DPDPA & data-protection terms
Clear, jargon-free definitions of the terms that matter for India's data-protection law.
Consent
ConceptsA free, specific, informed, unambiguous and withdrawable agreement to process personal data for stated purposes.
Data Discovery
PracticeThe automated process of finding and classifying personal data across an organisation's systems.
Data Fiduciary
RolesAn entity that alone or with others determines the purpose and means of processing personal data under the DPDPA.
Data Principal
RolesThe individual to whom personal data relates under the DPDPA.
Data Protection Officer
RolesThe individual designated to oversee data protection and act as a point of contact, required of Significant Data Fiduciaries.
DPDPA
LawIndia's Digital Personal Data Protection Act — the law governing how organisations process the personal data of individuals in India.
DPIA
PracticeA Data Protection Impact Assessment — a structured assessment of privacy risks in a processing activity.
DSAR
RightsA Data Subject Access Request — a Data Principal's request to access, correct or erase their personal data.
Personal Data
ConceptsAny data about an individual who is identifiable by or in relation to such data.
ROPA
PracticeRecords of Processing Activities — the inventory of how an organisation processes personal data.