Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026due today 15 OCTPF & ESI · Contributions · Sep 2026in 4 days 20 OCTGSTR-3B · Summary return · Sep 2026in 9 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 10 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 19 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 27 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 41 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 49 days
All due dates

Section 11 of the Digital Personal Data Protection Act, 2023: Right to access information

A Data Principal who has previously given consent, including consent under section 7(a), may request from that Data Fiduciary: (a) a summary of the personal data processed and the...

Published
Updated
Reading time
8 min
Views
10
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Data Protection
Published
September 30, 2026
Last updated
Oct 10, 2026
Reading time
8 min
0:00
Last updated: October 2026Verified against: Government sources

Section 11 gives a Data Principal the right to obtain from a Data Fiduciary a summary of her personal data being processed, the identities of all other Data Fiduciaries and Data Processors with whom it has been shared, and any other prescribed information. A legal consultation can help you build a response process that is ready before the first request arrives.

Section 11 at a glance

ProvisionContent
11(1) openingRight against the Data Fiduciary to whom she previously gave consent, including consent under section 7(a); request in the manner prescribed
11(1)(a)Summary of personal data being processed and processing activities
11(1)(b)Identities of all other Data Fiduciaries and Data Processors with whom data has been shared, with a description of the data shared
11(1)(c)Any other information related to the personal data and its processing, as may be prescribed
11(2)Clauses (b) and (c) do not apply to sharing with a Data Fiduciary authorised by law, on a written request, for prevention, detection or investigation of offences or cyber incidents, or prosecution or punishment of offences

Who can use it, and against whom

The right is given to "the Data Principal", who under section 2(j) includes the parent or lawful guardian of a child and the lawful guardian of a person with disability, acting on her behalf. After death or incapacity, a nominee may exercise rights under section 14. See section 14.

It lies against "the Data Fiduciary to whom she has previously given consent, including consent as referred to in clause (a) of section 7". The text has two parts.

  • Previously given consent. The right is tied to consent having been given. On a plain reading, it does not extend to a fiduciary that processes her data only under a section 7 use other than clause (a), for example a legal obligation or a State function.
  • Including section 7(a). Section 7(a) is the use where the Data Principal has voluntarily provided her data for a specified purpose and has not indicated that she does not consent. The Act treats that as covered for this right even though no separate consent was sought. See section 7(a) and (b).

The request is to be made "in such manner as may be prescribed". The Act does not state a form, a fee, a time for reply or a mode of delivery for the response. The DPDP Rules, 2025 (notified November 2025) prescribe the detail and different provisions commence on different dates; check the Rules for how the request is made and answered.

What the Data Principal can obtain

(a) Summary of data and processing activities

A summary "of personal data which is being processed" and "the processing activities undertaken" with respect to it. The text asks for a summary, not a copy of every record and not raw files. The summary should tell her what categories and items of data the fiduciary holds and what is done with them, using the actions in section 2(x) such as collection, storage, use and sharing. Note "which is being processed": the wording points to data currently processed.

(b) Identities of other Data Fiduciaries and Data Processors

This is the provision with operational impact. The fiduciary must be able to say who it has shared the data with, including Data Processors, and describe what data was shared. A business needs a live register of recipients: group companies, vendors, payment and logistics partners, cloud and analytics providers. If the register does not exist, this request cannot be answered from memory.

(c) Any other information

Anything related to the personal data and its processing "as may be prescribed". The Act adds nothing itself, so this category only has content to the extent the Rules supply it.

The law-enforcement carve-out: section 11(2)

Clauses (b) and (c) of sub-section (1) do not apply to "the sharing of any personal data by the said Data Fiduciary with any other Data Fiduciary authorised by law to obtain such personal data", where the sharing is:

  • pursuant to a request made in writing by that other Data Fiduciary, and
  • for the purpose of prevention or detection or investigation of offences or cyber incidents, or prosecution or punishment of offences.

All the elements are needed: authorised by law, written request, and the listed purposes. If so, the fiduciary need not disclose that recipient's identity. Note that the carve-out is from clauses (b) and (c) only. Clause (a), the summary of data and processing, still applies. Section 11(2) does not exempt a Data Processor from disclosure, and it does not remove other duties. A business that shares under an oral request, or with someone not authorised by law, cannot rely on it.

Where the right may not apply

  • Section 17(1): Chapter III, which contains section 11, does not apply in the situations listed there, such as enforcing a legal claim or processing by a court. See section 17(1).
  • Section 17(3): the Central Government may notify Data Fiduciaries or classes, including startups, to whom section 11 does not apply. Check for a notification.
  • Section 17(2): the Act does not apply at all to the processing it lists, for example by notified State instrumentalities for security purposes.

Section 11 and the other rights

Section 11 is the first of four rights in Chapter III: access (11), correction and erasure (12), grievance redressal (13) and nomination (14). They are covered together in the overview on rights of the Data Principal. Access is often the first step: a Data Principal checks what is held and then uses section 12 to correct or erase it. See section 12.

Consequence of breach

The Schedule has no separate entry for section 11. Item 7 covers breach of any other provision of the Act or the rules, with a ceiling of fifty crore rupees. A Data Principal who does not get a response can use the grievance mechanism under section 8(10) and section 13, and only after that approach the Board (section 13(3)). The Board acts after an inquiry, a hearing and a finding that the breach is significant (section 33(1)). See penalties.

Practical examples

Example 1: e-commerce customer. A customer asks an online store what it holds. The store gives a summary of the data categories and uses, and lists the payment gateway, courier and analytics vendors to which it disclosed data, describing what each received.

Example 2: police request. An authority authorised by law asks in writing for a customer's transaction data for investigating an offence. The store need not name that authority in response to the customer's access request, by section 11(2). It still gives the summary under clause (a).

Example 3: no recipient list. A company shares data with many tools but has no register. It cannot answer clause (b), which is a process gap to fix before requests arrive.

Common mistakes

  • Treating access as only a copy of one's data, and ignoring the list of recipients.
  • Omitting Data Processors from the answer.
  • Relying on section 11(2) without a written request or legal authority.
  • Not checking whether the processing rests on consent or on another section 7 use.

Need help setting up access request handling?

A workable access process needs a data map, a recipient register and a named owner. Get in touch through our legal consultation service and we can help you design it around your systems.

Key takeaways

  • The right lies against a fiduciary to whom she previously gave consent, including consent under section 7(a).
  • She can obtain a summary of data and processing, and the identities of other Data Fiduciaries and Data Processors with the data shared.
  • Other information is available only as prescribed.
  • Sharing with an authorised recipient on a written law-enforcement request is carved out of (b) and (c).
  • The manner of request and reply is left to the Rules.

Read next

Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.

Quick recapKey facts & short answers

Key Facts About Section 11

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

What can a Data Principal ask for under section 11?

A summary of data processed and processing activities, the identities of others with whom data was shared and a description of it, and any other prescribed information.

Does the right apply if I process data only under a legal obligation?

Section 11 is tied to a Data Fiduciary to whom she previously gave consent, including consent under section 7(a). The text does not mention the other section 7 uses.

Compliance is cheapest on the day it falls due and gets more expensive every day after.

— TaxClue Compliance Desk

Section 11: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

A summary of data processed and processing activities, the identities of others with whom data was shared and a description of it, and any other prescribed information.

Section 11 is tied to a Data Fiduciary to whom she previously gave consent, including consent under section 7(a). The text does not mention the other section 7 uses.

Not where section 11(2) applies: an authorised recipient, a written request and the listed purposes. Clause (a) still applies.

The Act states none in section 11. The manner is prescribed; check the Rules.

Section 2(j) includes the parents or lawful guardian within the Data Principal for a child.

No specific Schedule entry. Item 7 applies, up to fifty crore rupees, subject to section 33.