How long do we have to respond to a data principal request?

The DPDP Act and the DPDP Rules require Data Fiduciaries to respond to Data Principal requests within the prescribed period, and to publish a readily available means of making a request and of raising a grievance. Because the period runs from receipt, the practical requirement is an intake route that timestamps every request and a workflow that reaches every system holding the person's data.

Priya Gupta

Organisations usually fail this obligation not by refusing requests but by losing them — a request arrives by email to an individual who is on leave, and the clock runs. A single monitored intake with SLA tracking removes most of that risk.

Keep the log. Being able to show that every request was answered, and when, is what turns a claim of compliance into evidence of it.

General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.

Priya GuptaPriya writes on compliance operations at ProtectComply, including data principal rights, grievance handling and sector-specific programmes.

Where do you stand under DPDP?

Take the free readiness check and find out in 10 minutes.

Start free readiness check →