/The Rules · 2025
Rule 2: Definitions
DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. In force since 13 November 2025.
- Provision
- Rule 2 of The Digital Personal Data Protection Rules, 2025
- Status
- In force since 13 November 2025 (phase 1)
- Made under
- s. 40 Power to make rules
- Source
- Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF
In these rules, unless the context otherwise requires, –
“user account” means the online account registered by the Data Principal with the Data Fiduciary, and includes any profiles, pages, handles, email address, mobile number and other similar presences by means of which such Data Principal is able to access the services of such Data Fiduciary; and
The words and expressions used in these rules and not defined, but defined in the Act, shall have the same meanings respectively assigned to them in the Act.
This rule provides the specific definitions for terms used throughout the Digital Personal Data Protection Rules, 2025. It clarifies that whenever the rules mention the Act, they are referring to the Digital Personal Data Protection Act, 2023. It also states that any word or phrase used in these rules that is not defined here will carry the exact same meaning that it has in the main Act.
The rule defines a user account as the online account that a Data Principal (the individual whose data is being processed) registers with a Data Fiduciary (the entity deciding how and why data is processed). This definition is broad and includes profiles, pages, social media handles, email addresses, mobile numbers, and any other similar digital presence that allows the Data Principal to access the Data Fiduciary's services.
Finally, the rule points to other specific rules for two technical terms. It states that techno-legal measures are the measures described in rules 20 and 22. Similarly, it defines verifiable consent as the type of consent that meets the requirements set out in rule 10 or 11.
Key points
- The term Act refers specifically to the Digital Personal Data Protection Act, 2023 [(1)(a)].
- Techno-legal measures are defined by the requirements set out in rules 20 and 22 [(1)(b)].
- A user account includes registered online accounts, profiles, handles, emails, and mobile numbers used to access a Data Fiduciary's services [(1)(c)].
- Verifiable consent refers to consent that is obtained according to rule 10 or 11 [(1)(d)].
- Any term used in the rules but not defined in this section takes its meaning directly from the Act [(2)].
Common misreadings
- People might think a user account only means a traditional username and password login, but the rule explicitly includes emails, mobile numbers, profiles, and handles used to access services.
- People might assume undefined terms in the rules have standard dictionary meanings, but the rule requires them to have the specific meanings assigned in the Act.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.