DPDP Wiki Talk to us

/Glossary · Defined term

personal data

Defined in section 2(t) of the Act.

Official definition

Official definition

Verbatim

Act, section 2(t)

(t) “personal data” means any data about an individual who is identifiable by or in relation to such data;

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data PrincipalData Fiduciary

The Digital Personal Data Protection Act defines "personal data" as any data about an individual who can be identified by that data, or in relation to that data. This means the information must connect to a specific, identifiable human being to be considered personal data under the law. The definition is written broadly to capture different ways a person might be identified. It covers data that directly identifies someone on its own. It also covers data that can identify an individual when it is linked or evaluated "in relation to" other information. If a piece of data is completely anonymous and cannot be used to identify an individual, it does not meet this definition and is not considered personal data.

Key points

  • Personal data must be about an individual. [Section 2(t)]
  • The individual must be identifiable by the data itself or in relation to the data. [Section 2(t)]

Common misreadings

  • Assuming personal data only includes direct identifiers, when the text explicitly includes data where a person is identifiable "in relation to" such data.
  • Assuming data about a business or company is personal data, whereas the definition specifies it must be about an "individual".

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.