DPDP Grievance and Access Requests: Service-Desk SLA and Evidence Register
By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026
Final Rule 14 requires Data Fiduciaries and Consent Managers to publish a grievance-response period not exceeding 90 days, but this rights/grievance rule is on the May 2027 commencement track; service desks should build the intake and evidence workflow now.
Finin2min 2-Minute Summary
- Final Rule 14 requires clear means for Data Principals to exercise rights and identify themselves using appropriate particulars.
- Data Fiduciaries and Consent Managers must publish a reasonable grievance-response period not exceeding 90 days once the rule is operative.
- The Act provides rights relating to access information, correction/erasure, grievance redressal and nomination under the applicable provisions.
- Rule 14 and the relevant core Act rights are notified but scheduled for May 2027.
- Internal SLAs should be shorter than the legal maximum so identity verification, data search, legal exceptions and approval fit inside the published period.
Current status: build the service desk before rights go live
Create one intake taxonomy
Classify requests as access/information, correction, erasure, grievance, consent withdrawal or nomination-related. A generic support ticket queue can lose statutory deadlines because agents may close the ticket after answering only one part of a combined request.
Collect only identification details needed to reliably match the requester to the account/data; excessive identity collection defeats privacy by design.
The evidence register should tell the whole story
For each request, store receipt time, request type, identity verification, systems searched, data owners, legal/retention exception, decision, approval, response date and any follow-up. The register should also prove that processor/vendor data was searched where relevant.
Do not put sensitive response content into analytics dashboards visible to broad support teams.
Set a shorter internal SLA
The final rule's published period can be up to 90 days. A practical organisation may use triage within 1-3 days and much shorter routine-response targets, reserving escalation for complex requests. Whatever period is published once operative must be supported by staffing and tooling.
Escalate complaints that allege security breach, child data or unlawful processing into the relevant specialist workflow immediately.
October 2026 status: design the rights queue before Rule 14 commences
Rule 14 and the relevant core Data Principal rights remain on the May 2027 commencement schedule. Organisations should nevertheless start measuring present support volumes and identity-verification complexity so the future published grievance period is realistic. The legal maximum of 90 days should not become a default service target for routine requests.
Build a dry-run register using voluntary privacy requests received today. Measure how long it takes to search CRM, marketing, product logs, processors and archives. The bottleneck is often data discovery rather than drafting the response.
Define when a request is paused for clarification and who approves a refusal or retention exception. The eventual external response should be understandable to the Data Principal and traceable to internal evidence.
- Dry-run access/erasure requests before commencement.
- Measure search time across processors and archives.
- Set a shorter operational SLA for routine cases.
- Require legal/privacy approval for refusal or retention exceptions.
Service-desk readiness checklist
- Rights/grievance intake categories.
- Identity-verification standard.
- Request timestamp and SLA clock.
- System/processor search workflow.
- Legal retention/exemption review.
- Decision approval and response template.
- Evidence register and repeat-request analytics.
Questions readers commonly ask
Is the 90-day grievance rule already binding in October 2026?
No. Rule 14 is scheduled to commence in May 2027.
Does the final rule require exactly 90 days?
No. It requires a reasonable published period not exceeding 90 days.
Can support ask for full KYC for every request?
Use identification particulars appropriate to the service and avoid collecting unnecessary personal data.
Should breach complaints stay in the normal support queue?
No. Route them promptly into incident/privacy escalation while preserving the grievance record.
Official / primary sources
- DPDP Rules, 2025 - Rule 14 rights/grievance mechanism and 90-day maximum
- DPDP Act, 2023 - Data Principal rights and grievance framework
- DPDP enforcement timeline - Core rights/obligations scheduled after 18 months
- MeitY DPDP Rules landing page - Final rules, corrigendum and enforcement documents
Disclaimer
Important: General educational and professional-reference material. Apply the current Code, Rules, insurance contract/regulatory instrument or DPDP commencement status to the exact facts before acting. Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.