DPDP NavigatorAct 2023 · Rules 2025
40 Terms

The DPDP glossary.

Every statutory and operational term you'll run into while reading the Act, the Rules, or this site — explained plainly.

40 of 40 terms

Anonymisation

Security & Incidents

Processing personal data so that no individual can be identified from it by any means reasonably likely to be used. Data that is fully and irreversibly anonymised falls outside the definition of personal data, and therefore outside the Act's scope.

Section 2

Appellate Tribunal

Governance & Enforcement

The tribunal to which a person aggrieved by an order or direction of the Data Protection Board can appeal. The government has designated an existing appellate tribunal to perform this function under the Act.

Breach Intimation

Security & Incidents

A Data Fiduciary's obligation to notify both the affected Data Principals and the Data Protection Board whenever a personal data breach occurs, regardless of its scale. The DPDP Rules set out the required content and timelines for these notifications.

Section 8

Cross-Border Data Transfer

Governance & Enforcement

The Act permits transfer of personal data outside India by default, except to countries that the Central Government specifically restricts by notification - a more permissive approach than requiring a positive list of pre-approved countries.

Section 16

Any unauthorised processing of personal data, or any accidental disclosure, loss, alteration, or access to personal data that compromises its confidentiality, integrity, or availability.

Section 2

Data Fiduciary

Statutory Roles

Any person or organisation that, alone or with others, determines the purpose and means of processing personal data. This is the Act's primary duty-holder, similar in spirit to a 'data controller' under other data protection laws.

Example: A bank that decides why and how it collects and uses customer KYC data is acting as a Data Fiduciary.

Section 2

Data Localisation

Governance & Enforcement

A requirement to store or process certain personal data within India. The DPDP Act takes a comparatively light-touch approach to this, relying mainly on the restricted-country mechanism rather than blanket localisation mandates seen in earlier draft bills.

Section 16

Data Minimisation

Technical & Operational

The principle that a Data Fiduciary should collect and process only the personal data actually necessary for the specified purpose, and nothing more - closely tied to the requirement that consent be limited to necessary data.

Section 6

Data Principal

Statutory Roles

The individual to whom the personal data relates - the person the data is about. Where the individual is a child, or a person with a disability who has a lawful guardian, the parent or guardian exercises rights on their behalf.

Section 2

Data Processing Agreement (DPA)

Technical & Operational

The contract between a Data Fiduciary and a Data Processor setting out the terms on which the Processor handles personal data on the Fiduciary's behalf - a mechanism the Act contemplates as part of a Fiduciary's obligations.

Section 8

Data Processor

Statutory Roles

A person or entity that processes personal data on behalf of a Data Fiduciary, under a contract, and acting on the Fiduciary's instructions rather than deciding independently why or how the data is used.

Example: A cloud provider hosting a company's customer database purely as instructed is typically a Data Processor.

Section 2

Data Protection Board of India

Governance & Enforcement

The independent body established to enforce the Act - it inquires into breaches and complaints, can accept voluntary undertakings, and imposes penalties for non-compliance. It operates as a digital-first tribunal for the matters within its remit.

Section 18

A structured assessment, required of Significant Data Fiduciaries, that documents the risks a processing activity poses to Data Principals' rights and the measures taken to mitigate them, as part of a periodic compliance review.

Section 10

The individual within a Data Fiduciary who acts as the point of contact for Data Principals on questions about their personal data and handles grievances. Significant Data Fiduciaries must appoint a DPO based in India.

Section 8

Personal data that is in digital form, or that was collected in non-digital form and later digitised. This is the actual scope of what the DPDP Act regulates - it does not govern personal data that stays purely offline.

Section 3

Obligations placed on Data Principals alongside their rights, including not impersonating another person, not suppressing material information, not filing false or frivolous grievances, and providing only verifiably authentic information when exercising a right.

Section 15

Extraterritorial Application

Governance & Enforcement

The Act applies not only to processing of digital personal data within India, but also to processing outside India where it is connected to offering goods or services to Data Principals located in India.

Section 3

Grievance Officer

Statutory Roles

For Data Fiduciaries not required to appoint a DPO, a designated Grievance Officer performs the equivalent role - handling Data Principal complaints and queries about how their personal data is processed.

Section 8

Legitimate Use

Core Concepts

A set of specified situations in which a Data Fiduciary may process personal data without obtaining consent - for example, where the Data Principal voluntarily provides data for a stated purpose, for compliance with law, in medical emergencies, or for employment purposes.

Section 7

Notice

Core Concepts

The information a Data Fiduciary must give a Data Principal at or before seeking consent, describing what personal data is collected, why, how to exercise their rights, and how to complain to the Data Protection Board.

Section 5

Personal Data

Core Concepts

Any data about an individual who is identifiable by or in relation to that data. The definition is deliberately broad and covers data in any form, though the Act's obligations are directed at personal data in digital form.

Section 2

Processing

Core Concepts

Any operation or set of operations performed on digital personal data - including collection, recording, storage, use, sharing, disclosure, or erasure - whether carried out by automated means or not.

Section 2

Pseudonymisation

Security & Incidents

Replacing directly identifying details in a data set with artificial identifiers or tokens, so the data cannot be tied to a specific person without additional information held separately. Unlike anonymisation, pseudonymised data is generally still personal data, since re-identification remains possible.

Purpose Limitation

Technical & Operational

The principle that personal data collected for one specified purpose should not be reused for an unrelated purpose without fresh notice and, where required, fresh consent.

Section 5

Reasonable Security Safeguards

Security & Incidents

The technical and organisational measures a Data Fiduciary must implement to prevent personal data breaches, such as encryption, access controls, and monitoring. The DPDP Rules describe baseline expectations, including retaining access logs for a minimum period.

Section 8

Internal documentation a Data Fiduciary maintains listing what personal data it processes, for what purposes, with whom it is shared, and how long it is retained. Though not spelled out as a single named requirement in the Act, it is standard practice for demonstrating compliance with notice, purpose limitation, and security obligations.

Retention Period

Technical & Operational

The length of time a Data Fiduciary keeps personal data before erasure becomes mandatory. Under the DPDP Rules, retention periods can vary by sector and purpose, and erasure is often triggered once a Data Principal stops using a service and does not re-engage within a specified period.

A Data Principal's right to a readily available grievance-resolution mechanism from the Data Fiduciary or Consent Manager. This mechanism must be exhausted before the Data Principal can approach the Data Protection Board.

Section 13

Right to Access

Rights & Duties

A Data Principal's right to obtain a summary of the personal data being processed about them, the processing activities undertaken, and the identities of other Data Fiduciaries and Processors their data has been shared with.

Section 11

Right to Correction

Rights & Duties

A Data Principal's right to request correction of inaccurate or misleading personal data, completion of incomplete data, and updating of personal data held by a Data Fiduciary.

Section 12

Right to Erasure

Rights & Duties

A Data Principal's right to have their personal data erased once it is no longer necessary for the purpose it was collected for, unless retention is required by some other law.

Section 12

Right to Nominate

Rights & Duties

A Data Principal's right to nominate another individual - the nominee - to exercise their rights under the Act in the event of the Data Principal's death or incapacity.

Section 14

Schedule (to the Act)

Governance & Enforcement

The table appended to the DPDP Act listing categories of contravention - such as failing to implement security safeguards or failing to notify a breach - together with the maximum financial penalty the Board can impose for each, without fixing the amount for any particular case.

A Data Fiduciary, or class of Data Fiduciaries, notified by the government for heightened obligations based on factors such as the volume and sensitivity of personal data processed, risk to Data Principals, and potential impact on sovereignty or public order.

Section 10

Storage Limitation

Technical & Operational

The principle that personal data should not be kept for longer than necessary to fulfil the purpose it was collected for, or as required by applicable law, after which it must be erased.

Section 8

Voluntary Undertaking

Governance & Enforcement

A commitment a person offers to the Data Protection Board to take specific compliance steps, which the Board may accept instead of, or alongside, pursuing an inquiry or penalty. Once accepted, it becomes binding on the person who gave it.