4 min read

DPDP Act Access Rights Expose Fragmented CRM and HR Records, miniOrange Reports

miniOrange notes that Sections 11 and 12 of the DPDP Act require organizations to locate fragmented data across CRM and third-party systems to fulfill Data Subject Access Requests.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

What Happened

India CSR reported on a miniOrange analysis detailing operational obligations under the Digital Personal Data Protection Act, 2023. The publication evaluates Data Subject Access Requests and specific statutory duties connected to Data Principal rights. Retrieving this information presents distinct hurdles. Compliance exposes fragmented data records scattered across CRM platforms, HR databases, and third-party vendor systems. Organizations often fail to locate personal information across these separate internal networks. Solving this fragmentation remains a direct legal requirement for fiduciaries handling personal data. Establishing clear organizational workflows grants Data Principals greater data control.

Does The DPDP Act Apply Here

Section 3 of the Act applies to the processing of digital personal data within India. It covers processing outside the country if the activity involves offering goods or services to Data Principals in India. This jurisdictional scope captures large volumes of customer records held by domestic and foreign entities. The mandate extends to information collected digitally or digitized later. Physical server location is irrelevant. Data residing in a legacy core banking system or a modern cloud architecture falls under this framework. Fiduciaries remain fully accountable for the information they collect.

Legal Implications Under DPDP

Section 4 sets consent as the primary basis for processing, except where Section 7 legitimate uses apply. Once a fiduciary establishes a lawful purpose, specific statutory obligations attach. Section 11(1)(a) through (c) grants Data Principals the right to access their personal data. Individuals can request a summary of the data alongside the identities of all involved Data Fiduciaries and Data Processors. Section 12(1) and (2) adds the right to demand correction, updating, or erasure of those records. Fulfilling these requests requires internal coordination. General Counsels need to review limitation of liability clauses immediately. Fiduciaries hold ultimate responsibility for how their processors execute retrieval and erasure commands.

Could This Happen To You

Commercial organizations frequently operate with siloed IT architecture. Customer data spans a primary transaction system, an outsourced customer support vendor, and multiple legacy databases. An individual submitting an erasure request forces the company to locate every instance of that record. A third-party processor might fail to delete the file. Liability rests on the Data Fiduciary when that happens. An ensuing complaint triggers a Data Protection Board of India inquiry. The regulatory body expects documented DSAR workflows and executed processor contracts. Board members examine audit logs proving the deletion cascaded through all connected systems. Lacking these artifacts destroys legal defensibility and exposes the company to financial penalties.

What Companies Should Do In The Next 30 Days

1. Legal teams should initiate a review of all major processor contracts to establish explicit DSAR response service level agreements and clear indemnity allocations.

2. Compliance officers need to map the exact locations of personal data across CRM, HR, and external broker platforms.

3. Privacy professionals and IT departments have to finalize a documented process for handling Section 11 access requests and Section 12 erasure demands.

4. Fiduciaries need to implement a standardized verification protocol to confirm the identity of the Data Principal making the request before releasing any information.

What To Watch

Legal teams should monitor how the Data Protection Board of India staffs its enforcement divisions. Organizations need to integrate the operational mechanics and timelines specified strictly in the Digital Personal Data Protection Rules, 2025 into their existing compliance workflows. Fiduciaries cannot rely on manual data retrieval processes as request volumes scale. Evaluate your current vendor contracts to confirm they cover downstream erasure duties. Test your current defensibility against these statutory requirements at freescan.complydp.com.

Sources

Frequently asked questions

How does the DPDP Act address personal data scattered across multiple systems?

The Act holds the Data Fiduciary accountable for fulfilling access and erasure requests regardless of where the data lives. General Counsels have to ensure vendor contracts include strict turnaround timelines so third-party processors comply with downstream deletion commands.

Do organizations need a separate DSAR process for employee and customer data?

No, the framework is the same. The DPDP Act applies to all digital personal data processed in India. HR databases and customer CRM platforms both contain personal data subject to Section 11 access rights and Section 12 erasure rights.

What evidence will the DPBI demand if a company misses a DSAR deadline?

The Data Protection Board of India will request your documented DSAR workflow. Board members also require identity verification records and processor audit logs. Missing these artifacts limits your legal defensibility and increases penalty exposure.

What is the primary basis for processing personal data under the DPDP Act?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Organizations have to maintain verifiable records of this consent to defend against regulatory inquiries.

Who is responsible for fulfilling data erasure requests if a third party processes the information?

The Data Fiduciary holds the ultimate responsibility. Companies need to contractually obligate their Data Processors to execute deletion commands and provide audit logs confirming the action.