Reference
DPDP Glossary
Fast-reference definitions for India's Digital Personal Data Protection framework. Each entry is one sentence plus a citation. Deep dives live on dedicated DPDP pages.
C
- Child
- An individual who has not completed eighteen years of age under the DPDP Act.
- Section 2(f)
- Open term →
- Consent
- A free, specific, informed, unconditional and unambiguous agreement, given by clear affirmative action, to process personal data for a specified purpose.
- Sections 4 and 6
- Open term →
- Consent Artefact
- Not a defined statutory term in the Act or Rules; in operational systems it usually means the structured record of a consent decision and its context.
- Operational term (not defined in the Act/Rules)
- Open term →
- Consent Manager
- A person registered with the Board who enables a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform.
- Section 2(g); Section 6(7)–(9); Rule 4
- Open term →
- Consent Notice
- The notice that must accompany or precede a request for consent, informing the Data Principal of personal data, purpose and related rights information.
- Section 5; Rule 3
- Open term →
- Cross-Border Transfer
- Transfer of personal data outside India, which Rule 15 permits subject to requirements the Central Government may specify for making data available to a foreign State or related entities.
- Rule 15
- Open term →
D
- Data Fiduciary
- Any person who alone or with others determines the purpose and means of processing of personal data.
- Section 2(i)
- Open term →
- Data Processor
- Any person who processes personal data on behalf of a Data Fiduciary.
- Section 2(k)
- Open term →
- Data Protection Board
- The Data Protection Board of India established under the Act to inquire into breaches and perform other functions as provided.
- Sections 18–26
- Open term →
- Digital Personal Data
- Personal data in digital form, including personal data collected in non-digital form and digitised subsequently, within the Act’s application.
- Section 3
- Open term →
- DPDP Act
- The Digital Personal Data Protection Act, 2023 — India’s primary statute for processing of digital personal data.
- Act No. 22 of 2023
- Open term →
- DPDP Rules
- The Digital Personal Data Protection Rules, 2025 made under the Act, providing operational detail with phased commencement.
- Rules under Section 40; G.S.R. 846(E)
- Open term →
- Duties of Data Principal
- Statutory duties under Section 15, including not impersonating others or registering false or frivolous grievances — distinct from Data Principal rights.
- Section 15
- Open term →
E
- Erasure
- Removal of personal data when it is no longer necessary for the specified purpose, subject to legal retention requirements and Section 12 requests.
- Section 8; Section 12; Rule 8
- Open term →
L
- Lawful Guardian
- A parent or lawful guardian whose role is engaged for verifiable consent relating to a child or certain persons with disability.
- Section 9; Rules 10 and 11
- Open term →
- Legitimate Use
- Certain legitimate uses listed in Section 7 for which personal data may be processed without consent under Section 4.
- Sections 4 and 7
- Open term →
P
- Penalty
- A monetary penalty the Board may impose under Section 33 and the Schedule where it determines a breach is significant.
- Section 33; Schedule
- Open term →
- Personal Data
- Any data about an individual who is identifiable by or in relation to such data.
- Section 2(t)
- Open term →
- Personal Data Breach
- A breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to personal data that compromises confidentiality, integrity or availability.
- Section 2(u); Section 8(6); Rule 7
- Open term →
- Processing
- A wholly or partly automated operation or set of operations performed on digital personal data, including collection, storage, use and sharing.
- Section 2(x)
- Open term →
- Purpose
- The lawful purpose for which personal data is processed; consent is purpose-linked and certain legitimate uses are also provided.
- Sections 4, 6 and 7
- Open term →
R
- Reasonable Security Safeguards
- Measures a Data Fiduciary must take to protect personal data and prevent personal data breach, elaborated in Rule 6.
- Section 8(5); Rule 6
- Open term →
- Retention
- Keeping personal data only as long as necessary for the specified purpose, unless retention is required by law, with Rule 8 addressing certain deemed time periods.
- Section 8; Rule 8
- Open term →
- Right of Grievance Redressal
- The right to readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager.
- Section 13
- Open term →
- Right to Access
- The right to obtain a summary of personal data being processed and related processing information under the Act.
- Section 11
- Open term →
- Right to Correction and Erasure
- The right to seek correction, completion, updating and erasure of personal data in accordance with the Act.
- Section 12
- Open term →
- Right to Nominate
- The right to nominate another individual to exercise the Data Principal’s rights in the event of death or incapacity.
- Section 14
- Open term →
S
- Significant Data Fiduciary
- A Data Fiduciary or class of Data Fiduciaries notified as such by the Central Government, with additional obligations under Section 10 and Rule 13.
- Section 10; Rule 13
- Open term →
V
- Verifiable Consent
- Consent obtained in accordance with Rule 10 or Rule 11 for processing personal data of a child or of a person with disability who has a lawful guardian.
- Rules 2, 10 and 11
- Open term →
Definitions summarise the Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 for educational use. They are not legal advice. Official text: Act PDF · Rules PDF.