Skip to content

Data Principal portal

The portal is mobile-first, keyboard/screen-reader operable and available through an assisted route. It does not require a new account where an existing customer account can safely verify the person.

Plain choices:

  • See or change your choices
  • Ask about your personal data
  • Correct or update personal data
  • Ask us to erase personal data
  • Raise a grievance
  • Manage a nominee
  • Track a request

Microcopy: “Choose what you want to do. You will see what information is needed before you submit. If you cannot use this page, call or visit us using the assisted support details below.”

Ask first for an existing customer/application/employee reference or authenticated session. Show why step-up is needed and what is retained. Never reveal whether an account exists before a challenge succeeds. After repeated failure, offer a manual route without confirmshaming.

Error: “We could not verify this request using that method. No request has been lost. Choose another method or ask for assisted support. Reference: IDV-SYN-1042.”

Fields: entity/brand, request type, description, affected product/account reference, preferred language/channel, accessibility need, attachments (optional, warned/redacted), nominee/agent flag, declaration and acknowledgement. The form previews the submission and lets the user save a short-lived encrypted draft.

Acknowledgement:

We received your request on 29 July 2026 at 16:42 IST. Reference RR-SYN-2048. We may ask for more information if we cannot safely identify the record. You can track messages here.

Do not promise a statutory period shorter than the configured source. Show the published grievance response period and any case-specific target as separate labels.

User-facing states are received, identity needed, being reviewed, action with our systems, we need information from you, partly completed, completed, not completed—reason provided and closed. Internal team names, risk scores and connector details remain hidden.

Retention conflict copy:

We erased your marketing profile. We must keep the listed transaction record until 31 March 2032 under the cited record rule. We have restricted it to that purpose. You can raise a grievance if you disagree.

Each purpose shows data, use, recipients, current status, last notice and a withdrawal control at the same navigation depth as grant. Confirmation is neutral:

Withdraw this choice? We will stop the listed processing and send instructions to the named systems and service providers. Some records may be kept where law requires; we will show them.

No retention of consent is implied by a pre-ticked toggle; current status is shown separately from the next action.

Messages and disclosure packages expire, require step-up for high-risk content and are encrypted. Email/SMS carries a generic notification and reference, not the response data. Downloads include an integrity manifest and accessible format; machine-readable export is provided where required by the statutory Consent Manager profile, not mislabeled as a general DPDP portability right.

Rate limit by risk without blocking shared household/branch access. Detect duplicates and offer to link them. Support authorised representatives under customer policy. Staff cannot ask for full Aadhaar/PAN over chat. Attachments are malware-scanned, quarantined, access-limited and deleted per case policy.

  • At 320 px, every action and status remains readable without horizontal page scrolling.
  • A screen reader announces field error, summary and focus target.
  • Withdrawal is no harder to find or complete than grant.
  • A timed-out submission can retry with the same idempotency key and creates one case.
  • A partial result lists completed and lawfully retained categories without exposing third parties.