Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

Section 15 of the Digital Personal Data Protection Act, 2023: Duties of Data Principal

A Data Principal must (a) comply with applicable laws while exercising rights, (b) not impersonate another person when providing data for a specified purpose, (c) not suppress...

Published
Updated
Reading time
7 min
Views
10
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
Topic
Data Protection
Published
September 30, 2026
Last updated
Oct 10, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Section 15 lists five duties of a Data Principal: comply with applicable laws when exercising rights, not impersonate another person, not suppress material information in State-issued identity documents, not file false or frivolous grievances, and furnish only verifiably authentic information when seeking correction or erasure. A breach may attract a penalty up to ten thousand rupees. For how this affects your processes, see our legal consultation service.

The five duties at a glance

ClauseDutyWhere it bites
(a)Comply with all applicable laws for the time being in force while exercising rights under the ActRights requests
(b)Not impersonate another person while providing personal data for a specified purposeSign-ups, KYC-type forms
(c)Not suppress any material information while providing personal data for any document, unique identifier, proof of identity or proof of address issued by the State or its instrumentalitiesState-issued records
(d)Not register a false or frivolous grievance or complaint with a Data Fiduciary or the BoardSections 13 and 27
(e)Furnish only such information as is verifiably authentic, while exercising the right to correction or erasureSection 12 requests

Reading each duty

(a) Comply with applicable laws while exercising rights. The duty is tied to the act of exercising rights under the Act. It means a Data Principal cannot use, say, an erasure request to destroy records that another law requires to be kept or to get around a legal process. The Act does not list the laws.

(b) No impersonation. When giving personal data "for a specified purpose", the Data Principal must not pretend to be someone else. "Specified purpose" is the purpose in the notice (section 2(za)). This protects fiduciaries against fake sign-ups and also the real person whose identity is borrowed.

(c) No suppression of material information for State-issued documents. The duty covers data provided "for any document, unique identifier, proof of identity or proof of address issued by the State or any of its instrumentalities". The word "State" takes the meaning in section 2(zb): the State as defined in article 12 of the Constitution. The duty is on the Data Principal to give complete material information when applying for such documents. It is not a general duty of disclosure to private businesses.

(d) No false or frivolous grievance or complaint. This links to section 13, the grievance route with the fiduciary or Consent Manager, and the Board's inquiry under section 28. Section 28(12) lets the Board, if it is of the opinion that a complaint is false or frivolous, issue a warning or impose costs on the complainant. See section 13. The Act does not define "frivolous"; the Board will decide on the facts.

(e) Only verifiably authentic information for correction or erasure. When she asks for correction or erasure under section 12, what she supplies must be verifiably authentic. This supports a fiduciary that asks for supporting evidence before it changes or deletes a record. See section 12.

Not a defence for the fiduciary

Section 8(1) says a Data Fiduciary is responsible for complying with the Act "irrespective of ... failure of a Data Principal to carry out the duties provided under this Act". So a fiduciary cannot point to a customer's false data or false complaint as an excuse for breaching its own obligations. The duties are separate and run side by side. See section 8(1).

What the duties do give a fiduciary is context: evidence that a request was made in bad faith, or that the data was supplied falsely, is relevant to how the fiduciary acts, for example in asking for proof under section 12 and in answering a complaint.

What the section does not say

  • Who enforces it. Section 15 does not say the fiduciary can itself penalise the Data Principal. The penalty in the Schedule is imposed by the Board under section 33.
  • No duty on consent or on reading the notice. The Act does not require a Data Principal to read the notice or to give consent.
  • No definition of "false or frivolous".
  • No stated consequence other than the penalty. The Act does not say that an account may be closed because of a breach of duties. Whether a contract allows that is a matter of contract law.
  • Nominee and guardians. The section speaks of "a Data Principal". Section 2(j) includes a child's parents or lawful guardian and the lawful guardian of a person with disability as part of the Data Principal, so it is sensible to read the duties as binding them when they act, but the text does not say so separately.

Consequence of breach

Item 5 of the Schedule: breach in observance of the duties under section 15 may extend to ten thousand rupees. This is the lowest amount in the Schedule. The Board imposes the penalty after an inquiry, a hearing and a finding that the breach is significant (section 33(1)), weighing section 33(2) factors, including whether the person realised a gain or avoided a loss. See penalties.

Practical examples

Example 1: fake sign-up. A person registers on a platform using another person's name and details to get a benefit. That is impersonation under clause (b).

Example 2: repeated baseless complaints. A customer files complaint after complaint with the company and the Board, each without any basis. Clause (d) applies, and section 28(12) allows the Board to warn or impose costs.

Example 3: erasure with false proof. A user asks for correction of her date of birth and submits a forged document. Clause (e) requires only verifiably authentic information.

Example 4: incomplete application for an identity document. An applicant hides material information when applying for a State-issued identity proof. Clause (c) applies to that data.

Practical steps for fiduciaries

  • Put a short statement of the duties in your privacy notice or rights page, without overstating them.
  • Decide what evidence you will ask for before correcting or erasing data, so you ask everyone the same thing.
  • Log grievances so that a pattern of baseless complaints can be shown to the Board if needed.
  • Keep your own obligations intact, because the Data Principal's failure does not excuse them.

Need help reflecting this in your processes?

Verification steps for correction and erasure requests, and records of grievances, are easy to get wrong. Our legal consultation team can help you design them so they are fair to Data Principals and defensible before the Board.

Key takeaways

  • Section 15 lists five duties of the Data Principal.
  • They cover lawful exercise of rights, no impersonation, no suppression in State-issued documents, no false or frivolous complaints and authentic information for correction or erasure.
  • The fiduciary's own duties continue despite her failure (section 8(1)).
  • Breach may attract up to Rs 10,000 (Schedule, item 5).
  • The Board imposes the penalty; the fiduciary cannot.

Read next

Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.

Quick recapKey facts & short answers

Key Facts About Section 15

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

What are the duties of a Data Principal?

Five, in section 15(a) to (e): comply with applicable laws, no impersonation, no suppression in State-issued documents, no false or frivolous grievances, and verifiably authentic information for correction or erasure.

What is the penalty for breaching them?

Item 5 of the Schedule: up to ten thousand rupees, imposed by the Board.

Your vendors process data in your name; their lapses become yours.

— TaxClue Data Protection Desk

Section 15: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

Five, in section 15(a) to (e): comply with applicable laws, no impersonation, no suppression in State-issued documents, no false or frivolous grievances, and verifiably authentic information for correction or erasure.

Item 5 of the Schedule: up to ten thousand rupees, imposed by the Board.

The Act gives the penalty power to the Board under section 33. It does not give the fiduciary a power to penalise.

No. Section 8(1) says the fiduciary remains responsible irrespective of the Data Principal's failure of duties.

Section 28(12) allows the Board to issue a warning or impose costs on the complainant.

No. The Board will decide on the facts.