Section 15 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 15 lists five duties of a Data Principal: comply with applicable laws when exercising rights, not impersonate another person, not suppress material information in State-issued identity documents, not file false or frivolous grievances, and furnish only verifiably authentic information when seeking correction or erasure. A breach may attract a penalty up to ten thousand rupees. For how this affects your processes, see our legal consultation service.
A Data Principal must (a) comply with applicable laws while exercising rights, (b) not impersonate another person when providing data for a specified purpose, (c) not suppress material information when providing data for a State-issued document, unique identifier or proof of identity or address, (d) not register a false or frivolous grievance or complaint with a Data Fiduciary or the Board, and (e) furnish only verifiably authentic information when exercising the right to correction or erasure. Breach attracts up to Rs 10,000 (Schedule, item 5).
The five duties at a glance
| Clause | Duty | Where it bites |
|---|---|---|
| (a) | Comply with all applicable laws for the time being in force while exercising rights under the Act | Rights requests |
| (b) | Not impersonate another person while providing personal data for a specified purpose | Sign-ups, KYC-type forms |
| (c) | Not suppress any material information while providing personal data for any document, unique identifier, proof of identity or proof of address issued by the State or its instrumentalities | State-issued records |
| (d) | Not register a false or frivolous grievance or complaint with a Data Fiduciary or the Board | Sections 13 and 27 |
| (e) | Furnish only such information as is verifiably authentic, while exercising the right to correction or erasure | Section 12 requests |
Reading each duty
(a) Comply with applicable laws while exercising rights. The duty is tied to the act of exercising rights under the Act. It means a Data Principal cannot use, say, an erasure request to destroy records that another law requires to be kept or to get around a legal process. The Act does not list the laws.
(b) No impersonation. When giving personal data "for a specified purpose", the Data Principal must not pretend to be someone else. "Specified purpose" is the purpose in the notice (section 2(za)). This protects fiduciaries against fake sign-ups and also the real person whose identity is borrowed.
(c) No suppression of material information for State-issued documents. The duty covers data provided "for any document, unique identifier, proof of identity or proof of address issued by the State or any of its instrumentalities". The word "State" takes the meaning in section 2(zb): the State as defined in article 12 of the Constitution. The duty is on the Data Principal to give complete material information when applying for such documents. It is not a general duty of disclosure to private businesses.
(d) No false or frivolous grievance or complaint. This links to section 13, the grievance route with the fiduciary or Consent Manager, and the Board's inquiry under section 28. Section 28(12) lets the Board, if it is of the opinion that a complaint is false or frivolous, issue a warning or impose costs on the complainant. See section 13. The Act does not define "frivolous"; the Board will decide on the facts.
(e) Only verifiably authentic information for correction or erasure. When she asks for correction or erasure under section 12, what she supplies must be verifiably authentic. This supports a fiduciary that asks for supporting evidence before it changes or deletes a record. See section 12.
Not a defence for the fiduciary
Section 8(1) says a Data Fiduciary is responsible for complying with the Act "irrespective of ... failure of a Data Principal to carry out the duties provided under this Act". So a fiduciary cannot point to a customer's false data or false complaint as an excuse for breaching its own obligations. The duties are separate and run side by side. See section 8(1).
What the duties do give a fiduciary is context: evidence that a request was made in bad faith, or that the data was supplied falsely, is relevant to how the fiduciary acts, for example in asking for proof under section 12 and in answering a complaint.
What the section does not say
- Who enforces it. Section 15 does not say the fiduciary can itself penalise the Data Principal. The penalty in the Schedule is imposed by the Board under section 33.
- No duty on consent or on reading the notice. The Act does not require a Data Principal to read the notice or to give consent.
- No definition of "false or frivolous".
- No stated consequence other than the penalty. The Act does not say that an account may be closed because of a breach of duties. Whether a contract allows that is a matter of contract law.
- Nominee and guardians. The section speaks of "a Data Principal". Section 2(j) includes a child's parents or lawful guardian and the lawful guardian of a person with disability as part of the Data Principal, so it is sensible to read the duties as binding them when they act, but the text does not say so separately.
Consequence of breach
Item 5 of the Schedule: breach in observance of the duties under section 15 may extend to ten thousand rupees. This is the lowest amount in the Schedule. The Board imposes the penalty after an inquiry, a hearing and a finding that the breach is significant (section 33(1)), weighing section 33(2) factors, including whether the person realised a gain or avoided a loss. See penalties.
Practical examples
Example 1: fake sign-up. A person registers on a platform using another person's name and details to get a benefit. That is impersonation under clause (b).
Example 2: repeated baseless complaints. A customer files complaint after complaint with the company and the Board, each without any basis. Clause (d) applies, and section 28(12) allows the Board to warn or impose costs.
Example 3: erasure with false proof. A user asks for correction of her date of birth and submits a forged document. Clause (e) requires only verifiably authentic information.
Example 4: incomplete application for an identity document. An applicant hides material information when applying for a State-issued identity proof. Clause (c) applies to that data.
Practical steps for fiduciaries
- Put a short statement of the duties in your privacy notice or rights page, without overstating them.
- Decide what evidence you will ask for before correcting or erasing data, so you ask everyone the same thing.
- Log grievances so that a pattern of baseless complaints can be shown to the Board if needed.
- Keep your own obligations intact, because the Data Principal's failure does not excuse them.
Need help reflecting this in your processes?
Verification steps for correction and erasure requests, and records of grievances, are easy to get wrong. Our legal consultation team can help you design them so they are fair to Data Principals and defensible before the Board.
Key takeaways
- Section 15 lists five duties of the Data Principal.
- They cover lawful exercise of rights, no impersonation, no suppression in State-issued documents, no false or frivolous complaints and authentic information for correction or erasure.
- The fiduciary's own duties continue despite her failure (section 8(1)).
- Breach may attract up to Rs 10,000 (Schedule, item 5).
- The Board imposes the penalty; the fiduciary cannot.
Read next
- Section 12 of the DPDP Act, 2023: right to correction and erasure
- Section 13 of the DPDP Act, 2023: right of grievance redressal
- Section 14 of the DPDP Act, 2023: right to nominate
- Rights of the Data Principal under sections 11 to 14
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
