DPDPA Glossary

50 key terms from the Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025. Every definition cites the exact section of the statute.

ABCDEFGHIJKLMNOPQRSTUVWXYZ
A
Affirmative Action (Consent)
Section 6(1)
Consent must be signified by a clear affirmative action by the Data Principal. The Data Principal must take a deliberate, positive step to indicate agreement. Silence, pre-ticked boxes, or inactivity do not constitute consent under the Act.
Algorithmic Accountability
Section 10(2)(c) · DPDP Rules, 2025
A duty on Significant Data Fiduciaries to exercise due diligence so that the algorithmic software they use to process personal data does not pose a risk to Data Principals' rights. The Act itself does not use the phrase 'algorithmic accountability': Section 10(2)(c) lets the Central Government prescribe further SDF measures, and the DPDP Rules, 2025 add this duty. It applies only to entities notified as SDFs; broader concepts of algorithmic transparency or fairness are not imposed.
Anonymised Data
Section 3(a)
Data that is not personal data within the meaning of Section 2(t). The Act does not apply to data that has been anonymised. The Act does not itself define the standard or process for anonymisation.
Appellate Tribunal
Section 29
Appeals against orders of the Data Protection Board lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT). Appeals must be filed within sixty days of receipt of the Board's order or direction (Section 29(2)); the Tribunal may admit a late appeal if there was sufficient cause. Further appeals from TDSAT lie to the Supreme Court (Section 29(9), applying Section 18 of the TRAI Act, 1997).
B
Breach Notification
Section 8(6)
Upon becoming aware of a personal data breach, a Data Fiduciary must notify the Data Protection Board and each affected Data Principal in such form and manner as may be prescribed. Failure to notify is subject to a penalty of up to ₹200 crore under the Schedule.
C
Children's Data
Section 9
Processing personal data of a child (a person under 18 years) requires verifiable consent of the parent or lawful guardian before processing. A Data Fiduciary must not track or monitor children, conduct behavioural targeting of children, or process personal data of children in a manner that may be detrimental to their well-being. Breach attracts a penalty of up to ₹200 crore.
Cross-Border Data Transfer
Section 16
A Data Fiduciary may transfer personal data to countries outside India, except to countries notified by the Central Government under Section 16(1). The Central Government may, by notification, restrict or impose conditions on transfer to specific countries. As of April 2026, the restricted countries notification has not been issued. The Act does not impose data localisation.
D
Data Audit
Section 10(2)(b)
A periodic audit conducted by an independent data auditor appointed by a Significant Data Fiduciary to assess compliance with the Act and Rules. The obligation to undergo a data audit applies only to Significant Data Fiduciaries.
Data Fiduciary
Section 2(i)
Any person who, alone or in conjunction with other persons, determines the purpose and means of processing of personal data. Includes the State, companies, juristic entities, and individuals. A Data Fiduciary bears the primary compliance obligations under the Act.
Data Fiduciary Obligations
Section 8
General obligations applicable to all Data Fiduciaries: (a) ensuring personal data is complete, accurate, and consistent with purpose (Section 8(3)); (b) implementing reasonable security safeguards (Section 8(5)); (c) notifying the Board and affected Data Principals of any personal data breach (Section 8(6)); and (d) erasing personal data when the purpose is served or consent is withdrawn (Section 8(7)).
Data Minimisation
Section 6(1)
Personal data collected and processed must be limited to what is necessary for the specified purpose for which consent was obtained. The phrase 'data minimisation' is not used in the Act; the obligation arises from Section 6(1), which limits consent to such personal data as is necessary for the specified purpose.
Data Principal
Section 2(j)
The individual to whom personal data relates. Where the individual is a child, the term includes the parents or lawful guardian of that child. The Act confers rights — access, correction, erasure, nomination, and grievance redressal — exclusively on Data Principals.
Data Processing Agreement
Section 8(2)
A Data Fiduciary must ensure that a Data Processor processes personal data only for the purpose specified by the Data Fiduciary pursuant to a valid contract. The Act uses the term 'contract' — Data Processing Agreement is the industry label for this statutory contract. The contract must restrict the Processor to processing only as instructed by the Data Fiduciary.
Data Processor
Section 2(k)
Any person who processes personal data on behalf of a Data Fiduciary. A Data Processor acts only under the instructions of the Data Fiduciary pursuant to a valid contract. The Data Fiduciary remains responsible for ensuring the Processor complies with the Act.
Data Protection Board of India
Section 18
A quasi-judicial body established by the Central Government under Section 18 of the Act. The Board may receive and adjudicate complaints from Data Principals, inquire into breaches on receipt of a breach intimation, complaint, government reference or court direction, issue directions to Data Fiduciaries, and impose monetary penalties within the statutory limits prescribed in the Schedule. Appeals against Board orders lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
Data Protection Impact Assessment
Section 10(2)(c)(i)
A periodic assessment that a Significant Data Fiduciary must conduct to evaluate the risk to the rights of Data Principals arising from the processing of personal data. The frequency, scope, and process of the assessment are to be prescribed by the Central Government. Mandatory only for Significant Data Fiduciaries.
Data Protection Officer
Section 10(2)(a)
An individual appointed by a Significant Data Fiduciary who serves as the point of contact for the grievance redressal mechanism and for the Data Protection Board. Must be resident in India. Appointment of a DPO is mandatory only for Significant Data Fiduciaries — general Data Fiduciaries are not required to appoint a DPO under the Act.
De-identified Data
Section 17(2)(b)
Personal data from which a Data Fiduciary has removed the means by which the data can be attributed to a specific Data Principal. The Act does not define the term. The nearest provision is Section 17(2)(b): the Act does not apply to processing necessary for research, archiving or statistical purposes, provided the data is not used to take a decision specific to a Data Principal and prescribed standards are followed — de-identification is the practical route to meeting that condition.
Digital Personal Data
Section 2(n)
Personal data in digital form. Includes personal data that was originally collected in non-digital form and subsequently digitised. The Act applies only to digital personal data.
Duties of Data Principal
Section 15
A Data Principal must not: (a) impersonate another person while providing personal data, (b) suppress material information or provide false particulars while providing personal data for documents or identifiers, (c) register false or frivolous complaints with the Board, or (d) furnish false particulars or impersonate another person when providing personal data for any purpose. Breach of duties attracts a penalty of up to ₹10,000.
E
Erasure Obligation
Section 8(7)
A Data Fiduciary must erase personal data as soon as the purpose for which it was collected is no longer being served by its retention, unless retention is required under any law in force. Upon withdrawal of consent by the Data Principal, the Data Fiduciary must also cause the Data Processor to erase the data.
Exemptions
Section 17
The Act exempts specified processing from its provisions, including: processing by notified State instrumentalities in the interests of sovereignty, security of the State, public order, or prevention of incitement to offences (Section 17(2)(a)); processing for prevention, detection, investigation or prosecution of offences (Section 17(1)(c)); and processing for research, archiving, or statistical purposes with prescribed safeguards (Section 17(2)(b)). The Central Government may by notification exempt Data Fiduciaries or classes of Data Fiduciaries from specified provisions (Section 17(3) and (5)).
I
Inquiry
Section 28
The Board may inquire into a breach on receipt of a complaint from a Data Principal, an intimation of a personal data breach, a reference from the Central or a State Government, or a direction of a court (Section 27(1), read with Section 28(2)); the Act confers no suo motu power. The Board must first record that there are sufficient grounds to proceed, and must give the person against whom the inquiry is conducted an opportunity to be heard before imposing any penalty or direction.
M
Monetary Penalty
Section 33 and the Schedule
The Board may impose a monetary penalty on a Data Fiduciary or Data Processor found to have breached the Act, after completing an inquiry and giving the person an opportunity to be heard. Penalties are subject to the statutory maximums in the Schedule. There is no arithmetic formula for calculating penalties — the Board exercises full discretion within the Schedule caps after considering the Section 33(2) factors.
N
Negative List
Section 16(1)
The list of countries to which transfer of personal data is restricted, to be notified by the Central Government under Section 16(1). 'Negative List' is the industry label for this anticipated regulatory instrument — the term does not appear in the Act. As of April 2026, this notification has not been issued.
Notice
Section 5
Before seeking consent, or at the time of seeking consent, a Data Fiduciary must provide the Data Principal with a notice in clear and plain language describing: (a) the personal data to be collected, (b) the purpose of processing, (c) the manner in which the Data Principal may exercise their rights under the Act, and (d) the manner in which a complaint may be made to the Board.
P
Penalty Schedule
Schedule (appended to the Act)
The Schedule prescribes statutory maximum penalties by breach category: security safeguards failure (Section 8(5)) — up to ₹250 crore; breach notification failure (Section 8(6)) — up to ₹200 crore; children's data obligations breach (Section 9) — up to ₹200 crore; Significant Data Fiduciary obligations breach (Section 10) — up to ₹150 crore; Data Principal duties breach (Section 15) — up to ₹10,000; breach of voluntary undertaking (Section 32) — up to original breach cap; breach of any other Act or Rules provision — up to ₹50 crore.
Personal Data
Section 2(t)
Any data about an individual who is identifiable by or in relation to such data. The Act applies to processing of digital personal data. The Act does not create tiered categories of personal data — all personal data is governed under the same framework.
Personal Data Breach
Section 2(u)
Any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data, that compromises the confidentiality, integrity, or availability of personal data.
Processing
Section 2(x)
An automated operation or set of operations performed on digital personal data. Includes collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment, combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure, or destruction.
Processing by the State
Section 7(b) and (c)
Two of the Section 7 legitimate uses are specific to the State and its instrumentalities: (b) providing or issuing to the Data Principal a subsidy, benefit, service, certificate, licence or permit as may be prescribed — where she has previously consented to such processing by the State, or the data is already held in a government database notified by the Central Government; and (c) performing any function under any law in force in India, or acting in the interest of the sovereignty and integrity of India or the security of the State. Such processing does not require prior consent from the Data Principal. Legal disclosure obligations and court orders (Section 7(d)–(e)) and medical emergencies or epidemics (Section 7(f)–(g)) are separate legitimate uses open to any Data Fiduciary, not only the State.
Publicly Available Data
Section 3(c)(ii)
Personal data that the Data Principal has themselves made publicly available, or that another person is legally obliged to make public. Under Section 3(c)(ii) the Act does not apply to such data at all — it is an exclusion from the Act, not a Section 7 legitimate use. The exclusion covers only data the Data Principal voluntarily made public — accidental or unauthorised disclosure does not bring data within it.
Purpose Limitation
Section 6 and Section 8(7)
Personal data may only be processed for the specified purpose for which consent was obtained (Section 6). Once that purpose is served, the data must be erased (Section 8(7)). The phrase 'purpose limitation' does not appear in the Act; the obligation arises from reading Sections 6 and 8(7) together.
R
Right to Access Information
Section 11
A Data Principal may request a Data Fiduciary to provide: (a) a summary of personal data being processed and the processing activities undertaken, and (b) the identities of all Data Processors and other Data Fiduciaries with whom personal data has been shared. The Data Fiduciary must respond within the period prescribed by the Central Government.
Right to Correction and Erasure
Section 12
A Data Principal may request a Data Fiduciary to: (a) correct inaccurate or misleading personal data, (b) complete incomplete personal data, (c) update personal data, and (d) erase personal data — which the Data Fiduciary must do unless retention is necessary for the specified purpose or for compliance with any law (Section 12(3)). The duty to erase data when consent is withdrawn, or once the specified purpose is no longer served, arises separately under Section 8(7)(a).
Right to Grievance Redressal
Section 13
A Data Principal may make a complaint to the Data Fiduciary's grievance redressal mechanism. If the complaint is not resolved within the period prescribed by the Central Government, the Data Principal may escalate the complaint to the Data Protection Board.
Right to Nominate
Section 14
A Data Principal may nominate another individual who, in the event of the Data Principal's death or incapacity to exercise their rights, will exercise the rights of the Data Principal under the Act. The manner of nomination is to be prescribed by the Central Government.
S
Section 33(2) Factors
Section 33(2)
Before imposing a penalty, the Board must consider: (a) nature, gravity, and duration of the breach; (b) type and nature of personal data affected; (c) repetitive nature of the breach; (d) financial gain realised or loss avoided by the Data Fiduciary due to the breach; (e) timeliness and effectiveness of mitigation action taken; (f) whether the penalty is proportionate and effective for observance and deterrence; and (g) likely impact of the penalty on the person.
Security Safeguards
Section 8(5)
A Data Fiduciary must implement appropriate technical and organisational measures to prevent personal data breaches. The Act uses the phrase 'reasonable security safeguards.' Failure to implement reasonable security safeguards is subject to a penalty of up to ₹250 crore under the Schedule.
Significant Data Fiduciary
Section 10
A Data Fiduciary notified by the Central Government based on its assessment of factors including: volume and sensitivity of personal data processed, risk to rights of Data Principals, risk to sovereignty and national security, risk to public order, and risk to electoral democracy. SDFs are subject to additional obligations under Section 10(2).
Significant Data Fiduciary Obligations
Section 10(2)
In addition to general Data Fiduciary obligations, a Significant Data Fiduciary must: (a) appoint a Data Protection Officer resident in India; (b) appoint an independent data auditor; (c) undertake periodic Data Protection Impact Assessments; (d) undertake periodic data audits; and (e) publish algorithmic accountability standards.
State and its Instrumentalities
Section 2(zb) and Section 7
Section 2(zb) defines the 'State' as the State as defined under article 12 of the Constitution — the Act does not itself list the bodies covered. The State and its instrumentalities may process personal data without separate consent for the State-specific legitimate uses in Section 7(b) and (c). The Central Government may by notification exempt the State or its instrumentalities from specified provisions of the Act.
U
V
Voluntary Undertaking
Section 32
A person against whom proceedings are pending before the Board may offer a voluntary undertaking to take specific remedial action. The Board may accept such undertaking and stay the proceedings. Breach of an accepted voluntary undertaking is subject to a penalty up to the statutory maximum applicable to the original breach.
W
Statutory reference note: All definitions are sourced from the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. Section numbers cited are those of the Act unless stated otherwise. This glossary is for educational reference only and does not constitute legal advice. Consult a qualified lawyer for compliance guidance.

Free Download

The Complete DPDPA Compliance Guide

Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.

Download Free

Know your DPDPA risk in 3–5 minutes

Check My Readiness →