significant (section 33(1)), considering section 33(2). See penalties.

Practical examples

Example 1: small online retailer. The retailer is not a Significant Data Fiduciary. It publishes a named privacy contact with a business email on its site and is able to state what data it holds. That meets the "person able to answer" option in section 8(9).

Example 2: dead mailbox. A company publishes a privacy email address that bounces. The mechanism exists on paper but is not effective under section 8(10).

Example 3: Significant Data Fiduciary. It must publish the business contact information of the DPO, who under section 10(2)(a)(iv) is also the point of contact for the grievance mechanism.

Common mistakes

  • Publishing a generic "contact us" page with no link to data queries.
  • Naming a person who cannot answer on the company's behalf.
  • Using a staff member's personal number.
  • Not keeping a log of grievances and outcomes.
  • Forgetting that the mechanism must exist before the Data Principal needs it.

Need help with your grievance and contact set-up?

Many businesses have a policy page but no working process behind it. Through our legal consultation service, we can help you choose a contact person, draft the published details and build a simple grievance routine.

Key takeaways

  • Publish business contact information of a DPO (if applicable) or a person able to answer queries.
  • Every Data Fiduciary must have an effective grievance redressal mechanism.
  • The manner of publication and response periods are left to the Rules.
  • The Data Principal must use the fiduciary's grievance route before going to the Board (section 13(3)).
  • Breach falls under Schedule item 7, up to fifty crore rupees.

Read next

Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.

Quick recapKey facts & short answers

Key Facts About Section 8

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Does every business need a Data Protection Officer?

No. Under section 2(l) and section 10(2)(a), a DPO is appointed by a Significant Data Fiduciary. Other fiduciaries publish the contact of a person able to answer questions.

What does "business contact information" mean?

The Act does not define it. It points to work contact details, such as an official email or phone number.

A breach is handled well or badly in the first few hours — have the plan before the incident.

— TaxClue Data Protection Desk

Section 8: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

No. Under section 2(l) and section 10(2)(a), a DPO is appointed by a Significant Data Fiduciary. Other fiduciaries publish the contact of a person able to answer questions.

The Act does not define it. It points to work contact details, such as an official email or phone number.

The Act says "a person who is able to answer on behalf of the Data Fiduciary". It does not limit the post held.

The Act does not define "effective". It should be reachable, acknowledged, owned by someone and capable of resolving complaints.

Yes, section 13(3) requires her to exhaust the opportunity of redress under that section before approaching the Board.

Item 7 of the Schedule: up to fifty crore rupees, subject to section 33.