India DPDP Act
DPDP Data Principal Rights (Sec 11-14)

India DPDP Act DPDP-DataPrincipalRights-Sec11to14-Access-Correction-Erasure-Grievance-Nominate-Withdraw: DPDP Act Sections 11-14 + Data Principal Rights + Access + Correction + Erasure + Grievance Redressal + Right to Nominate + Withdraw Consent + Duties + Verification of Identity

Sections 11-14 of DPDP Act 2023 establish the rights granted to Data Principals and Data Principal duties. Section 11 Right to Information: Data Principal shall have the right to obtain from the Data Fiduciary to whom she has previously given consent + including consent as referred to in Section 7 (Legitimate Uses): (a) a summary of personal data which is being processed by such Data Fiduciary and the processing activities undertaken; (b) the identities of all other Data Fiduciaries and Data Processors with whom the personal data has been shared + along with a description of the personal data so shared; (c) any other information related to the personal data of such Data Principal and its processing as may be prescribed. Section 12 Right to Correction + Completion + Updation + Erasure: Data Principal shall have the right to correction + completion + updating and erasure of her personal data + to the extent reasonably possible + balanced against legitimate business purpose + retention obligation + statutory requirements. Section 13 Right of Grievance Redressal: Data Principal shall have the right to have readily available means of grievance redressal provided by Data Fiduciary or Consent Manager + before approaching the Board (DPBI) + Data Fiduciary or Consent Manager shall respond to any grievances within prescribed period (per DPDP Rules 2025 - typically 7 to 30 days). Section 14 Right to Nominate: Data Principal shall have the right to nominate any other individual who shall in the event of death or incapacity of the Data Principal exercise the rights of the Data Principal in accordance with the provisions of this Act and the rules made thereunder. Section 15 Duties of Data Principal: shall comply with the provisions of all applicable laws in any case to which she is referred to as Data Principal + shall not impersonate another person + shall not suppress any material information + shall not register a false or frivolous grievance or complaint with Data Fiduciary or the Board + shall furnish only such information as is verifiably authentic. Verification of Identity: Data Fiduciary may verify identity of Data Principal exercising rights to prevent fraud + impersonation. Operational implementation: customer rights portal + multi-channel intake + verification of identity (Aadhaar + PAN + KYC tier) + intake-to-resolution workflow + Service Level Agreement + statistics + reporting to DPBI + integration with grievance redressal mechanism per Sec 8(8). Coordinates with GDPR Arts 15-22 + Right to Information + Rectification + Erasure (Right to be Forgotten) + Data Portability (NOT in DPDP) + Objection (NOT in DPDP) + Automated Decision-Making (NOT explicitly in DPDP) + UK GDPR + Singapore PDPA + RBI Integrated Ombudsman Scheme 2021 + India Stack Customer Awareness. DPDP Sec 11-14 Data Principal Rights applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 74 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

HITECH Act · 3 controls

  • HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC
  • HITECH-Scope-ARRA-XIII-42USC-Ch156-Subtitles HITECH Act Statutory Scope, ARRA Title XIII Origin and 42 USC Chapter 156 Structure (Subtitles A through D)
  • HITECH-SubtitleA-ONC-HIT-Standards-EHR-MU-PI HITECH Subtitle A - ONC, HIT Standards Committee, EHR Certification, Meaningful Use / Promoting Interoperability

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

APPI · 2 controls

  • APPI-A27 Restriction on Provision to Third Parties
  • APPI-A34 Request for Correction, Addition or Deletion
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection

Bahrain PDPL · 2 controls

  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.8 Records of processing activities (UAE PDPL Article 8)
  • DOM172-Data-Subject-ARCO-Rights-Habeas-Data-Action-Constitutional-Article-70-Access-Rectification-Cancellation-Opposition Dominican Republic Law 172-13 ARCO Rights + Habeas Data Action + Constitutional Article 70
  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification

OWASP ASVS · 2 controls

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-5 APP 12-13 Access and Correction of Personal Information
  • 502 Interoperability with Assistive Technology
  • 707 Real-Time Text Functionality
  • ASD37-17 TLS encryption between email servers (Limited)

BSI IT-Grundschutz · 1 control

  • BSI-08 Cryptographic protection of data
  • BB-DPA-14 Section 15 - Right to Data Portability
  • DIQ-1 Data Integration and Interoperability

FDA 21 CFR Part 11 · 1 control

  • Part11.30 Controls for open systems (21 CFR §11.30)

FIDO2 / WebAuthn · 1 control

FISMA · 1 control

  • FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

FedRAMP Rev 5 · 1 control

  • FedRAMP-Baselines FedRAMP Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters

GLBA · 1 control

  • GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines
  • GhCSA-Service-Provider-Licensing-Professional Cybersecurity Service Provider Licensing and Professional Accreditation

HKMA SPM · 1 control

  • HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF
  • IACS-UR-E26-Protect-RemoteAccess-Wireless-Physical-Boundary IACS UR E26 Protect Goal - Remote Access + Wireless + Physical Security + Boundary Protection
  • 62351-9 Cyber security key management

ISO/IEC 27010:2015 · 1 control

  • 27010-10.1 Cryptographic Protection

ISO/IEC 27011:2024 · 1 control

  • 27011-8.3 Cryptography and key management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.2 Device Identity and Authentication
  • 29115-7.4 Level of Assurance 4 (LoA4)

MITRE D3FEND · 1 control

  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • CPSC-STD.4 Interoperability Safety
  • VERMONTAICDA-1 AI System Inventory and Risk Assessment

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 74 it maps to, and the evidence behind each claim, over MCP and REST.