Saaksh
Blog
How-to30 June 2026·7 min read·Saaksh

How to fill BRSR Principle 9 (Consumer Responsibility)

Principle 9 covers consumer complaints, product recalls, cyber-security and data-privacy policy, data breaches, and product labelling. A guide to answering it from complaints and product records, and to getting the data-breach and DPDP-Act disclosures right.

How to fill BRSR Principle 9 (Consumer Responsibility)

Principle 9 is about the relationship with consumers: complaints, product recalls, cyber-security and data privacy, and product information. With the Digital Personal Data Protection Act 2023 now in force, its data-breach and privacy disclosures have moved from routine to closely watched.

Key takeaways

  • 01Principle 9 covers consumer complaints, product recalls, cyber-security and data-privacy policy, and data breaches.
  • 02It is split between customer service (complaints, recalls) and Legal or IT-security (privacy policy, breaches).
  • 03The data-breach disclosure (P9-E7) is under growing scrutiny under the DPDP Act 2023.
  • 04P9-E2 asks what share of turnover carries environmental, safe-usage and disposal information on the product.

What Principle 9 asks

DisclosureWhat it asksICAI page
P9-E1Mechanisms to receive and respond to consumer complaints and feedback150
P9-E2Share of turnover carrying environmental, safe-usage and disposal information151
P9-E3Consumer complaints by type: data privacy, advertising, cyber-security, quality151
P9-E4Instances of product recalls on account of safety issues152
P9-E5Whether a cyber-security and data-privacy policy exists, with a web link152
P9-E7Data breaches: number, share involving personal information, and impact153

The Leadership indicators cover the channels where product information can be accessed (P9-L1), consumer education on safe usage (P9-L2), and any consumer-satisfaction survey (P9-L4).

Who owns the data

Principle 9 is split between Customer service and Legal/IT

Customer service owns the complaints (P9-E1, P9-E3) and product-recall data (P9-E4); the legal, IT-security or data-protection function owns the cyber-security and data-privacy policy (P9-E5) and the data-breach figures (P9-E7). Send the complaints questions to customer service and the privacy and security questions to Legal or IT.

How to answer the data-breach disclosure (P9-E7)

P9-E7 asks for three things: the number of data-breach instances in the year, the percentage that involved personally identifiable customer information, and the impact of those breaches. Draw it from the information-security incident register, and reconcile it with your breach-notification records. Under the Digital Personal Data Protection Act 2023 this disclosure is read closely, so a nil return should be one you can stand behind, not a default.

Best practice for Principle 9

  • Build data-privacy controls for the Digital Personal Data Protection Act 2023 and comply with the Consumer Protection Act 2019, including transparent labelling.
  • Operate a customer grievance-redressal system and disclose resolution rates.
  • Certify information security to ISO/IEC 27001 and adopt privacy-by-design.
  • Run a product-safety and stewardship management system and track customer-satisfaction metrics.

Frequently asked questions

What does BRSR Principle 9 cover?
Responsible engagement with consumers: mechanisms for consumer complaints (P9-E1), the share of turnover carrying environmental, safe-usage and disposal information (P9-E2), consumer complaints by type including data privacy and cyber-security (P9-E3), product recalls on safety grounds (P9-E4), a cyber-security and data-privacy policy (P9-E5), and data-breach disclosures (P9-E7).
How do I answer the data-breach disclosure (P9-E7)?
P9-E7 asks for the number of data-breach instances in the year, the percentage involving personally identifiable customer information, and their impact. Draw it from the information-security incident register. With the Digital Personal Data Protection Act 2023 in force, this disclosure is under growing scrutiny, so reconcile it with your breach-notification records.
Who owns Principle 9 data?
It is split between customer service, which owns the complaints and recall data, and the legal, IT-security or data-protection function, which owns the cyber-security and data-privacy policy (P9-E5) and the data-breach figures (P9-E7). Route the complaints questions to customer service and the privacy and security questions to legal or IT.

Map Principle 9 alongside the other eight

Saaksh gap-analyses all nine principles, cited to SEBI and ICAI, and shows what your client's records already cover. See a sample report or start a free one.

Try Saaksh free

BRSR gap analysis in under 60 seconds. No login, no data leaves your browser.

Start a free report

Stay ahead of the regulation

SEBI, BRSR, CBAM and CCTS moves that matter, plus the newest guides, in your inbox. No spam.

More from the blog