DPDP glossary: key terms of India's data protection law
Plain-language definitions of the terms used in the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, from Data Fiduciary to verifiable parental consent. Curated by ConsentLo's DPDP audit team.
- Appellate Tribunal
- The Telecom Disputes Settlement and Appellate Tribunal (TDSAT), which hears appeals against orders of the Data Protection Board of India.
- Breach intimation
- The initial report a Data Fiduciary sends the Data Protection Board without delay after becoming aware of a personal data breach, followed by a detailed report within 72 hours. Read the guide
- Child
- Under the DPDP Act, any individual who has not completed 18 years of age. Processing a child's data needs verifiable consent of a parent or lawful guardian. Read the guide
- Consent
- A free, specific, informed, unconditional and unambiguous indication of a Data Principal's wishes, given by a clear affirmative action, for a specified purpose. Read the guide
- Consent management platform (CMP)
- Software an organisation uses to show notices, capture and record consent, honour withdrawal and prove compliance. Read the guide
- Consent Manager
- An entity registered with the Data Protection Board that gives Data Principals a single, interoperable platform to give, manage, review and withdraw consent. Read the guide
- Cross-border transfer
- Moving personal data outside India. Allowed under the DPDP Act except to countries restricted by Government notification, and subject to stricter sectoral laws. Read the guide
- Data
- A representation of information, facts, concepts, opinions or instructions suitable for communication, interpretation or processing by humans or automated means.
- Data Fiduciary
- Any person or organisation that alone or with others decides the purpose and means of processing personal data. Most obligations under the DPDP Act fall on Data Fiduciaries. Read the guide
- Data Principal
- The individual to whom personal data relates. For a child it includes the parent or lawful guardian, and for a person with disability, their lawful guardian. Read the guide
- Data Processor
- Any person who processes personal data on behalf of a Data Fiduciary, such as a cloud, payroll or marketing vendor. A Data Fiduciary may engage one only under a valid contract.
- Data Protection Board of India
- The body set up under the DPDP Act to handle complaints and breaches, conduct inquiries, direct remedies and impose penalties. Read the guide
- Data Protection Impact Assessment (DPIA)
- A process that describes processing, assesses risks to Data Principals and records how those risks are managed. Mandatory every twelve months for Significant Data Fiduciaries. Read the guide
- Data Protection Officer (DPO)
- An individual based in India appointed by a Significant Data Fiduciary to represent it under the Act, responsible to its board and the point of contact for grievances. Read the guide
- Digital personal data
- Personal data collected in digital form, or collected in non-digital form and digitised afterwards. This is the data the DPDP Act covers.
- DPDP Act
- The Digital Personal Data Protection Act, 2023: India's law on processing digital personal data. Read the guide
- DPDP Rules
- The Digital Personal Data Protection Rules, 2025, notified in November 2025, which set the detailed requirements and phased timelines under the Act. Read the guide
- Eighth Schedule languages
- The 22 languages listed in the Eighth Schedule to the Constitution of India. DPDP notices must be available in English or any of these languages. Read the guide
- Erasure
- Deleting personal data when consent is withdrawn or the purpose is no longer served, unless retention is required by law. Processors must erase as well.
- Grievance redressal
- The mechanism a Data Fiduciary must provide for Data Principals to raise complaints, answered within the period set by the Rules, not exceeding 90 days. Read the guide
- Independent data auditor
- An auditor a Significant Data Fiduciary must appoint to evaluate its compliance with the DPDP Act. Read the guide
- Legitimate uses
- The closed list of situations in Section 7 of the DPDP Act where personal data may be processed without consent, such as employment and medical emergencies. Read the guide
- Nomination
- A Data Principal's right to nominate another individual to exercise their rights in the event of death or incapacity.
- Notice
- The information a Data Fiduciary must give with or before a request for consent: the itemised personal data, the purpose, and how to withdraw, exercise rights and complain. Read the guide
- Personal data
- Any data about an individual who is identifiable by or in relation to that data.
- Personal data breach
- Any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability. Read the guide
- Processing
- Any wholly or partly automated operation on digital personal data, including collection, recording, storage, use, sharing, disclosure and erasure.
- Purpose limitation
- The principle that personal data is used only for the specified purpose for which consent was given or a legitimate use applies.
- Reasonable security safeguards
- Measures a Data Fiduciary must take to prevent personal data breaches, such as encryption, access control, logging and monitoring. Failure can attract a penalty of up to ₹250 crore. Read the guide
- Significant Data Fiduciary (SDF)
- A Data Fiduciary notified by the Government on the basis of factors such as data volume, sensitivity and risk, with extra duties including a DPO, an independent auditor and annual DPIAs. Read the guide
- Verifiable parental consent
- Consent from a child's parent or lawful guardian whose identity and age are verified, for example using reliable details already held or a token from an authorised entity such as DigiLocker. Read the guide
- Withdrawal of consent
- A Data Principal's right to take back consent at any time, as easily as it was given, after which processing on that basis must stop. Read the guide
Turn the definitions into workflows
ConsentLo runs every DPDP obligation with the deadlines built in.