How to Reclaim Your Privacy: A Guide to the DPDP Act
• DPDPA 2023: India’s primary framework for data privacy, fully operationalized with the 2025 Rules.
• Data Fiduciary: Any entity (company or government) that determines the purpose and means of processing your personal data.
• Data Protection Board (DPBI): The digital-first adjudicatory body established in late 2025 to handle escalations and penalize violations.
The era of "implied consent" in India is officially dead. With the notification of the Digital Personal Data Protection (DPDP) Rules in late 2025, your personal data is no longer a free-roaming commodity for corporations. However, rights are only as good as their enforcement. This guide breaks down the tiered mechanism you must follow to reclaim your digital sovereignty under the new legal regime.
Step 1: The Grievance Officer (GRO) - Your First Contact
Under the DPDP Act, every company (Data Fiduciary) is legally required to appoint a Grievance Redressal Officer. You cannot skip this step; the law mandates that you attempt to resolve the issue with the entity first.
• Find the GRO: Check the company's Privacy Policy page. Look for "Grievance Officer" or "Data Protection Officer." They must provide an email and a physical address.
• Draft your notice: Explicitly state that you are exercising your rights under the DPDP Act 2023. Attach evidence—screenshots of data leaks, unauthorized marketing emails, or refusals to delete your account.
• The 7-Day Rule: Per the 2025 Rules, fiduciaries are expected to acknowledge and ideally resolve your grievance within 7 days. If they don't respond within 30 days, you have the legal right to escalate.
Step 2: Escalation to the Data Protection Board (DPBI)
If the company ignores you or provides an unsatisfactory response, the Data Protection Board of India is your next stop. Established as a "digital-by-design" office in November 2025, the DPBI handles complaints through a centralized online portal.
• File Online: Access the DPBI portal (accessible via MeitY or dpbi.gov.in). You will need your Aadhaar-linked mobile for OTP verification.
• Submit Documentation: Upload a copy of your initial grievance sent to the company and their response (or lack thereof). This "paper trail" is mandatory for the Board to take up your case.
• Nature of Relief: The DPBI is a quasi-judicial body. It can order the company to correct, complete, or erase your data and can impose penalties of up to ₹250 crore for systemic failures.
Step 3: The Right to be Forgotten (Deletion)
One of the most powerful tools in your kit is the Right to Erasure. You can withdraw your consent at any time. Once consent is withdrawn, the fiduciary must stop processing your data and delete it unless its retention is required by another law (like tax or banking regulations).
• Technical Context: The law now differentiates between "specified purpose" and "general processing." If you gave your data to a food delivery app to deliver food, they cannot legally retain your location history for "marketing analytics" once you delete your account.
The BharatLens Perspective: Digital Humanism
The DPDP Act is not just a regulatory hurdle for businesses; it is a fundamental shift toward digital humanism. By mandating "Consent Managers" (expected to be live by November 2026), the system will eventually allow you to manage all your digital consents through a single dashboard. Until then, stay vigilant. Your data is an extension of your personhood; treat any unauthorized access as a trespass.
Comments ()