---
title: "Section 2: Definitions"
url: https://dpdp.myndsolution.com/wiki/act/section-2-definitions/
description: "Section 2 of the Digital Personal Data Protection Act, 2023 (Definitions). Official text verbatim, in force since 13 november 2025, with plain-English…"
kind: act-section
updated: 2026-09-09
official_source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
text_type: official-text-plus-interpretation
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/act/section-2-definitions/
---
# Section 2: Definitions

*The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Chapter I: PRELIMINARY. In force since 13 November 2025.*

## Official text

In this Act, unless the context otherwise requires,—
- **(a)** “Appellate Tribunal” means the Telecom Disputes Settlement and Appellate Tribunal established under section 14 of the Telecom Regulatory Authority of India Act, 1997;

- **(b)** “automated” means any digital process capable of operating automatically in response to instructions given or otherwise for the purpose of processing data;

- **(c)** “Board” means the Data Protection Board of India established by the Central Government under section 18;

- **(d)** “certain legitimate uses” means the uses referred to in section 7;

- **(e)** “Chairperson” means the Chairperson of the Board;

- **(f)** “child” means an individual who has not completed the age of eighteen years;

- **(g)** “Consent Manager” means a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform;

- **(h)** “data” means a representation of information, facts, concepts, opinions or instructions in a manner suitable for communication, interpretation or processing by human beings or by automated means;

- **(i)** “Data Fiduciary” means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data;

- **(j)** “Data Principal” means the individual to whom the personal data relates and where such individual is—
  - **(i)** a child, includes the parents or lawful guardian of such a child;
  - **(ii)** a person with disability, includes her lawful guardian, acting on her behalf;

- **(k)** “Data Processor” means any person who processes personal data on behalf of a Data Fiduciary;

- **(l)** “Data Protection Officer” means an individual appointed by the Significant Data Fiduciary under clause (a) of sub-section (2) of section 10;

- **(m)** “digital office” means an office that adopts an online mechanism wherein the proceedings, from receipt of intimation or complaint or reference or directions or appeal, as the case may be, to the disposal thereof, are conducted in online or digital mode;

- **(n)** “digital personal data” means personal data in digital form;

- **(o)** “gain” means—
  - **(i)** a gain in property or supply of services, whether temporary or permanent; or
  - **(ii)** an opportunity to earn remuneration or greater remuneration or to gain a financial advantage otherwise than by way of legitimate remuneration;

- **(p)** “loss” means—
  - **(i)** a loss in property or interruption in supply of services, whether temporary or permanent; or
  - **(ii)** a loss of opportunity to earn remuneration or greater remuneration or to gain a financial advantage otherwise than by way of legitimate remuneration;

- **(q)** “Member” means a Member of the Board and includes the Chairperson;

- **(r)** “notification” means a notification published in the Official Gazette and the expressions “notify” and “notified” shall be construed accordingly;

- **(s)** “person” includes—
  - **(i)** an individual;
  - **(ii)** a Hindu undivided family;
  - **(iii)** a company;
  - **(iv)** a firm;
  - **(v)** an association of persons or a body of individuals, whether incorporated or not;
  - **(vi)** the State; and
  - **(vii)** every artificial juristic person, not falling within any of the preceding sub-clauses;

- **(t)** “personal data” means any data about an individual who is identifiable by or in relation to such data;

- **(u)** “personal data breach” means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data;

- **(v)** “prescribed” means prescribed by rules made under this Act;

- **(w)** “proceeding” means any action taken by the Board under the provisions of this Act;

- **(x)** “processing” in relation to personal data, means a wholly or partly automated operation or set of operations performed on digital personal data, and includes operations such as collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction;

- **(y)** “she” in relation to an individual includes the reference to such individual irrespective of gender;

- **(z)** “Significant Data Fiduciary” means any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10;

- **(za)** “specified purpose” means the purpose mentioned in the notice given by the Data Fiduciary to the Data Principal in accordance with the provisions of this Act and the rules made thereunder; and

- **(zb)** “State” means the State as defined under article 12 of the Constitution.




## Interpretation in plain English (not legal advice)

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

Section 2 provides the official definitions for key terms used throughout the Digital Personal Data Protection Act, 2023. These definitions establish the exact scope of the parties, concepts, and operations governed by the law.

The provision defines the primary actors involved in data activities. A "Data Principal" is the individual to whom the personal data relates, and this term includes parents or lawful guardians if the individual is a child (under eighteen years of age) or a person with disability. A "Data Fiduciary" is any person who determines the purpose and means of processing personal data, while a "Data Processor" processes personal data on behalf of a Data Fiduciary. Additionally, a "Consent Manager" is an entity registered with the Data Protection Board of India that provides an interoperable platform for individuals to give, manage, review, and withdraw consent.

The section also specifies core operational concepts. "Personal data" refers to any data about an identifiable individual, and "processing" covers automated or partly automated operations performed on digital personal data, including collection, storage, sharing, and erasure. A "personal data breach" is defined as any unauthorized processing, accidental disclosure, acquisition, alteration, destruction, or loss of access that compromises data confidentiality, integrity, or availability.

### Key points

- Defines a "child" as an individual who has not reached the age of eighteen years [clause (f)].
- Specifies that a "Data Principal" includes parents or lawful guardians when the individual is a child or a person with disability [clause (j)].
- Distinguishes a "Data Fiduciary" (who decides the purpose and means of processing) from a "Data Processor" (who processes data on the Data Fiduciary's behalf) [clauses (i) and (k)].
- Defines a "personal data breach" broadly to include unauthorized processing or accidental events compromising data confidentiality, integrity, or availability [clause (u)].
- Establishes that the pronoun "she" refers to an individual of any gender [clause (y)].
- Clarifies that "processing" applies to wholly or partly automated operations performed on digital personal data [clause (x)].

### Common misreadings

- A Data Principal is not limited strictly to the individual directly named; it legally includes parents or lawful guardians when dealing with children or persons with disabilities.
- The pronoun 'she' in the statutory text does not limit protections or obligations to women, as it explicitly includes individuals irrespective of gender.
- A Data Processor does not determine the purpose and means of processing; that function is reserved to the Data Fiduciary.

*Interpretation prepared 2026-09-09 from the official text only; the official text prevails.*

---
Cite as: Digital Personal Data Protection Act, 2023, s. 2. Official source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
