DPDP Glossary: Every Term in India’s Data Protection Act, Explained

A plain-English glossary of the terms used in India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules — written for the people who actually have to implement them: DPOs, CISOs, compliance leads, founders and engineering teams. Each entry is self-contained, so you can jump straight to the term you need.

If you are starting a DPDP programme, the practical order is: understand the vocabulary here, then run a free DPDP readiness assessment, then work the prioritised gaps. For the statute itself, see our section-by-section DPDP Act explainers.
Breach Notification
The requirement to intimate each affected Data Principal and the Data Protection Board of a personal data breach, in the form and within the timelines prescribed by the DPDP Rules. Indian organisations must also account for the separate CERT-In incident reporting directions, which run on their own clock.
Child (under DPDP)
An individual who has not completed eighteen years of age. Beyond verifiable parental consent, Data Fiduciaries must not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
Consent (DPDP §6)
Under §6, consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the personal data necessary for the specified purpose. Consent requests must be accompanied by a plain-language notice, be available in English or any language in the Eighth Schedule, and be as easy to withdraw as to give.
Consent Artefact
A machine-readable record capturing the parameters of a consent — purpose, data types, duration, the parties involved and the revocation status. Consent artefacts make consent auditable and portable rather than a checkbox buried in a log.
Consent Manager
An entity registered with the Data Protection Board that gives Data Principals a single interface to give, manage, review and withdraw consent. Consent Managers are accountable to the Data Principal and must meet the technical and organisational conditions prescribed under the DPDP Rules.
Consent Withdrawal Propagation
The technical process of carrying a withdrawal signal from the point of capture through every downstream system, processor and backup that holds the data. It is where most consent implementations break, because the collection path is built first and the reversal path is built late or never.
Cross-Border Transfer
Under the DPDP Act, transfer of personal data outside India is permitted except to countries the Central Government restricts by notification. This “negative list” approach is more permissive than GDPR’s adequacy regime, but sectoral rules — notably RBI’s payment data localisation — continue to apply independently.
Data Audit
The periodic independent audit a Significant Data Fiduciary must have conducted by a data auditor to evaluate its compliance with the DPDP Act. The audit is evidence-driven, which is why audit-ready recordkeeping matters more than policy documents alone.
Data Classification
Labelling data by sensitivity and regulatory relevance so that controls, retention and access rules can be applied consistently. Classification lets an organisation apply strong controls where the risk is, rather than uniformly and expensively everywhere.
Data Discovery
The process of finding where personal data actually resides across databases, file stores, SaaS applications and backups. Discovery is what converts a theoretical RoPA into an accurate one, and it is the precondition for honouring erasure requests completely.
Data Fiduciary
Any person who, alone or with others, determines the purpose and means of processing personal data. The Data Fiduciary carries the primary compliance burden under the DPDP Act — notice, consent, security safeguards, breach reporting and rights fulfilment. It is the DPDP counterpart to the GDPR “data controller”.
Data Fiduciary vs Data Controller
Functionally the same role under two laws: the DPDP Act says “Data Fiduciary”, GDPR says “data controller”. The naming difference is deliberate — “fiduciary” signals a duty of care owed to the individual, not merely a lawful basis for processing.
Data Minimisation
The obligation to collect only the personal data necessary for the specified purpose. Under DPDP this is embedded in the definition of valid consent itself, which is limited to data necessary for the stated purpose.
Data Principal
The individual whom the personal data relates to under India’s DPDP Act, 2023. Where the individual is a child, the Data Principal includes the parent or lawful guardian; for a person with a disability, it includes the lawful guardian. This is the DPDP equivalent of the “data subject” in GDPR.
Data Principal Rights
The rights the DPDP Act confers on individuals: the right to access information about processing, the right to correction, completion, updating and erasure, the right to grievance redressal, and the right to nominate another individual to exercise rights in the event of death or incapacity.
Data Processor
A person who processes personal data on behalf of a Data Fiduciary. Processors act only under a valid contract with the Fiduciary, and the Fiduciary remains accountable to the Data Principal regardless of what it outsources.
Data Protection Board of India
The adjudicating body established under the DPDP Act. It investigates personal data breaches and complaints, directs remedial measures, and imposes monetary penalties. It functions as a digital-by-design regulator rather than a rule-making authority — rule-making sits with the Central Government.
Data Protection Officer
The individual a Significant Data Fiduciary must appoint to represent it under the DPDP Act. The DPO must be based in India, report to the board or equivalent governing body, and serve as the contact point for grievance redressal.
Data Retention Schedule
The documented rule set defining how long each category of personal data is kept and what triggers its deletion. Under DPDP, retention beyond the specified purpose requires a legal basis, making the schedule an operational necessity rather than paperwork.
DEPA
Data Empowerment and Protection Architecture — India’s consent-based data-sharing framework, operating through Consent Managers and machine-readable consent artefacts. DEPA interoperability matters for Fiduciaries that need consent to travel between institutions rather than sit in a single silo.
DPDP Gap Assessment
A structured comparison of an organisation’s current state against DPDP Act and Rules obligations, producing a prioritised list of gaps and remediation owners. A gap assessment is normally the first step in a DPDP programme, before tooling decisions are made.
DPDP Readiness Assessment
A scored evaluation of how prepared an organisation is for its DPDP obligations across consent, notice, rights, security, breach, retention and governance. ProtectComply offers a free DPDP readiness assessment that returns a prioritised gap report.
DPDP Rules
The subordinate legislation that operationalises the DPDP Act — prescribing the form of notices, consent-manager conditions, breach intimation, retention periods, verifiable parental consent mechanisms and the phased timelines by which obligations come into force. The Act sets the principles; the Rules set the mechanics and dates.
DPDP vs GDPR
Both regulate personal data through notice, consent, rights and accountability, but they differ in several practical ways: DPDP covers digital personal data only, uses a closed list of “legitimate uses” rather than an open legitimate-interest balancing test, permits cross-border transfer except to restricted countries, and adds a right to nominate. A GDPR programme is a head start on DPDP, not a substitute for it.
DPIA (Data Protection Impact Assessment)
A structured assessment of the rights of Data Principals and the risks posed by a processing activity, along with the measures adopted to manage those risks. Significant Data Fiduciaries must conduct DPIAs periodically; other Fiduciaries commonly adopt them voluntarily for high-risk processing.
Exemptions
Categories of processing to which certain DPDP obligations do not apply — including processing for enforcement of legal rights, judicial functions, prevention and investigation of offences, approved corporate restructuring, and processing of non-residents’ data under foreign contract. Exemptions are specific and narrow; they do not switch off the Act wholesale.
Grievance Redressal
The obligation on every Data Fiduciary and Consent Manager to provide an effective mechanism for Data Principals to raise grievances, and to respond within the period prescribed by the DPDP Rules. Exhausting the Fiduciary’s grievance mechanism is a precondition to complaining to the Data Protection Board.
Legitimate Uses
The set of grounds under the DPDP Act that permit processing without consent — including the voluntary provision of data by the Data Principal for a specified purpose, State functions and benefits, medical emergencies, employment-related purposes, and disaster response. “Legitimate uses” is a closed statutory list, not an open balancing test like GDPR’s legitimate interest.
Notice
The statement a Data Fiduciary must give the Data Principal when seeking consent, describing the personal data sought, the purpose of processing, how to exercise rights, and how to complain to the Data Protection Board. Consent obtained without a compliant notice is not valid consent.
Notice-and-Consent Architecture
The pattern of pairing every consent request with a plain-language notice, capturing the consent as an auditable record, and honouring withdrawal end-to-end. DPDP compliance failures most often occur not at collection but at withdrawal, where downstream systems keep processing.
Penalties under the DPDP Act
Financial penalties set out in the Schedule to the Act, imposed by the Data Protection Board after inquiry. The heaviest tier attaches to failure to take reasonable security safeguards to prevent a personal data breach, with lower tiers for breach-notification failures, children-related obligations, Significant Data Fiduciary obligations and general non-compliance.
Personal Data
Any data about an individual who is identifiable by or in relation to such data. The DPDP Act applies specifically to personal data in digital form — either collected digitally, or collected on paper and subsequently digitised.
Personal Data Breach
Any unauthorised processing, accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability. Every breach must be notified — the DPDP Act contains no materiality threshold that exempts minor breaches.
Processing
A wholly or partly automated operation performed on digital personal data — including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, sharing, dissemination, restriction, erasure or destruction. Almost anything an organisation does with personal data is “processing”.
Purpose-Specific Consent
Consent captured separately for each distinct purpose, rather than a single bundled acceptance. Bundling purposes is one of the most common ways otherwise-valid consent fails the §6 “specific” and “unconditional” tests.
Purpose Limitation
The principle that personal data may be processed only for the specified purpose for which consent was given or the legitimate use applies. Re-purposing data for an unrelated use requires fresh consent.
Reasonable Security Safeguards
The obligation on every Data Fiduciary to protect personal data in its possession or control — including data processed on its behalf — by taking reasonable security safeguards to prevent a breach. Failure to do so attracts the highest penalty tier under the Act.
Right to Access Information
The Data Principal’s right to obtain a summary of the personal data being processed and the processing activities undertaken, the identities of other Fiduciaries and Processors with whom the data has been shared, and a description of the data shared.
Right to Correction and Erasure
The Data Principal’s right to have inaccurate or misleading personal data corrected, incomplete data completed, data updated, and data erased once the specified purpose is no longer being served — unless retention is required by law.
Right to Nominate
The DPDP Act’s distinctive right allowing a Data Principal to nominate another individual to exercise their rights in the event of death or incapacity. It has no direct GDPR equivalent and requires Fiduciaries to build nominee handling into rights workflows.
RoPA (Records of Processing Activities)
The inventory of what personal data an organisation holds, why it is processed, who it is shared with, where it lives and how long it is retained. RoPA is the practical backbone of DPDP compliance: rights fulfilment, breach scoping, retention and audits are all unanswerable without it.
Significant Data Fiduciary
A Data Fiduciary, or class of them, notified by the Central Government based on factors such as volume and sensitivity of data processed, risk to Data Principals, and impact on sovereignty, electoral democracy or public order. An SDF carries heightened obligations: appointing a Data Protection Officer based in India, appointing an independent data auditor, and conducting periodic Data Protection Impact Assessments and audits.
Storage Limitation / Erasure
The requirement to erase personal data once the Data Principal withdraws consent or the specified purpose is no longer served, unless retention is required by law. Fiduciaries must also cause their Processors to erase the corresponding data.
Vendor / Third-Party Risk
The assessment and contractual control of processors and sub-processors handling personal data on the Fiduciary’s behalf. Because accountability does not transfer with the data, weak vendor governance is a direct DPDP exposure for the Fiduciary.
Verifiable Parental Consent (Rule 9)
The obligation to obtain verifiable consent from a parent or lawful guardian before processing the personal data of a child (under 18) or a person with a disability with a lawful guardian. The DPDP Rules prescribe how that verification is to be performed, including reliance on reliable identity or virtual token mechanisms.
Withdrawal of Consent
The Data Principal’s right to withdraw consent at any time, with the ease of withdrawal being comparable to the ease of giving it. On withdrawal, the Data Fiduciary must cease processing and cause its processors to do the same within a reasonable time, unless another lawful ground applies.