Glossary

DPDP Act glossary of terms

A plain-English glossary of DPDP Act terms — Data Fiduciary, Data Principal, Consent Manager, SDF, and more, defined simply.

By DreamyHook Consultancy ServicesUpdated 5 min read

The DPDP Act uses specific terms with precise meanings. Here they are in plain English. For the full picture, start with What is the DPDP Act?.

Core roles

Data Principal — The individual whom the personal data is about. If it's a child, the parent or lawful guardian; if a person with disability, their lawful guardian.

Data Fiduciary — The person or organization that, alone or with others, determines the purpose and means of processing personal data. Most businesses are Data Fiduciaries.

Data Processor — Anyone who processes personal data on behalf of a Data Fiduciary (for example, a cloud host or analytics vendor).

Significant Data Fiduciary (SDF) — A Data Fiduciary notified by the government as higher-risk, with extra duties. See the SDF guide.

Consent Manager — A registered intermediary, accountable to the Data Principal, that provides a single interface to give, manage, review, and withdraw consent.

Data Protection Officer (DPO) — The individual an SDF must appoint, based in India, as the point of contact for data-protection grievances. Available as a service via DPO-as-a-Service.

Data & processing

Personal data — Any data about an individual who is identifiable by or in relation to such data.

Digital personal data — Personal data in digital form — what the Act governs.

Processing — Any operation on personal data: collection, storage, use, sharing, erasure, and more.

Purpose — The specific reason for which personal data is processed, which must be lawful and stated to the Data Principal.

Consent — Agreement that is free, specific, informed, unconditional, and unambiguous, given by a clear affirmative action, and limited to the stated purpose.

Notice — The clear, itemized information a Data Fiduciary must give a Data Principal about what data is collected and why, and how to withdraw consent and complain.

Withdrawal of consent — The right to take back consent, which must be as easy to do as it was to give.

Legitimate uses — Certain situations where personal data may be processed without fresh consent (for example, where a Data Principal has voluntarily provided data for a specified purpose, or for certain state functions).

Rights & duties

Right to access — A Data Principal's right to a summary of their personal data and the recipients it's shared with.

Right to correction and erasure — The right to have personal data corrected, completed, updated, or erased.

Right to grievance redressal — The right to a readily available means of complaint.

Right to nominate — The right to nominate another person to exercise one's rights in case of death or incapacity.

Enforcement

Data Protection Board of India — The independent regulator that investigates breaches and complaints and can impose penalties.

Personal data breach — Any unauthorized processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data, that compromises its confidentiality, integrity, or availability.

Data Protection Impact Assessment (DPIA) — A structured assessment of the risks processing poses to Data Principals and the measures to manage them; required (annually) for SDFs.


Not sure how these apply to your business? The free DPDP Quick Scan translates the terms into your specific situation.

General information, not legal advice. Definitions are simplified — confirm against the official Act.

See how this applies to you

The Quick Scan turns this guide into a personalized snapshot — your risk, your likely SDF status, and your top gaps — in five minutes.

Take the free Quick Scan

The deadline isn't moving. Start today.

Get your free DPDP Quick Scan — no obligation, instant results. See where you stand in five minutes.