The DPDP Act and the DPDP Rules require Data Fiduciaries to respond to Data Principal requests within the prescribed period, and to publish a readily available means of making a request and of raising a grievance. Because the period runs from receipt, the practical requirement is an intake route that timestamps every request and a workflow that reaches every system holding the person's data.
Organisations usually fail this obligation not by refusing requests but by losing them — a request arrives by email to an individual who is on leave, and the clock runs. A single monitored intake with SLA tracking removes most of that risk.
Keep the log. Being able to show that every request was answered, and when, is what turns a claim of compliance into evidence of it.
General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.
Priya Gupta — Priya writes on compliance operations at ProtectComply, including data principal rights, grievance handling and sector-specific programmes.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →