Skip to main content

Data Principal Rights

The Data Principal Rights Module (DPRM) empowers individuals to exercise their rights under the Digital Personal Data Protection Act (DPDPA), 2023 while enabling the Consent Management Platform (CMP) privacy team to review, act, and track these requests for compliance and accountability.

1. Objectives

  • Provide a self-service interface for Data Principals to exercise their rights.
  • Support Section 11 (Right to Information, Correction, Erasure) and Section 12 (Right to Grievance Redressal) of DPDPA.
  • Allow CMP privacy teams to manage, validate, and fulfill requests within statutory timelines.
  • Maintain audit-ready logs of requests and actions taken.

2. Rights Under DPDPA Covered

SectionRightDescription
Section 11(1)Right to InformationKnow what data is processed, purpose, recipients, and how to exercise rights.
Section 11(2)Right to Correction and ErasureRequest correction of inaccurate data and erasure of data no longer necessary or consent withdrawn.
Section 12Right to Grievance RedressalRaise complaints about data processing or non-compliance with the Act.

3. Core Features

FeatureDescription
Rights DashboardData Principals can view, submit, and track their rights requests.
Request CategoriesAccess, Correction, Erasure, Nomination, Grievance.
Secure SubmissionRequests submitted through authenticated sessions or tokenized links.
Internal Review ConsoleCMP privacy team dashboard to validate and fulfill requests.
SLA TrackingMonitor statutory deadlines for responding to Data Principals.
NotificationsInform Data Principals at each stage of their request lifecycle.
Audit LogsImmutable record of each request and corresponding action.
Integration APIsAllow DFs/DPs to receive and act on requests directly from CMP.

4. Workflow

4.1 Data Principal Side

  1. Submit Request – Access via CMP dashboard or Data Fiduciary portal.
  2. Authenticate – Verify identity using OTP, password, or digital signature.
  3. Select Right – Choose from Access, Correction, Erasure, Nomination, or Grievance.
  4. Provide Details – Add necessary context (data element, purpose, supporting docs).
  5. Track Progress – Receive updates on status and final outcome.

4.2 CMP Privacy Team Side

  1. Review Request – Validate identity and scope.
  2. Coordinate – Forward request to relevant Data Fiduciary/Data Processor systems.
  3. Fulfill Request – Provide data, correct errors, erase data, or acknowledge grievance.
  4. Notify Outcome – Communicate resolution to the Data Principal.
  5. Report – Log outcome and maintain records for DPBI inspection.