Skip to content
DPDP deadline in
Learn more →
PrivacySuraksha - Privacy. Trust. Compliance

India's DPDP privacy operations platform

Chapter III · Rights and Duties of Data Principal

Section 15 — Duties of Data Principal

What this section requires

Section 15 puts five duties directly on the Data Principal, not the fiduciary: comply with applicable law while exercising her rights; don't impersonate someone else when providing personal data for a specified purpose; don't suppress material information when providing data for a State-issued document, identifier, or proof of identity/address; don't register a false or frivolous grievance or complaint with a Data Fiduciary or the Board; and furnish only verifiably authentic information when exercising her correction or erasure rights.

Who it applies to

The Data Principal herself — this is the one section in the guide that binds the individual, not the Data Fiduciary or Processor.

Checklist

  • This section has no fiduciary-side checklist — the duties run to the individual. A Data Fiduciary's relevant safeguard is simply knowing that a breach here can be raised as a defence or mitigating factor if a Data Principal's own conduct contributed to a dispute.

Penalty exposure

A Data Principal who breaches these duties faces a monetary penalty of up to ₹10,000, per item 5 of the Schedule to Section 33 — a deliberately small figure, and the only Schedule item that penalises the Data Principal rather than the Data Fiduciary.

Implementation timeline

Not yet in force. Commences 13 May 2027, eighteen months after the DPDP Rules, 2025 were published (13 November 2025) — per the commencement notification G.S.R. 843(E).

Section 15

← Back to the DPDP guide index