DPDP glossary

The vocabulary of India’s Digital Personal Data Protection Act, defined plainly.

DPDP Act

The Digital Personal Data Protection Act, 2023 is India's data protection law governing the processing of digital personal data, supported by the Digi

Data Fiduciary

A Data Fiduciary is any person who, alone or with others, determines the purpose and means of processing personal data. The Act's obligations fall pri

Data Processor

A Data Processor is a person who processes personal data on behalf of a Data Fiduciary, under contract and on that fiduciary's documented instructions

Data Principal

A Data Principal is the individual to whom personal data relates. Where the individual is a child it includes the parent or lawful guardian, and where

Data Principal Rights

The rights individuals hold under the DPDP Act: to obtain a summary of their personal data and the processing undertaken, to correction, completion, u

Significant Data Fiduciary

A Data Fiduciary, or class of them, notified as Significant by the Central Government based on factors including the volume and sensitivity of persona

Consent Manager

A Consent Manager is a person registered with the Data Protection Board of India who gives Data Principals a single, accessible, transparent and inter

Consent Management Platform

Software a Data Fiduciary uses to request, record and honour consent for its own processing — presenting the notice, capturing consent with its purpos

Consent

Under the DPDP Act, consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, limited to the perso

Notice

The information a Data Fiduciary must give a Data Principal when seeking consent — what personal data is sought, for what purpose, how to exercise rig

RoPA

A Record of Processing Activities is the documented record of what an organisation does with personal data: each activity, its purpose, the categories

Data Inventory

A record of where personal data lives across an organisation — which databases, object stores, SaaS applications and file shares hold it, and what cat

PII

Personally identifiable information is any data that identifies an individual, directly or in combination with other data. The DPDP Act uses the term

DPIA

A structured assessment of a processing activity that identifies the rights and risks involved for Data Principals and the measures taken to manage th

Data Protection Officer

The individual a Significant Data Fiduciary must appoint to be based in India, be answerable to its board or equivalent governing body, and act as the

Grievance Redressal

The mechanism a Data Fiduciary must make readily available for Data Principals to raise complaints about the processing of their personal data, with r

Data Protection Board of India

The adjudicating body established by the DPDP Act. It inquires into personal data breaches and complaints, directs remedial measures, and imposes fina

Third-Party Risk Management

The process of assessing and monitoring the processors and vendors that handle personal data on your behalf. Under the DPDP Act the Data Fiduciary rem