18,000 fans. One grievance email. Zero privacy policy.

A fan in Jowai sent an email with the subject line DPDPA grievance — fan data deletion request, citing Section 11 of the Digital Personal Data Protection Act 2023, and asked for everything: a list of all personal data held, an audit of every third-party share, and full erasure. Badaplin had forty-eight hours to respond before the clock toward a Data Protection Board complaint started running.

18,000 fans. One grievance email. Zero privacy policy.

🎸 Badaplin, 27, dream-pop and indie-folk songwriter in Laitumkhrah, Shillong — 95k Instagram, 12k Spotify monthly listeners, Bandcamp, Khasi + English songs, solo with friend collaborators.

🚨 The problem

The DPDPA 2023 defines a "data fiduciary" under Section 2(i) as any person who determines the purpose and means of processing personal data. Badaplin's 18,000-member Telegram fan group had a pinned message asking members to send their email and phone number for newsletter access and early single drops — no privacy notice, no consent record, no withdrawal mechanism, no DPO. That made her a data fiduciary with 6,400 data subjects and zero compliance infrastructure. Under Section 11, every one of those data subjects has the right to know what data she holds on them, the right to erasure, and the right to a grievance response. Under Section 33, the penalty for failing to observe data fiduciary obligations ranges from ₹50 lakh to ₹250 crore depending on the breach. The fan's email was polite, specific, and legally accurate. The last line said: If I do not receive a response within the prescribed period, I intend to file a complaint with the Data Protection Board of India under Section 28.

🚀 How GabFORGE helped

  • Named the exact DPDPA sections in play: Section 4 (applicability to solo creators, no size threshold), Section 6 (consent notice requirements — data type, purpose, withdrawal mechanism, grievance contact), Section 8 (data fiduciary obligations — security, accuracy, erasure, grievance response), Section 11 (data principal rights), Section 33 (penalty schedule).
  • Drafted a Section 11-compliant grievance acknowledgement that stopped the Data Protection Board complaint clock — Badaplin sent it within two hours of the agent's response.
  • Walked through the Google Sheet audit: 6,400 rows, one row located for the complainant, no third-party sharing confirmed, deletion done and documented.
  • Drafted a Section 6-compliant privacy notice for the Telegram group — pinned and sent to all 18,000 members the same week.

✅ The outcome

Grievance resolved within 48 hours. No Data Protection Board complaint filed. Section 6-compliant privacy notice sent to 18,000 members. New data collection requests now link to the notice. Retention policy in place: inactive entries deleted on a rolling 12-month basis. Badaplin's drummer, a Bengaluru SaaS engineer who works on DPDPA compliance platforms, sat at the table in Laitumkhrah while the agent ran — which is how most of this country's compliance knowledge travels, between friends, on a Saturday morning, over tea.

🇮🇳 Why this matters

The DPDPA applies to every Indian creator who collects personal data — regardless of size, revenue, or whether they think of themselves as a business. There is no small-operator exemption in Section 4. The estimated 80 lakh Indian creators who earn meaningful income from audiences are also, in most cases, unregistered data fiduciaries: Telegram groups, WhatsApp lists, Mailchimp newsletters, Notion signup forms, Google Sheets. All of it personal data. All of it subject to Section 11 rights from the Act's commencement. The Data Protection Board is not yet fully operational — but the complaint portal exists, the jurisdiction is explicit, and the penalty schedule under Section 33 runs to ₹250 crore. The creator who resolves the first grievance before it reaches the Board is in a very different position from the one who learns about DPDPA compliance during a formal inquiry.

Read the full story →