Home / Glossary
48 terms · DPDP Act 2023 + Rules 2025

The DPDP glossary

Words the DPDP Act and Rules use, defined without a lawyer's hedge. Every entry cites the section, rule or judgment it comes from so you can check us. Use this alongside the deep pages under Act and Rules whenever a term shows up and you want to know exactly what it means before nodding through it in a meeting.

Verified 8 Sep 2026 Citations on every entry CC BY 4.0

AAadhaar-based verification and 1 more

Aadhaar-based verification

A method of establishing identity by matching the biometric or OTP-linked demographic details of an individual against the Unique Identification Authority of India's database. Used in Rule 10 verifiable parental consent flows.

Rule 10 read with Aadhaar Act 2016

Access, right to

A Data Principal's right to obtain from the Data Fiduciary a summary of the personal data being processed and the processing activities.

Sec. 11

BBehavioural monitoring and 1 more

Behavioural monitoring

Systematic collection of a user's activity signals to build a profile that predicts future behaviour or interests. Banned for children under Sec. 9(3), regardless of consent.

Sec. 9(3)

Breach, personal data

Any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises confidentiality, integrity or availability.

Sec. 2(u)

CCERT-In and 5 more

CERT-In

The Indian Computer Emergency Response Team. Its 28 April 2022 Directions require most cyber incidents to be reported within 6 hours. This obligation is separate from DPDP breach notification under Rule 7.

MEA and IT Act 2000 Sec. 70B

Child

An individual who has not completed 18 years of age. All processing of children's personal data requires verifiable parental consent (Sec. 9).

Sec. 2(f)

Consent

The Data Principal's free, specific, informed, unconditional and unambiguous agreement, given by a clear affirmative action, to the processing of her personal data for a specified purpose.

Sec. 6

Consent Manager

A person registered with the Data Protection Board who acts as a single point of contact for a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. Accountable to the Data Principal.

Sec. 2(g), Sec. 6(3), Rule 4

Consent notice

The written notice a Data Fiduciary must give the Data Principal before or at the time of collecting personal data. Contents and format prescribed by Rule 3.

Sec. 5, Rule 3

Cross-border transfer

Any transfer of personal data by a Data Fiduciary outside India for processing. Permitted by default under a negative-list model; the Central Government may notify restricted countries.

Sec. 16, Rule 15

DData and 8 more

Data

A representation of information, facts, concepts, opinions or instructions in a manner suitable for communication, interpretation or processing by human beings or by automated means.

Sec. 2(h)

Data Fiduciary

Any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data. Equivalent of the GDPR "controller."

Sec. 2(i)

Data Principal

The individual to whom the personal data relates. Equivalent of the GDPR "data subject." Where the individual is a child, the parent or lawful guardian; where a person with disability, the lawful guardian.

Sec. 2(j)

Data Processor

Any person who processes personal data on behalf of a Data Fiduciary. Equivalent of the GDPR "processor."

Sec. 2(k)

Data Protection Board of India (DPBI)

The digital-by-design adjudicatory body constituted under Section 18 of the DPDP Act. Hears complaints, opens inquiries, imposes penalties. Chairperson and four Members appointed by the Central Government.

Sec. 18 to 26

Data Protection Impact Assessment (DPIA)

A structured evaluation of the risks a processing activity poses to Data Principals' rights, together with mitigation. Mandatory for Significant Data Fiduciaries once every twelve months.

Rule 12(1)

Data Protection Officer (DPO)

The person designated by a Significant Data Fiduciary who resides in India and reports to the Board of Directors or an equivalent governing body. Also used loosely to describe the Sec. 8(9) contact point for any Data Fiduciary.

Sec. 8(9), Rule 12(1)

Digital personal data

Personal data in digital form or personal data digitised after collection. Paper records outside this definition are outside DPDP until digitised.

Sec. 2(n) read with Sec. 3

DigiLocker

A Central Government-backed digital document wallet used to verify a parent's identity and parent-child link in Rule 10 verifiable parental consent flows.

Rule 10

EErasure and 1 more

Erasure

The Data Principal's right to have their personal data erased when the specified purpose is no longer being served or on withdrawal of consent, subject to legal retention exceptions.

Sec. 12(3), Sec. 8(7)

Eighth Schedule languages

The 22 official languages listed in the Eighth Schedule to the Constitution of India. Consent notices must be available in any of these on request under Rule 3.

Constitution Eighth Schedule read with Rule 3

GGazette Notification and 1 more

Gazette Notification

The official publication route by which Government notifications acquire legal force. DPDP Rules 2025 were notified via G.S.R. 846(E) in the Gazette of India dated 13 November 2025.

General Clauses Act 1897

Grievance officer

The contact point a Data Fiduciary must publish under Sec. 8(9) to receive complaints and rights requests. Rule 3(b)(iii) requires this to be published on a specific link accessible from the notice.

Sec. 8(9), Sec. 13, Rule 3

IIndia-resident DPO

India-resident DPO

The DPO of a Significant Data Fiduciary must reside in India. Rule 12(1) makes this an SDF obligation.

Rule 12(1)

LLegitimate uses

Legitimate uses

The grounds under Section 7 on which personal data may be processed without consent: State functions, medical emergencies, court orders, employment, disaster response and specified others.

Sec. 7

NNegative-list model and 2 more

Negative-list model

The cross-border transfer regime under Section 16. Transfers are permitted by default; the Central Government may restrict specific countries by notification. Opposite of the GDPR whitelist / adequacy model.

Sec. 16, Rule 15

Nomination

The Data Principal's right under Section 14 to nominate a person to exercise rights on death or incapacity. A DPDP-specific right without a direct GDPR equivalent.

Sec. 14

Notice

The Rule 3 notice a Data Fiduciary gives the Data Principal before collecting personal data. Must be understandable on its own, in plain language, and available in English and any Eighth Schedule language on request.

Sec. 5, Rule 3

PPersonal data and 3 more

Personal data

Any data about an individual who is identifiable by or in relation to that data.

Sec. 2(t)

Personal data breach

See Breach, personal data.

Sec. 2(u)

Persons with disability

Individuals with a disability who have a lawful guardian appointed. Rule 11 applies verifiable guardian consent equivalent to Rule 10 for children.

Sec. 9(2), Rule 11

Puttaswamy judgment

The unanimous nine-judge Supreme Court judgment in Justice K.S. Puttaswamy v. Union of India (2017) 10 SCC 1 recognising the fundamental right to privacy under Article 21. The constitutional foundation of the DPDP framework.

Constitution Art. 21 read with (2017) 10 SCC 1

RRetention and 6 more

Retention

The period for which personal data may be held by a Data Fiduciary. Section 8(7) requires erasure when the specified purpose is no longer served or on withdrawal of consent, subject to legal exceptions.

Sec. 8(7), Rule 8

Rule 3

The DPDP Rule that prescribes the format of the consent notice. Effective 14 May 2027.

Rule 3

Rule 7

The DPDP Rule that prescribes the form and timeline for breach notification: notify without delay, comprehensive report to the Board within 72 hours. Effective 14 May 2027.

Rule 7

Rule 10

The DPDP Rule that prescribes verifiable parental consent methods for processing children's personal data. Effective 14 May 2027.

Rule 10

Rule 12

The DPDP Rule that sets additional obligations on Significant Data Fiduciaries: India-resident DPO, annual DPIA, annual audit, Rule 12(4) targeted localisation. Effective 14 May 2027.

Rule 12

Rule 12(4)

The sub-rule under Rule 12 that empowers the Central Government to notify specific data categories SDFs must keep within India. A parallel lever to Section 16.

Rule 12(4)

Rule 15

The DPDP Rule that operationalises Section 16's negative-list cross-border transfer regime. Effective 14 May 2027.

Rule 15

SSchedule to the Act and 4 more

Schedule to the Act

The Schedule to the DPDP Act 2023 read with Section 33. Sets four penalty caps: Rs. 250 crore, Rs. 200 crore (two triggers), Rs. 150 crore, Rs. 50 crore, plus Rs. 10,000 for Data Principal duty breaches.

The Schedule

Section 8(5)

The obligation to take reasonable security safeguards to prevent a personal data breach. Failure attracts the Rs. 250 crore cap.

Sec. 8(5), Rule 6

Section 8(6)

The obligation to notify a personal data breach to the Board and to affected Data Principals. Failure attracts a Rs. 200 crore cap.

Sec. 8(6), Rule 7

Significant Data Fiduciary (SDF)

A Data Fiduciary designated by the Central Government under Section 10, individually or as part of a class. Takes on the extra obligations under Rules 12 and 13.

Sec. 2(z), Sec. 10

Standard Contractual Clauses (SCCs)

A GDPR cross-border safeguard mechanism. Not required under DPDP because Section 16 uses a negative-list model.

GDPR Art. 46 (not adopted in DPDP)

TTargeted advertising and 1 more

Targeted advertising

Advertising selected based on inferred characteristics of the user rather than the current page or app context. Banned for children under Sec. 9(3), regardless of consent.

Sec. 9(3)

TDSAT

The Telecom Disputes Settlement and Appellate Tribunal. Appeals from Data Protection Board orders lie to TDSAT within 60 days under Sec. 29.

Sec. 29, Rule 21

VVerifiable parental consent (VPC)

Verifiable parental consent (VPC)

Consent given by a parent or lawful guardian, verified as to the identity of the parent and the parent-child relationship. Required before processing any child's personal data. Rule 10 sets verification methods.

Sec. 9(1), Rule 10

WWithdrawal

Withdrawal

The Data Principal's right under Section 6(4) to withdraw consent at any time, with ease comparable to how consent was given.

Sec. 6(4)
Term missing? Add it via GitHub issues. Every entry is CC BY 4.0 and cite-friendly.