India now has a dedicated data protection statute, the Digital Personal Data Protection Act, 2023. It replaced the earlier patchwork under Section 43A of the IT Act and the 2011 rules.
The structure
- You are the Data Principal. The organisation processing your data is the Data Fiduciary.
- Processing generally requires your consent, which must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and preceded by a plain-language notice.
- Certain legitimate uses permit processing without consent, including where you voluntarily provide data for a specified purpose, and for defined State functions, employment purposes, medical emergencies and disasters.
Your rights
- Right to access a summary of your personal data being processed and the identities of those it has been shared with
- Right to correction, completion, updating and erasure
- Right to grievance redressal, which you must ordinarily exhaust with the Data Fiduciary before approaching the Board
- Right to nominate another person to exercise your rights in the event of death or incapacity
- Right to withdraw consent at any time, with the same ease with which it was given
This is the part that matters and it is widely misreported. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, and they switch the regime on in phases. Taking effect immediately: the definitions, the establishment of the Data Protection Board, and the Government's rule-making powers. After one year, from 13 November 2026: registration and operation of consent managers. After eighteen months, from 13 May 2027: the core provisions on consent, the obligations of Data Fiduciaries, and the remaining powers of the Board. So the substantive duties, and the machinery to enforce your rights against a company, largely arrive in 2027.
What to do in practice, today
- Write to the organisation's grievance contact or Data Protection Officer, exercising the specific right and setting a deadline. Many companies are already building compliance ahead of the deadline and will act on a well-framed request.
- For unsolicited commercial calls and messages, use the TRAI DND mechanism, which works now.
- Where the misuse involves a breach of your account, impersonation or financial loss, the Information Technology Act offences and the cybercrime portal remain the faster and currently more effective remedies.
- Escalation to the Data Protection Board becomes the route once the corresponding provisions commence.
Note that the Act carries significant financial penalties on Data Fiduciaries for breaches, but it does not create a direct right to compensation for the individual, which is a genuine gap compared with some other regimes.
How to write the request so that it gets answered
A vague email asking a company to "delete my data" is ignored. A request that identifies itself does better, and companies already building towards the 2027 deadline tend to answer it. Address it to the Data Protection Officer or the person designated to answer questions about processing, whose details most privacy policies now carry. Then set out, numbered: who you are and which account or record you mean; the specific right you are exercising, in the statutory language; the processing you object to; and a date for a substantive reply in writing. Keep the delivery proof.
On access, ask for the two things the statute gives: a summary of the personal data being processed and the processing undertaken, and the identities of those it has been shared with. On erasure, expect a lawful pushback on records the company must retain under tax, banking, telecom or company law; ask which obligation is relied on and for how long rather than insisting on deletion of everything. On withdrawal of consent, note that it must be as easy as the giving was, and ask for confirmation of what has stopped and what continues on another basis.
What already works, today
- Unsolicited calls and messages. The TRAI regime on commercial communications is live, works through your operator's preference registration, and gives a complaint route against the sender's own provider.
- Account breach, impersonation or financial loss. The Information Technology Act offences and the cybercrime portal are the working remedy, and there is a separate offence where someone who obtained material under a power conferred by that Act discloses it without consent.
- Deficiency in service. Where mishandling of your data has caused actual loss, a consumer complaint can carry compensation, which the data protection statute itself does not provide.
- Constitutional remedy. Informational privacy is protected as part of the right to life and personal liberty, and a writ petition lies against the State and its instrumentalities, independent of the phased commencement.
One point of sequencing catches people out: the new statute is also what removes the older compensation provision in Section 43A of the Information Technology Act and the 2011 rules under it, and that removal is itself part of the staged commencement. Check which provisions are in force on the date you send the notice, and plead in the alternative where it is uncertain. Our guide to DPDP Act compliance for businesses sets out the same timeline from the company's side, and where the complaint is about a recorded conversation rather than stored data, our note on recording calls without consent in India deals with a different question.
If the data was leaked rather than misused
A breach is a different problem, and the first steps are practical. Change the credentials on the affected service and on everything sharing that password or recovery number, and watch for the follow-on fraud, because leaked records are resold and used for calls that quote real details back at you to establish credibility. Ask the company in writing what was taken, when it knew and whom it has told, and keep the reply. If money follows, treat it as an online fraud and use the 1930 route the same day, as our note on how to report a cyber crime in India sets out.