Section 2(f)
Child
An individual who has not completed eighteen years of age. The Act places additional obligations on Data Fiduciaries when processing a child’s personal data.
Complete definitions of key terms from India's Digital Personal Data Protection Act. Essential reference for compliance officers and legal teams.
Section 2(f)
An individual who has not completed eighteen years of age. The Act places additional obligations on Data Fiduciaries when processing a child’s personal data.
Section 6(1)
A deliberate and unambiguous action through which a Data Principal signifies agreement to the processing of personal data for a specified purpose. Silence or inactivity does not meet this standard.
Section 6
Under DPDP, consent must be free, specific, informed, unconditional, and unambiguous. It must be given through a clear affirmative action and can be withdrawn at any time. Consent forms the legal basis for processing personal data.
Section 6(8)
A platform registered with the Data Protection Board that enables Data Principals to give, manage, review, and withdraw consent through a single accessible interface. AquaConsento is designed to serve as a Consent Manager under DPDP.
Section 6(3)
A request for consent presented in clear and plain language, with access to the request in English or an Eighth Schedule language and the contact details needed to exercise rights.
Section 6(4)–(6)
The Data Principal’s right to withdraw consent at any time, with a process that is as easy as giving consent. Processing based on that consent must then cease unless another legal basis permits it.
Section 16
Transfer of personal data outside India's borders. Under DPDP, such transfers are permitted to countries notified by the Central Government, while transfers to restricted countries are prohibited.
Section 8(3)
The obligation to make reasonable efforts to ensure personal data is complete, accurate, and consistent when it is used to make a decision affecting a Data Principal or disclosed to another Data Fiduciary.
Section 10(2)(b)
An independent auditor appointed by a Significant Data Fiduciary to evaluate compliance with the Act and its applicable obligations.
Section 8(6)
Any unauthorized processing of personal data or accidental disclosure, destruction, or loss of personal data that compromises its confidentiality, integrity, or availability. Data Fiduciaries must notify the Board and affected Data Principals.
Section 2(i)
Any person (including a company, firm, or individual) who alone or in conjunction with other persons determines the purpose and means of processing personal data. Data Fiduciaries bear primary responsibility for DPDP compliance.
Section 2(j)
An individual whose personal data is being collected or processed. Under DPDP Act 2023, Data Principals have specific rights including the right to access, correct, and erase their personal data.
Section 2(k)
Any person who processes personal data on behalf of a Data Fiduciary. While Data Processors act under the instructions of Data Fiduciaries, they must also ensure data security.
Section 18
The regulatory body established under DPDP Act 2023 to adjudicate disputes, impose penalties, and ensure compliance. The Board has the power to impose penalties up to ₹250 crore for violations.
Section 10(2)(c)
A periodic assessment used by a Significant Data Fiduciary to identify and evaluate the impact, risks, and safeguards associated with its personal data processing activities.
Section 10(2)
A senior official appointed by Significant Data Fiduciaries to oversee data protection strategy and compliance. The DPO serves as the point of contact for the Data Protection Board.
Section 8(7)
The obligation of a Data Fiduciary to erase personal data when consent is withdrawn or the specified purpose is no longer being served, unless retention is necessary for compliance with law.
Section 2(n)
Personal data that is in digital form. This includes data that was originally collected in non-digital form but subsequently digitized. DPDP Act 2023 primarily governs digital personal data.
Section 15
Responsibilities that apply when a Data Principal exercises rights under the Act, including providing authentic information, avoiding false or frivolous complaints, and not impersonating another person.
Section 17
Specified circumstances in which some or all obligations and rights under the Act do not apply to particular processing, subject to the conditions set out in the Act.
Section 13
The readily available mechanism through which a Data Principal can raise a complaint with a Data Fiduciary or Consent Manager. This mechanism must generally be exhausted before approaching the Board.
Section 4
A purpose for processing personal data that is not expressly forbidden by law. Processing must be based on consent or another use recognised by the Act.
Section 7
Lawful grounds for processing personal data without explicit consent, including voluntary data provision, state functions, legal obligations, medical emergencies, employment, and public interest purposes.
Section 5
Information given to a Data Principal describing the personal data and purpose for which it will be processed, along with the means to exercise rights and make a complaint to the Board.
Schedule (Penalties)
Monetary fines imposed by the Data Protection Board for DPDP violations. Penalties range from ₹10,000 for minor violations to ₹250 crore for significant breaches affecting national security.
Section 2(t)
Any data about an individual who is identifiable by or in relation to such data. This includes names, addresses, phone numbers, email addresses, biometric data, and any other identifying information.
Section 8(6)
The requirement for a Data Fiduciary to notify the Data Protection Board of India and each affected Data Principal about a personal data breach in the manner prescribed by applicable rules.
Section 2(x)
Any operation performed on personal data including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, dissemination, restriction, erasure, or destruction.
Section 7(i)
A legitimate use that may permit processing without consent for employment-related purposes, including safeguarding an employer from loss or liability and providing benefits sought by an employee.
Section 8(5)
Appropriate protections that a Data Fiduciary must implement to prevent a personal data breach, including where processing is carried out on its behalf by a Data Processor.
Section 11
The right of a Data Principal to obtain a summary of personal data being processed and processing activities, together with prescribed information about other Data Fiduciaries and Data Processors with whom it has been shared.
Section 12
The right of Data Principals to request correction or completion of inaccurate or misleading personal data, and to update personal data that is incomplete.
Section 12
The right of Data Principals to request deletion of their personal data when it is no longer necessary for the purpose it was collected, or when consent is withdrawn.
Section 14
The right of a Data Principal to nominate another individual who may exercise specified rights in the event of the Data Principal’s death or incapacity.
Sections 11–14
The set of rights available to a Data Principal under the Act, including access to information, correction and erasure, grievance redressal, and nomination.
Section 10
A Data Fiduciary notified by the Central Government based on factors such as volume and sensitivity of personal data processed, risk of harm, and potential impact on sovereignty and security of India.
Section 2(z)
The particular purpose stated in the notice given by a Data Fiduciary for processing a Data Principal’s personal data.
Section 8(4)
Measures a Data Fiduciary must implement to ensure effective observance of the Act, combining suitable technical controls with accountable organisational practices.
Section 9(1)
Consent that a Data Fiduciary must obtain from a parent or lawful guardian before processing the personal data of a child, subject to the Act and applicable rules.