Reference
Concepts and glossary
Every important DPDP term, defined in plain English next to the official definition it comes from, with the exact clause cited.
Personal data
Any information about a person who can be identified by it or in relation to it: names, contact details, identifiers, records tied to a person.
Official definition: section 2(t) →
Digital personal data
Personal data on computers, phones or servers, including data collected on paper and digitised later.
Official definition: section 2(n) →
Data Fiduciary
The organisation that decides why and how personal data is used. Most duties in the framework attach to this role.
Official definition: section 2(i) →
Data Processor
An organisation that processes personal data on behalf of a Data Fiduciary. Duties reach it mainly through its contract with the fiduciary: section 8(2) allows a fiduciary to engage a processor only under a valid contract. Section 8(2) commences on 13 May 2027, a date computed from the notification, so treat it as interpretation until officially confirmed.
Official definition: section 2(k) →
Data Principal
The person the data is about. For children, the term includes the parents or lawful guardian; for persons with disability, the lawful guardian acting on their behalf.
Official definition: section 2(j) →
Consent Manager
A person registered with the Board who gives individuals a single point of contact to give, manage, review and withdraw their consent through an accessible, transparent and interoperable platform. Registration rests on section 6(9) of the Act and Rule 4, which applies the conditions and obligations in the First Schedule. Both commence on 13 November 2026, a date computed from the notifications, so treat it as interpretation until officially confirmed. The duty under section 6(8) to act on the individual's behalf follows on a computed 13 May 2027, on the same basis.
Official definition: section 2(g) →
Significant Data Fiduciary
A Data Fiduciary, or class of them, that the Central Government notifies as significant under section 10(1). Extra duties include a Data Protection Officer based in India and responsible to the board of directors or similar governing body, an independent data auditor, and an impact assessment and audit once in every 12 months under Rule 13. None of these duties is in force yet: section 10 and Rule 13 commence on 13 May 2027, a date computed from the notifications, so treat it as interpretation until officially confirmed.
Official definition: section 2(z) →
Data Protection Officer
One named individual, and only a Significant Data Fiduciary has to appoint one. The definition does nothing on its own: it points at section 10(2)(a), which is where the duty and its 4 limbs live. Every other Data Fiduciary owes a different thing, publishing a contact under section 8(9) and Rule 9, with no appointment duty anywhere in either instrument. Neither duty is in force yet: sections 8(9) and 10, Rule 9 and Rule 13 commence on a computed 13 May 2027, which is interpretation until officially confirmed.
Official definition: section 2(l) →
Personal data breach
Unauthorised or accidental events that compromise the confidentiality, integrity or availability of personal data. The definition is in force. The duty to tell affected people and the Board, under section 8(6) and Rule 7, commences on 13 May 2027, a date computed from the notification, so treat it as interpretation until officially confirmed.
Official definition: section 2(u) →
Processing
Nearly anything done to digital personal data by automated means, from collection and storage through sharing to erasure.
Official definition: section 2(x) →
Child
Anyone under 18. From 13 May 2027, when section 9 and Rule 10 commence on a date computed from the notification (interpretation until officially confirmed), processing a child's data requires verifiable parental consent, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited. Rule 12 and the Fourth Schedule lift both duties for listed classes and purposes, subject to their conditions, and other exemptions also apply.
Official definition: section 2(f) →
Data Protection Board of India
The enforcement body established under section 18, which is in force. Most of its core work is not in force yet. Receiving breach intimations and complaints and inquiring under section 27 commence on 13 May 2027, as does section 28 on the Board's procedure, although Rule 20, in force since 13 November 2025, already provides that the Board shall function as a digital office. From 13 May 2027, individuals can approach it only after exhausting the organisation's grievance channel under section 13(3). One exception is section 27(1)(d), inquiry into breaches of a Consent Manager's registration conditions, which commences on 13 November 2026. The 13 May 2027 and 13 November 2026 dates are computed from the notification, so treat them as interpretation until officially confirmed.
Official definition: section 2(c) →
Specified purpose
The purpose named in the notice. Consent covers only the data necessary for it under section 6(1), and once the purpose is no longer served, section 8(7) requires erasure unless a law requires retention. Both duties commence on 13 May 2027, a date computed from the notification, so treat it as interpretation until officially confirmed. The definition in section 2 is in force.
Official definition: section 2(za) →