Work / Chitragupt / Wiki / Flows
dpdp-grievance
Flowcanonicalverified 2026-06-26
FLOW.DPDP-GRIEVANCEFlow — DPDP grievance (user-initiated)
Summary
Any user (signed-in or out) files a DPDP §13 grievance via the public form or settings; the system assigns a case ID, kicks off the statutory 30-day SLA, and the admin desk works it to a documented outcome.
Audience
end-user · admin
Entry
Settings → Privacy → "File a grievance" OR public /grievance form (marketing-grievance).
Steps
| # | Step | Surface | Notes |
|---|---|---|---|
| 1 | Public intake | marketing-grievance | DPDP §13 form: kind (erasure / access / correction / portability / withdraw consent / complaint) + body. Copy follows copy-strings |
| 2 | Identity verification | auth-verify-email | Email OTP + PAN last-4; auto-PASS if signed-in session matches |
| 3 | Case ID + ack email | email-dpdp-data-export | Includes case ID + statutory 30-day deadline per data-residency-dpdp |
| 4 | Admin desk receives | admin-grievances | Days-left countdown + auto-escalation rules |
| 5 | Admin action | admin-grievances | Data export / hard delete / anonymise / send response — all audit-logged |
| 6 | Response email sent | email-dpdp-data-export | Outcome + DPDP Board appeal path |
Exit
Grievance closed with outcome documented; user receives a response email with appeal path.
Escapes
- Identity verification fails: form re-prompts; if signed-out user cannot verify, grievance still recorded with limited action surface.
- Admin misses 30-day SLA: auto-escalation tagged in admin-grievances; statutory record preserved.
- Hard delete: post-action, user account closed per 2026-06-10-account-deletion-messaging and 30-day grace window.
- Withdraw consent: subsequent processing paused; see settings-privacy-data.
Sources
- .context/wiki/flows/* § "Flow 9 — DPDP grievance (user-initiated)"
Every project of mine is written down like this.
Read the résumé