Glossary
Key terms and definitions from the Digital Personal Data Protection Act, 2023.
4 min read
A
- Adjudication
- The inquiry process under Sections 18-19 of the DPDPA by which the Data Protection Board determines whether a Data Fiduciary or Data Processor has failed to comply with provisions of the Act, and decides on appropriate penalties. See the adjudication process for procedural details.
- Algorithmic Software Verification
- An obligation under Rule 13 of the DPDP Rules 2025 requiring Significant Data Fiduciaries to periodically verify that their algorithmic software does not pose a risk to the rights of Data Principals. This includes assessing algorithms used for profiling, automated decision-making, and content recommendation.
- Anonymised Data
- Data that has been processed in such a manner that the individual to whom it relates is no longer identifiable. Anonymised data falls outside the scope of the DPDPA since it no longer constitutes personal data. However, the Act does not prescribe a specific anonymisation standard. See personal data scope for the boundary between personal and anonymised data.
- Appellate Tribunal
- The Telecom Disputes Settlement and Appellate Tribunal (TDSAT), designated under Section 29 of the DPDPA as the body to hear appeals against orders of the Data Protection Board. Appeals must be filed within 60 days of the Board's order. See appeals to TDSAT for the appellate process.
B
- Breach Notification
- The obligation under Rule 7 of the DPDP Rules 2025 requiring a Data Fiduciary to notify both the Data Protection Board and affected Data Principals of a personal data breach. The framework requires a preliminary intimation followed by a detailed report within 72 hours. See breach notification requirements.
C
- Child
- An individual who has not completed eighteen years of age, as defined in Section 2(f) of the DPDPA. Processing of a child's personal data requires verifiable parental consent and is subject to additional restrictions including a prohibition on tracking, behavioural monitoring, and targeted advertising directed at children.
- Civil Penalty
- A financial penalty (not criminal) imposed by the Data Protection Board for non-compliance with the DPDPA. Penalties are specified in the Schedule to the Act and range up to Rs 250 crore depending on the nature of the contravention. See the penalties schedule for the full table of amounts.
- Consent
- An agreement given by the Data Principal for the processing of their personal data for a specified purpose. Consent must be free, specific, informed, unconditional, and unambiguous with a clear affirmative action. See the consent framework for detailed requirements.
- Consent Manager
- A person registered with the Data Protection Board who acts as a single point of contact to enable Data Principals to give, manage, review, and withdraw their consent through an accessible, transparent, and interoperable platform. See Consent Manager provisions for registration and obligations.
- Consent Notice
- A notice given by a Data Fiduciary to the Data Principal before or at the time of requesting consent under Section 5 of the DPDPA. It must contain an itemised description of the personal data sought and the purpose of processing. The DPDP Rules 2025 further require this to be a standalone notice independent of terms of service. See privacy notice requirements.
- Cross-Border Data Transfer
- The transfer of personal data by a Data Fiduciary for processing to any territory outside India. Under Section 16 of the DPDPA, transfers are permitted to all countries except those specified in a negative list notified by the Central Government. See cross-border transfer provisions and the practical guide.
D
- Data Auditor
- An independent data auditor appointed under Section 10(2)(c) of the DPDPA by a Significant Data Fiduciary to carry out periodic data protection audits. The auditor evaluates compliance with the Act and the effectiveness of measures implemented to protect personal data.
- Data Fiduciary
- Any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data. Data Fiduciaries bear primary compliance obligations under the DPDPA.
- Data Principal
- The individual to whom the personal data relates. Where such individual is a child, their parent or lawful guardian. Where such individual has a disability, their lawful guardian.
- Data Principal Duties
- Obligations imposed on Data Principals under Section 15 of the DPDPA, including the duty to comply with applicable laws when exercising rights, not to file false or frivolous complaints with the Data Protection Board, not to suppress material information, and not to furnish false particulars or impersonate another person when exercising rights.
- Data Processor
- Any person who processes personal data on behalf of a Data Fiduciary. See the Data Processor role for how obligations flow through contractual arrangements.
- Data Protection Board
- The Data Protection Board of India, established under the Act as the body responsible for determining non-compliance with the provisions of the Act and imposing penalties. See Board structure and powers.
- Data Protection Impact Assessment
- A periodic assessment undertaken by Significant Data Fiduciaries to evaluate the impact of their data processing activities on the rights of Data Principals. Use the DPIA Framework resource for guidance.
- Data Protection Officer
- An individual appointed by a Significant Data Fiduciary who is based in India and represents the Data Fiduciary before the Data Protection Board.
- Data Retention
- The principle under Rule 8 of the DPDP Rules 2025 requiring Data Fiduciaries to erase personal data once the purpose for which it was collected has been fulfilled and retention is no longer necessary. For qualifying platforms with a large user base, a 3-year inactivity threshold applies after which data must be erased unless the Data Principal re-engages. See data retention rules.
- Digital Personal Data
- Personal data that is in digital form, including data collected in non-digital form and subsequently digitized.
E
- Encryption
- A security safeguard mandated under Rule 6 of the DPDP Rules 2025 requiring Data Fiduciaries to encrypt personal data both in transit and at rest. Encryption is one of several reasonable security safeguards that must be implemented to protect personal data from unauthorised access or breach.
- Exemptions
- Categories of processing that are exempt from some or all provisions of the DPDPA under Section 17. These include processing by the State for sovereignty and security purposes, processing necessary for legal proceedings, and processing of publicly available personal data. See exemptions under the Act for the full list and conditions.
G
- Grievance Redressal
- The mechanism established by a Data Fiduciary to address complaints and concerns raised by Data Principals regarding the processing of their personal data. See the grievance redressal mechanism under Rule 14.
L
- Lawful Purpose
- The requirement under Section 4 of the DPDPA that personal data may only be processed for a purpose that is not expressly forbidden by law. A Data Fiduciary must ensure that the purpose of processing is lawful before collecting or using personal data. See Data Fiduciary obligations.
- Legitimate Uses
- Nine lawful bases for processing personal data without the consent of the Data Principal, as specified in Section 7 of the DPDPA. These include processing for employment purposes, voluntary provision of data, public interest, medical emergencies, and compliance with court orders or legal obligations. See legitimate uses for all nine grounds.
N
- Negative List
- A list of countries or territories to which cross-border transfer of personal data is restricted, to be notified by the Central Government under Section 16 of the DPDPA. As of the DPDP Rules 2025, this list has not yet been populated. See the negative list page for current status.
P
- Personal Data
- Any data about an individual who is identifiable by or in relation to such data.
- Personal Data Breach
- Any unauthorized processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction of, or loss of access to personal data that compromises its confidentiality, integrity, or availability. See breach notification requirements under Rule 7.
- Privacy Notice
- A standalone, itemised notice required under Rule 3 of the DPDP Rules 2025 that must be provided to the Data Principal independent of an organisation's terms of service. The notice must describe the personal data being collected, the purpose of processing, and the rights available to the Data Principal. See privacy notice requirements.
- Processing
- In relation to personal data, means an entirely or partly automated operation or set of operations performed on digital personal data, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, alignment, combination, indexing, sharing, disclosure, restriction, erasure, or destruction.
- Purpose Limitation
- The principle under Sections 4 and 6 of the DPDPA that personal data collected for one specified purpose must not be processed for any other purpose without obtaining fresh consent from the Data Principal. This is a foundational obligation for all Data Fiduciaries.
R
- Right to Access
- The right of a Data Principal under Section 11 of the DPDPA to obtain from a Data Fiduciary a summary of their personal data being processed and the processing activities undertaken. See right to access for how to exercise this right.
- Right to Correction and Erasure
- The right of a Data Principal under Section 12 of the DPDPA to request the correction, completion, updating, or erasure of their personal data held by a Data Fiduciary. See correction and erasure for the process and limitations.
- Right to Grievance Redressal
- The right of a Data Principal under Section 13 of the DPDPA to raise a complaint with the Data Fiduciary's grievance redressal mechanism. Rule 14 of the DPDP Rules 2025 mandates a response within a specified time frame. See grievance redressal for the full process.
- Right to Nomination
- The right of a Data Principal under Section 14 of the DPDPA to nominate another individual who may exercise the Data Principal's rights in the event of their death or incapacity. See nomination rights for how this operates.
S
- Security Safeguards
- Reasonable technical and organisational measures required under Rule 6 of the DPDP Rules 2025 to protect personal data. These include encryption, data masking, tokenisation, access controls, monitoring for breaches, and retention of logs for at least one year. See security safeguards for detailed requirements.
- Significant Data Fiduciary
- A Data Fiduciary or class of Data Fiduciaries notified by the Central Government as significant based on assessment of factors such as volume and sensitivity of personal data processed, risk to rights of Data Principals, and potential impact on sovereignty and integrity of India. See SDF designation and obligations.
- Specified Purpose
- The specific purpose for which a Data Fiduciary collects and processes personal data, as declared in the consent notice or identified under a legitimate use ground. Under the DPDPA, processing must be limited to this declared purpose. See the consent framework for how specified purpose operates in practice.
V
- Verifiable Parental Consent
- A higher standard of consent required under Section 9(1) of the DPDPA before processing any personal data of a child. The Data Fiduciary must obtain verifiable consent from the child's parent or lawful guardian before any collection or processing takes place.
- Voluntary Undertaking
- An offer made by a Data Fiduciary to the Data Protection Board during inquiry proceedings under Section 19 of the DPDPA. If the Board accepts the undertaking, it may close the inquiry without imposing a penalty. A breach of the accepted undertaking is treated as a deemed violation. See adjudication process.
Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
