Independent DPDP educationBrowser-only workspace · no accounts, analytics or submissions

01 Source-aware working language

Know which words come from the law. Know which do not.

Short explanations for navigation—not substitutes for the complete Act, Rules, corrigendum or fact-specific analysis.

Term type

Showing all 24 terms

Definitions last checked with the source ledger on 2026-08-30

DPDP working glossary

01Act term

Child

An individual who has not completed eighteen years of age.

02Act term

Consent

A free, specific, informed, unconditional and unambiguous indication of wishes through clear affirmative action, signifying agreement to processing for the specified purpose.

03Act term

Consent Manager

A person registered with the Board who enables a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform.

04Act term

Data Fiduciary

A person who alone or with others determines the purpose and means of processing personal data.

05Act term

Data Principal

The individual to whom personal data relates, including a parent or lawful guardian in the situations described by the Act.

06Act term

Data Processor

A person who processes personal data on behalf of a Data Fiduciary.

07Act term

Digital personal data

Personal data in digital form. The Act’s application also addresses certain data first collected non-digitally and later digitised.

08Act term

Lawful purpose

A purpose not expressly forbidden by law.

09Act term

Nomination

The Data Principal’s ability, subject to the Act, to nominate another individual to exercise specified rights in the event of death or incapacity.

10Act term

Personal data

Any data about an individual who is identifiable by or in relation to such data.

11Act term

Personal data breach

An unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises confidentiality, integrity or availability.

12Act term

Processing

A wholly or partly automated operation or set of operations performed on digital personal data, including collection, storage, use, sharing and erasure.

13Act term

Significant Data Fiduciary

A Data Fiduciary or class notified by the Central Government after assessment of the statutory factors.

14Act term

Specified purpose

The purpose mentioned in the notice given by the Data Fiduciary to the Data Principal.

15Act term

Certain legitimate uses

The limited situations in section 7 under which a Data Fiduciary may process personal data for the described uses.

16Rules term

Board intimation

The Rule 7 information path to the Data Protection Board following awareness of a personal data breach, with an initial intimation and later specified detail.

17Rules term

Contact information

Published business contact information for a person able to answer questions about personal-data processing on behalf of the Data Fiduciary.

18Rules term

Reasonable security safeguards

The future-cohort minimum safeguards described in Rule 6, including measures addressing access, protection, visibility, continuity, logs and processor arrangements.

19Rules term

Verifiable consent

The future-cohort Rule 10 process for checking that the person identifying as a parent is an adult and is identifiable if required in relation to compliance.

20Workspace term

Commencement cohort

This workspace’s label for provisions grouped by the commencement notification or Rule 1 into publication-date, one-year and eighteen-month stages.

21Workspace term

Evidence artefact

A retrievable, versioned record that helps a team demonstrate a decision, configuration, action, review or test.

Editorial implementation language
22Workspace term

Evidence state

One of four assessment answers: evidenced, partial, unknown or gap.

Editorial implementation language
23Workspace term

Purpose gate

A product or operating checkpoint that asks whether a named purpose, applicable route, notice and owner exist before data proceeds.

Editorial implementation language
24Workspace term

Retention-by-event

A lifecycle method that ties the start and end of a retention rule to observable events, exceptions, system actions and evidence.

02 Follow the source

Definitions are a doorway, not the decision.

Open the dated official record and phased status before applying a term to a real organisation, role or system.