Glossary
The vocabulary of the Act
The DPDP Act uses its own terms, and they are not translations of GDPR terms. Using the right word is not pedantry. It decides which obligation you are talking about.
- Data PrincipalSec 2(j)
- The individual to whom the personal data relates. For a child, it includes the parent or lawful guardian; for a person with disability, the lawful guardian. The GDPR term 'data subject' has no standing under the DPDP Act.
- Data FiduciarySec 2(i)
- Any person who, alone or with others, determines the purpose and means of processing personal data. The obligations of the Act, and the burden of proof, sit here. The GDPR calls this a controller; India does not.
- Data ProcessorSec 2(k)
- Any person who processes personal data on behalf of a Data Fiduciary. TruPriv, as a software supplier, is a Data Processor to the Data Fiduciaries who deploy it.
- Consent ManagerSec 6(7)–(9), Rule 4
- A specific intermediary, registered with the Data Protection Board, through which a Data Principal can give, manage, review and withdraw consent across Data Fiduciaries. It is a registered role with its own conditions. TruPriv is not a Consent Manager. It is a Consent Management Platform deployed by a Data Fiduciary for its own governance.
- Consent artefact
- The record of a consent decision: who, which purposes, when, by what capture method, against which notice version and language, with a signature. Versioned and never overwritten, it is the object you produce when asked to prove consent. Not to be confused with the GDPR-era phrase 'consent receipt'.
- Significant Data Fiduciary (SDF)Sec 10
- A Data Fiduciary, or class of them, notified as significant by the Central Government on the basis of volume and sensitivity of data, risk to Data Principals, risk to electoral democracy and security of the State. SDFs carry additional obligations: a DPO in India, an independent data auditor, and periodic DPIAs and audits.
- Data Protection Board of IndiaSec 18–27
- The adjudicating body constituted under the Act, which determines non-compliance and imposes monetary penalties. Constituted on 13 November 2025. Not a 'supervisory authority': that is GDPR vocabulary for a differently-shaped institution.
- Eighth Schedule languagesSec 5(3)
- The 22 languages listed in the Eighth Schedule to the Constitution of India. Notices must be available in English or any of them, at the Data Principal's option. Calling these 'regional' or 'vernacular' languages both misstates the obligation and misreads the country.
- Personal data breachSec 2(u)
- Any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises its confidentiality, integrity or availability. Note that loss of availability counts: a ransomware event is a breach even if nothing leaves.
- Verifiable consentSec 9(1)
- The standard for processing a child's personal data: consent of a parent or lawful guardian, obtained in a manner that can be verified. A tick-box asserting adulthood does not meet it.
Terms we do not use
Data subject, data controller, supervisory authority, consent receipt, vernacular languages. Each belongs to a different statute with different obligations. A platform that reaches for them is describing a product built for somewhere else.
