Chapter III · Rights and Duties of Data Principal
Section 11 — Right to access information about personal data
What this section requires
A Data Principal can require a Data Fiduciary she has given consent to (including consent under the Section 7(a) voluntary-data ground) to provide: a summary of what personal data is being processed and the processing activities carried out on it; the identities of every other Data Fiduciary and Data Processor the data has been shared with, and a description of what was shared; and any other prescribed information.
This doesn't apply to sharing done with another Data Fiduciary who is legally authorised to obtain the data — for example, sharing made pursuant to a written request for the prevention, detection, investigation or prosecution of an offence or cyber incident.
Who it applies to
Any Data Fiduciary a Data Principal has previously given consent to for processing — the right runs against that specific relationship, not against fiduciaries generally.
Checklist
- Build a process to produce, on request: a summary of the personal data held and how it's being processed.
- Track and be able to disclose every other Data Fiduciary and Data Processor the data has been shared with, and what was shared.
- Exclude from that disclosure any sharing made under a written law-enforcement or cyber-incident request from another legally authorised Data Fiduciary — that carve-out is mandatory, not optional.
- Respond within the timeframe Rule 14 sets once in force.
Penalty exposure
No Schedule item names Section 11. Failing to honour an access request falls under the residual item 7 — up to ₹50 crore.
Implementation timeline
Not yet in force. Commences 13 May 2027, eighteen months after the DPDP Rules, 2025 were published (13 November 2025) — per the commencement notification G.S.R. 843(E).
Section 11 · Rule 14
