Skip to content
Ritesh FirodiyaGet in touch

Work / Chitragupt / Wiki / Flows

dpdp-grievance

Flowcanonicalverified 2026-06-26

FLOW.DPDP-GRIEVANCE

Flow — DPDP grievance (user-initiated)

Summary

Any user (signed-in or out) files a DPDP §13 grievance via the public form or settings; the system assigns a case ID, kicks off the statutory 30-day SLA, and the admin desk works it to a documented outcome.

Audience

end-user · admin

Entry

Settings → Privacy → "File a grievance" OR public /grievance form (marketing-grievance).

Steps

# Step Surface Notes
1 Public intake marketing-grievance DPDP §13 form: kind (erasure / access / correction / portability / withdraw consent / complaint) + body. Copy follows copy-strings
2 Identity verification auth-verify-email Email OTP + PAN last-4; auto-PASS if signed-in session matches
3 Case ID + ack email email-dpdp-data-export Includes case ID + statutory 30-day deadline per data-residency-dpdp
4 Admin desk receives admin-grievances Days-left countdown + auto-escalation rules
5 Admin action admin-grievances Data export / hard delete / anonymise / send response — all audit-logged
6 Response email sent email-dpdp-data-export Outcome + DPDP Board appeal path

Exit

Grievance closed with outcome documented; user receives a response email with appeal path.

Escapes

  • Identity verification fails: form re-prompts; if signed-out user cannot verify, grievance still recorded with limited action surface.
  • Admin misses 30-day SLA: auto-escalation tagged in admin-grievances; statutory record preserved.
  • Hard delete: post-action, user account closed per 2026-06-10-account-deletion-messaging and 30-day grace window.
  • Withdraw consent: subsequent processing paused; see settings-privacy-data.

Sources

  • .context/wiki/flows/* § "Flow 9 — DPDP grievance (user-initiated)"

Every project of mine is written down like this.

Read the résumé