DPDPA Section 13: Grievance Redressal Rights and the Two-Tier Complaint Path

DPDPA Section 13: Grievance Redressal Rights and the Two-Tier Complaint Path

Ensure your business meets DPDP Act compliance requirements. Discover key obligations for data fiduciaries, penalty risks, and steps to protect user privacy.

Sahil Pugalia

Written by

Sahil Pugalia

Date

Read time

5 min

Most privacy policies end with a generic “contact us” email address that forwards to an unmonitored inbox. Under DPDPA Section 13, that inbox is a ticking clock.

Section 13 establishes a clear right for every Data Principal to get their grievances addressed by a Data Fiduciary or Consent Manager. It replaces the illusion of customer support with a strict, two-tier escalation system:

  • Tier 1: You must first approach the Data Fiduciary or Consent Manager through their internal grievance mechanism.
  • Tier 2: If the response is unsatisfactory or simply never arrives, you escalate to the Data Protection Board.

Rules under the Act prescribe the exact timelines and procedures. The days of indefinitely “reviewing” a user’s complaint are over.

Scope and Applicability

Section 13 applies to any grievance linked to the Data Principal’s rights or the Data Fiduciary’s obligations under the Act and Rules.

This is not limited to massive data breaches. It includes:

  • Consent violations
  • Purpose limitation violations
  • Security lapses or breaches
  • Missing or inadequate privacy notices
  • Ignored access, correction, or erasure requests
  • Improper handling of children’s data
  • Non-compliance by Significant Data Fiduciaries

If the grievance concerns the performance of a Consent Manager engaged by the Data Principal, the exact same structure applies.

Tier 1: Internal Grievance Handling

A grievance mechanism is not optional. Every Data Fiduciary must provide one that is readily available. Significant Data Fiduciaries must have a Data Protection Officer who handles grievances. Others must designate a DPDP grievance officer and publish their contact details.

Illustration of a user submitting a grievance to a DPDP grievance officer under DPDPA Section 13.

Practical filing steps that align with Rule 13 are straightforward. A user finds the published contact (which should be easy to locate in a website footer), prepares their grievance with facts and evidence, and submits it.

Then, the clock starts. Timelines to expect under the Rules:

  • Acknowledgment within 7 days
  • Full response within 30 days
  • In complex cases, an extension up to 60 days,but only with a documented justification

If you provide a complete and correct resolution, the matter ends. If your response is partial, dismissive, or missing after the timeline expires, you have just handed the user a free pass to escalate.

Tier 2: Complaint to the Data Protection Board

You cannot stop a user from filing a Data Protection Board complaint if they are not satisfied with your response, or if you simply failed to respond within the prescribed period.

When filing under Rule 14, the user provides a timeline of events, a copy of their initial grievance, your response (if any), and the specific remedy they seek.

From there, the Board takes over:

  • The Board acknowledges the complaint and may ask for more information.
  • The Board can seek a response from the Data Fiduciary, conduct an inquiry, and call a hearing.
  • The Board can dismiss the complaint or issue directions.
  • Orders are binding.

Appeals lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), and thereafter to the Supreme Court.

Complaint Fees

To discourage frivolous filings while preserving access, the Act allows the Central Government to prescribe a nominal fee structure for Board complaints:

  • Standard individual fee: ₹500
  • Reduced fee for specified vulnerable categories: ₹100
  • Class action filings: ₹5,000
  • Fee waivers are available for hardship on application.

If the Board finds in the user’s favor, fees may be reimbursed and costs may be ordered directly against the Data Fiduciary.

What This Means for Data Fiduciaries

Treat Section 13 as an operational requirement, not a formality. You need a system that works under scrutiny.

Minimum expectations include:

  • Publishing grievance contact information that is actually easy to find.
  • Designating a responsible officer (or a Data Protection Officer for Significant Data Fiduciaries).
  • Logging every grievance with timestamps and status tracking.
  • Acknowledging receipt within 7 days and resolving within 30 days (or justifying a 60-day extension).
  • Providing a clear, respectful, and reasoned outcome.
  • Informing the Data Principal about their right to escalate to the Board.
  • Keeping records of decisions, evidence considered, corrective actions, and preventive measures.

Do not obstruct filing, bury the contact, or retaliate against complainants. If a Consent Manager is part of your flow, align roles and responsibilities to ensure responses are timely and consistent. A policy that does not reflect reality is just a well-written lie.

Common Failure Modes and Consequences

The Board does not just send angry letters. They can investigate, direct compliance, order correction or erasure, restore access, award compensation, and impose severe penalties.

Frequent non-compliance patterns include missing contact details, ignoring grievances, sending dismissive responses, refusing to investigate facts, or failing to log and track complaints.

The financial exposure is massive. Penalties can reach up to ₹250 crores depending on the nature of the breach. Specific penalty exposures include:

  • Up to ₹10 crores for failure to publish contacts.
  • Up to ₹200 crores for denial of rights.
  • Up to ₹250 crores for non-cooperation with the Board.

These figures underscore the sheer operational risk of poor grievance handling.

Illustration of a two-tier complaint path for grievance redressal under DPDPA Section 13.

Interpretation Boundaries You Should Note

  • Exhaustion requirement: Users must give the Data Fiduciary or Consent Manager a chance to resolve the complaint before going to the Board. However, if there is no functioning grievance mechanism, the Board may accept a direct complaint.
  • Timelines arise from the Rules: The statute mandates a response within a period “as may be prescribed,” and the Rules fill in the exact 7-day and 30-day deadlines.
  • “Not satisfied” is subjective: A partial fix may be acceptable to some Data Principals and not to others. The Board decides disputes on their merits.
  • The default path: The two-tier structure is the default path for all grievances under the Act, including issues related to Consent Managers.

How India’s Approach Compares

India requires an internal first step before a regulator takes over. Many GDPR jurisdictions encourage internal resolution, but it is not always mandatory. Under the CCPA, there is no mandated internal prerequisite before filings with state authorities.

India also permits a nominal complaint fee, whereas GDPR and CCPA complaint mechanisms are generally free to file. Remedies and penalties in India are enforced through the Board, with appeals to TDSAT, then the Supreme Court.

Putting Section 13 Into Practice

Section 13 turns abstract data rights into enforceable outcomes. Data Principals get a clear path to be heard. Data Fiduciaries get a chance to fix issues before a regulator steps in.

That balance only works if internal mechanisms are real, discoverable, and responsive. The hard part is execution. You need intake channels that work, a triage process that does not miss deadlines, accurate root-cause analysis, and evidence trails that stand up when the Board asks for records.

At Regodit, we did not start by asking how to build a better dashboard. We started by asking how to make compliance operational. We give teams a structured way to operationalize these exact requirements, from intake to closure, with traceability that helps you pass scrutiny.

If you want a predictable way to meet Section 13 expectations without scrambling, explore how Regodit can help you design, track, and evidence your grievance workflows. Schedule a discussion to see what this looks like in your environment and where it can reduce your risk.

Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.

Keep reading

All blogs →