Glossary

Every DPDP term, defined the way we would explain it on a call.

Most compliance failures we see begin as vocabulary failures. A team reads "legitimate use" as "anything reasonable for our business", or assumes "processing" means analysis rather than simply holding a file. These definitions are written to stop that happening — precise about what the law says, blunt about what it does not.

A–C

Affirmative action

The positive, deliberate act that makes consent valid. Silence, inactivity, continued use of a service and pre-ticked boxes are none of them.

Automated decision-making

A decision about a person taken by software without meaningful human review. Not banned by the Act, but it raises accuracy duties and, for Significant Data Fiduciaries, an obligation to test the algorithm.

Breach

Any unauthorised processing, accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability.

CERT-In directions

A separate 2022 obligation, unaffected by the DPDP Act, requiring specified cyber incidents to be reported to CERT-In within six hours and logs retained for 180 days. Two clocks, one incident.

Consent artefact

The stored record of a consent decision: who, what purpose, which notice version, what exact text, when, through which channel. The thing you produce when the Board asks you to prove consent.

Consent Manager

A Board-registered intermediary through which an individual can give, review and withdraw consent across organisations from a single interface. A licence, not a software feature.

Cross-border transfer

Moving personal data outside India. Permitted by default under the Act, restricted only for countries notified by the Central Government, and still subject to sector rules such as RBI's payment data localisation.

D–F

Dark pattern

Interface design that pushes a person towards a choice they would not otherwise make — buried opt-outs, confusing double negatives, a prominent 'accept all' beside a hidden 'manage'. It destroys the 'free' element of consent.

Data Fiduciary

Whoever determines the purpose and means of processing personal data, alone or with others. If you decide why the data is collected, this is you.

Data Principal

The individual the data is about — including children, whose consent is given by a parent or lawful guardian. India's equivalent of GDPR's 'data subject'.

Data Processor

Anyone processing personal data on a fiduciary's behalf and instruction: cloud hosts, SaaS platforms, payroll bureaus, agencies. Engaged only under a valid contract.

Data Protection Board of India

The regulator created by Chapter V. Digital by design: complaints, hearings and orders online, with appeals going to the TDSAT.

Data Protection Officer

The person accountable for the privacy programme, mandatory and India-based for Significant Data Fiduciaries, and the named contact for the Board.

DPIA

A structured assessment of the privacy risk in a processing activity: what could go wrong, how likely, how badly, and what reduces it. Mandatory for SDFs, sensible for anyone launching something new.

Digital personal data

Personal data in digital form — collected digitally, or collected on paper and later digitised. The scoping test for the entire Act.

G–P

Grievance redressal

The fiduciary's own complaints channel, which an individual must use before escalating to the Board. It must be published, staffed and responsive.

Legitimate use

The non-consent lawful bases listed in Section 7. A closed list, not a catch-all for anything commercially convenient.

Nomination

The right of an individual to appoint someone to exercise their DPDP rights if they die or become incapable of doing so themselves.

Notice

The standalone, plain-language statement given before or at collection: what data, which purpose, how to withdraw, how to exercise rights, how to complain.

Personal data

Any data about an individual who is identifiable by or in relation to it. The Act deliberately avoids GDPR-style 'sensitive' categories — one standard covers everything.

Processing

Essentially anything you do with data: collection, storage, use, indexing, sharing, disclosure, alteration, erasure. Even holding it untouched is processing.

Purpose limitation

The principle that data collected for one stated purpose cannot be silently repurposed. New purpose, new notice, usually new consent.

Q–Z

Reasonable security safeguards

Section 8(5)'s standard, given content by Rule 6: encryption, access control, logging, backups and detection capability. Judged after the fact, against what a competent organisation would have done.

Retention limitation

The duty to erase personal data once the purpose is served, unless another law requires you to retain it. The cheapest security control available to any business.

Significant Data Fiduciary

A fiduciary notified by the government on grounds of data volume, sensitivity, or risk to rights, electoral democracy, sovereignty or public order. Carries DPO, audit, DPIA and algorithmic duties.

Verifiable parental consent

Consent for a child's data confirmed against a reliable identity or age signal for the adult granting it, before any processing begins.

Withdrawal

The individual's ability to revoke consent at any time, with the same ease as it was given, after which processing must stop and the data must generally be erased.

Next

Knowing the words is step one. Proving compliance is the job.

We map where your personal data lives, close the technical gaps, monitor them around the clock and produce the evidence a regulator or enterprise customer asks for.