Does the DPDP Act Require a Grievance Officer? Section 13 Explained
If you have started mapping your obligations under India's Digital Personal Data Protection Act 2023, you have probably run into a common question: does the law actually require you to appoint a "grievance officer"? The short answer is that Section 13 gives every Data Principal a right to grievance redressal, and to honour that right your organization must provide a readily-available mechanism for people to raise and resolve complaints. Whether you call the person behind it a grievance officer, a contact person, or a Data Protection Officer depends on your size and status.
This guide explains what Section 13 requires, how it connects to the Data Protection Board of India, what "readily available" means in practice, and how to stand up a grievance process that holds up to scrutiny.
What Section 13 Actually Says
Section 13 of the DPDP Act establishes that a Data Principal has the right to a readily available means of grievance redressal provided by the Data Fiduciary (or, where applicable, a Consent Manager) in respect of any act or omission regarding the processing of their personal data.
Two obligations flow from this:
- You must respond. The Data Fiduciary is required to respond to grievances within a defined period. The Act itself leaves the exact timeline to be set by the DPDP Rules rather than fixing a number in the statute, so you should track the Rules (see the timeline note below) rather than rely on a figure you saw quoted somewhere.
- You must make the channel easy to find and use. A grievance mechanism buried three menus deep, or one that only exists as a legal-sounding clause in a privacy policy, does not satisfy the "readily available" standard.
Importantly, Section 13 is a right of the individual, not merely a box-ticking appointment. The law cares less about the job title on someone's business card and more about whether a real person actually resolves complaints in reasonable time.
Grievance Redressal Is Part of a Larger Set of Rights
Section 13 does not stand alone. It sits inside a cluster of Data Principal rights that your grievance process will inevitably touch:
- Section 11 — Right to access information about whether and how their personal data is being processed.
- Section 12 — Right to correction, completion, updating, and erasure of personal data.
- Section 13 — Right to grievance redressal.
- Section 14 — Right to nominate another individual to exercise these rights in case of death or incapacity.
In practice, a "grievance" is often a rights request that went unanswered or was handled poorly — someone asked for their data to be corrected, heard nothing, and escalated. That is why it makes sense to run grievances through the same workflow you use for access, correction, and erasure requests, rather than treating them as a separate inbox. For the full picture of the underlying rights, see our guide on what the DPDP Act requires.
The Board Comes After You, Not Before
A frequent misconception is that data principals complain directly to the regulator. Under the DPDP Act, the Data Protection Board of India generally sits at the end of the escalation chain, not the beginning.
The intended flow looks like this:
- The Data Principal raises a grievance with you, the Data Fiduciary, using your readily-available mechanism.
- You investigate and respond within the applicable timeline.
- Only if the individual is unsatisfied with your response — or you fail to respond — may they escalate to the Data Protection Board.
This ordering matters for two reasons. First, it means a well-run internal grievance process is your best defense: most complaints should never reach the Board because you resolved them. Second, it means your records matter. If a matter does reach the Board, you will want a clean, timestamped trail showing that you received the grievance, acted on it, and communicated the outcome.
What "Readily Available" Means in Practice
The Act does not prescribe a single format, but "readily available" has become a practical checklist. A grievance mechanism generally should be:
- Easy to locate — linked from your privacy notice, your website footer, and ideally your consent banner, not hidden.
- Easy to use — a clear web form, email address, or in-product option, with no requirement to send physical letters or navigate a call-centre maze.
- Named and reachable — the contact details of the person or team responsible should be published so a Data Principal knows exactly where their complaint lands.
- Acknowledged — the individual should get confirmation that their grievance was received, not silence.
- Tracked and resolved — every grievance needs a status, an owner, and a resolution within the applicable timeline.
If any of these is missing, you may technically have a policy but not a readily-available mechanism in the sense Section 13 intends.
Grievance Officer, Contact Person, or DPO — Which Do You Need?
The DPDP Act uses different labels depending on your organization's status, and it helps to keep them straight:
| Role | Who it applies to | What the Act says | | --- | --- | --- | | Contact person / point of contact | Every Data Fiduciary | You must publish the contact details of a person able to answer questions about processing and handle grievances. | | Data Protection Officer (DPO) | Significant Data Fiduciaries (Section 10) | An SDF, as notified by the Central Government based on volume and sensitivity of data, risk, and other factors, must appoint a DPO based in India who is the point of contact for grievance redressal and is answerable to its board. |
So the honest answer to "does the Act require a grievance officer?" is:
- Every Data Fiduciary must provide a grievance redressal mechanism and a published point of contact under Section 13 read with the notice and transparency obligations.
- Significant Data Fiduciaries additionally carry the Section 10 obligations — a formal DPO, independent data audits, and Data Protection Impact Assessments. For most SDFs the DPO becomes the named face of grievance redressal.
You do not need to invent a new job title. You do need a real person who owns the process and whose contact details are public.
Setting Up a Section 13 Grievance Process
Here is a practical sequence that satisfies the spirit and letter of Section 13:
- Publish a channel. Add a grievance option to your privacy notice and website — a form is cleaner than a bare email address because it captures structured information from the start.
- Name an owner. Assign a person or team responsible for grievances, and publish their contact details. If you are an SDF, this ties into your DPO appointment.
- Acknowledge on receipt. Send an automatic confirmation so the Data Principal knows the complaint landed and has a reference.
- Log and classify. Record whether the grievance relates to access (S.11), correction or erasure (S.12), consent withdrawal (S.6), a suspected breach, or something else.
- Investigate and resolve within the timeline. Route it to the right team, take action, and close the loop with a written response.
- Keep the evidence. Maintain an immutable, timestamped record of every step. This is what protects you if the matter escalates to the Board.
- Watch the Rules. Adjust your target response time once the DPDP Rules fix the applicable period.
A quick note on timelines: the draft DPDP Rules 2025 propose specific response periods for grievances and rights requests, but the Act itself sets no fixed number, and the Rules were still in draft as of 2025. Treat any specific figure as provisional and confirm it against the final Rules before you hard-code it into your SLAs.
How DPDP Comply Helps
Grievance redressal is only as good as the workflow behind it, and that is exactly what DPDP Comply is built to run. Grievances are handled inside the same rights request workflow as access, correction, erasure, and nomination requests — so a complaint never falls into an unmonitored inbox.
With DPDP Comply you can:
- Accept grievances and rights requests through a hosted, readily-available intake that you link from your notice and website.
- Automatically acknowledge each submission and assign it an owner and a status.
- Classify each request by type (grievance, access, correction, erasure, nomination) so it routes to the right team.
- Track every request against a configurable deadline, with reminders as the target date approaches, so nothing quietly ages out.
- Keep an immutable, timestamped audit trail of receipt, action, and resolution — the evidence you want if a matter ever reaches the Data Protection Board.
You can see how the rights and grievance workflow fits alongside consent and audit tooling on our features overview, and dig deeper into the consent side in our guide to consent management under DPDP.
Get Your Grievance Process in Place
Section 13 is not a heavy obligation, but it is one regulators can check quickly: is there a real, reachable, responsive way for people to complain, and do you actually resolve what comes in? If you cannot answer yes with evidence, it is worth fixing before it becomes a Board matter.
Create a free DPDP Comply account to stand up a readily-available grievance and rights workflow — with intake, ownership, deadline tracking, and an audit trail — in a single afternoon.
This article is general information, not legal advice.