Last updated: 6 August 2026
Plain-language explanations of terms commonly used in data protection and cyber law. These are simplified summaries for general understanding. For the precise legal meaning, refer to the relevant statute.
Any data about an individual who is identifiable by or in relation to such data (Digital Personal Data Protection Act, 2023).
The individual to whom the personal data relates. Where the individual is a child, it includes the parents or lawful guardian (DPDP Act, 2023).
Any person who, alone or with others, determines the purpose and means of processing personal data — in practice, the organisation that decides why and how personal data is used (DPDP Act, 2023).
Any person who processes personal data on behalf of a Data Fiduciary (DPDP Act, 2023).
An automated operation, or set of operations, performed on digital personal data — such as collection, recording, storage, use, sharing, or erasure (DPDP Act, 2023).
A person registered with the Data Protection Board who acts as a single point of contact enabling an individual to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform (DPDP Act, 2023).
A Data Fiduciary, or class of Data Fiduciaries, that the Central Government notifies as “significant” on the basis of factors such as the volume and sensitivity of the personal data processed and the risks involved. A Significant Data Fiduciary has additional obligations, including appointing a Data Protection Officer, appointing an independent data auditor, and undertaking Data Protection Impact Assessments (DPDP Act, 2023).
An individual appointed by a Significant Data Fiduciary who serves as the point of contact for grievance redressal and is responsible for the fiduciary’s data-protection compliance (DPDP Act, 2023).
A process to describe, assess, and manage the risks to the rights of individuals arising from the processing of their personal data (DPDP Act, 2023).
Any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data, that compromises its confidentiality, integrity, or availability (DPDP Act, 2023).
The authority established under the DPDP Act, 2023 to determine instances of non-compliance with the Act and to impose penalties.
Under the Information Technology Act, 2000, a person who, on behalf of another, receives, stores, or transmits an electronic record, or provides any service in respect of it — for example, internet service providers, search engines, and social media platforms.
A fraudulent attempt to obtain sensitive information, such as passwords or bank details, by impersonating a trustworthy person or organisation — typically through email, messages, or fake websites.
The General Data Protection Regulation, the European Union’s data protection law. It can apply to organisations outside the EU that handle the personal data of individuals located in the EU.