DPDP Act 2023 · Compliance guide

Grievance officer under the DPDP Act: who needs one, and how to appoint them

Published July 2026 · ~7 min read · by Ronin Works
Short answer

Every data fiduciary — effectively every Indian business that handles personal data — must give people a readily available way to raise data grievances and must publish the contact details of the person who answers them. It doesn't have to be a lawyer or a new hire. Only Significant Data Fiduciaries have the extra obligation of appointing a Data Protection Officer based in India.

Of all the DPDP Act's obligations, the grievance mechanism is the cheapest to set up and the most visible when it's missing. It's also the front door of the whole law: a person must route their complaint through you before they can escalate to the Data Protection Board of India. Here's exactly what's required and how to get it done this week.

What the Act actually requires

Two related duties sit on every data fiduciary:

The escalation order matters: the Act expects a data principal to exhaust your grievance process first before approaching the Data Protection Board. A working grievance channel is therefore your chance to fix problems privately, before they become a regulator's case file.

Grievance officer vs Data Protection Officer — don't confuse the two

These get mixed up constantly:

If you're an SME and haven't been notified as an SDF, you need the first, not the second. If you process large volumes of personal data — especially health, financial or children's data — plan as though the SDF bar may reach you.

Who should you appoint?

The Act doesn't prescribe qualifications for the grievance role. In practice, the right person is whoever can actually move your data, because most grievances end in an action: find my record, correct it, delete it, tell me what you hold. That usually means:

What the role handles day to day

Expect four kinds of requests, and build a simple playbook for each:

1. Access requests

"What data do you hold about me?" You need to search every system where the person might exist — CRM, billing, support desk, marketing lists — and produce a summary.

2. Correction requests

"My number/address is wrong." Correct it everywhere, not just in the system the person happens to know about.

3. Erasure requests

"Delete my data." The hardest one. If a customer exists as five inconsistent duplicates across your CRM and spreadsheets, you will miss copies — which is why data cleansing and data discovery are the real preparation for this role.

4. Consent withdrawal

"Stop using my data for marketing." Withdrawal must be as easy as the consent was, and it must actually propagate to your tools.

Setting it up: the checklist

Not sure where you stand?

Take our free, 2-minute DPDP Readiness Scorecard — answer 12 questions and get a per-area gap report showing exactly what to fix first.

How Ronin Works helps

We set up the grievance function end to end: the published contact and notice language, the four request playbooks, and — the part most consultants skip — the data mapping and cleanup that make requests answerable at all. When a deletion request arrives, your officer should be able to find every copy of that person in minutes, not weeks.

Keep reading

Not a business — just you?

The DPDP Act gives individuals rights too. Saaph.in — a Ronin Works product — finds where your personal data is exposed across the open web and gets it removed under the Act, then keeps watch.

Scan your exposure at Saaph.in →
Enquiry

Need help setting up your grievance process?

Send us a note — we reply within one working day.

✓ Thank you — we'll be in touch.

This article is general information, not legal advice. The DPDP Act's rules and enforcement timeline are determined by the Government of India and may change. For a formal assessment of your obligations, consult a qualified professional or talk to Ronin Works.