DPDP GLOSSARY

Use the Act’s terms with care.

These short definitions are orientation aids. The Act’s text controls, and legal status depends on the relevant provision’s commencement.

Core terms

Data Fiduciary

A person who, alone or together with others, determines the purpose and means of processing personal data. Possession alone does not settle the role.

Act, section 2(i)

Data Processor

A person who processes personal data on behalf of a Data Fiduciary. Assess the relationship for the relevant processing activity.

Act, section 2(k)

Data Principal

The individual to whom personal data relates. For a child or a person with disability, the definition also includes the parent or lawful guardian acting on that person’s behalf, as provided in the Act. “Citizen” is not a synonym for “individual.”

Act, section 2(j)

Processing

A wholly or partly automated operation or set of operations performed on digital personal data, including collection, recording, storage, use, sharing and erasure.

Act, section 2(x)

Consent Manager

A person registered with the Board for the statutory consent-management role. An organisation’s ordinary consent interface does not by itself make it a Consent Manager.

Act, section 2(g); section 6(7)–(9); Rule 4

Significant Data Fiduciary

A Data Fiduciary or class notified by the Central Government under section 10. Do not infer this status solely from sector, scale or use of AI.

Act, section 10; Rule 13

Personal data

Any data about an individual who is identifiable by or in relation to that data.

Act, section 2(t)

Certain legitimate uses

Section 7 lists specific uses that may be processed without consent under section 4. Check the exact category and conditions; this is not general discretion to use personal data for any business purpose. Sections 4 and 7 are not yet in force on the 23 September 2026 status snapshot.

Act, sections 4 and 7

Notice

Section 5 requires a notice to accompany or precede a request for consent. Rule 3 specifies clear, standalone content, including the personal data and purposes, the goods, services or uses involved, and ways to withdraw consent, exercise rights and complain to the Board. Section 5 and Rule 3 are not yet in force on the status snapshot.

Act, section 5; Rules, Rule 3

Personal data breach

The Act defines this as unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises confidentiality, integrity or availability. Rule 7 requires initial intimation without delay and updated, detailed information to the Board within 72 hours, unless a longer period is allowed. Section 8 and Rule 7 are not yet in force on the status snapshot.

Act, sections 2(u) and 8(6); Rules, Rule 7

Data Protection Board of India

A statutory body established by the Central Government under section 18, which commenced on publication. The Board’s functions, inquiries and penalty process have separate commencement; sections 27–34 are not yet in force on the status snapshot.

Act, sections 18 and 27–34; G.S.R. 843(E)

Data Protection Officer

A notified Significant Data Fiduciary must appoint an individual based in India, responsible to its Board of Directors or similar governing body and serving as a point of contact for grievance redressal. This DPDP duty is not a blanket DPO requirement for every organisation. Section 10 and Rule 13 are not yet in force on the status snapshot.

Act, sections 2(l) and 10(2)(a); Rules, Rule 13

Data Protection Impact Assessment

The Act requires periodic assessment of Data Principals’ rights, processing purposes and risks for a notified Significant Data Fiduciary. Rule 13 gives further requirements. These provisions are not yet in force on the status snapshot and do not establish a blanket DPDP assessment duty for every organisation.

Act, section 10(2)(c)(i); Rules, Rule 13

Grievance response contact

Section 8(9) refers to published business contact information for a Data Protection Officer, if applicable, or another authorised person who can answer questions about processing. Section 8(10) requires an effective grievance-redressal mechanism. Check commencement and any other law that applies; these DPDP duties are not yet in force on the status snapshot.

Act, section 8(9)–(10); Rules, Rule 9

Cross-border transfer

Section 16 empowers the Central Government to restrict transfer to a specified country or territory by notification and preserves stricter requirements under other Indian laws. Rule 15 addresses making data available to a foreign State or an entity under its control; Rule 13(4) adds a condition for certain data specified for a Significant Data Fiduciary. These provisions are not yet in force on the status snapshot.

Act, section 16; Rules, Rules 13(4) and 15

Right to nominate

A Data Principal may nominate another individual to exercise rights under the Act in the event of death or incapacity, subject to the Act and prescribed manner. Section 14 and Rule 14 are not yet in force on the status snapshot. See the rights guide for the other statutory rights.

Act, section 14; Rules, Rule 14

Read the official Act ↗ · Read the Rules ↗

The definition and the duty can have different commencement.

Status snapshot reviewed 23 September 2026. Some definitions commenced earlier than the substantive duties they support. The entries above flag provisions that have not yet commenced; check the official commencement notification and later updates before applying them.

Read the source register →