The DPDP glossary.
Every statutory and operational term you'll run into while reading the Act, the Rules, or this site — explained plainly.
Anonymisation
Security & IncidentsProcessing personal data so that no individual can be identified from it by any means reasonably likely to be used. Data that is fully and irreversibly anonymised falls outside the definition of personal data, and therefore outside the Act's scope.
Section 2 →Appellate Tribunal
Governance & EnforcementThe tribunal to which a person aggrieved by an order or direction of the Data Protection Board can appeal. The government has designated an existing appellate tribunal to perform this function under the Act.
Breach Intimation
Security & IncidentsA Data Fiduciary's obligation to notify both the affected Data Principals and the Data Protection Board whenever a personal data breach occurs, regardless of its scale. The DPDP Rules set out the required content and timelines for these notifications.
Section 8 →Consent
Core ConceptsPermission given by a Data Principal for processing of their personal data, which must be free, specific, informed, unconditional, and unambiguous, given through clear affirmative action, and limited to the personal data necessary for the stated purpose.
Section 6 →Consent Manager
Statutory RolesA registered intermediary through which a Data Principal can give, manage, review, and withdraw consent across multiple Data Fiduciaries via a single, accessible, and interoperable platform.
Section 2 →Consent Withdrawal
Core ConceptsA Data Principal's ability to withdraw previously given consent at any time, through a process that must be at least as easy as giving consent was. Once withdrawn, the Data Fiduciary must stop the related processing within a reasonable time, subject to any legal retention requirement.
Section 6 →Cross-Border Data Transfer
Governance & EnforcementThe Act permits transfer of personal data outside India by default, except to countries that the Central Government specifically restricts by notification - a more permissive approach than requiring a positive list of pre-approved countries.
Section 16 →Data Breach / Personal Data Breach
Security & IncidentsAny unauthorised processing of personal data, or any accidental disclosure, loss, alteration, or access to personal data that compromises its confidentiality, integrity, or availability.
Section 2 →Data Fiduciary
Statutory RolesAny person or organisation that, alone or with others, determines the purpose and means of processing personal data. This is the Act's primary duty-holder, similar in spirit to a 'data controller' under other data protection laws.
Example: A bank that decides why and how it collects and uses customer KYC data is acting as a Data Fiduciary.
Section 2 →Data Localisation
Governance & EnforcementA requirement to store or process certain personal data within India. The DPDP Act takes a comparatively light-touch approach to this, relying mainly on the restricted-country mechanism rather than blanket localisation mandates seen in earlier draft bills.
Section 16 →Data Minimisation
Technical & OperationalThe principle that a Data Fiduciary should collect and process only the personal data actually necessary for the specified purpose, and nothing more - closely tied to the requirement that consent be limited to necessary data.
Section 6 →Data Principal
Statutory RolesThe individual to whom the personal data relates - the person the data is about. Where the individual is a child, or a person with a disability who has a lawful guardian, the parent or guardian exercises rights on their behalf.
Section 2 →Data Processing Agreement (DPA)
Technical & OperationalThe contract between a Data Fiduciary and a Data Processor setting out the terms on which the Processor handles personal data on the Fiduciary's behalf - a mechanism the Act contemplates as part of a Fiduciary's obligations.
Section 8 →Data Processor
Statutory RolesA person or entity that processes personal data on behalf of a Data Fiduciary, under a contract, and acting on the Fiduciary's instructions rather than deciding independently why or how the data is used.
Example: A cloud provider hosting a company's customer database purely as instructed is typically a Data Processor.
Section 2 →Data Protection Board of India
Governance & EnforcementThe independent body established to enforce the Act - it inquires into breaches and complaints, can accept voluntary undertakings, and imposes penalties for non-compliance. It operates as a digital-first tribunal for the matters within its remit.
Section 18 →Data Protection Impact Assessment (DPIA)
Security & IncidentsA structured assessment, required of Significant Data Fiduciaries, that documents the risks a processing activity poses to Data Principals' rights and the measures taken to mitigate them, as part of a periodic compliance review.
Section 10 →Data Protection Officer (DPO)
Statutory RolesThe individual within a Data Fiduciary who acts as the point of contact for Data Principals on questions about their personal data and handles grievances. Significant Data Fiduciaries must appoint a DPO based in India.
Section 8 →Digital Personal Data
Core ConceptsPersonal data that is in digital form, or that was collected in non-digital form and later digitised. This is the actual scope of what the DPDP Act regulates - it does not govern personal data that stays purely offline.
Section 3 →Duties of Data Principal
Rights & DutiesObligations placed on Data Principals alongside their rights, including not impersonating another person, not suppressing material information, not filing false or frivolous grievances, and providing only verifiably authentic information when exercising a right.
Section 15 →Extraterritorial Application
Governance & EnforcementThe Act applies not only to processing of digital personal data within India, but also to processing outside India where it is connected to offering goods or services to Data Principals located in India.
Section 3 →Grievance Officer
Statutory RolesFor Data Fiduciaries not required to appoint a DPO, a designated Grievance Officer performs the equivalent role - handling Data Principal complaints and queries about how their personal data is processed.
Section 8 →Legitimate Use
Core ConceptsA set of specified situations in which a Data Fiduciary may process personal data without obtaining consent - for example, where the Data Principal voluntarily provides data for a stated purpose, for compliance with law, in medical emergencies, or for employment purposes.
Section 7 →Notice
Core ConceptsThe information a Data Fiduciary must give a Data Principal at or before seeking consent, describing what personal data is collected, why, how to exercise their rights, and how to complain to the Data Protection Board.
Section 5 →Personal Data
Core ConceptsAny data about an individual who is identifiable by or in relation to that data. The definition is deliberately broad and covers data in any form, though the Act's obligations are directed at personal data in digital form.
Section 2 →Processing
Core ConceptsAny operation or set of operations performed on digital personal data - including collection, recording, storage, use, sharing, disclosure, or erasure - whether carried out by automated means or not.
Section 2 →Pseudonymisation
Security & IncidentsReplacing directly identifying details in a data set with artificial identifiers or tokens, so the data cannot be tied to a specific person without additional information held separately. Unlike anonymisation, pseudonymised data is generally still personal data, since re-identification remains possible.
Purpose Limitation
Technical & OperationalThe principle that personal data collected for one specified purpose should not be reused for an unrelated purpose without fresh notice and, where required, fresh consent.
Section 5 →Reasonable Security Safeguards
Security & IncidentsThe technical and organisational measures a Data Fiduciary must implement to prevent personal data breaches, such as encryption, access controls, and monitoring. The DPDP Rules describe baseline expectations, including retaining access logs for a minimum period.
Section 8 →Record of Processing Activities (ROPA)
Technical & OperationalInternal documentation a Data Fiduciary maintains listing what personal data it processes, for what purposes, with whom it is shared, and how long it is retained. Though not spelled out as a single named requirement in the Act, it is standard practice for demonstrating compliance with notice, purpose limitation, and security obligations.
Retention Period
Technical & OperationalThe length of time a Data Fiduciary keeps personal data before erasure becomes mandatory. Under the DPDP Rules, retention periods can vary by sector and purpose, and erasure is often triggered once a Data Principal stops using a service and does not re-engage within a specified period.
Right of Grievance Redressal
Rights & DutiesA Data Principal's right to a readily available grievance-resolution mechanism from the Data Fiduciary or Consent Manager. This mechanism must be exhausted before the Data Principal can approach the Data Protection Board.
Section 13 →Right to Access
Rights & DutiesA Data Principal's right to obtain a summary of the personal data being processed about them, the processing activities undertaken, and the identities of other Data Fiduciaries and Processors their data has been shared with.
Section 11 →Right to Correction
Rights & DutiesA Data Principal's right to request correction of inaccurate or misleading personal data, completion of incomplete data, and updating of personal data held by a Data Fiduciary.
Section 12 →Right to Erasure
Rights & DutiesA Data Principal's right to have their personal data erased once it is no longer necessary for the purpose it was collected for, unless retention is required by some other law.
Section 12 →Right to Nominate
Rights & DutiesA Data Principal's right to nominate another individual - the nominee - to exercise their rights under the Act in the event of the Data Principal's death or incapacity.
Section 14 →Schedule (to the Act)
Governance & EnforcementThe table appended to the DPDP Act listing categories of contravention - such as failing to implement security safeguards or failing to notify a breach - together with the maximum financial penalty the Board can impose for each, without fixing the amount for any particular case.
Significant Data Fiduciary
Statutory RolesA Data Fiduciary, or class of Data Fiduciaries, notified by the government for heightened obligations based on factors such as the volume and sensitivity of personal data processed, risk to Data Principals, and potential impact on sovereignty or public order.
Section 10 →Storage Limitation
Technical & OperationalThe principle that personal data should not be kept for longer than necessary to fulfil the purpose it was collected for, or as required by applicable law, after which it must be erased.
Section 8 →Verifiable Parental Consent
Rights & DutiesThe requirement that a Data Fiduciary obtain consent from a parent or lawful guardian, verified in the manner prescribed by the DPDP Rules, before processing a child's personal data. Fiduciaries are also barred from behavioural tracking or targeted advertising directed at children.
Section 9 →Voluntary Undertaking
Governance & EnforcementA commitment a person offers to the Data Protection Board to take specific compliance steps, which the Board may accept instead of, or alongside, pursuing an inquiry or penalty. Once accepted, it becomes binding on the person who gave it.