Back to Key Provisions
Definitions and Key Concepts
Understand the foundational definitions in the Digital Personal Data Protection Act, 2023 - including Data Principal, Data Fiduciary, personal data, and processing.
10 min read
Why Definitions Matter
The Digital Personal Data Protection Act, 2023 (DPDPA) establishes a comprehensive set of definitions in Section 2 that form the interpretive backbone of the entire statute. These definitions determine who falls within the Act's scope, what activities are regulated, and how obligations are assigned across the data processing chain.
Unlike many international counterparts, the DPDPA deliberately limits its scope to digital personal data. This design choice narrows the Act's regulatory surface while ensuring coverage of the vast majority of modern data processing activities.
Personal Data (Section 2(t))
"Personal data" means any data about an individual who is identifiable by or in relation to such data. The definition has two essential elements:
1. The data must relate to a natural person (not a company or other legal entity)
2. That person must be identifiable - either directly from the data itself or in combination with other available information
The Act applies exclusively to digital personal data - data that is collected in digital form, or collected in non-digital form and subsequently digitised. Purely offline paper records that are never converted to digital form fall outside the Act's scope.
Data that has been anonymised such that the individual is no longer identifiable is generally outside the scope. However, the Act does not provide a detailed anonymisation standard, leaving this to evolve through Board guidance and industry practice.
Data Principal (Section 2(j))
The "Data Principal" is the individual to whom the personal data relates. This is the person whose rights the Act seeks to protect. In the case of a child (under 18), the lawful guardian is considered the Data Principal for the purposes of consent. For a person with a disability, the lawful guardian acts as Data Principal as prescribed under the Rules.
The concept of Data Principal aligns with the GDPR's "data subject" but uses distinctly Indian terminology. The choice of the word "Principal" emphasises the fiduciary relationship - the individual entrusts their data to the Fiduciary, who holds a position of trust.
Data Fiduciary (Section 2(i))
A "Data Fiduciary" is any person (including a company, firm, association, or the State) who alone or in conjunction with others determines the purpose and means of processing of personal data. This is the entity that bears primary compliance obligations under the Act.
Key characteristics:
• The determination of purpose (why data is processed) is the decisive factor
• Joint determination creates joint Fiduciary status
• Both private sector entities and government bodies can be Data Fiduciaries
• The designation is activity-based, not entity-based - the same organisation may be a Fiduciary for some processing and a Processor for other processing
The fiduciary concept draws from Indian trust law, implying a higher standard of care than a mere contractual obligation. This is a deliberate legislative choice that underpins the entire regulatory framework.
Data Processor (Section 2(k))
A "Data Processor" is any person who processes personal data on behalf of a Data Fiduciary. Unlike the GDPR, the DPDPA does not impose direct statutory obligations on Data Processors. Instead, the Data Fiduciary remains responsible for ensuring its Processors comply through contractual arrangements.
This approach simplifies the regulatory landscape but places a heavier burden on Data Fiduciaries to conduct due diligence and maintain adequate vendor agreements. The DPDP Rules further clarify the contractual obligations expected between Fiduciaries and Processors.
Processing (Section 2(x))
"Processing" in relation to personal data means a wholly or partly automated operation or set of operations performed on digital personal data. The definition includes:
• Collection, recording, and organisation
• Structuring, storage, and adaptation
• Retrieval, use, and alignment
• Disclosure by transmission or dissemination
• Restriction, erasure, and destruction
This is an expansive definition that covers virtually any operation performed on personal data in digital form. Even merely storing data constitutes processing and triggers the Act's obligations.
Other Important Definitions
Consent Manager (Section 2(g)): A person registered with the Data Protection Board who acts as a single point of contact for Data Principals to manage consent across multiple Fiduciaries.
Data Protection Board of India (Section 2(c)): The regulatory body established under the Act to adjudicate complaints and impose penalties.
Significant Data Fiduciary (Section 2(z)): A Data Fiduciary designated by the Central Government based on factors like volume and sensitivity of data processed, with enhanced compliance obligations.
Data Protection Officer (Section 2(l)): An individual appointed by a Significant Data Fiduciary, based in India, to represent the Fiduciary and serve as the point of contact for the Board and Data Principals.
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
