Rights

DSR Response Timeline

Defined in §11, DPDPA 2023; Rule 14, Rules 2025

The mandatory deadline within which Data Fiduciaries must respond to Data Principal rights requests under DPDPA.

What does “DSR Response Timeline” mean?

Under DPDPA and its Rules, Data Fiduciaries must respond to Data Principal rights requests within prescribed timelines. For access, correction, erasure, and other rights requests under Rule 14(3), the deadline is 90 days from receipt of a valid request. If the Fiduciary cannot comply (e.g., due to a legal retention obligation), they must provide a reasoned refusal within the same timeline.

Why does this matter for your business?

Missing a single 90-day deadline gives the Data Principal grounds to complain to the DPB. At scale, even a 5% miss rate can generate significant regulatory exposure. SLA tracking and escalation workflows are essential.

Real example

A Bengaluru fintech receives an erasure request on March 1st. By May 30th, they must either: (a) confirm deletion is complete, or (b) provide a written response explaining why certain data cannot be deleted (e.g., RBI KYC retention mandate). Silence is non-compliance.

Common misconception

The 90-day clock starts from when you receive the request, not from when you verify the requester's identity. You cannot use lengthy identity verification as a mechanism to extend your response deadline.

Related terms

DPDPA Shield automates Data Principal Rights. See how →