All articles
Data Principal Rights 6 min read 23 July 2026 Primitra

Grievance Redressal Under the DPDP Act: The 90-Day Obligation Indian SMEs Keep Postponing

Every Indian data fiduciary must publish a grievance officer and resolve complaints within 90 days. Here's what the DPDP Act's grievance-redressal rules mean for SMEs and startups.

Grievance Redressal Under the DPDP Act: The 90-Day Obligation Indian SMEs Keep Postponing

Most Indian businesses reading up on the DPDP Act fixate on consent banners and breach reporting. Grievance redressal under the DPDP Act rarely makes the top of the to-do list, and that is a mistake. A grievance officer, a published point of contact, and a working process to answer complaints within a fixed window are not optional extras. They sit at the core of what the Digital Personal Data Protection Act, 2023 asks every data fiduciary to have in place before the substantive rules take full effect, expected around 13 May 2027.

Here is the part that catches people off guard. You do not get to decide whether a complaint counts. If a customer, an employee, or a job applicant writes in asking why you still hold their data, or how to correct it, or to have it erased, the clock starts. And the Act sets an outer limit on how long that clock can run.

What the Act actually requires

Two provisions do the work here. Section 8(10) obliges every data fiduciary to publish the contact details of a person able to answer questions about the processing of personal data. In practice that is your grievance officer, or a data protection officer where one is appointed. Section 13 gives the data principal, the person whose data you hold, a matching right: readily available means of grievance redressal for any act or omission tied to your obligations or their rights.

The Digital Personal Data Protection Rules, 2025, notified on 13 November 2025, put a timeline on it. A data fiduciary must respond to grievances within a period that does not exceed ninety days. Ninety days is the ceiling, not the target. A customer who has waited three months for a straight answer about their own data is already halfway to a complaint before the Data Protection Board of India.

The grievance officer does not have to be a lawyer or a new hire. The Act lets you assign the role to a competent person already inside the business, often someone in legal, compliance, operations, or IT. What matters is that the name and contact details are published, usually in your privacy notice and on your website, and that the person actually has the authority and the process to resolve things.

Why this is more than a formality

Look at how this is playing out in Europe, because Indian regulators tend to borrow enforcement logic even where the statutes differ. The European Data Protection Board named transparency and information obligations its enforcement priority for 2026, which means regulators across the EU are actively checking how companies inform people and handle their requests. In a Romanian case decided on 1 July 2026, a company was penalised after investigators found it routinely took up to 37 months to close data erasure requests without giving people a final answer. Under GDPR, failures of this kind sit in the top penalty band, up to 20 million euros or 4 percent of global turnover.

India's penalty structure is different but not gentle. The DPDP Act attaches a residuary penalty of up to ₹50 crore for breach of provisions that do not have their own specific figure, and grievance redressal falls into that category. Set that against the headline numbers you may already know: up to ₹250 crore for failing to keep personal data secure, and up to ₹200 crore for failing to notify a breach. A neglected complaints inbox will not bankrupt a mid-sized company, but ₹50 crore is a real number, and it is easy to avoid.

What a working grievance process looks like

The good news is that this is one of the cheaper obligations to get right. You are building a small operational loop, not a legal department.

Start with a single, monitored channel. A dedicated email address or a form on your site, routed to a named owner, beats a general info@ inbox that no one checks. Publish the grievance officer's name and contact in your privacy notice so a person does not have to hunt for it.

Acknowledge fast. The Rules cap resolution at ninety days, but a same-day or next-day acknowledgement with a reference number and an expected timeline is what keeps a mild query from turning into a formal complaint. Log every request with the date received, so you can prove you stayed inside the window.

Connect grievances to the underlying rights. Many complaints are really access, correction, or erasure requests in disguise. If your team cannot actually locate and delete a person's data across your systems and your vendors, the ninety-day promise is hollow. This is where grievance handling overlaps with the data-principal rights work covered in our DPDP Act compliance guide, and why a mapped inventory of where personal data lives pays off.

Decide who owns it before you are tested. For most SMEs an internal grievance officer is enough. If you handle large volumes of sensitive data or get classified as a Significant Data Fiduciary, a formal data protection officer becomes mandatory, and the bar for seniority and independence rises. If you are unsure which side of that line you fall on, our DPO services walk through the assessment.

Where this fits in the wider timeline

Grievance redressal does not stand alone. It is the customer-facing edge of the same rights machinery that consent, notice, and data retention all feed into. Consent Manager registration is expected to open around 13 November 2026, and the core obligations, including notice, consent, breach notification, and Significant Data Fiduciary duties, are expected to take full effect around 13 May 2027. Businesses that already run for GDPR will recognise the pattern, and our note on GDPR compliance draws out where the two regimes line up and where they part ways.

Treat the grievance mechanism as a test of your whole programme. If a stranger can email you today and get a clear, timely, documented answer about their own data, most of your DPDP foundations are probably in decent shape. If that email would sit unread, you have found your first gap, and it is a cheap one to close.

This article is general guidance for Indian businesses and is not legal advice; specific situations should be checked against the DPDP Act, 2023, the DPDP Rules, 2025, and qualified counsel. For a structured starting point, see our DPDP readiness checklist or get in touch to talk through your grievance process.

Get help implementing this

Turn this reading into a compliance plan.

Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.

Book a free 30-minute consultation