Grievance officer under the DPDP Act: who needs one, and how to appoint them
Every data fiduciary — effectively every Indian business that handles personal data — must give people a readily available way to raise data grievances and must publish the contact details of the person who answers them. It doesn't have to be a lawyer or a new hire. Only Significant Data Fiduciaries have the extra obligation of appointing a Data Protection Officer based in India.
Of all the DPDP Act's obligations, the grievance mechanism is the cheapest to set up and the most visible when it's missing. It's also the front door of the whole law: a person must route their complaint through you before they can escalate to the Data Protection Board of India. Here's exactly what's required and how to get it done this week.
What the Act actually requires
Two related duties sit on every data fiduciary:
- A grievance channel. Data principals must have a "readily available means" of registering a grievance about how you handle their personal data — and you must respond within the timelines prescribed under the rules.
- A published contact. Your privacy notice must tell people how to reach the person able to answer questions about their data — commonly titled the grievance officer — typically a name or designation plus an email address, published on your website and in your notice.
The escalation order matters: the Act expects a data principal to exhaust your grievance process first before approaching the Data Protection Board. A working grievance channel is therefore your chance to fix problems privately, before they become a regulator's case file.
Grievance officer vs Data Protection Officer — don't confuse the two
These get mixed up constantly:
- The grievance/contact function applies to all data fiduciaries, from a two-person agency to a listed company.
- A Data Protection Officer (DPO) is an additional, senior appointment required only for Significant Data Fiduciaries — a category the government notifies based on factors like the volume and sensitivity of data processed and risk to data principals. The DPO must be based in India, represent the fiduciary before the Data Protection Board, and answer to the board of directors or similar governing body. SDFs also face periodic audits and data protection impact assessments.
If you're an SME and haven't been notified as an SDF, you need the first, not the second. If you process large volumes of personal data — especially health, financial or children's data — plan as though the SDF bar may reach you.
Who should you appoint?
The Act doesn't prescribe qualifications for the grievance role. In practice, the right person is whoever can actually move your data, because most grievances end in an action: find my record, correct it, delete it, tell me what you hold. That usually means:
- In a startup or SME: a founder, COO or operations head.
- In a mid-size company: a compliance or customer-experience manager with authority over the CRM and core systems.
- What to avoid: appointing someone senior in title but with no access — a grievance officer who has to file internal tickets to get a record deleted will blow through your response timelines.
What the role handles day to day
Expect four kinds of requests, and build a simple playbook for each:
1. Access requests
"What data do you hold about me?" You need to search every system where the person might exist — CRM, billing, support desk, marketing lists — and produce a summary.
2. Correction requests
"My number/address is wrong." Correct it everywhere, not just in the system the person happens to know about.
3. Erasure requests
"Delete my data." The hardest one. If a customer exists as five inconsistent duplicates across your CRM and spreadsheets, you will miss copies — which is why data cleansing and data discovery are the real preparation for this role.
4. Consent withdrawal
"Stop using my data for marketing." Withdrawal must be as easy as the consent was, and it must actually propagate to your tools.
Setting it up: the checklist
- Name the person (or designation) and get their sign-off on the responsibility.
- Create a dedicated channel — e.g. privacy@yourcompany.in — that more than one person can monitor.
- Publish the contact in your privacy notice and website footer.
- Write the four playbooks (access, correction, erasure, withdrawal) with target turnaround times.
- Map where personal data lives so requests can actually be completed — this is the step most businesses skip.
- Log every grievance — date received, action taken, date closed — so you can prove your process worked.
- Test it quarterly: file a dummy erasure request and time how long it takes to complete.
Not sure where you stand?
Take our free, 2-minute DPDP Readiness Scorecard — answer 12 questions and get a per-area gap report showing exactly what to fix first.
How Ronin Works helps
We set up the grievance function end to end: the published contact and notice language, the four request playbooks, and — the part most consultants skip — the data mapping and cleanup that make requests answerable at all. When a deletion request arrives, your officer should be able to find every copy of that person in minutes, not weeks.
Keep reading
- DPDP Act 2023: a practical compliance checklist for Indian businesses
- DPDP Act penalties: what "₹250 crore per instance" actually means
- What to do after a data breach — Saaph's guide for the people your grievance officer will hear from
The DPDP Act gives individuals rights too. Saaph.in — a Ronin Works product — finds where your personal data is exposed across the open web and gets it removed under the Act, then keeps watch.
Scan your exposure at Saaph.in →Need help setting up your grievance process?
Send us a note — we reply within one working day.
This article is general information, not legal advice. The DPDP Act's rules and enforcement timeline are determined by the Government of India and may change. For a formal assessment of your obligations, consult a qualified professional or talk to Ronin Works.