Glossary

Every term used on this site, in one plain sentence. New to the law itself? Start with DPDP basics.

The law

DPDP ActDigital Personal Data Protection Act, 2023
India's law on how organisations collect and use personal data, and the rights people have over it.
DPDP Rules 2025Digital Personal Data Protection Rules, 2025
The rules that put the DPDP Act into practice. Notified on 13 November 2025; most duties apply from May 2027.
Data Fiduciary
The organisation that decides why and how personal data is used. Most DPDP duties fall on it.
Data Principal
The person the data is about: a customer, employee or user. For a child, the parent also acts.
Data Processor
A vendor that handles personal data on a Data Fiduciary's behalf, such as a cloud or payroll provider.
Data Protection BoardData Protection Board of India
The regulator that hears DPDP complaints, investigates breaches and imposes penalties.
SDFSignificant Data Fiduciary
An organisation the government names for extra duties: an India-based DPO, a yearly DPIA and an independent audit.
GDPRGeneral Data Protection Regulation
The European Union's data protection law. It applies when you handle personal data of people in the EU.
CCPA and CPRACalifornia Consumer Privacy Act and Privacy Rights Act
California's privacy laws, giving consumers there rights over the personal data businesses hold.

Breach and security

Breach notice (Rule 7)
After a personal data breach: tell affected people and the Board without delay, then send the Board a report within 72 hours.
CERT-InIndian Computer Emergency Response Team
India's national cyber-security agency. Most cyber incidents must be reported to it within 6 hours.
DAKSH
RBI's supervisory portal. Under RBI's 2026 cyber Directions, regulated entities report cyber incidents on it within 6 hours.
SEBI CSCRFSEBI Cybersecurity and Cyber Resilience Framework
SEBI's cyber rules for market entities: a 6-hour incident notice and a portal report within 24 hours.
IRDAIInsurance Regulatory and Development Authority of India
The insurance regulator. Insurers report cyber incidents to CERT-In within 6 hours and copy IRDAI.
Security duties (S.8(4), S.8(5))
Take the technical and organisational measures the Act needs, and reasonable safeguards to prevent a breach.

Programme

DPIAData Protection Impact Assessment
A structured check of the privacy risks of a system or process before and while you run it.
ROPARecord of Processing Activities
A register of what personal data you process, why, where it goes and how long you keep it.
DSARData Subject (Principal) Access Request
A request from a person to see, correct or erase their data. Under DPDP these are rights requests.
PMLAPrevention of Money-laundering Act, 2002
Requires financial firms to keep transaction and identity records for five years, which can override erasure.
DPOData Protection Officer
The person who answers for data protection. A Significant Data Fiduciary must appoint one based in India.
DPAData Processing Agreement
The contract that sets how a vendor may handle your personal data, and what happens when it ends.
NBFCNon-Banking Financial Company
A lender or finance company regulated by RBI that is not a bank, such as a microfinance firm.
BFSIBanking, financial services and insurance
The industry group of banks, lenders, brokers and insurers, regulated by RBI, SEBI and IRDAI.

Security products

DSPMData Security Posture Management
Software that finds where personal and sensitive data lives, and shows who can reach it and how exposed it is.
DAMDatabase Activity Monitoring
Software that watches who reads or changes data in databases, and flags unusual activity.
DDRData Detection and Response
Software that checks each data request as it happens and allows, masks or blocks it, then responds to threats.
TPRMThird-Party Risk Management
Checking vendors and partners who handle your data: tiering, questionnaires, scoring, contracts and exit.
SIEM and SOAR
The security team's tools: SIEM collects and alerts on security events; SOAR runs automated responses.
CMDBConfiguration Management Database
IT's register of servers, databases and applications, with their owners. Often kept in ServiceNow.
EDREndpoint Detection and Response
Security software on laptops and servers that spots and stops threats on each machine.
SSO and SCIM
SSO lets staff sign in with their company login; SCIM adds and removes their accounts automatically.

Definitions are simplified for clarity and checked on 28 September 2026. They are not legal advice.