Grievances
SL-03Section 13 gives every Data Principal a right to a readily available grievance mechanism, and requires the Data Fiduciary to respond within the period it has published for itself. A principal may only approach the Data Protection Board of India after exhausting this route — which makes this queue the last chance to resolve something internally.
5 grievances allege a withdrawal was not honoured or raise a breach concern
These are the two categories that most often become Board complaints, because both describe a failure the principal can see from outside. A withdrawal not honoured should be checked against the propagation map before responding — if a downstream system never acknowledged, the grievance is correct.
Grievances
15
Open
9
Past the published period
3
Escalated
3
Resolved
6
15 records
By category
- No response to an earlier request3
- Response was incorrect or incomplete2
- Data handled improperly3
- Withdrawal of consent not honoured5
- More data collected than necessary1
- Concern about a data breach1
The escalation ladder
Published under Rule 13 and binding on us. Each rung has a named holder, because a ladder that escalates to a department rather than a person does not escalate.
- 1Day 0–7 · Grievance officerAcknowledge, verify identity, investigate.
- 2Day 8–14 · Data Protection OfficerEscalated automatically if unresolved. The DPO takes the decision, not a recommendation.
- 3Day 15–30 · Head of DepartmentFinal internal rung. A response must issue before day 30 whether or not the investigation is complete.
- 4After day 30 · Data Protection Board of IndiaThe principal may complain to the Board. Our published period having lapsed is itself part of their complaint.