Glossary of Key Terms

Last updated: 6 August 2026

Plain-language explanations of terms commonly used in data protection and cyber law. These are simplified summaries for general understanding. For the precise legal meaning, refer to the relevant statute.

Personal data

Any data about an individual who is identifiable by or in relation to such data (Digital Personal Data Protection Act, 2023).

Data Principal

The individual to whom the personal data relates. Where the individual is a child, it includes the parents or lawful guardian (DPDP Act, 2023).

Data Fiduciary

Any person who, alone or with others, determines the purpose and means of processing personal data — in practice, the organisation that decides why and how personal data is used (DPDP Act, 2023).

Data Processor

Any person who processes personal data on behalf of a Data Fiduciary (DPDP Act, 2023).

Processing

An automated operation, or set of operations, performed on digital personal data — such as collection, recording, storage, use, sharing, or erasure (DPDP Act, 2023).

Consent Manager

A person registered with the Data Protection Board who acts as a single point of contact enabling an individual to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform (DPDP Act, 2023).

Significant Data Fiduciary

A Data Fiduciary, or class of Data Fiduciaries, that the Central Government notifies as “significant” on the basis of factors such as the volume and sensitivity of the personal data processed and the risks involved. A Significant Data Fiduciary has additional obligations, including appointing a Data Protection Officer, appointing an independent data auditor, and undertaking Data Protection Impact Assessments (DPDP Act, 2023).

Data Protection Officer (DPO)

An individual appointed by a Significant Data Fiduciary who serves as the point of contact for grievance redressal and is responsible for the fiduciary’s data-protection compliance (DPDP Act, 2023).

Data Protection Impact Assessment (DPIA)

A process to describe, assess, and manage the risks to the rights of individuals arising from the processing of their personal data (DPDP Act, 2023).

Personal data breach

Any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data, that compromises its confidentiality, integrity, or availability (DPDP Act, 2023).

Data Protection Board of India

The authority established under the DPDP Act, 2023 to determine instances of non-compliance with the Act and to impose penalties.

Intermediary

Under the Information Technology Act, 2000, a person who, on behalf of another, receives, stores, or transmits an electronic record, or provides any service in respect of it — for example, internet service providers, search engines, and social media platforms.

Phishing

A fraudulent attempt to obtain sensitive information, such as passwords or bank details, by impersonating a trustworthy person or organisation — typically through email, messages, or fake websites.

GDPR

The General Data Protection Regulation, the European Union’s data protection law. It can apply to organisations outside the EU that handle the personal data of individuals located in the EU.