DPDP glossary: key terms of India's data protection law

Plain-language definitions of the terms used in the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, from Data Fiduciary to verifiable parental consent. Curated by ConsentLo's DPDP audit team.

Appellate Tribunal
The Telecom Disputes Settlement and Appellate Tribunal (TDSAT), which hears appeals against orders of the Data Protection Board of India.
Breach intimation
The initial report a Data Fiduciary sends the Data Protection Board without delay after becoming aware of a personal data breach, followed by a detailed report within 72 hours. Read the guide
Child
Under the DPDP Act, any individual who has not completed 18 years of age. Processing a child's data needs verifiable consent of a parent or lawful guardian. Read the guide
Cross-border transfer
Moving personal data outside India. Allowed under the DPDP Act except to countries restricted by Government notification, and subject to stricter sectoral laws. Read the guide
Data
A representation of information, facts, concepts, opinions or instructions suitable for communication, interpretation or processing by humans or automated means.
Data Fiduciary
Any person or organisation that alone or with others decides the purpose and means of processing personal data. Most obligations under the DPDP Act fall on Data Fiduciaries. Read the guide
Data Principal
The individual to whom personal data relates. For a child it includes the parent or lawful guardian, and for a person with disability, their lawful guardian. Read the guide
Data Processor
Any person who processes personal data on behalf of a Data Fiduciary, such as a cloud, payroll or marketing vendor. A Data Fiduciary may engage one only under a valid contract.
Data Protection Board of India
The body set up under the DPDP Act to handle complaints and breaches, conduct inquiries, direct remedies and impose penalties. Read the guide
Data Protection Impact Assessment (DPIA)
A process that describes processing, assesses risks to Data Principals and records how those risks are managed. Mandatory every twelve months for Significant Data Fiduciaries. Read the guide
Data Protection Officer (DPO)
An individual based in India appointed by a Significant Data Fiduciary to represent it under the Act, responsible to its board and the point of contact for grievances. Read the guide
Digital personal data
Personal data collected in digital form, or collected in non-digital form and digitised afterwards. This is the data the DPDP Act covers.
DPDP Act
The Digital Personal Data Protection Act, 2023: India's law on processing digital personal data. Read the guide
DPDP Rules
The Digital Personal Data Protection Rules, 2025, notified in November 2025, which set the detailed requirements and phased timelines under the Act. Read the guide
Eighth Schedule languages
The 22 languages listed in the Eighth Schedule to the Constitution of India. DPDP notices must be available in English or any of these languages. Read the guide
Erasure
Deleting personal data when consent is withdrawn or the purpose is no longer served, unless retention is required by law. Processors must erase as well.
Grievance redressal
The mechanism a Data Fiduciary must provide for Data Principals to raise complaints, answered within the period set by the Rules, not exceeding 90 days. Read the guide
Independent data auditor
An auditor a Significant Data Fiduciary must appoint to evaluate its compliance with the DPDP Act. Read the guide
Legitimate uses
The closed list of situations in Section 7 of the DPDP Act where personal data may be processed without consent, such as employment and medical emergencies. Read the guide
Nomination
A Data Principal's right to nominate another individual to exercise their rights in the event of death or incapacity.
Notice
The information a Data Fiduciary must give with or before a request for consent: the itemised personal data, the purpose, and how to withdraw, exercise rights and complain. Read the guide
Personal data
Any data about an individual who is identifiable by or in relation to that data.
Personal data breach
Any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability. Read the guide
Processing
Any wholly or partly automated operation on digital personal data, including collection, recording, storage, use, sharing, disclosure and erasure.
Purpose limitation
The principle that personal data is used only for the specified purpose for which consent was given or a legitimate use applies.
Reasonable security safeguards
Measures a Data Fiduciary must take to prevent personal data breaches, such as encryption, access control, logging and monitoring. Failure can attract a penalty of up to ₹250 crore. Read the guide
Significant Data Fiduciary (SDF)
A Data Fiduciary notified by the Government on the basis of factors such as data volume, sensitivity and risk, with extra duties including a DPO, an independent auditor and annual DPIAs. Read the guide

Turn the definitions into workflows

ConsentLo runs every DPDP obligation with the deadlines built in.

Book a demo