Compliance

Why Publishing a Data Grievance Contact Matters for Indian Businesses

Section 16 of the DPDP Act forces every data‑fiduciary to display a working grievance contact and to answer complaints within the time the Rules set, otherwise the firm breaches section 8(10) and faces regulator scrutiny and possible penalties.

Check your DPDP readiness — free More on the blog

Why Publishing a Data Grievance Contact Matters for Indian Businesses

The Digital Personal Data Protection Act, 2023, introduced a clear duty for any entity that processes personal data – called a Data Fiduciary – to make a specific grievance contact publicly available. This contact is either the Data Protection Officer for Significant Data Fiduciaries or a designated person for smaller players. The contact details must be real, reachable and capable of handling queries about data processing. The rule is the first statutory step before a Data Principal can approach the Data Protection Board.

What the law requires

Under Section 16, the Data Fiduciary must publish business‑level contact information – phone, email or address – of the person responsible for data‑related queries. The published contact must be able to acknowledge a grievance and resolve it within the period prescribed by the Rules. Only after the internal mechanism is exhausted may the Data Principal approach the Board. The requirement applies to every data‑handling business, regardless of size, but the title of the contact differs for Significant Data Fiduciaries.

Common compliance gaps

Many small firms treat the grievance channel as a casual help‑desk address, leaving emails unanswered or routing them to staff without authority. This creates a breach of section 8(10) because the contact is not effectively reachable. The law does not accept placeholders; the contact must be a real person who can act on statutory requests. Ignoring this can trigger regulator action, fines and damage to reputation.

  • Using a generic support email that no one monitors
  • Failing to appoint a resident Data Protection Officer for Significant Data Fiduciaries
  • Not setting internal timelines before the Rules become effective
  • Treating grievance tickets as ordinary customer service requests

Cost of non‑compliance

If a business fails to publish a working grievance contact, it is deemed to have breached section 8(10). The breach opens the door for Data Principals to approach the Data Protection Board directly, increasing the likelihood of investigations, penalties and enforcement notices. While the Act does not prescribe a fixed monetary penalty for this specific breach, regulators have discretion to levy fines, and the indirect cost of legal defence and loss of consumer trust can be substantial. Beyond monetary penalties, the inability to resolve grievances internally can lead to escalated complaints, media attention and loss of business partners who demand robust data‑protection practices. For startups seeking funding, investors often scrutinise DPDP compliance, and a missing grievance contact can be a red flag during due‑diligence. To avoid these costs, firms should assign a dedicated individual, ensure their contact details are displayed on the website and privacy notice, and set up a tracking system that logs receipt, acknowledgement and resolution of each grievance within the prescribed timeframe. Regular audits of the grievance process help confirm that the contact remains active and that response timelines are met. Training staff on the statutory nature of these requests prevents the mistake of treating them as ordinary support tickets. In summary, publishing a functional grievance contact is not a nicety but a legal prerequisite. It safeguards the business from regulator action, protects brand reputation and provides a clear path for Data Principals to raise concerns, thereby reducing the risk of costly escalations.

Common questions

What information must a Data Fiduciary publish as a grievance contact?

The Fiducary must display business‑level contact details – such as a phone number, email address or physical address – of the Data Protection Officer for Significant Data Fiduciaries or a designated person for others. The contact must be reachable and capable of handling statutory data‑protection complaints.

How long does a Data Fiduciary have to respond to a grievance?

The response and resolution must be completed within the period prescribed by the Rules made under the DPDP Act. The exact number of days is set by those Rules, not by the Act itself.

What happens if a grievance contact is just a generic support email?

A generic, unmonitored email is treated as a placeholder and does not satisfy the requirement. The Fiducary would be in breach of section 8(10), allowing the Data Principal to approach the Data Protection Board directly.

Do small businesses need to appoint a Data Protection Officer?

Only Significant Data Fiduciaries are required to appoint a resident Data Protection Officer. Smaller Data Fiduciaries must still publish a designated contact, but the person does not need the DPO title.

Related reading

  • Understanding the Writing Requirement for Arbitration Agreements — Section 7 of the Arbitration and Conciliation Act mandates that arbitration agreements be in writing, and a mere venue clause does not satisfy the requirement, costing businesses delays and extra litigation if ignored
  • Cost of Ignoring Internal Committee Rules Under POSH Act — Failing to set up an Internal Committee or file the required annual report can attract a fine of up to fifty thousand rupees and, on repeat, double the penalty plus possible licence cancellation, threatening a small business’s ability to operate.
  • Understanding Section 73 Compensation for Breach of Contract — Section 73 limits recoverable damages to losses that naturally flow from a breach or were foreseen by the parties, excluding remote or indirect losses and reducing awards where the injured party failed to mitigate.

Written by Swaraj Layek

Founder & CEO at VidhiSar. I have watched four companies pay for the same mistake, and it was never the mistake anyone expected. VidhiSar is software, not a law firm: every answer names the section it relies on so you can check it, and anything turning on your specific facts is worth putting to a professional. More about who builds this