Glossary
Every term used on this site, in one plain sentence. New to the law itself? Start with DPDP basics.
The law
- DPDP ActDigital Personal Data Protection Act, 2023
- India's law on how organisations collect and use personal data, and the rights people have over it.
- DPDP Rules 2025Digital Personal Data Protection Rules, 2025
- The rules that put the DPDP Act into practice. Notified on 13 November 2025; most duties apply from May 2027.
- Data Fiduciary
- The organisation that decides why and how personal data is used. Most DPDP duties fall on it.
- Data Principal
- The person the data is about: a customer, employee or user. For a child, the parent also acts.
- Data Processor
- A vendor that handles personal data on a Data Fiduciary's behalf, such as a cloud or payroll provider.
- Data Protection BoardData Protection Board of India
- The regulator that hears DPDP complaints, investigates breaches and imposes penalties.
- SDFSignificant Data Fiduciary
- An organisation the government names for extra duties: an India-based DPO, a yearly DPIA and an independent audit.
- Consent Manager
- A company registered with the Data Protection Board to manage people's consents. A registered legal role, not a software category.
- GDPRGeneral Data Protection Regulation
- The European Union's data protection law. It applies when you handle personal data of people in the EU.
- CCPA and CPRACalifornia Consumer Privacy Act and Privacy Rights Act
- California's privacy laws, giving consumers there rights over the personal data businesses hold.
Consent and rights
- Privacy notice (S.5)
- What you must tell people before asking consent: the data, the purpose, how to withdraw and how to complain.
- Withdrawal (S.6(4))
- People can withdraw consent at any time, and it must be as easy as giving it.
- Stop processing (S.6(6))
- Once consent is withdrawn, you and your vendors must stop using that person's data within a reasonable time.
- Erasure (S.8(7))
- Personal data must be erased once its purpose is served or consent is withdrawn, unless a law requires keeping it.
- Children's data (S.9)
- Processing a child's data needs verifiable parental consent, and tracking or targeted ads at children are not allowed.
- Right to access (S.11)
- People can ask what data you hold about them, how it is used and who it was shared with.
- Correction and erasure (S.12)
- People can ask you to correct, complete, update or erase their personal data.
- Grievance (S.13)
- A complaint to you first. The Rules give you up to 90 days to resolve it; then people can go to the Board.
- Nomination (S.14)
- A person can name someone to exercise their rights if they die or cannot act themselves.
- Third Schedule
- The Rules' list of large e-commerce, gaming and social platforms that must erase data of users inactive for three years.
Breach and security
- Breach notice (Rule 7)
- After a personal data breach: tell affected people and the Board without delay, then send the Board a report within 72 hours.
- CERT-InIndian Computer Emergency Response Team
- India's national cyber-security agency. Most cyber incidents must be reported to it within 6 hours.
- DAKSH
- RBI's supervisory portal. Under RBI's 2026 cyber Directions, regulated entities report cyber incidents on it within 6 hours.
- SEBI CSCRFSEBI Cybersecurity and Cyber Resilience Framework
- SEBI's cyber rules for market entities: a 6-hour incident notice and a portal report within 24 hours.
- IRDAIInsurance Regulatory and Development Authority of India
- The insurance regulator. Insurers report cyber incidents to CERT-In within 6 hours and copy IRDAI.
- Security duties (S.8(4), S.8(5))
- Take the technical and organisational measures the Act needs, and reasonable safeguards to prevent a breach.
Programme
- DPIAData Protection Impact Assessment
- A structured check of the privacy risks of a system or process before and while you run it.
- ROPARecord of Processing Activities
- A register of what personal data you process, why, where it goes and how long you keep it.
- DSARData Subject (Principal) Access Request
- A request from a person to see, correct or erase their data. Under DPDP these are rights requests.
- PMLAPrevention of Money-laundering Act, 2002
- Requires financial firms to keep transaction and identity records for five years, which can override erasure.
- DPOData Protection Officer
- The person who answers for data protection. A Significant Data Fiduciary must appoint one based in India.
- DPAData Processing Agreement
- The contract that sets how a vendor may handle your personal data, and what happens when it ends.
- NBFCNon-Banking Financial Company
- A lender or finance company regulated by RBI that is not a bank, such as a microfinance firm.
- BFSIBanking, financial services and insurance
- The industry group of banks, lenders, brokers and insurers, regulated by RBI, SEBI and IRDAI.
Security products
- DSPMData Security Posture Management
- Software that finds where personal and sensitive data lives, and shows who can reach it and how exposed it is.
- DAMDatabase Activity Monitoring
- Software that watches who reads or changes data in databases, and flags unusual activity.
- DDRData Detection and Response
- Software that checks each data request as it happens and allows, masks or blocks it, then responds to threats.
- TPRMThird-Party Risk Management
- Checking vendors and partners who handle your data: tiering, questionnaires, scoring, contracts and exit.
- SIEM and SOAR
- The security team's tools: SIEM collects and alerts on security events; SOAR runs automated responses.
- CMDBConfiguration Management Database
- IT's register of servers, databases and applications, with their owners. Often kept in ServiceNow.
- EDREndpoint Detection and Response
- Security software on laptops and servers that spots and stops threats on each machine.
- SSO and SCIM
- SSO lets staff sign in with their company login; SCIM adds and removes their accounts automatically.
Definitions are simplified for clarity and checked on 28 September 2026. They are not legal advice.