Asked by a reader in Bengaluru

A company keeps using my personal data. What rights do I have under the new data law?

Answered by Advocate Sharan Jain··Cyber Crime & Online Fraud

Legal Shorts · 76 words

The new data law is being brought into force in stages. As of September 2026, its core access, correction, erasure and grievance rights have not yet commenced. The notification schedules those provisions eighteen months after publication. You can still write to the company identifying the data and use you object to, and ask for its response under the rules currently applicable to it. Keep that correspondence. Do not assume every DPDP right is already enforceable today.

Short sources checked:

WhatsApp

India now has a dedicated data protection statute, the Digital Personal Data Protection Act, 2023. It replaced the earlier patchwork under Section 43A of the IT Act and the 2011 rules.

The structure

  • You are the Data Principal. The organisation processing your data is the Data Fiduciary.
  • Processing generally requires your consent, which must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and preceded by a plain-language notice.
  • Certain legitimate uses permit processing without consent, including where you voluntarily provide data for a specified purpose, and for defined State functions, employment purposes, medical emergencies and disasters.

Your rights

  • Right to access a summary of your personal data being processed and the identities of those it has been shared with
  • Right to correction, completion, updating and erasure
  • Right to grievance redressal, which you must ordinarily exhaust with the Data Fiduciary before approaching the Board
  • Right to nominate another person to exercise your rights in the event of death or incapacity
  • Right to withdraw consent at any time, with the same ease with which it was given
Most of this is not enforceable yet
This is the part that matters and it is widely misreported. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, and they switch the regime on in phases. Taking effect immediately: the definitions, the establishment of the Data Protection Board, and the Government's rule-making powers. After one year, from 13 November 2026: registration and operation of consent managers. After eighteen months, from 13 May 2027: the core provisions on consent, the obligations of Data Fiduciaries, and the remaining powers of the Board. So the substantive duties, and the machinery to enforce your rights against a company, largely arrive in 2027.

What to do in practice, today

  1. Write to the organisation's grievance contact or Data Protection Officer, exercising the specific right and setting a deadline. Many companies are already building compliance ahead of the deadline and will act on a well-framed request.
  2. For unsolicited commercial calls and messages, use the TRAI DND mechanism, which works now.
  3. Where the misuse involves a breach of your account, impersonation or financial loss, the Information Technology Act offences and the cybercrime portal remain the faster and currently more effective remedies.
  4. Escalation to the Data Protection Board becomes the route once the corresponding provisions commence.

Note that the Act carries significant financial penalties on Data Fiduciaries for breaches, but it does not create a direct right to compensation for the individual, which is a genuine gap compared with some other regimes.

A request that says "send me all my data" is easy to ignore. One that works reads: identify yourself with the account or customer number, state the statutory right relied on, specify the categories sought, name the period, and set a date for compliance. Send it to the published Data Protection Officer or Grievance Officer address, not to a general support inbox, and keep proof of delivery. The reply, or the silence, is what you take to the regulator.

How to write the request so that it gets answered

A vague email asking a company to "delete my data" is ignored. A request that identifies itself does better, and companies already building towards the 2027 deadline tend to answer it. Address it to the Data Protection Officer or the person designated to answer questions about processing, whose details most privacy policies now carry. Then set out, numbered: who you are and which account or record you mean; the specific right you are exercising, in the statutory language; the processing you object to; and a date for a substantive reply in writing. Keep the delivery proof.

On access, ask for the two things the statute gives: a summary of the personal data being processed and the processing undertaken, and the identities of those it has been shared with. On erasure, expect a lawful pushback on records the company must retain under tax, banking, telecom or company law; ask which obligation is relied on and for how long rather than insisting on deletion of everything. On withdrawal of consent, note that it must be as easy as the giving was, and ask for confirmation of what has stopped and what continues on another basis.

What already works, today

  • Unsolicited calls and messages. The TRAI regime on commercial communications is live, works through your operator's preference registration, and gives a complaint route against the sender's own provider.
  • Account breach, impersonation or financial loss. The Information Technology Act offences and the cybercrime portal are the working remedy, and there is a separate offence where someone who obtained material under a power conferred by that Act discloses it without consent.
  • Deficiency in service. Where mishandling of your data has caused actual loss, a consumer complaint can carry compensation, which the data protection statute itself does not provide.
  • Constitutional remedy. Informational privacy is protected as part of the right to life and personal liberty, and a writ petition lies against the State and its instrumentalities, independent of the phased commencement.

One point of sequencing catches people out: the new statute is also what removes the older compensation provision in Section 43A of the Information Technology Act and the 2011 rules under it, and that removal is itself part of the staged commencement. Check which provisions are in force on the date you send the notice, and plead in the alternative where it is uncertain. Our guide to DPDP Act compliance for businesses sets out the same timeline from the company's side, and where the complaint is about a recorded conversation rather than stored data, our note on recording calls without consent in India deals with a different question.

If the data was leaked rather than misused

A breach is a different problem, and the first steps are practical. Change the credentials on the affected service and on everything sharing that password or recovery number, and watch for the follow-on fraud, because leaked records are resold and used for calls that quote real details back at you to establish credibility. Ask the company in writing what was taken, when it knew and whom it has told, and keep the reply. If money follows, treat it as an online fraud and use the 1930 route the same day, as our note on how to report a cyber crime in India sets out.

Sources

The law this answer relies on, so you can read it yourself.

  1. 1.DPDP Act commencement notification, GSR 843(E), 13 November 2025 Read the source
  2. 2.Section 43A, Information Technology Act, 2000. Bare text of the provision. Read the source
  3. 3.Digital Personal Data Protection Act, 2023. Official consolidated text on India Code, the Government of India repository of Central Acts. Read the source
  4. 4.Section 72, Information Technology Act, 2000. Bare text of the provision. Read the source

The short answer's sources were checked on 12 September 2026. Statutes and judgments can change, so check the current position before you act on anything here.

Nothing there yet? Send the question in and it gets answered here.

Related legal service

Dealing with this yourself rather than reading about it? Our Bangalore advocates work in this area.

Go deeper on this

This answer is the short version. These guides cover the same ground in full, with the procedure, the timelines and the leading cases.

SJ

Answered by

Advocate Sharan Jain

Advocate based in Bangalore, practising before the Karnataka High Court and District, Sessions, Consumer and Family courts. Answers public legal questions to make Indian law more accessible.

This answer is general information on Indian law as at July 26, 2026, published for public education. It is not legal advice, it does not take account of your facts, and reading it does not create an advocate-client relationship. Law changes and every case turns on its own circumstances. Please consult a qualified advocate about your own matter.

People also asked

Cyber & Online Fraud

Someone has created a fake social media profile in my name. What do I do?

Capture the fake profile's URL, username and posts, and report it as impersonation. Rule 3(2)(b) of the IT Rules now requires reasonable and practicable removal measures within two hours of a qualifying complaint about electronic impersonation of an individual. State clearly that the account is pretending to be you. If it is asking people for money or threatening them, also report that conduct to the police. Tell your contacts which account is genuine without circulating unnecessary personal documents.

Cyber & Online Fraud

Someone is harassing and threatening me online. What can I actually do?

Save the full messages, account details and dates, then report the account to the platform and the conduct to the cybercrime portal or police. Threats intended to cause alarm can amount to criminal intimidation under Section 351 BNS. Not every rude message meets that test. Explain the pattern and quote the threats accurately. If you face immediate danger, seek urgent police help. Blocking the account can protect you, but keep an evidence copy first if safe.

Consumer Protection

Money was taken from my account fraudulently and the bank says it is my fault. What now?

Report the transaction to the bank immediately and keep the complaint number. RBI's framework distinguishes bank fault, customer negligence and third-party breaches. Zero liability for a third-party breach depends on reporting within the specified period, while sharing credentials can change who bears the loss. Ask for the bank's written investigation and calculation. If unresolved, check the current RBI Ombudsman process and deadlines. Do not assume that reporting cybercrime by itself also counts as notifying your bank.

Cyber & Online Fraud

I lost money to an online scam. What do I do in the first hour?

Call 1930 and notify your bank immediately, then complete the complaint on cybercrime.gov.in. Give the transaction number, amount, time and receiving account or UPI ID. Prompt reporting can help the authorities try to stop further movement of the money, but it does not guarantee recovery. Save the messages and payment records, and secure any account the scammer accessed. Ask the bank for a complaint number and written response about your disputed transaction.

Cyber & Online Fraud

People claiming to be police kept me on a video call and I paid them. What do I do now?

End the call and contact your bank immediately. A demand to stay on video and transfer money for a supposed police verification is a fraud warning, not a reason to keep paying. Call 1930, report on cybercrime.gov.in, and save the transaction IDs, messages, phone numbers and notices they sent. Tell a trusted person what happened. Recovery is not guaranteed, but prompt reporting gives the authorities a chance to act before more money is moved.

Cyber & Online Fraud

I was cheated by a match on a matrimonial site. Is that a police matter or just my bad luck?

It can be a police matter if deception was used to obtain money or property. Section 318 BNS focuses on the dishonest inducement, so a relationship ending or a promise remaining unfulfilled does not alone establish cheating. Preserve the profile, identity claims, messages requesting money and payment trail. Describe what was false and how it led you to pay. If money has just moved, notify your bank and 1930 immediately while also making the criminal complaint.

S Jain & Attorneys · Ask Me

Still not the question you had in mind?

Search the column, or send your question in. Questions of general interest are answered here, anonymously, so the next person does not have to ask.