DPDP Act 2023 Glossary: 20 Key Terms Explained in Plain English (2026 Guide)

Last Updated: July 7, 2026 Reading Time: 10 minutes Author: Saurabh Gupta, CISM, CIPP/E For: Founders · Compliance Teams · Legal · IT Leaders
DPDP Act 2023 glossary of key terms – Data Fiduciary, Data Principal, DPBI, Consent Manager, DPIA definitions with DPBI shield DPDP ACT 2023 Glossary of Key Terms Data Fiduciary · Data Principal · DPBI · Consent Manager · DPIA Definitions Quick Answers Section References Roles & Parties Compliance Terms
What this page is for: A single, quotable reference for every core DPDP Act 2023 term — Data Fiduciary, Data Principal, DPBI, Consent Manager, DPIA, and 15 more. Each definition is written to stand on its own: read it, understand it, cite it. For implementation guidance, see our DPDP Compliance Checklist or book a free gap assessment.

The DPDP Act 2023 introduces a specific vocabulary that doesn’t map cleanly onto GDPR or other frameworks many Indian compliance teams already know — a “Data Fiduciary” is not quite a “Data Controller,” and a “Significant Data Fiduciary” designation carries obligations with no direct GDPR equivalent. Getting these terms right matters: they determine who is legally responsible for what, which obligations apply to your organisation, and how you should be describing your own compliance posture to customers, auditors, and regulators.

This glossary defines 20 terms in plain English, each with the exact statutory hook (Section or Rule reference) where relevant, so you can go from “what does this mean” to “where is this in the Act” in one page.

Core Terms

Data Fiduciary

Quick answer: A Data Fiduciary is any person or organisation that, alone or with others, decides the purpose and means of processing personal data — roughly equivalent to a “Data Controller” under GDPR. Under Section 2(i) of the DPDP Act 2023, this is the entity that carries the primary legal obligations: obtaining consent, providing notice, securing the data, and responding to Data Principal rights requests.

Every organisation that collects and decides how to use personal data of Indian residents — a hospital, a SaaS company, an NGO, a school — is a Data Fiduciary for that data, regardless of size or sector. A single entity can be a Data Fiduciary for its own customers’ data and simultaneously a Data Processor for a client’s end-user data, depending on the relationship.

Data Principal

Quick answer: A Data Principal is the individual whose personal data is being processed — the person GDPR would call a “Data Subject.” Under Section 2(j), where the individual is a child, their parent or lawful guardian acts on their behalf as the Data Principal; where the individual has a disability, their lawful guardian acts similarly.

Every customer, patient, employee, student, donor, or app user whose data an organisation processes is a Data Principal, holding the specific rights described in the Act — access, correction, erasure, grievance redressal, and nomination.

Data Processor

Quick answer: A Data Processor is any person or organisation that processes personal data on behalf of a Data Fiduciary, under a contract, without deciding the purpose or means of that processing. Under Section 2(k), the Data Fiduciary remains primarily accountable to the Data Principal, but Section 8 requires a written Data Processing Agreement (DPA) between the two.

Cloud hosting providers, payroll vendors, customer support platforms, and marketing tools acting purely on a client’s instructions are typically Data Processors. If a vendor starts using that data for its own separate purposes — training its own models, for example — it may become an independent Data Fiduciary instead, which changes the legal analysis considerably.

Personal Data

Quick answer: Personal Data is any data about an individual who is identifiable by or in relation to that data. Under Section 2(t), the DPDP Act applies only to personal data in digital form, or non-digital data that is subsequently digitised — a distinction that doesn’t exist under GDPR, which covers non-digital structured filing systems too.

Unlike GDPR, the DPDP Act does not create a separate legal category of “special” or “sensitive” personal data (health, biometric, religious belief, etc.) with heightened default obligations. All personal data is treated under one uniform standard, though sector regulators (RBI, IRDAI, medical councils) can and do impose additional sector-specific sensitivity requirements on top.

Processing

Quick answer: Processing means any wholly or partly automated operation performed on digital personal data — collection, recording, organisation, storage, use, sharing, or erasure. Section 2(x) defines it broadly enough to cover nearly every operational touchpoint with personal data, from a signup form to a backup job to a deletion request.

Because the definition is deliberately broad, “we’re not really processing that data” is rarely a valid compliance argument — if data is being stored, transmitted, analysed, or even just retained on a server, it is being processed under the Act.

Legitimate Uses (Deemed Consent)

Quick answer: Section 7 lists specific circumstances where a Data Fiduciary may process personal data without obtaining consent, including when a Data Principal voluntarily provides data for a specified purpose, for compliance with law or court orders, medical emergencies, disaster and public health response, employment purposes in limited cases, and other public-interest scenarios.

These exemptions are narrow and purpose-specific, not general-purpose workarounds — each one requires the Data Fiduciary to document the specific legal basis it is relying on, and processing must stay strictly within the scope of that legitimate use.

Significant Data Fiduciary (SDF)

Quick answer: A Significant Data Fiduciary is a Data Fiduciary (or class of Data Fiduciaries) designated by the Central Government under Section 10, based on factors like the volume and sensitivity of data processed, risk to Data Principal rights, and potential impact on India’s sovereignty and public order. SDFs face additional obligations: appointing a India-based Data Protection Officer, an independent data auditor, and conducting periodic Data Protection Impact Assessments.

SDF status is not self-assessed in the sense of a voluntary label — it is a formal government designation. However, organisations likely to qualify (large platforms, high-volume processors of sensitive categories like health or financial data) should proactively build SDF-grade governance ahead of formal designation.

Data Protection Officer (DPO)

Quick answer: A Data Protection Officer is an individual appointed under Section 8(7) to represent a Significant Data Fiduciary on all data protection matters, act as the point of contact for grievance redressal, and report to the organisation’s board or governing body. The DPO must be based in India for Significant Data Fiduciaries.

DPO appointment is mandatory only for designated SDFs, but many mid-sized organisations proactively appoint a full-time or Virtual DPO as a governance signal well before any formal designation, since building the role and its processes takes months, not weeks.

DPBI (Data Protection Board of India)

Quick answer: The Data Protection Board of India is the adjudicating body established under Section 18 to enforce the DPDP Act — investigating breaches, hearing complaints from Data Principals, and imposing penalties of up to ₹250 crore per violation. It functions as a digital-first tribunal, with proceedings conducted primarily online.

The DPBI is not a general data protection regulator in the way some other countries’ DPAs are — it does not issue broad policy guidance or pre-approve products; its role is narrower and adjudicatory, focused on breach response, complaint resolution, and penalty enforcement.

DPIA (Data Protection Impact Assessment)

Quick answer: A DPIA is a structured assessment of the risk to Data Principal rights posed by a specific processing activity, mandatory for Significant Data Fiduciaries under Rule 12 of the DPDP Rules 2025, to be conducted at least once every 12 months alongside an independent data audit.

Even organisations not designated as SDFs are strongly advised to run voluntary DPIAs before launching high-risk processing — new AI/ML features, large-scale biometric collection, or significant new data-sharing arrangements — since it is the clearest way to demonstrate “privacy by design” if a regulator or customer later asks.

Personal Data Breach

Quick answer: A Personal Data Breach is any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data that compromises its confidentiality, integrity, or availability. Under Rule 7 of the DPDP Rules 2025, there is no materiality threshold — every breach, regardless of scale, triggers notification obligations.

Data Fiduciaries must issue a preliminary alert to the DPBI “without delay,” followed by a detailed report within 72 hours, plus individual notification to every affected Data Principal — a stricter, less discretionary standard than many equivalent global breach laws.

Cross-Border Data Transfer

Quick answer: Under Section 16, the DPDP Act does not require default data localisation — personal data may generally be transferred outside India — but the Central Government may restrict transfers to specific countries or territories by notification, and sector regulators can impose their own localisation rules independent of DPDP.

This is notably more permissive than the default position under many other data protection regimes. However, sector-specific rules already require localisation regardless of DPDP — for example, RBI’s payment system data storage circular mandates that certain payment data be stored only in India.

Notice

Quick answer: Under Section 5, a Data Fiduciary must give a Data Principal a clear, itemised notice describing the personal data being collected and the purpose of processing, before or at the time of seeking consent, in plain language the Data Principal can understand.

The notice must also describe how the Data Principal can exercise their rights and lodge a complaint with the DPBI. Where consent was obtained before the Act’s commencement, Data Fiduciaries must issue this notice “as soon as reasonably practicable.”

Data Principal Rights

Quick answer: The DPDP Act grants Data Principals five core rights: the right to access information about their personal data, the right to correction and erasure, the right to grievance redressal, the right to nominate another person to exercise these rights on their behalf in the event of death or incapacity, and the right to withdraw consent at any time.

Unlike GDPR, the DPDP Act does not include an explicit “right to data portability” or “right to object” as standalone rights — a meaningful drafting difference for any organisation adapting an existing GDPR rights-request workflow for the Indian market.

Grievance Officer

Quick answer: A Grievance Officer is the designated contact a Data Fiduciary must publish to receive and respond to Data Principal complaints about how their personal data is being processed, before the Data Principal can escalate a complaint to the DPBI.

For organisations without a Significant Data Fiduciary designation, the Grievance Officer role does not require the same independence or seniority as a formal DPO, but it must still be a genuinely functioning, monitored channel — not just an unmonitored inbox.

Data Processing Agreement (DPA)

Quick answer: A Data Processing Agreement is the written contract required under Section 8 between a Data Fiduciary and any Data Processor it engages, defining the scope of processing, security obligations, sub-processor restrictions, breach notification duties, and data return or deletion on contract termination.

Every vendor that touches personal data on an organisation’s behalf — cloud hosting, payroll, CRM, analytics — needs a signed DPA. This is one of the most commonly missed obligations in early-stage DPDP gap assessments, since many vendor contracts predate the Act and were never updated.

Anonymisation / De-identification

Quick answer: Anonymisation is the process of transforming personal data so that a Data Principal can no longer be identified, directly or indirectly, by any party. Once data is genuinely and irreversibly anonymised, the DPDP Act no longer applies to it, since it is no longer “personal data” under Section 2(t).

True anonymisation is a high bar — data that has merely been pseudonymised or hashed, where re-identification remains technically feasible, is not anonymised for DPDP purposes and remains fully in scope of the Act.

Reasonable Security Safeguards

Quick answer: Under Section 8(5), every Data Fiduciary must implement “reasonable security safeguards” to prevent personal data breaches, proportionate to the volume and sensitivity of the data processed — the Act does not prescribe a fixed technical checklist, leaving the standard to be interpreted against prevailing industry practice.

In practice, this typically means encryption, access controls, audit logging, multi-factor authentication, regular VAPT, vendor security assessments, and tested backup/recovery processes — largely overlapping with what ISO 27001 and SOC 2 already require, which is why organisations pursuing those certifications can often satisfy this DPDP obligation with the same control set.

Need these mapped against your own organisation’s specific processing activities? Book a Free DPDP Gap Assessment

Frequently Asked Questions

What is the difference between a Data Fiduciary and a Data Controller under GDPR?

They are functionally very similar — both refer to the entity that decides the purpose and means of processing personal data and carries the primary compliance obligations. The main practical differences are in the surrounding framework: DPDP does not have GDPR’s “legitimate interest” lawful basis (it has a narrower “legitimate uses” list under Section 7 instead), and DPDP does not distinguish “special category” sensitive data the way GDPR Article 9 does.

What is the difference between a Data Principal and a Data Subject?

They refer to the same concept — the individual whose personal data is being processed. “Data Principal” is the DPDP Act’s terminology (Section 2(j)); “Data Subject” is the equivalent term under GDPR. One notable DPDP-specific feature is that for children and persons with disabilities, a parent or lawful guardian exercises the Data Principal’s rights on their behalf.

Is every organisation processing personal data automatically a Significant Data Fiduciary?

No. Significant Data Fiduciary status is a specific designation made by the Central Government under Section 10, based on criteria including data volume, sensitivity, and risk to Data Principal rights. Most small and mid-sized organisations are ordinary Data Fiduciaries with the base set of obligations, not SDFs with the additional DPO, auditor, and DPIA requirements.

Does the DPDP Act define “sensitive personal data” like GDPR does?

No. The DPDP Act applies a single uniform standard to all personal data rather than creating a separate “special category” with heightened default obligations, unlike GDPR Article 9. However, sector regulators can and do impose extra sensitivity requirements on specific data types — health data under medical council norms, financial data under RBI rules, and so on.

What is the difference between “consent” and “legitimate uses” under DPDP?

Consent (Section 6) is the default, general-purpose legal basis for processing personal data, requiring a clear affirmative action from the Data Principal. Legitimate uses (Section 7) are a specific, narrow list of scenarios — such as medical emergencies, legal compliance, or voluntarily provided data — where an organisation may process personal data without seeking consent, provided it stays strictly within that scenario’s scope.

Who enforces the DPDP Act, and what powers do they have?

The Data Protection Board of India (DPBI), established under Section 18, is the adjudicating body responsible for investigating complaints and data breaches and imposing penalties of up to ₹250 crore per violation. It functions as a digital-first tribunal rather than a broad policy regulator.

Need Help Applying These Terms to Your Organisation?

A free DPDP Gap Assessment maps every one of these obligations against your actual data flows — written, RAG-scored report in 5 business days.

Book My Free Assessment →