How Fast Should Companies Respond to Data Subject Requests? A 2026 Guide to DPDP Compliance
As India transitions into a highly regulated digital economy under the Digital Personal Data Protection (DPDP) Act, consumer rights have taken center stage. Users now possess statutory authority over their personal information, and businesses must adapt quickly.
At the core of this transformation are data subject requests. If your business processes digital personal data, acknowledging these inquiries is no longer optional—it is a strict legal obligation with tightly defined timelines.
In this guide, we break down the finalized legal timeframes for addressing user data inquiries and how businesses can leverage automation solutions like RuleExpert to stay ahead of the May 2027 enforcement deadlines.
What Are Data Subject Requests?
When a consumer exercises their rights under the DPDP Act, they submit data subject requests to the business. Individuals have the right to request:
Access: Obtaining a summary of their processed data.
Correction: Fixing factual inaccuracies.
Erasure: Deleting data when the original purpose is fulfilled.
Grievance Redressal: Raising complaints about data management.
The Official Timeline: How Fast Must You Respond?
With the DPDP Rules 2025 officially finalized, the ambiguity around response times has ended.
The 90-Day Maximum Mandate
Under Rule 14, businesses must resolve data subject requests within a maximum of 90 days from the date of receipt.
The 72-Hour Breach Rule
If a personal data breach occurs, the business must notify the Data Protection Board and the affected users within 72 hours.
The 48-Hour Deletion Warning
When preparing to erase a user's data, the rules state you must notify the user 48 hours prior to the actual deletion.
The Challenges of Manual Processing
Organizations attempting to manage these obligations manually face severe bottlenecks, including difficult identity verification, complex data mapping across multiple software platforms, and the inability to maintain proper audit trails.
Automating DPDP Compliance with RuleExpert
Given the strict timelines, manual processes are no longer viable. Software like RuleExpert transforms how Indian businesses manage privacy obligations by providing:
Centralized Request Portals: For users to securely submit data subject requests.
Data Discovery at Scale: Instantly locating personal data across internal systems.
Timeline Monitoring: Real-time dashboards to track the 90-day countdown.
The May 2027 enforcement deadline is rapidly approaching. Start streamlining your data processes today to ensure your business remains compliant and trusted.
Comments
Post a Comment