The DPDP Act (Digital Personal Data Protection) Act is made for individual’s digital personal data protection. This Act uses various terminology for businesses, individuals, and service providers. Data Principal is the term used to describe an individual whose data is collected and processed by the business. Here in this guide, you will learn what a Data Principal is, what the rights of a Data Principal are, as well as their duties and penalties.

What is a Data Principal?

In simple words, a Data Principal is the person whose data is collected and processed. e.g., a user or an employee.

DPDP Act 2023, Section 2 (j) definition

Data principal is a person whose personal data is collected or used. However, the term can also be used for another person if:

 

The individual is a baby or child.

 

For a child: The lawful guardian or parents are considered the data principal.

 

For a person with a disability: If the person is physically disabled, then the data principal will be the lawful guardian.

 

Act is not applicable if:

 

Self-Publish Data (Section 3 (c): If the person has published their data publicly by themselves. Ex: like blogging where a person shares their personal information for views.

 

Foreign Data Principal (Sec 17 (1)(d): If an Indian company handles the data of people outside India for a foreign company, some DPDP Act rules may not apply.

Rights of Data Principals Under the DPDP Act

DPDP Act gives various rights to the Data Principals:

 

Right to Access Information – Sec 11

Data Principal may ask for information about personal data used and processed from the Data Fiduciary. The name of the company, data processor that will process and share the data.

 

Exception

Sharing information with authorised bodies for crime- or cybercrime-related information does not require disclosure.

 

Right to Correction and Erasure (Section 12)

They have the right to ask the company to correct inaccurate or misleading data, complete incomplete data, update the information, or erase their data. It is mandatory for the company to complete the request unless it has a legitimate purpose or law requirement.

 

Right to Grievance Redressal (Section 13)

They have the right to have a complaint mechanism from the company and consent manager. So they submit their request and get a response within a defined timeline (not more than 90 days, Rule 14 (3). The data principal first needs to use the offered grievance procedure; after that, they can reach the DPB (Data Protection Board).

 

Right to Nominate

They can appoint someone to exercise their rights if they die or become unable to do so. The appointed person may also nominate one or more persons as per Rule 14(4) of the DPDP Rules. 

Automate your KYC Process & Reduce Fraud!

We have helped 3000+ companies in reducing Fraud by 95%

Book a demo to learn more

Right to Notice

Before or during obtaining consent, the Data Fiduciary must tell the Data Principal:

  • What data will be collected
  • Purpose of collection
  • How to complain to the board

Apart from this, Data Fiduciaries should provide notices in clear language with an itemised list of data and a link to withdraw consent, exercise rights, and complain (Rule 3).

Right to Choose Language

The Data Fiduciaries are required to create consent notices in English and any of the 22 languages mentioned in the Eighth Schedule.

Consent must be freely, clearly and without conditions. It may only be used for a specific purpose and may not be part of a request.

The Data Principal has the right to withdraw consent at any time. It is mandatory for the data fiduciary to obey the request and stop processing their data and any law applicable to keep it.

Data Principal has the right to give, manage, review, or withdraw consent through a Registered Consent Manager (Sec 6(7).

Right to be Informed of Data Breach

The data principal should be informed about the breach without delay through the account or registered contact with complete information.

 

Some of the key rights of Data Principals are given below. Apart from these, the DPDP Act gives various rights, including rights to responsible data, accurate data, deletion, warning, complaint to the Data Protection Board, etc.

What are Data Principal Responsibilities?

Data Principals must follow the following responsibilities:

  • Follow the law: They must follow all applicable laws while applying their rights.
  • Do not pretend to be someone else: They must not use someone else’s identity while providing personal information.
  • Do not hide important information: While applying for government documents, IDs, or proof of identity/address. They must provide all important information with honesty.
  • Do not make false complaints: They should not make false or unnecessary complaints against a company or to the Data Protection Board.
  • Give Correct Information: If they ask the data fiduciary to correct or delete their personal information. They must provide a legitimate reason along with verifiable information.

What are penalties for the Data Principal under the DPDP Act?

A Data Principal may face the consequences of violating the duties (Section 15).

Monetary penalty of up to ₹10,000

Under Schedule, Serial No. 5, a Data Principal who violates any duty under Section 15 may face a monetary penalty of up to ₹10,000. 

Warning or Costs for a false complaint or frivolous complaint. 

Under Section 28(12), if the Data Protection Board finds a complaint is false or frivolous, it may issue a warning or impose a penalty or costs on the complainant.

Penalties for Breach of a voluntary undertaking

If a Data Principal gives a voluntary undertaking to the Board and later breaches it, Section 32 (5) allows the Board to proceed against the breach. Under the schedule, Serial No. 6, the penalty may extend to the amount applicable to the underlying breach for which proceedings were initiated.

Conclusion

Data Principal is the term used for the people whose data is collected and processed under the DPDP Act. This Act gives various rights to Data Principals such as the right to consent, erasure, correction, nomination, and more. However, they should not violate these rights, as it can bring legal penalties.

FAQs

Ques: What is a Data Principal?

Ans: In simple terms, a Data Principal is the person whose data is used and processed by the companies.

 

Ques: What is the difference between a Data Principal and Data Fiduciary?
Ans: Data Principal is the person whose data is processed, and a Data Fiduciary is the company that processes the data.

 

Ques: What is the duty of the data principal regarding grievances?

Ans: A data principal should follow the law, not impersonate or provide incorrect or fake information.

 

Ques: Can a Data Principal withdraw consent at any time?

Ans: Yes, the Data Principal has the right to withdraw consent at any time.

 

Ques: Can a Data Principal be penalised under the DPDP Act?

Ans: Yes, violating the law and rights can result in a penalty of rupees 10,000.

Automate your KYC Process & Reduce Fraud!

We have helped 3000+ companies in reducing Fraud by 95%

Book a demo to learn more

Share On
Author Image

Vijay Kandari

administrator

Vijay Kandari is part of the marketing team, driving brand growth and digital campaigns. He is passionate about automation, digital transformation, and the evolving trends shaping the future of customer onboarding and verification.