Everything you need to understand and exercise your data rights
An online retailer collects your address without consent
Applicable Rights:
Action: Request they provide notice and delete unauthorized data
Game collects child data without parental consent
Applicable Rights:
Action: Contact Data Protection Board for unauthorized collection
Platform suffers breach exposing millions of accounts
Applicable Rights:
Action: If the company fails to notify affected users without delay and/or fails to report the breach to the Data Protection Board within 72 hours, you may submit a grievance to the Board.
Note: The 72-hour deadline applies to the Data Protection Board; user notification must happen without undue delay.
Financial institution has wrong information about you
Applicable Rights:
Action: Request correction and get updated documents
Key definitions and terms from the official legal text.
Note: Offline personal data is not covered by the Rules — only digital personal data is within scope.
Any data about an individual who is identifiable by or in relation to such data.
Free, specific, informed, unconditional and unambiguous indication of wishes by which the Data Principal agrees to the processing of her personal data.
The individual to whom the personal data relates. Includes parents/guardians for children and persons with disabilities.
Any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data.
Any person who processes personal data on behalf of a Data Fiduciary.
Unauthorized access, disclosure, or loss of personal data
Digital Personal Data Protection Rules, 2025 - India's data privacy law
Your right to request permanent deletion of your personal data
A Data Fiduciary designated by the Central Government based on volume/sensitivity of data or risk of harm.
A person registered with the Board who enables a Data Principal to give, manage, review and withdraw consent through an accessible platform.
The Board established by the Central Government under section 18 of the Act to adjudicate disputes and enforce the law.
A breach of digital personal data under the control of a Data Fiduciary that leads to, or is likely to lead to, harm to a Data Principal (Rule 2(1)(n)).
Consent obtained from the parent or lawful guardian of a child (under 18 years) or person with disability.