Glossary
Every DPDP term, defined the way we would explain it on a call.
Most compliance failures we see begin as vocabulary failures. A team reads "legitimate use" as "anything reasonable for our business", or assumes "processing" means analysis rather than simply holding a file. These definitions are written to stop that happening — precise about what the law says, blunt about what it does not.
A–C
Affirmative action
The positive, deliberate act that makes consent valid. Silence, inactivity, continued use of a service and pre-ticked boxes are none of them.
Automated decision-making
A decision about a person taken by software without meaningful human review. Not banned by the Act, but it raises accuracy duties and, for Significant Data Fiduciaries, an obligation to test the algorithm.
Breach
Any unauthorised processing, accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability.
CERT-In directions
A separate 2022 obligation, unaffected by the DPDP Act, requiring specified cyber incidents to be reported to CERT-In within six hours and logs retained for 180 days. Two clocks, one incident.
Consent artefact
The stored record of a consent decision: who, what purpose, which notice version, what exact text, when, through which channel. The thing you produce when the Board asks you to prove consent.
Consent Manager
A Board-registered intermediary through which an individual can give, review and withdraw consent across organisations from a single interface. A licence, not a software feature.
Cross-border transfer
Moving personal data outside India. Permitted by default under the Act, restricted only for countries notified by the Central Government, and still subject to sector rules such as RBI's payment data localisation.
D–F
Dark pattern
Interface design that pushes a person towards a choice they would not otherwise make — buried opt-outs, confusing double negatives, a prominent 'accept all' beside a hidden 'manage'. It destroys the 'free' element of consent.
Data Fiduciary
Whoever determines the purpose and means of processing personal data, alone or with others. If you decide why the data is collected, this is you.
Data Principal
The individual the data is about — including children, whose consent is given by a parent or lawful guardian. India's equivalent of GDPR's 'data subject'.
Data Processor
Anyone processing personal data on a fiduciary's behalf and instruction: cloud hosts, SaaS platforms, payroll bureaus, agencies. Engaged only under a valid contract.
Data Protection Board of India
The regulator created by Chapter V. Digital by design: complaints, hearings and orders online, with appeals going to the TDSAT.
Data Protection Officer
The person accountable for the privacy programme, mandatory and India-based for Significant Data Fiduciaries, and the named contact for the Board.
DPIA
A structured assessment of the privacy risk in a processing activity: what could go wrong, how likely, how badly, and what reduces it. Mandatory for SDFs, sensible for anyone launching something new.
Digital personal data
Personal data in digital form — collected digitally, or collected on paper and later digitised. The scoping test for the entire Act.
G–P
Grievance redressal
The fiduciary's own complaints channel, which an individual must use before escalating to the Board. It must be published, staffed and responsive.
Legitimate use
The non-consent lawful bases listed in Section 7. A closed list, not a catch-all for anything commercially convenient.
Nomination
The right of an individual to appoint someone to exercise their DPDP rights if they die or become incapable of doing so themselves.
Notice
The standalone, plain-language statement given before or at collection: what data, which purpose, how to withdraw, how to exercise rights, how to complain.
Personal data
Any data about an individual who is identifiable by or in relation to it. The Act deliberately avoids GDPR-style 'sensitive' categories — one standard covers everything.
Processing
Essentially anything you do with data: collection, storage, use, indexing, sharing, disclosure, alteration, erasure. Even holding it untouched is processing.
Purpose limitation
The principle that data collected for one stated purpose cannot be silently repurposed. New purpose, new notice, usually new consent.
Q–Z
Reasonable security safeguards
Section 8(5)'s standard, given content by Rule 6: encryption, access control, logging, backups and detection capability. Judged after the fact, against what a competent organisation would have done.
Retention limitation
The duty to erase personal data once the purpose is served, unless another law requires you to retain it. The cheapest security control available to any business.
Significant Data Fiduciary
A fiduciary notified by the government on grounds of data volume, sensitivity, or risk to rights, electoral democracy, sovereignty or public order. Carries DPO, audit, DPIA and algorithmic duties.
Verifiable parental consent
Consent for a child's data confirmed against a reliable identity or age signal for the adult granting it, before any processing begins.
Withdrawal
The individual's ability to revoke consent at any time, with the same ease as it was given, after which processing must stop and the data must generally be erased.
Next
Knowing the words is step one. Proving compliance is the job.
We map where your personal data lives, close the technical gaps, monitor them around the clock and produce the evidence a regulator or enterprise customer asks for.
