Grievance Redressal Under DPDP: How to Actually File a Complaint Against a Company
TL;DR: If a company mishandles your personal data under India's DPDP Act, there's a defined process for raising it — starting with the company's own grievance officer and escalating to the Data Protection Board of India if it isn't resolved. Here's how that process actually works in practice.
👉 See if your data's already leaked — free 30-second check →
Knowing your rights under the DPDP Act is one thing; knowing the actual mechanism to act on them is another. The grievance redressal process is designed as a two-step system, and understanding both steps matters if you actually want a resolution rather than just a complaint that goes nowhere.
Step 1: The company's own grievance officer
Every data fiduciary (the company or entity processing your data) operating under the DPDP Act is required to have a grievance redressal mechanism, typically a designated grievance officer or contact point. This is meant to be your first stop — most privacy policies now include a section specifying how to reach this contact, often via a dedicated email address.
When raising a grievance at this stage, it helps to be specific: name the exact right you're exercising (correction, deletion, or simply asking what data is held), reference the DPDP Act directly, and set a clear expectation for a response timeline.
Step 2: Escalating to the Data Protection Board
If the company doesn't respond, or the response doesn't actually resolve the issue, the next step is escalating to the Data Protection Board of India (DPBI). The Board is empowered to inquire into the complaint, direct the company to take corrective action, and in serious cases, levy penalties for non-compliance.
What to have ready before you file
- A record of your original request to the company and the date it was made.
- Any response (or lack of one) you received, with timestamps.
- A clear, specific statement of what right you believe was violated.
What this process doesn't cover
Grievance redressal under the DPDP Act addresses how a company handles data it's already legitimately collected — it isn't the right mechanism for reporting active fraud, scams, or unauthorized account access, which should go to India's cybercrime helpline at 1930 or cybercrime.gov.in instead.
Separately, if you're trying to understand what's already exposed about you before deciding whether a grievance is even worth filing, a Scan My Shadow report gives you that starting picture.
Frequently Asked Questions
Who do I contact first if a company misuses my data?
Start with the company's own grievance officer or designated privacy contact, usually listed in their privacy policy — this is the required first step before escalating.
What if the company doesn't respond to my grievance?
You can escalate to the Data Protection Board of India, which can inquire into the complaint and direct corrective action or penalties.
Is this the right process for reporting a scam or fraud?
No — active fraud or scams should be reported to India's cybercrime helpline at 1930 or cybercrime.gov.in, not through DPDP grievance redressal, which addresses data handling by legitimate fiduciaries.
What should I include when filing a grievance with a company?
A specific statement of the right you're exercising, reference to the DPDP Act, and a clear timeline expectation — vague complaints are harder to act on.
Does filing a grievance guarantee my data gets deleted?
Not automatically — it starts a process that can lead to correction, deletion, or explanation, depending on the specifics of your request and the company's obligations.
Curious what's already out there about you? Scan My Shadow checks your phone number and email across 1,500+ sources and sends you a clear report — no guesswork, just facts. Start your scan.
- Results within about 5 minutes
- Clear, plain-English report
- Delivered straight to your inbox
- No login or passwords required
- Scan data deleted after report is generated