DPDPA Glossary
50 key terms from the Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025. Every definition cites the exact section of the statute.
DPDPA Guide
- Affirmative Action (Consent) Section 6(1)
- Consent must be signified by a clear affirmative action by the Data Principal. The Data Principal must take a deliberate, positive step to indicate agreement. Silence, pre-ticked boxes, or inactivity do not constitute consent under the Act.
- Algorithmic Accountability Section 10(2)(c) · DPDP Rules, 2025
- A duty on Significant Data Fiduciaries to exercise due diligence so that the algorithmic software they use to process personal data does not pose a risk to Data Principals' rights. The Act itself does not use the phrase 'algorithmic accountability': Section 10(2)(c) lets the Central Government prescribe further SDF measures, and the DPDP Rules, 2025 add this duty. It applies only to entities notified as SDFs; broader concepts of algorithmic transparency or fairness are not imposed.
- Anonymised Data Section 3(a)
- Data that is not personal data within the meaning of Section 2(t). The Act does not apply to data that has been anonymised. The Act does not itself define the standard or process for anonymisation.
- Appellate Tribunal Section 29
- Appeals against orders of the Data Protection Board lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT). Appeals must be filed within sixty days of receipt of the Board's order or direction (Section 29(2)); the Tribunal may admit a late appeal if there was sufficient cause. Further appeals from TDSAT lie to the Supreme Court (Section 29(9), applying Section 18 of the TRAI Act, 1997).
- Breach Notification Section 8(6)
- Upon becoming aware of a personal data breach, a Data Fiduciary must notify the Data Protection Board and each affected Data Principal in such form and manner as may be prescribed. Failure to notify is subject to a penalty of up to ₹200 crore under the Schedule.
- Children's Data Section 9
- Processing personal data of a child (a person under 18 years) requires verifiable consent of the parent or lawful guardian before processing. A Data Fiduciary must not track or monitor children, conduct behavioural targeting of children, or process personal data of children in a manner that may be detrimental to their well-being. Breach attracts a penalty of up to ₹200 crore.
- Consent Section 6
- A freely given, specific, informed, unconditional, and unambiguous indication of the Data Principal's wishes, signified by a clear affirmative action. Consent must be for a specified purpose only. A request for consent must be accompanied or preceded by a notice. Consent must not be bundled with other terms and conditions unrelated to the purpose of processing. Consent is required for all processing unless a deemed consent provision under Section 7 applies.
- Consent Artefact Rule 3(3) of the DPDP Rules, 2025
- A machine-readable record that captures the terms under which consent has been given or withdrawn by a Data Principal through a Consent Manager. The format and required contents of a consent artefact are specified in the DPDP Rules, 2025.
- Consent Manager Section 2(g) and Section 6(7)–(9)
- A person registered with the Data Protection Board who acts as a single point of contact through which a Data Principal may give, manage, review, and withdraw consent given to Data Fiduciaries. Consent Managers are subject to obligations prescribed by the Central Government.
- Cross-Border Data Transfer Section 16
- A Data Fiduciary may transfer personal data to countries outside India, except to countries notified by the Central Government under Section 16(1). The Central Government may, by notification, restrict or impose conditions on transfer to specific countries. As of April 2026, the restricted countries notification has not been issued. The Act does not impose data localisation.
- Data Audit Section 10(2)(b)
- A periodic audit conducted by an independent data auditor appointed by a Significant Data Fiduciary to assess compliance with the Act and Rules. The obligation to undergo a data audit applies only to Significant Data Fiduciaries.
- Data Fiduciary Section 2(i)
- Any person who, alone or in conjunction with other persons, determines the purpose and means of processing of personal data. Includes the State, companies, juristic entities, and individuals. A Data Fiduciary bears the primary compliance obligations under the Act.
- Data Fiduciary Obligations Section 8
- General obligations applicable to all Data Fiduciaries: (a) ensuring personal data is complete, accurate, and consistent with purpose (Section 8(3)); (b) implementing reasonable security safeguards (Section 8(5)); (c) notifying the Board and affected Data Principals of any personal data breach (Section 8(6)); and (d) erasing personal data when the purpose is served or consent is withdrawn (Section 8(7)).
- Data Minimisation Section 6(1)
- Personal data collected and processed must be limited to what is necessary for the specified purpose for which consent was obtained. The phrase 'data minimisation' is not used in the Act; the obligation arises from Section 6(1), which limits consent to such personal data as is necessary for the specified purpose.
- Data Principal Section 2(j)
- The individual to whom personal data relates. Where the individual is a child, the term includes the parents or lawful guardian of that child. The Act confers rights — access, correction, erasure, nomination, and grievance redressal — exclusively on Data Principals.
- Data Processing Agreement Section 8(2)
- A Data Fiduciary must ensure that a Data Processor processes personal data only for the purpose specified by the Data Fiduciary pursuant to a valid contract. The Act uses the term 'contract' — Data Processing Agreement is the industry label for this statutory contract. The contract must restrict the Processor to processing only as instructed by the Data Fiduciary.
- Data Processor Section 2(k)
- Any person who processes personal data on behalf of a Data Fiduciary. A Data Processor acts only under the instructions of the Data Fiduciary pursuant to a valid contract. The Data Fiduciary remains responsible for ensuring the Processor complies with the Act.
- Data Protection Board of India Section 18
- A quasi-judicial body established by the Central Government under Section 18 of the Act. The Board may receive and adjudicate complaints from Data Principals, inquire into breaches on receipt of a breach intimation, complaint, government reference or court direction, issue directions to Data Fiduciaries, and impose monetary penalties within the statutory limits prescribed in the Schedule. Appeals against Board orders lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
- Data Protection Impact Assessment Section 10(2)(c)(i)
- A periodic assessment that a Significant Data Fiduciary must conduct to evaluate the risk to the rights of Data Principals arising from the processing of personal data. The frequency, scope, and process of the assessment are to be prescribed by the Central Government. Mandatory only for Significant Data Fiduciaries.
- Data Protection Officer Section 10(2)(a)
- An individual appointed by a Significant Data Fiduciary who serves as the point of contact for the grievance redressal mechanism and for the Data Protection Board. Must be resident in India. Appointment of a DPO is mandatory only for Significant Data Fiduciaries — general Data Fiduciaries are not required to appoint a DPO under the Act.
- De-identified Data Section 17(2)(b)
- Personal data from which a Data Fiduciary has removed the means by which the data can be attributed to a specific Data Principal. The Act does not define the term. The nearest provision is Section 17(2)(b): the Act does not apply to processing necessary for research, archiving or statistical purposes, provided the data is not used to take a decision specific to a Data Principal and prescribed standards are followed — de-identification is the practical route to meeting that condition.
- Deemed Consent Section 7
- Processing for which the Data Principal's separate consent is not required. The 2023 Act calls these 'certain legitimate uses' — 'deemed consent' was the 2022 draft's term. Section 7 specifies nine exhaustive circumstances: (a) data voluntarily provided for a specified purpose, (b) the State providing subsidies, benefits, services, certificates, licences or permits, (c) State functions under law, or in the interest of sovereignty and security, (d) a legal obligation to disclose information to the State, (e) compliance with a judgment, decree or order, (f) a medical emergency, (g) medical treatment or health services during an epidemic or public-health threat, (h) safety and assistance during a disaster or breakdown of public order, and (i) employment-related purposes. This list is exhaustive.
- Digital Personal Data Section 2(n)
- Personal data in digital form. Includes personal data that was originally collected in non-digital form and subsequently digitised. The Act applies only to digital personal data.
- Duties of Data Principal Section 15
- A Data Principal must not: (a) impersonate another person while providing personal data, (b) suppress material information or provide false particulars while providing personal data for documents or identifiers, (c) register false or frivolous complaints with the Board, or (d) furnish false particulars or impersonate another person when providing personal data for any purpose. Breach of duties attracts a penalty of up to ₹10,000.
- Erasure Obligation Section 8(7)
- A Data Fiduciary must erase personal data as soon as the purpose for which it was collected is no longer being served by its retention, unless retention is required under any law in force. Upon withdrawal of consent by the Data Principal, the Data Fiduciary must also cause the Data Processor to erase the data.
- Exemptions Section 17
- The Act exempts specified processing from its provisions, including: processing by notified State instrumentalities in the interests of sovereignty, security of the State, public order, or prevention of incitement to offences (Section 17(2)(a)); processing for prevention, detection, investigation or prosecution of offences (Section 17(1)(c)); and processing for research, archiving, or statistical purposes with prescribed safeguards (Section 17(2)(b)). The Central Government may by notification exempt Data Fiduciaries or classes of Data Fiduciaries from specified provisions (Section 17(3) and (5)).
- Inquiry Section 28
- The Board may inquire into a breach on receipt of a complaint from a Data Principal, an intimation of a personal data breach, a reference from the Central or a State Government, or a direction of a court (Section 27(1), read with Section 28(2)); the Act confers no suo motu power. The Board must first record that there are sufficient grounds to proceed, and must give the person against whom the inquiry is conducted an opportunity to be heard before imposing any penalty or direction.
- Monetary Penalty Section 33 and the Schedule
- The Board may impose a monetary penalty on a Data Fiduciary or Data Processor found to have breached the Act, after completing an inquiry and giving the person an opportunity to be heard. Penalties are subject to the statutory maximums in the Schedule. There is no arithmetic formula for calculating penalties — the Board exercises full discretion within the Schedule caps after considering the Section 33(2) factors.
- Negative List Section 16(1)
- The list of countries to which transfer of personal data is restricted, to be notified by the Central Government under Section 16(1). 'Negative List' is the industry label for this anticipated regulatory instrument — the term does not appear in the Act. As of April 2026, this notification has not been issued.
- Notice Section 5
- Before seeking consent, or at the time of seeking consent, a Data Fiduciary must provide the Data Principal with a notice in clear and plain language describing: (a) the personal data to be collected, (b) the purpose of processing, (c) the manner in which the Data Principal may exercise their rights under the Act, and (d) the manner in which a complaint may be made to the Board.
- Penalty Schedule Schedule (appended to the Act)
- The Schedule prescribes statutory maximum penalties by breach category: security safeguards failure (Section 8(5)) — up to ₹250 crore; breach notification failure (Section 8(6)) — up to ₹200 crore; children's data obligations breach (Section 9) — up to ₹200 crore; Significant Data Fiduciary obligations breach (Section 10) — up to ₹150 crore; Data Principal duties breach (Section 15) — up to ₹10,000; breach of voluntary undertaking (Section 32) — up to original breach cap; breach of any other Act or Rules provision — up to ₹50 crore.
- Personal Data Section 2(t)
- Any data about an individual who is identifiable by or in relation to such data. The Act applies to processing of digital personal data. The Act does not create tiered categories of personal data — all personal data is governed under the same framework.
- Personal Data Breach Section 2(u)
- Any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data, that compromises the confidentiality, integrity, or availability of personal data.
- Processing Section 2(x)
- An automated operation or set of operations performed on digital personal data. Includes collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment, combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure, or destruction.
- Processing by the State Section 7(b) and (c)
- Two of the Section 7 legitimate uses are specific to the State and its instrumentalities: (b) providing or issuing to the Data Principal a subsidy, benefit, service, certificate, licence or permit as may be prescribed — where she has previously consented to such processing by the State, or the data is already held in a government database notified by the Central Government; and (c) performing any function under any law in force in India, or acting in the interest of the sovereignty and integrity of India or the security of the State. Such processing does not require prior consent from the Data Principal. Legal disclosure obligations and court orders (Section 7(d)–(e)) and medical emergencies or epidemics (Section 7(f)–(g)) are separate legitimate uses open to any Data Fiduciary, not only the State.
- Publicly Available Data Section 3(c)(ii)
- Personal data that the Data Principal has themselves made publicly available, or that another person is legally obliged to make public. Under Section 3(c)(ii) the Act does not apply to such data at all — it is an exclusion from the Act, not a Section 7 legitimate use. The exclusion covers only data the Data Principal voluntarily made public — accidental or unauthorised disclosure does not bring data within it.
- Purpose Limitation Section 6 and Section 8(7)
- Personal data may only be processed for the specified purpose for which consent was obtained (Section 6). Once that purpose is served, the data must be erased (Section 8(7)). The phrase 'purpose limitation' does not appear in the Act; the obligation arises from reading Sections 6 and 8(7) together.
- Right to Access Information Section 11
- A Data Principal may request a Data Fiduciary to provide: (a) a summary of personal data being processed and the processing activities undertaken, and (b) the identities of all Data Processors and other Data Fiduciaries with whom personal data has been shared. The Data Fiduciary must respond within the period prescribed by the Central Government.
- Right to Correction and Erasure Section 12
- A Data Principal may request a Data Fiduciary to: (a) correct inaccurate or misleading personal data, (b) complete incomplete personal data, (c) update personal data, and (d) erase personal data — which the Data Fiduciary must do unless retention is necessary for the specified purpose or for compliance with any law (Section 12(3)). The duty to erase data when consent is withdrawn, or once the specified purpose is no longer served, arises separately under Section 8(7)(a).
- Right to Grievance Redressal Section 13
- A Data Principal may make a complaint to the Data Fiduciary's grievance redressal mechanism. If the complaint is not resolved within the period prescribed by the Central Government, the Data Principal may escalate the complaint to the Data Protection Board.
- Right to Nominate Section 14
- A Data Principal may nominate another individual who, in the event of the Data Principal's death or incapacity to exercise their rights, will exercise the rights of the Data Principal under the Act. The manner of nomination is to be prescribed by the Central Government.
- Section 33(2) Factors Section 33(2)
- Before imposing a penalty, the Board must consider: (a) nature, gravity, and duration of the breach; (b) type and nature of personal data affected; (c) repetitive nature of the breach; (d) financial gain realised or loss avoided by the Data Fiduciary due to the breach; (e) timeliness and effectiveness of mitigation action taken; (f) whether the penalty is proportionate and effective for observance and deterrence; and (g) likely impact of the penalty on the person.
- Security Safeguards Section 8(5)
- A Data Fiduciary must implement appropriate technical and organisational measures to prevent personal data breaches. The Act uses the phrase 'reasonable security safeguards.' Failure to implement reasonable security safeguards is subject to a penalty of up to ₹250 crore under the Schedule.
- Significant Data Fiduciary Section 10
- A Data Fiduciary notified by the Central Government based on its assessment of factors including: volume and sensitivity of personal data processed, risk to rights of Data Principals, risk to sovereignty and national security, risk to public order, and risk to electoral democracy. SDFs are subject to additional obligations under Section 10(2).
- Significant Data Fiduciary Obligations Section 10(2)
- In addition to general Data Fiduciary obligations, a Significant Data Fiduciary must: (a) appoint a Data Protection Officer resident in India; (b) appoint an independent data auditor; (c) undertake periodic Data Protection Impact Assessments; (d) undertake periodic data audits; and (e) publish algorithmic accountability standards.
- State and its Instrumentalities Section 2(zb) and Section 7
- Section 2(zb) defines the 'State' as the State as defined under article 12 of the Constitution — the Act does not itself list the bodies covered. The State and its instrumentalities may process personal data without separate consent for the State-specific legitimate uses in Section 7(b) and (c). The Central Government may by notification exempt the State or its instrumentalities from specified provisions of the Act.
- Unconditional Consent Section 6(1)
- One of the required attributes of valid consent under Section 6(1). Consent must not be conditional on acceptance of any other terms or conditions. Consent obtained as a condition of receiving a service is conditional and does not meet the statutory standard.
- Verifiable Parental Consent Section 9(1) and Rule 10 of the DPDP Rules, 2025
- Before processing personal data of a child, a Data Fiduciary must verify that the individual is a child and obtain verifiable consent of the parent or lawful guardian. The mechanism for verifying the age of the child and the identity of the parent or guardian is prescribed in Rule 10 of the DPDP Rules, 2025.
- Voluntary Undertaking Section 32
- A person against whom proceedings are pending before the Board may offer a voluntary undertaking to take specific remedial action. The Board may accept such undertaking and stay the proceedings. Breach of an accepted voluntary undertaking is subject to a penalty up to the statutory maximum applicable to the original breach.
- Withdrawal of Consent Section 6(4)
- A Data Principal may withdraw consent at any time. Withdrawal must be as easy as giving consent. Withdrawal does not affect the lawfulness of processing carried out based on consent before its withdrawal. The Data Principal must bear any consequential effects of withdrawing consent.
A
B
C
D
E
I
M
N
P
R
S
U
V
W
Statutory reference note: All definitions are sourced from the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. Section numbers cited are those of the Act unless stated otherwise. This glossary is for educational reference only and does not constitute legal advice. Consult a qualified lawyer for compliance guidance.
Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Know your DPDPA risk in 3–5 minutes
Check My Readiness →