/The Act · Chapter I · Preliminary
Section 2: Definitions
DPDP Act, 2023 (No. 22 of 2023). In force since 13 November 2025.
- Provision
- Section 2 of The Digital Personal Data Protection Act, 2023
- Status
- In force since 13 November 2025 (phase 1) G.S.R. 843(E)
- Rules made under it
- None identified
- Source
- Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF
In this Act, unless the context otherwise requires,—
“Appellate Tribunal” means the Telecom Disputes Settlement and Appellate Tribunal established under section 14 of the Telecom Regulatory Authority of India Act, 1997;
“automated” means any digital process capable of operating automatically in response to instructions given or otherwise for the purpose of processing data;
“Board” means the Data Protection Board of India established by the Central Government under section 18;
“Consent Manager” means a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform;
“data” means a representation of information, facts, concepts, opinions or instructions in a manner suitable for communication, interpretation or processing by human beings or by automated means;
“Data Fiduciary” means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data;
“Data Protection Officer” means an individual appointed by the Significant Data Fiduciary under clause (a) of sub-section (2) of section 10;
“digital office” means an office that adopts an online mechanism wherein the proceedings, from receipt of intimation or complaint or reference or directions or appeal, as the case may be, to the disposal thereof, are conducted in online or digital mode;
“notification” means a notification published in the Official Gazette and the expressions “notify” and “notified” shall be construed accordingly;
“personal data” means any data about an individual who is identifiable by or in relation to such data;
“personal data breach” means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data;
“processing” in relation to personal data, means a wholly or partly automated operation or set of operations performed on digital personal data, and includes operations such as collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction;
“she” in relation to an individual includes the reference to such individual irrespective of gender;
“Significant Data Fiduciary” means any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10;
“specified purpose” means the purpose mentioned in the notice given by the Data Fiduciary to the Data Principal in accordance with the provisions of this Act and the rules made thereunder; and
Section 2 provides the official definitions for key terms used throughout the Digital Personal Data Protection Act, 2023. These definitions establish the exact scope of the parties, concepts, and operations governed by the law.
The provision defines the primary actors involved in data activities. A "Data Principal" is the individual to whom the personal data relates, and this term includes parents or lawful guardians if the individual is a child (under eighteen years of age) or a person with disability. A "Data Fiduciary" is any person who determines the purpose and means of processing personal data, while a "Data Processor" processes personal data on behalf of a Data Fiduciary. Additionally, a "Consent Manager" is an entity registered with the Data Protection Board of India that provides an interoperable platform for individuals to give, manage, review, and withdraw consent.
The section also specifies core operational concepts. "Personal data" refers to any data about an identifiable individual, and "processing" covers automated or partly automated operations performed on digital personal data, including collection, storage, sharing, and erasure. A "personal data breach" is defined as any unauthorized processing, accidental disclosure, acquisition, alteration, destruction, or loss of access that compromises data confidentiality, integrity, or availability.
Key points
- Defines a "child" as an individual who has not reached the age of eighteen years [clause (f)].
- Specifies that a "Data Principal" includes parents or lawful guardians when the individual is a child or a person with disability [clause (j)].
- Distinguishes a "Data Fiduciary" (who decides the purpose and means of processing) from a "Data Processor" (who processes data on the Data Fiduciary's behalf) [clauses (i) and (k)].
- Defines a "personal data breach" broadly to include unauthorized processing or accidental events compromising data confidentiality, integrity, or availability [clause (u)].
- Establishes that the pronoun "she" refers to an individual of any gender [clause (y)].
- Clarifies that "processing" applies to wholly or partly automated operations performed on digital personal data [clause (x)].
Common misreadings
- A Data Principal is not limited strictly to the individual directly named; it legally includes parents or lawful guardians when dealing with children or persons with disabilities.
- The pronoun 'she' in the statutory text does not limit protections or obligations to women, as it explicitly includes individuals irrespective of gender.
- A Data Processor does not determine the purpose and means of processing; that function is reserved to the Data Fiduciary.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.