DPDP Act 2023 Glossary: 20 Key Terms Explained in Plain English (2026 Guide)
The DPDP Act 2023 introduces a specific vocabulary that doesn’t map cleanly onto GDPR or other frameworks many Indian compliance teams already know — a “Data Fiduciary” is not quite a “Data Controller,” and a “Significant Data Fiduciary” designation carries obligations with no direct GDPR equivalent. Getting these terms right matters: they determine who is legally responsible for what, which obligations apply to your organisation, and how you should be describing your own compliance posture to customers, auditors, and regulators.
This glossary defines 20 terms in plain English, each with the exact statutory hook (Section or Rule reference) where relevant, so you can go from “what does this mean” to “where is this in the Act” in one page.
Core Terms
Data Fiduciary
Every organisation that collects and decides how to use personal data of Indian residents — a hospital, a SaaS company, an NGO, a school — is a Data Fiduciary for that data, regardless of size or sector. A single entity can be a Data Fiduciary for its own customers’ data and simultaneously a Data Processor for a client’s end-user data, depending on the relationship.
Data Principal
Every customer, patient, employee, student, donor, or app user whose data an organisation processes is a Data Principal, holding the specific rights described in the Act — access, correction, erasure, grievance redressal, and nomination.
Data Processor
Cloud hosting providers, payroll vendors, customer support platforms, and marketing tools acting purely on a client’s instructions are typically Data Processors. If a vendor starts using that data for its own separate purposes — training its own models, for example — it may become an independent Data Fiduciary instead, which changes the legal analysis considerably.
Personal Data
Unlike GDPR, the DPDP Act does not create a separate legal category of “special” or “sensitive” personal data (health, biometric, religious belief, etc.) with heightened default obligations. All personal data is treated under one uniform standard, though sector regulators (RBI, IRDAI, medical councils) can and do impose additional sector-specific sensitivity requirements on top.
Processing
Because the definition is deliberately broad, “we’re not really processing that data” is rarely a valid compliance argument — if data is being stored, transmitted, analysed, or even just retained on a server, it is being processed under the Act.
Consent
Pre-ticked boxes, bundled “accept all” screens that combine unrelated purposes, and consent buried in dense terms and conditions do not meet this bar. Consent obtained before the Act commenced remains valid only if it already meets these standards; otherwise Data Fiduciaries must give Data Principals the option to withdraw or re-consent as soon as reasonably practicable.
Legitimate Uses (Deemed Consent)
These exemptions are narrow and purpose-specific, not general-purpose workarounds — each one requires the Data Fiduciary to document the specific legal basis it is relying on, and processing must stay strictly within the scope of that legitimate use.
Consent Manager
This is a novel mechanism with no direct GDPR equivalent, modelled loosely on India’s Account Aggregator framework in financial services. Large Data Fiduciaries and Significant Data Fiduciaries are expected to integrate with registered Consent Managers as the ecosystem matures.
Significant Data Fiduciary (SDF)
SDF status is not self-assessed in the sense of a voluntary label — it is a formal government designation. However, organisations likely to qualify (large platforms, high-volume processors of sensitive categories like health or financial data) should proactively build SDF-grade governance ahead of formal designation.
Data Protection Officer (DPO)
DPO appointment is mandatory only for designated SDFs, but many mid-sized organisations proactively appoint a full-time or Virtual DPO as a governance signal well before any formal designation, since building the role and its processes takes months, not weeks.
DPBI (Data Protection Board of India)
The DPBI is not a general data protection regulator in the way some other countries’ DPAs are — it does not issue broad policy guidance or pre-approve products; its role is narrower and adjudicatory, focused on breach response, complaint resolution, and penalty enforcement.
DPIA (Data Protection Impact Assessment)
Even organisations not designated as SDFs are strongly advised to run voluntary DPIAs before launching high-risk processing — new AI/ML features, large-scale biometric collection, or significant new data-sharing arrangements — since it is the clearest way to demonstrate “privacy by design” if a regulator or customer later asks.
Personal Data Breach
Data Fiduciaries must issue a preliminary alert to the DPBI “without delay,” followed by a detailed report within 72 hours, plus individual notification to every affected Data Principal — a stricter, less discretionary standard than many equivalent global breach laws.
Cross-Border Data Transfer
This is notably more permissive than the default position under many other data protection regimes. However, sector-specific rules already require localisation regardless of DPDP — for example, RBI’s payment system data storage circular mandates that certain payment data be stored only in India.
Notice
The notice must also describe how the Data Principal can exercise their rights and lodge a complaint with the DPBI. Where consent was obtained before the Act’s commencement, Data Fiduciaries must issue this notice “as soon as reasonably practicable.”
Data Principal Rights
Unlike GDPR, the DPDP Act does not include an explicit “right to data portability” or “right to object” as standalone rights — a meaningful drafting difference for any organisation adapting an existing GDPR rights-request workflow for the Indian market.
Grievance Officer
For organisations without a Significant Data Fiduciary designation, the Grievance Officer role does not require the same independence or seniority as a formal DPO, but it must still be a genuinely functioning, monitored channel — not just an unmonitored inbox.
Data Processing Agreement (DPA)
Every vendor that touches personal data on an organisation’s behalf — cloud hosting, payroll, CRM, analytics — needs a signed DPA. This is one of the most commonly missed obligations in early-stage DPDP gap assessments, since many vendor contracts predate the Act and were never updated.
Anonymisation / De-identification
True anonymisation is a high bar — data that has merely been pseudonymised or hashed, where re-identification remains technically feasible, is not anonymised for DPDP purposes and remains fully in scope of the Act.
Reasonable Security Safeguards
In practice, this typically means encryption, access controls, audit logging, multi-factor authentication, regular VAPT, vendor security assessments, and tested backup/recovery processes — largely overlapping with what ISO 27001 and SOC 2 already require, which is why organisations pursuing those certifications can often satisfy this DPDP obligation with the same control set.
Frequently Asked Questions
What is the difference between a Data Fiduciary and a Data Controller under GDPR?
They are functionally very similar — both refer to the entity that decides the purpose and means of processing personal data and carries the primary compliance obligations. The main practical differences are in the surrounding framework: DPDP does not have GDPR’s “legitimate interest” lawful basis (it has a narrower “legitimate uses” list under Section 7 instead), and DPDP does not distinguish “special category” sensitive data the way GDPR Article 9 does.
What is the difference between a Data Principal and a Data Subject?
They refer to the same concept — the individual whose personal data is being processed. “Data Principal” is the DPDP Act’s terminology (Section 2(j)); “Data Subject” is the equivalent term under GDPR. One notable DPDP-specific feature is that for children and persons with disabilities, a parent or lawful guardian exercises the Data Principal’s rights on their behalf.
Is every organisation processing personal data automatically a Significant Data Fiduciary?
No. Significant Data Fiduciary status is a specific designation made by the Central Government under Section 10, based on criteria including data volume, sensitivity, and risk to Data Principal rights. Most small and mid-sized organisations are ordinary Data Fiduciaries with the base set of obligations, not SDFs with the additional DPO, auditor, and DPIA requirements.
Does the DPDP Act define “sensitive personal data” like GDPR does?
No. The DPDP Act applies a single uniform standard to all personal data rather than creating a separate “special category” with heightened default obligations, unlike GDPR Article 9. However, sector regulators can and do impose extra sensitivity requirements on specific data types — health data under medical council norms, financial data under RBI rules, and so on.
What is the difference between “consent” and “legitimate uses” under DPDP?
Consent (Section 6) is the default, general-purpose legal basis for processing personal data, requiring a clear affirmative action from the Data Principal. Legitimate uses (Section 7) are a specific, narrow list of scenarios — such as medical emergencies, legal compliance, or voluntarily provided data — where an organisation may process personal data without seeking consent, provided it stays strictly within that scenario’s scope.
Who enforces the DPDP Act, and what powers do they have?
The Data Protection Board of India (DPBI), established under Section 18, is the adjudicating body responsible for investigating complaints and data breaches and imposing penalties of up to ₹250 crore per violation. It functions as a digital-first tribunal rather than a broad policy regulator.
Need Help Applying These Terms to Your Organisation?
A free DPDP Gap Assessment maps every one of these obligations against your actual data flows — written, RAG-scored report in 5 business days.
Book My Free Assessment →Related Resources
- DPDP Act Compliance Checklist India 2026
- DPDP Act Penalties India 2026
- DPDP Breach Notification — Timelines & Templates
- DPIA Under DPDP Act — When & How
- Consent Manager India — DPDP Rules 2025
- Data Processing Agreement Under DPDP Act
- DPO as a Service India
- DPDP Act Compliance Services
- Virtual CISO (vCISO) Services India
- ISO 27001 Consultant India — Cost, Timeline & Checklist
- SOC 2 Compliance India — Readiness & Cost