Data Principal Rights Portal
Every rights request, verified, fulfilled and proven.
One portal for access, correction, erasure, nomination and grievances, in your brand and on your domain. Each request is verified, routed to the right owners, closed with evidence and answered well inside the time the law allows.
Trusted by leading enterprises
Every request in. Every answer on record.
People raise requests wherever they meet you. Each one ends as a verified, evidenced answer.
- Your website
- Your app
- Branch and call centre
- Consent preference centre
- Grievance channel
- Identity verified
- Every system holding the person's data
- Tickets to data owners
- Replies from your domain
- Closure certificate
- Board-ready export
90 days is the ceiling, not the target
90 days
The most the Rules allow. Your published timeline becomes the clock, and settings can't exceed the law
7 · 3 · 1
Days' warning before a clock runs out, so the DPO hears before the person does
1 certificate
For every closed request, with every step behind it on record
Five steps from request to proof
What the rights portal does for you
Erasure that respects retention law
Not every record can be erased on request. PMLA, RBI and SEBI rules often require keeping data for years. Here a system can decline erasure with its legal citation. The request closes as partly fulfilled, and the person is told what stays, why, and until when. That's what Section 12(3) asks for.
A process nobody can weaken
The steps are fixed by the Act. Automation can be switched on or off at each step, but identity checks can't be removed, and no setting can promise slower than the law allows. The process your auditor reviews is the process that runs.
Your brand, your domain
The person wrote to you, so you answer. The portal runs on your domain, in your colours. Every reply goes out from your sending domain, carrying your Data Protection Officer's contact. DataSurity's name appears nowhere the person looks.
One queue for everyone who acts
Data owners get one list: rights requests to fulfil and consent withdrawals to carry out, from every module. They close each with evidence. The DPO sees every clock, every overdue item and every exemption waiting for approval.
What the Act asks, and how the Rights Portal answers
Every request type maps to a section of the Act, and nothing in the product goes beyond it.
- s.11
A summary of the person's data, how it's used, and everyone it's shared with
Access requests assembled from every system and recipient, with the consent history
- s.12
Correction, completion, updating and erasure
Tickets to each system's owner, closed with evidence
- s.12(3)
Erasure unless the law requires retention
Exemptions with legal citations, and a partly fulfilled outcome explained to the person
- s.13
Grievances answered within the published time, before any complaint to the Board
Grievance threads with clocks, escalation and the Board line on closure
- s.14
Nominating someone to act on death or incapacity
Nomination requests recorded against the person
- s.8(9), s.8(10)
Published contact and a working grievance mechanism
DPO contact on the portal and every reply
- s.6(4)
Withdrawal as easy as giving consent
Withdrawals on the same portal, carried out through the Consent module
- s.9
Children's rights exercised by a parent or guardian
Requests about children flagged and routed for guardian handling
What the Rights Portal draws on
- Consent ManagementThe person sees and withdraws their consents on the same portal, and their consent history answers access requests.
- Data Discovery & ClassificationFindings show which systems hold a person's data, so no copy is missed.
- Data Journey MappingSystems and recipients per activity tell each request where to go and whom to name.
Deploy it your way
Built for regulated Indian enterprises: your data stays where your policies say it must.
- 01
SaaS, hosted in India
Managed by SARC AI on infrastructure in Indian data centres.
- 02
Private cloud
Runs in your own cloud account, under your keys and access policies.
- 03
On-premises
Installed in your data centre. Scanners read in place, and nothing leaves your network.
Connects to
PostgreSQL
MySQL
Oracle Database
Microsoft SQL Server
MongoDB
MariaDB
- IDIBM Db2
SAP HANA
Snowflake
Amazon Redshift
Google BigQuery
Databricks
Teradata
Amazon DynamoDB
Azure SQL
Apache Cassandra
Redis
Elasticsearch
Couchbase
ClickHouse
Apache Hive
Apache Kafka
SQLite
Neo4j
Connectors are enabled during onboarding. Logos belong to their owners and indicate compatibility, not endorsement.
Certified
Frequently asked questions
How long do we have to respond?
The Rules allow up to 90 days for rights requests and grievances. You publish your own timeline, and that becomes the clock on every request. DataSurity won't let a setting exceed what the law allows, and warns the DPO seven, three and one day before any clock runs out.
Which rights does the DPDP Act give?
Access to a summary of your data, how it's used and who it's shared with. Correction, completion, updating and erasure. A grievance channel. And nomination of someone to act for you. Data portability is a GDPR right and isn't in the DPDP Act, so we don't sell it as one.
How do you verify the person asking?
By an OTP to an email address or mobile number you already hold for them. Nothing is shown or changed before that. Their identifiers are stored as one-way fingerprints, and any time a staff member reveals a person's details, the reveal is logged.
What if the law requires us to keep the data?
The system owner marks it exempt and picks the legal citation, such as PMLA or an RBI retention rule. The DPO approves. The request closes as partly fulfilled, and the person is told what was erased, what stays, why, and until when.
When can a person complain to the Data Protection Board?
Only after using your grievance channel and not getting a resolution within your published time. That makes your grievance process the front line. A logged, timed, answered grievance is the best protection against a complaint reaching the Board at all.
Will our customers see DataSurity's name?
No. The portal runs on your domain and in your brand. Replies go from your own sending domain, signed with your DPO's contact. The person deals with you from start to finish.
Trusted by leaders across industries
“We knew patient data sat in our hospital information system. We didn't know how much had spread into lab exports, scanned reports and shared drives until DataSurity's assessment showed us. The team understood hospital realities, from paediatric records to staff data, and gave us a plan we could actually run. Implementation is now moving ward by ward, with consent and rights handled in one place.”
Rakesh G
Head - Compliance, KDSG Hospitals (350-bed multispecialty hospital)





