Skip to content
FaceOff Technologies

DPDP glossary

The Act, in plain terms

The vocabulary the Digital Personal Data Protection Act uses, what each term actually means, and the control that implements it.

Terms
16 defined
Source
DPDP Act, 2023
Most confused
Consent Manager vs CMP

Data Fiduciary

Sec. 2(i)

The organisation that decides why and how personal data is processed.

Any person who, alone or with others, determines the purpose and means of processing personal data. The Fiduciary carries the obligations under the Act and remains responsible for processing carried out on its behalf by a Data Processor — which is the structural trap in Sec. 8(1): you inherit the penalty for your vendor's failure.

Privacy Program Governance is the control that implements this.

Data Principal

Sec. 2(j)

The individual the personal data is about.

The individual to whom the personal data relates. Where the individual is a child, it includes the parent or lawful guardian; where the individual is a person with disability, it includes their lawful guardian. The Principal holds the rights of access, correction, erasure, grievance redressal and nomination.

DSAR Management is the control that implements this.

Data Processor

Sec. 2(k)

A vendor processing personal data on the Fiduciary's behalf.

Any person who processes personal data on behalf of a Data Fiduciary. Processors must be engaged under a valid contract, and the Fiduciary stays liable for their processing — which is why a processor register mapped to purposes and consents is the difference between mapped exposure and discovered exposure.

Privacy Program Governance is the control that implements this.

Significant Data Fiduciary (SDF)

Sec. 10

A Fiduciary notified by government as carrying elevated duties.

The Central Government may notify any Data Fiduciary or class of Fiduciaries as Significant, based on the volume and sensitivity of personal data processed, risk to Data Principals, and factors including sovereignty, electoral democracy and public order. An SDF must appoint an India-based DPO answerable to the board, appoint an independent data auditor, and undertake periodic DPIAs, audits and algorithmic due diligence. Notification is by class — an enterprise can become an SDF without changing anything it does.

PIA / DPIA Assessment is the control that implements this.

Personal data breach

Sec. 2(u)

Broader than a hack — it includes loss of access.

Any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises the confidentiality, integrity or availability of personal data. The definition covers unauthorised internal processing and loss of access, not only external exfiltration, which is why detection scoped to attack alone under-reports.

Data Breach Management is the control that implements this.

Notice

Sec. 5

The itemised statement served before or with consent.

A statement itemising the personal data to be collected, the purpose of processing, how the Data Principal may exercise their rights, and how to complain to the Board. It must be available in English or any language in the Eighth Schedule to the Constitution — twenty-two languages besides English.

Consent Management is the control that implements this.

Legitimate uses

Sec. 7

The narrow set of grounds that do not need consent.

The specified circumstances in which personal data may be processed without consent, including where the Principal has voluntarily provided data for a purpose, for State functions and subsidies, for compliance with law or a court order, for medical emergencies, and for employment purposes. Narrower than the GDPR's legitimate-interest balancing test — it is a closed list rather than an assessment.

Privacy Program Governance is the control that implements this.

Data Protection Board of India

Sec. 18, 27, 28

The regulator that inquires and imposes penalties.

The adjudicating body established under the Act. It inquires into breaches and complaints and determines penalties, weighing the nature, gravity and duration of the breach, the type of personal data affected, repetitive conduct, and any mitigating action taken promptly. An inability to produce records under a Sec. 28 inquiry does not attract its own penalty — it removes the defence against every other one.

Audit & Evidence Management is the control that implements this.

Data Protection Officer (DPO)

Sec. 8(9), 10(2)(a)

The accountable individual, based in India, for an SDF.

The individual an SDF must appoint to be the point of contact for grievance redressal, based in India and answerable to the board of directors or equivalent governing body. Every Data Fiduciary must publish the contact details of the DPO or of a person able to answer questions about its processing.

Audit & Evidence Management is the control that implements this.

DPIA / Privacy Impact Assessment

Sec. 10(2)(c)

The periodic assessment an SDF must run.

A process comprising a description of the rights of Data Principals and the purpose of processing, assessment and management of risk to those rights, and such other matters as prescribed. An SDF must undertake DPIAs periodically, alongside periodic audit and due diligence of algorithmic software.

PIA / DPIA Assessment is the control that implements this.

Algorithmic due diligence

Sec. 10(2)(c)(iii)

The obligation that makes AI governance statutory.

The duty on an SDF to undertake due diligence to verify that algorithmic software it deploys for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data does not pose a risk to the rights of Data Principals. This is the clause that turns model inventory, bias testing and human oversight from good practice into a compliance obligation.

AI Governance is the control that implements this.

Erasure on withdrawal

Sec. 8(7)–(8)

Consent withdrawal triggers deletion, not just a flag.

On withdrawal of consent, or as soon as it is reasonable to assume the specified purpose is no longer being served, the Fiduciary and its Processors must erase the personal data unless retention is necessary for compliance with law. Delivering this depends on being able to enumerate every store holding that individual's data.

Intelligent Data Mapper is the control that implements this.

Cross-border transfer

Sec. 16

Permitted by default, restricted by notification.

Transfer of personal data outside India is permitted except to territories the Central Government restricts by notification. This is a negative-list model rather than the adequacy-decision model used under GDPR, so the control is evaluating each transfer against the current restricted list at processing time.

Privacy Program Governance is the control that implements this.

Know the terms. Now find the gaps.

A readiness walkthrough maps your current controls onto the eighteen obligations and names what is missing.