DPDP reference guide

DPDP Act 2023 glossary

Complete definitions of key terms from India's Digital Personal Data Protection Act. Essential reference for compliance officers and legal teams.

DPDP 2023 compliantOfficial terminology

Section 6(1)

Clear Affirmative Action

A deliberate and unambiguous action through which a Data Principal signifies agreement to the processing of personal data for a specified purpose. Silence or inactivity does not meet this standard.

Section 16

Cross-Border Data Transfer

Transfer of personal data outside India's borders. Under DPDP, such transfers are permitted to countries notified by the Central Government, while transfers to restricted countries are prohibited.

Section 8(3)

Data Accuracy

The obligation to make reasonable efforts to ensure personal data is complete, accurate, and consistent when it is used to make a decision affecting a Data Principal or disclosed to another Data Fiduciary.

Section 8(6)

Data Breach

Any unauthorized processing of personal data or accidental disclosure, destruction, or loss of personal data that compromises its confidentiality, integrity, or availability. Data Fiduciaries must notify the Board and affected Data Principals.

Section 2(i)

Data Fiduciary

Any person (including a company, firm, or individual) who alone or in conjunction with other persons determines the purpose and means of processing personal data. Data Fiduciaries bear primary responsibility for DPDP compliance.

Section 2(j)

Data Principal

An individual whose personal data is being collected or processed. Under DPDP Act 2023, Data Principals have specific rights including the right to access, correct, and erase their personal data.

Section 2(k)

Data Processor

Any person who processes personal data on behalf of a Data Fiduciary. While Data Processors act under the instructions of Data Fiduciaries, they must also ensure data security.

Section 18

Data Protection Board of India

The regulatory body established under DPDP Act 2023 to adjudicate disputes, impose penalties, and ensure compliance. The Board has the power to impose penalties up to ₹250 crore for violations.

Section 10(2)(c)

Data Protection Impact Assessment (DPIA)

A periodic assessment used by a Significant Data Fiduciary to identify and evaluate the impact, risks, and safeguards associated with its personal data processing activities.

Section 10(2)

Data Protection Officer (DPO)

A senior official appointed by Significant Data Fiduciaries to oversee data protection strategy and compliance. The DPO serves as the point of contact for the Data Protection Board.

Section 8(7)

Data Retention and Erasure

The obligation of a Data Fiduciary to erase personal data when consent is withdrawn or the specified purpose is no longer being served, unless retention is necessary for compliance with law.

Section 2(n)

Digital Personal Data

Personal data that is in digital form. This includes data that was originally collected in non-digital form but subsequently digitized. DPDP Act 2023 primarily governs digital personal data.

Section 15

Duties of Data Principal

Responsibilities that apply when a Data Principal exercises rights under the Act, including providing authentic information, avoiding false or frivolous complaints, and not impersonating another person.

Section 17

Exemptions

Specified circumstances in which some or all obligations and rights under the Act do not apply to particular processing, subject to the conditions set out in the Act.

Section 4

Lawful Purpose

A purpose for processing personal data that is not expressly forbidden by law. Processing must be based on consent or another use recognised by the Act.

Section 7

Legitimate Uses

Lawful grounds for processing personal data without explicit consent, including voluntary data provision, state functions, legal obligations, medical emergencies, employment, and public interest purposes.

Section 5

Notice

Information given to a Data Principal describing the personal data and purpose for which it will be processed, along with the means to exercise rights and make a complaint to the Board.

Schedule (Penalties)

Penalties

Monetary fines imposed by the Data Protection Board for DPDP violations. Penalties range from ₹10,000 for minor violations to ₹250 crore for significant breaches affecting national security.

Section 2(t)

Personal Data

Any data about an individual who is identifiable by or in relation to such data. This includes names, addresses, phone numbers, email addresses, biometric data, and any other identifying information.

Section 2(x)

Processing

Any operation performed on personal data including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, dissemination, restriction, erasure, or destruction.

Section 7(i)

Processing for Employment Purposes

A legitimate use that may permit processing without consent for employment-related purposes, including safeguarding an employer from loss or liability and providing benefits sought by an employee.

Section 11

Right to Access Information

The right of a Data Principal to obtain a summary of personal data being processed and processing activities, together with prescribed information about other Data Fiduciaries and Data Processors with whom it has been shared.

Section 12

Right to Correction

The right of Data Principals to request correction or completion of inaccurate or misleading personal data, and to update personal data that is incomplete.

Section 12

Right to Erasure

The right of Data Principals to request deletion of their personal data when it is no longer necessary for the purpose it was collected, or when consent is withdrawn.

Section 10

Significant Data Fiduciary

A Data Fiduciary notified by the Central Government based on factors such as volume and sensitivity of personal data processed, risk of harm, and potential impact on sovereignty and security of India.

Section 2(z)

Specified Purpose

The particular purpose stated in the notice given by a Data Fiduciary for processing a Data Principal’s personal data.

Section 8(4)

Technical and Organisational Measures

Measures a Data Fiduciary must implement to ensure effective observance of the Act, combining suitable technical controls with accountable organisational practices.

Official sources

DPDP Act 2023Full Text (MeitY Official)
Gazette of IndiaDPDP Rules 2025

Need help with DPDP compliance?

AquaConsento simplifies consent management and DPDP compliance for your business. Get started with our expert-led platform today.

Book Demo
Chat on WhatsApp
+91 6290447344