⚖️ DPDP ACT 2023

Your Data Rights in India — Explained Simply

The Digital Personal Data Protection Act 2023 is India's most powerful privacy law. It gives every Indian citizen the legal right to know what data companies hold about them — and demand its deletion.

📅 Act passed: August 2023 📜 Rules notified: November 2025 ⏱ Erasure right takes effect: May 2027
In this guide
  1. What is the DPDP Act?
  2. Your 6 Rights Under the Act
  3. Who Must Comply?
  4. How to File a Data Erasure Request
  5. DPDP Erasure Email Template
  6. Penalties for Non-Compliance
  7. Frequently Asked Questions
  8. 📊 Indian Data Brokers Guide →
01 — OVERVIEW

What is the DPDP Act 2023?

The Digital Personal Data Protection Act 2023 (DPDP Act) is India's first comprehensive data protection law. Passed by Parliament on August 11, 2023, it gives Indian citizens meaningful control over their personal data held by companies — whether Indian or foreign.

Before this law, Indian users had no formal legal mechanism to demand that companies delete their data. Data brokers, telemarketing firms, and people-search platforms could hold and sell your phone number, address, and identity information indefinitely with no accountability.

The DPDP Act changes this. It requires any company that collects or processes personal data of Indian residents (called a Data Fiduciary) to follow strict rules around consent, use, and deletion.

🇮🇳
Why this matters for you

Your phone number is listed on TrueCaller, JustDial, Acxiom, and dozens of other platforms — many without your knowledge or consent. The DPDP Act gives you the legal right to demand its removal. Saaph.in helps you find where your data is held and prepare and send your own erasure requests under Section 12 — as a tool and communication facilitator, not your legal representative.

02 — YOUR RIGHTS

Your 6 Rights Under the DPDP Act

The Act grants Indian citizens six core rights over their personal data held by any Data Fiduciary:

📋
Right to Information

You can ask any company to tell you exactly what personal data they hold about you and why they're processing it. This becomes enforceable in May 2027; asking now still often works.

✏️
Right to Correction

You can request that a company correct inaccurate or incomplete personal data they hold about you.

🗑️
Right to Erasure

This is the most powerful right. You can demand permanent deletion of your personal data. It becomes legally enforceable in May 2027 — until then, a request asks a company to act voluntarily, and many do.

🚫
Right to Withdraw Consent

If a company collected your data with your consent, you can withdraw that consent at any time. Processing must stop after withdrawal.

⚖️
Right to Grievance Redressal

If a company ignores your request or violates your rights, you can file a complaint with India's Data Protection Board.

👤
Right to Nominate

The DPDP Act lets you nominate someone to exercise your rights if you're unable to. Saaph doesn't take that role — you stay in control, and Saaph simply makes it easier to find your data and send your own requests.

03 — SCOPE

Who Must Comply?

The DPDP Act applies to any entity that processes the personal data of Indian residents — regardless of where the company is headquartered. This includes:

  • Indian telecom & caller ID platforms — TrueCaller, Hiya, Bharat Caller
  • Business directories — JustDial, IndiaMART, Sulekha, Quikr
  • Real estate portals — MagicBricks, 99acres, Housing.com
  • Job portals — Naukri, Shine, Monster India
  • Global data brokers operating in India — Acxiom, ZoomInfo, Experian India
  • Company records sites — Zaubacorp, Zauba Corp, Tofler
  • Social & professional networks — LinkedIn India, Facebook
  • Search engines — Google Search results containing Indian personal data
⚠️
Important limitation

The DPDP Act does not apply to personal data processed for national security, law enforcement, or journalistic purposes. Government bodies and certain research organisations may also be exempt under rules notified by the Central Government.

🏢 FOR INDIAN BUSINESSES & MSMEs:

Need to make your company audit-ready before India's 13 May 2027 DPDP enforcement deadline? Check your governance, consent logs, and vendor contracts across 62 checkpoints:

Ronin Works 62-Item DPDP Audit Prerequisites Checklist →
04 — HOW TO FILE

How to File a Data Erasure Request

You file the data erasure request yourself — Saaph.in just makes it far easier by finding where your data is held and preparing and sending your own requests for you. Here's the step-by-step process:

  1. Identify where your data is listed. Run a free scan at saaph.in to discover which platforms hold your information.
  2. Find the platform's Data Protection Officer (DPO). The DPDP Act requires every significant Data Fiduciary to appoint a DPO and publish their contact information.
  3. Send a written erasure request to the DPO email citing Section 12 of the DPDP Act 2023. Include your full name, phone, and email. Use our template below.
  4. Give it about 90 days. There is no statutory erasure deadline in force yet, so treat 90 days as a sensible follow-up window. Many companies process requests within 2–4 weeks anyway.
  5. Escalate if ignored. Raise it with the company's published Grievance Officer, and keep your dated request — you can file it with the Data Protection Board of India once its powers commence in May 2027. If the problem is unwanted calls or messages rather than stored data, your telecom operator's 1909 channel is live today and is the faster route.
🤖
Saaph.in makes this effortless

Our Pro plan transmits your DPDP-compliant erasure emails to the platform DPOs for you — as a communication facilitator, with you kept in copy — tracks responses, and re-sends if there's no reply. You never have to write a single email yourself.

05 — EMAIL TEMPLATE

DPDP Erasure Email Template

Copy and send this email to the Data Protection Officer of any platform. Replace the highlighted fields with your information.

Data Erasure Request — DPDP Act 2023
Subject: Data Erasure Request — DPDP Act 2023, Section 12 To: dpo@[platform].com Dear Data Protection Officer, I, [Your Full Name], hereby exercise my right to erasure of personal data under the Digital Personal Data Protection Act 2023 (DPDP Act), Section 12. I request the immediate and permanent deletion of all personal data you hold pertaining to: • Name: [Your Full Name] • Phone: [Your Mobile Number with +91] • Email: [Your Email Address] • City: [Your City] This includes but is not limited to: contact details, location data, profile information, marketing lists, and any derived or inferred data. This request is made under Section 12 of the DPDP Act 2023, whose erasure provisions commence in May 2027. I ask you to act on it now, and to route it to your Grievance Officer if that is your published process. Please confirm deletion at this email address within 7 business days of receiving this request. Regards, [Your Full Name] Data Principal, under Section 12 of the DPDP Act 2023 Sent using Saaph.in — a tool that helps individuals send their own DPDP requests.

Saaph.in Pro subscribers: we transmit your own request to all relevant platform DPOs for you, as a communication facilitator — with you kept in copy. No copy-pasting needed.

06 — PENALTIES

Penalties for Non-Compliance

The DPDP Act 2023 gives real teeth to your data rights. Companies that fail to comply face significant financial penalties:

₹250 Cr
Failure to implement adequate security safeguards — highest penalty tier for data breaches due to negligence.
₹200 Cr
Failure to notify Data Protection Board of a data breach — companies must report breaches promptly.
₹150 Cr
Non-compliance with obligations towards children's data — stricter rules apply to data of minors under 18.
₹50 Cr
Failure to honour data principal rights — including ignoring erasure requests, right to information, or correction requests.
₹10,000
Failure by data principal to comply — penalties also apply to individuals who provide false information when exercising rights.
💡
What this means in practice

The ₹50 Crore penalty for ignoring data rights is the most relevant for everyday users. When a platform receives a properly formatted DPDP Act erasure request, they have strong financial incentive to comply — the risk of non-compliance far exceeds the cost of simply deleting your data.

07 — FAQ

Frequently Asked Questions

The Act was passed in August 2023, but it commences in stages rather than all at once — which is why there is no single yes-or-no answer. The definitions and the provisions constituting the Data Protection Board came first; the substantive obligations, including the right to erasure, become legally enforceable in May 2027. Until then a request asks a company to act voluntarily, and many already do.
Yes. Many platforms obtain your data from third parties — data brokers, public records, or other apps you used. You don't need to have directly registered with a platform to exercise your right to erasure. If they hold your data, you can request its deletion.
Companies can legitimately refuse if the data is required for legal compliance, active service delivery, or national security. However, they must tell you why they're refusing. If they simply ignore your request, you can file a complaint with the Data Protection Board of India once it is operational. Saaph.in will flag such platforms in your dashboard and advise on next steps.
Yes. The DPDP Act applies to any entity processing personal data of Indian residents, regardless of where the company is based. WhatsApp, Facebook, Google, LinkedIn, and international data brokers like Acxiom are all covered if they process data of Indian users.
There is no erasure deadline in force yet — that arrives with the Act's substantive provisions in May 2027 — but many platforms process requests in 2–4 weeks regardless. TrueCaller, for example, has a self-service unlisting process that takes effect immediately. Google results may take 1–3 weeks to de-index. Some data broker databases can take the full 90 days. Saaph.in monitors each request and alerts you when removal is confirmed.
Not necessarily. Data can reappear — especially if you use services that re-share your information, or if a platform refreshes its database from public records. This is why Saaph.in re-scans every 90 days and automatically re-sends removal requests when data reappears. Privacy is an ongoing process, not a one-time fix.

Ready to exercise your DPDP rights? Saaph.in finds where your data is exposed and helps you demand erasure — removal routes for 250+ companies on file (220+ with a published grievance contact).

Free Scan — Takes 30 Seconds