Compliance
Section 16 of the DPDP Act forces every data‑fiduciary to display a working grievance contact and to answer complaints within the time the Rules set, otherwise the firm breaches section 8(10) and faces regulator scrutiny and possible penalties.
Check your DPDP readiness — free More on the blogThe Digital Personal Data Protection Act, 2023, introduced a clear duty for any entity that processes personal data – called a Data Fiduciary – to make a specific grievance contact publicly available. This contact is either the Data Protection Officer for Significant Data Fiduciaries or a designated person for smaller players. The contact details must be real, reachable and capable of handling queries about data processing. The rule is the first statutory step before a Data Principal can approach the Data Protection Board.
Under Section 16, the Data Fiduciary must publish business‑level contact information – phone, email or address – of the person responsible for data‑related queries. The published contact must be able to acknowledge a grievance and resolve it within the period prescribed by the Rules. Only after the internal mechanism is exhausted may the Data Principal approach the Board. The requirement applies to every data‑handling business, regardless of size, but the title of the contact differs for Significant Data Fiduciaries.
Many small firms treat the grievance channel as a casual help‑desk address, leaving emails unanswered or routing them to staff without authority. This creates a breach of section 8(10) because the contact is not effectively reachable. The law does not accept placeholders; the contact must be a real person who can act on statutory requests. Ignoring this can trigger regulator action, fines and damage to reputation.
If a business fails to publish a working grievance contact, it is deemed to have breached section 8(10). The breach opens the door for Data Principals to approach the Data Protection Board directly, increasing the likelihood of investigations, penalties and enforcement notices. While the Act does not prescribe a fixed monetary penalty for this specific breach, regulators have discretion to levy fines, and the indirect cost of legal defence and loss of consumer trust can be substantial. Beyond monetary penalties, the inability to resolve grievances internally can lead to escalated complaints, media attention and loss of business partners who demand robust data‑protection practices. For startups seeking funding, investors often scrutinise DPDP compliance, and a missing grievance contact can be a red flag during due‑diligence. To avoid these costs, firms should assign a dedicated individual, ensure their contact details are displayed on the website and privacy notice, and set up a tracking system that logs receipt, acknowledgement and resolution of each grievance within the prescribed timeframe. Regular audits of the grievance process help confirm that the contact remains active and that response timelines are met. Training staff on the statutory nature of these requests prevents the mistake of treating them as ordinary support tickets. In summary, publishing a functional grievance contact is not a nicety but a legal prerequisite. It safeguards the business from regulator action, protects brand reputation and provides a clear path for Data Principals to raise concerns, thereby reducing the risk of costly escalations.
The Fiducary must display business‑level contact details – such as a phone number, email address or physical address – of the Data Protection Officer for Significant Data Fiduciaries or a designated person for others. The contact must be reachable and capable of handling statutory data‑protection complaints.
The response and resolution must be completed within the period prescribed by the Rules made under the DPDP Act. The exact number of days is set by those Rules, not by the Act itself.
A generic, unmonitored email is treated as a placeholder and does not satisfy the requirement. The Fiducary would be in breach of section 8(10), allowing the Data Principal to approach the Data Protection Board directly.
Only Significant Data Fiduciaries are required to appoint a resident Data Protection Officer. Smaller Data Fiduciaries must still publish a designated contact, but the person does not need the DPO title.
Founder & CEO at VidhiSar. I have watched four companies pay for the same mistake, and it was never the mistake anyone expected. VidhiSar is software, not a law firm: every answer names the section it relies on so you can check it, and anything turning on your specific facts is worth putting to a professional. More about who builds this