Skip to main content
Finin2minAction Guide · source-controlled
DPDP, Privacy & DataUpdated 5 October 2026

DPDP Grievance and Access Requests: Service-Desk SLA and Evidence Register

By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026

Final Rule 14 requires Data Fiduciaries and Consent Managers to publish a grievance-response period not exceeding 90 days, but this rights/grievance rule is on the May 2027 commencement track; service desks should build the intake and evidence workflow now.

Finin2min 2-Minute Summary

Current status: build the service desk before rights go live

Create one intake taxonomy

Classify requests as access/information, correction, erasure, grievance, consent withdrawal or nomination-related. A generic support ticket queue can lose statutory deadlines because agents may close the ticket after answering only one part of a combined request.

Collect only identification details needed to reliably match the requester to the account/data; excessive identity collection defeats privacy by design.

The evidence register should tell the whole story

For each request, store receipt time, request type, identity verification, systems searched, data owners, legal/retention exception, decision, approval, response date and any follow-up. The register should also prove that processor/vendor data was searched where relevant.

Do not put sensitive response content into analytics dashboards visible to broad support teams.

Set a shorter internal SLA

The final rule's published period can be up to 90 days. A practical organisation may use triage within 1-3 days and much shorter routine-response targets, reserving escalation for complex requests. Whatever period is published once operative must be supported by staffing and tooling.

Escalate complaints that allege security breach, child data or unlawful processing into the relevant specialist workflow immediately.

October 2026 status: design the rights queue before Rule 14 commences

Rule 14 and the relevant core Data Principal rights remain on the May 2027 commencement schedule. Organisations should nevertheless start measuring present support volumes and identity-verification complexity so the future published grievance period is realistic. The legal maximum of 90 days should not become a default service target for routine requests.

Build a dry-run register using voluntary privacy requests received today. Measure how long it takes to search CRM, marketing, product logs, processors and archives. The bottleneck is often data discovery rather than drafting the response.

Define when a request is paused for clarification and who approves a refusal or retention exception. The eventual external response should be understandable to the Data Principal and traceable to internal evidence.

Service-desk readiness checklist

Questions readers commonly ask

Is the 90-day grievance rule already binding in October 2026?

No. Rule 14 is scheduled to commence in May 2027.

Does the final rule require exactly 90 days?

No. It requires a reasonable published period not exceeding 90 days.

Can support ask for full KYC for every request?

Use identification particulars appropriate to the service and avoid collecting unnecessary personal data.

Should breach complaints stay in the normal support queue?

No. Route them promptly into incident/privacy escalation while preserving the grievance record.

Official / primary sources

Disclaimer

Important: General educational and professional-reference material. Apply the current Code, Rules, insurance contract/regulatory instrument or DPDP commencement status to the exact facts before acting. Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.

Educational and professional reference only — not financial, tax or legal advice. Verify the current official position from the primary source before relying on any figure, rate, provision or deadline.