All articles
Data Principal Rights 6 min read 23 September 2026 Primitra

The DPDP Act's Right to Nominate: The Compliance Item Most Indian SMEs Haven't Built Yet

Section 14 of the DPDP Act lets a user name a nominee to manage their data after death or incapacity. Rule 14(4) makes building that process a Data Fiduciary obligation, not a feature only social platforms need.

The DPDP Act's Right to Nominate: The Compliance Item Most Indian SMEs Haven't Built Yet

Most Indian founders working through their DPDP Act compliance checklist can recite the big items by heart: notice, consent, breach reporting, grievance redressal. Fewer have heard of Section 14, the DPDP Act's right to nominate, and almost none have built anything for it. That's a gap, because Rule 14(4) of the DPDP Rules, 2025 turns this into an operational requirement for Data Fiduciaries, not just a nice-to-have feature buried in a privacy policy.

The right itself is unusual. No other major privacy law grants it in quite the same form. GDPR leaves "what happens to your data when you die" to national inheritance law and platform terms of service. The DPDP Act puts it directly into the statute: a Data Principal can name another individual who steps into their shoes, with full rights to access, correct, or erase their data, if they die or become incapacitated.

What Section 14 and Rule 14(4) Actually Say

Section 14 of the DPDP Act, 2023 gives an individual Data Principal the right to nominate, "in such manner as may be prescribed," another individual to exercise their rights on their behalf in the event of death or incapacity. Incapacity is defined narrowly: inability to exercise those rights due to unsoundness of mind or infirmity of body, not simply old age or a temporary illness.

Rule 14(4) of the DPDP Rules, 2025 is the "manner as may be prescribed" part. It requires Data Fiduciaries and Consent Managers to publish a clear, accessible way for a Data Principal to name a nominee, and to have a defined process for handling that nominee's requests once the trigger event occurs. That means a business collecting personal data through an app, website, or SaaS product needs somewhere for users to register a nominee, a way to verify a death certificate or proof of incapacity, and a documented basis for accepting or rejecting a nominee's claim.

This sits alongside the same broader timeline covered in our checklist: most substantive obligations, including this one, move from "build it" to "expected to be operating" territory as the Data Protection Board's supervisory role expands after 13 November 2026, with full applicability across the board by May 2027. Nomination handling is not a headline deadline the way breach notification or consent architecture are, but it is squarely inside the same rulebook, and it is the kind of requirement that gets missed precisely because it sounds like a feature for social media platforms rather than something a B2B SaaS company or a regional e-commerce app needs to worry about.

Why This Isn't Just "A Feature for Facebook"

The instinct is to assume nomination only matters for consumer platforms holding photos, messages, or social accounts. That's wrong for two reasons.

First, the DPDP Act's definition of Data Fiduciary is broad. Any entity that determines the purpose and means of processing personal data qualifies, whether it's a fintech app, a healthtech platform, an HR software vendor, or a D2C brand with a loyalty program. If you hold personal data tied to an identifiable individual, Section 14 rights apply to that individual regardless of what industry you're in.

Second, the failure mode is not a fine so much as a stuck grievance. Picture a family member arriving with a death certificate, asking a company to close an account or hand over data tied to unresolved dues, insurance, or a small business the deceased ran through your platform. Without a documented nomination process, the request lands on a support inbox with no owner, no defined verification standard, and no clear answer for how long it should take. That's a grievance redressal problem waiting to happen, and it's also a bad experience for a grieving family at the worst possible time.

Building a Workable Nomination Process

A workable version of this doesn't need to be elaborate. Four pieces cover most of it.

The first is a nomination field somewhere accessible, typically account settings, where a Data Principal can name one nominee with basic identifying details. Keep it simple: name, relationship, and a contact method is enough for most SMEs; you don't need a notarized form.

The second is a verification standard for the trigger event. Decide in advance what counts as adequate proof of death (typically a death certificate) or incapacity (a medical certificate or, for court-declared cases, a court order), and write it down so support staff aren't improvising under pressure.

The third is a defined turnaround and escalation path. Rule 14(4)'s expectation of a clear, accessible process implies a Data Principal, or in this case a nominee, shouldn't be left waiting indefinitely. A documented internal SLA, even an informal one, protects you as much as it protects the requester.

The fourth is a rejection-and-appeal path. If a nomination claim looks fraudulent, involves a disputed family situation, or fails identity verification, you need a documented reason for declining and a route for the person to escalate, rather than a flat no with no explanation.

None of this needs new software. For most SMEs it's a short policy document, a support-team runbook, and one new field in an existing account settings page. It's the kind of gap a Data Protection Officer or outsourced DPO function would normally catch during a gap assessment, and it fits naturally alongside the other data principal rights processes you're already building for access and correction requests.

Where This Fits in Your Broader Compliance Work

Nomination handling isn't the obligation that will get a company its first notice from the Data Protection Board. Security safeguards, breach notification, and consent architecture carry higher immediate risk and larger potential penalties. But it's a low-cost, high-visibility fix: the kind of thing that takes an afternoon to document properly and makes a real difference the one time it actually matters to a real family dealing with a real loss.

If you're mapping out what else sits in this second tier of "easy to build, easy to overlook," it's worth running through a full gap assessment rather than patching requirements one at a time as they surface. Our team at Primitra works with Indian SMEs and startups on exactly this kind of practical, prioritized DPDP build-out.

This article is general guidance for informational purposes and does not constitute legal advice. For advice specific to your business, consult a qualified professional. Use our DPDP compliance checklist to see where nomination handling and other data principal rights processes stand in your build, or get in touch for a structured gap assessment.

Get help implementing this

Turn this reading into a compliance plan.

Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.

Book a free 30-minute consultation