DPDP Wiki Talk to us

/The Rules · 2025

Rule 2: Definitions

DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. In force since 13 November 2025.

In forceOfficial textIn force since 13 November 2025 (phase 1) · rule 1(2)
Provision
Rule 2 of The Digital Personal Data Protection Rules, 2025
Status
In force since 13 November 2025 (phase 1)
Made under
s. 40 Power to make rules
Source
Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF

Rule 2. Definitions

Verbatim from the Gazette of India
(1)

In these rules, unless the context otherwise requires, –

(a)

“Act” means the Digital Personal Data Protection Act, 2023 (22 of 2023);

(b)

techno-legal measures” means as referred to under rules 20 and 22;

(c)

user account” means the online account registered by the Data Principal with the Data Fiduciary, and includes any profiles, pages, handles, email address, mobile number and other similar presences by means of which such Data Principal is able to access the services of such Data Fiduciary; and

(d)

verifiable consent” means a consent as specified in rule 10 or 11.

(2)

The words and expressions used in these rules and not defined, but defined in the Act, shall have the same meanings respectively assigned to them in the Act.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data PrincipalData Fiduciary

This rule provides the specific definitions for terms used throughout the Digital Personal Data Protection Rules, 2025. It clarifies that whenever the rules mention the Act, they are referring to the Digital Personal Data Protection Act, 2023. It also states that any word or phrase used in these rules that is not defined here will carry the exact same meaning that it has in the main Act.

The rule defines a user account as the online account that a Data Principal (the individual whose data is being processed) registers with a Data Fiduciary (the entity deciding how and why data is processed). This definition is broad and includes profiles, pages, social media handles, email addresses, mobile numbers, and any other similar digital presence that allows the Data Principal to access the Data Fiduciary's services.

Finally, the rule points to other specific rules for two technical terms. It states that techno-legal measures are the measures described in rules 20 and 22. Similarly, it defines verifiable consent as the type of consent that meets the requirements set out in rule 10 or 11.

Key points

  • The term Act refers specifically to the Digital Personal Data Protection Act, 2023 [(1)(a)].
  • Techno-legal measures are defined by the requirements set out in rules 20 and 22 [(1)(b)].
  • A user account includes registered online accounts, profiles, handles, emails, and mobile numbers used to access a Data Fiduciary's services [(1)(c)].
  • Verifiable consent refers to consent that is obtained according to rule 10 or 11 [(1)(d)].
  • Any term used in the rules but not defined in this section takes its meaning directly from the Act [(2)].

Common misreadings

  • People might think a user account only means a traditional username and password login, but the rule explicitly includes emails, mobile numbers, profiles, and handles used to access services.
  • People might assume undefined terms in the rules have standard dictionary meanings, but the rule requires them to have the specific meanings assigned in the Act.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.