DPDPA Section 2: A Practical Guide to Core Definitions

DPDPA Section 2: A Practical Guide to Core Definitions

Ensure your organization meets all requirements with our comprehensive DPDP Act compliance guide. Discover key obligations for data fiduciaries in India.

Himanshu Jotwani

Written by

Himanshu Jotwani

Date

Read time

7 min

Most compliance programs do not fail because of a sophisticated zero-day. They fail because engineering, legal, and product teams cannot agree on what a single word means.

DPDPA Section 2 sets the vocabulary for India’s data privacy law. If your teams do not align on what “personal data,” “processing,” or “Data Fiduciary” actually mean in production, your DPDP Act compliance requirements are already drifting. This is not a theoretical glossary. It is the boundary line for your legal exposure.

This guide translates the statutory definitions into practical terms you can use to design controls, assign accountability, and make faster decisions.

Core actors and what they do

  • Data Principal: The individual whose personal data is involved. If the individual is a child, the definition includes a parent or lawful guardian. If the individual has a disability, it includes a lawful guardian acting on her behalf. Rights attach to the Data Principal. Plan for identification and authentication of guardians where relevant,if you cannot authenticate a guardian, you cannot legally process the data.
  • Data Fiduciary: Any person who alone or with others determines the purpose and means of processing personal data. If you decide why data is collected and how it is processed, you are a Data Fiduciary. This includes companies, firms, associations, and the State, since “person” is defined broadly.
  • Data Processor: Any person who processes personal data on behalf of a Data Fiduciary. Processors act on instructions and do not decide purposes or means. But remember: you remain responsible for your processors’ actions as the Fiduciary. Contracts, oversight, and technical assurances are not optional.
  • Significant Data Fiduciary: A Data Fiduciary or class of Fiduciaries that the Central Government may notify under section 10. If notified, you must meet additional obligations, including the mandatory appointment of a Data Protection Officer defined in Section 2.
  • Data Protection Officer: An individual appointed by a Significant Data Fiduciary under section 10(2)(a). Treat this as a senior, accountable role tied to risk and assurance, not a sacrificial compliance title.
  • Consent Manager: A person registered with the Data Protection Board who enables a Data Principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform. If you integrate with Consent Managers, design consent capture and withdrawal to be machine-readable and near real-time.
  • Board, Chairperson, Member: The Data Protection Board of India is the regulator established under section 18. The Chairperson leads the Board, and “Member” includes the Chairperson. Expect proceedings, directions, and penalties to flow through this body.
  • Appellate Tribunal: The Telecom Disputes Settlement and Appellate Tribunal under the Telecom Regulatory Authority of India Act. This is where appeals from the Board’s orders go. Preserve records and evidence accordingly.
Illustration of core actors in DPDPA Section 2, including Data Principal, Fiduciary, and Processor.

What data is covered

  • Data: Any representation of information, facts, concepts, opinions, or instructions suitable for communication, interpretation, or processing by humans or automated means. This scope is broad by design.
  • Personal data: Any data about an individual who is identifiable by or in relation to such data. If an individual can be identified on its own or with other reasonably available data, it qualifies.
  • Digital personal data: Personal data in digital form. Paper records are outside scope unless they are digitised. But the second you convert paper to a digital format, the DPDPA applies from that point. Plan your scanning and ingestion pipelines accordingly.
  • Specified purpose: The purpose stated in the notice given by the Data Fiduciary to the Data Principal, as required under the Act and Rules. Your notice sets the legal boundary for processing. Keep it precise and consistent with actual uses.

What counts as processing

The definition of processing is a trap for the optimistic. It means any wholly or partly automated operation performed on digital personal data. The definition includes collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure, or destruction.

Two practical realities:

  • Almost everything you do with digital personal data counts as processing. Even retention in backups is processing. Treat all environments as in-scope. You cannot protect what you do not acknowledge.
  • “Automated” means any digital process. Manual-only actions on physical records are not processing under this Act. The second you introduce a system, it is.
Illustration showing a digital process flow, representing automated data processing under DPDPA Section 2.

Children and guardianship

“Child” means an individual who has not completed 18 years. The Data Principal definition extends to parents or lawful guardians for children, and to lawful guardians for persons with disabilities.

This affects consent capture, notices, profiling restrictions, and data minimisation. You must build age and guardian verification into onboarding flows that touch minors.

Institutional and procedural terms

  • Digital office: An office that adopts online mechanisms so that proceedings, from receipt to disposal of cases, are in digital mode. Expect filings, notices, submissions, and hearings to run electronically.
  • Notification and prescribed: “Notification” means publication in the Official Gazette. “Prescribed” means prescribed by Rules under this Act. Track these closely; they will determine details like timelines, formats, and thresholds.
  • Proceeding: Any action taken by the Board under the Act. Your litigation readiness program should treat Board interactions as formal proceedings.
  • State and person: “State” has the meaning under Article 12 of the Constitution. “Person” includes individuals, Hindu undivided families, companies, firms, associations of persons or bodies of individuals, incorporated or not, the State, and every other artificial juristic person. This breadth means public bodies, startups, and large enterprises can all be Data Fiduciaries or Processors under the Act.
  • “She”: References to “she” include all individuals irrespective of gender. Maintain neutral language in your policies and notices.

Security and incident taxonomy

  • Personal data breach: Any unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data that compromises confidentiality, integrity, or availability. Read that carefully. A loss of access (availability) is just as reportable as a leak (confidentiality). Your incident response must detect, assess, and notify based on all three.
  • Gain and loss: “Gain” includes financial benefit, services, or opportunities for remuneration beyond legitimate remuneration. “Loss” includes loss of property, interruption of services, or loss of opportunity for remuneration. These terms matter when assessing harm and enforcement exposure. Document the presence or absence of gain or loss in incident reports.

Practical boundaries and tests

Are you a Data Fiduciary or a Data Processor?

If you determine why personal data is processed and how it is processed, you are a Data Fiduciary. If you only process on documented instructions from another party, you are a Data Processor. Mixed roles are common. If you reuse data for your own purposes, you become a Data Fiduciary for that processing.

Is the dataset in scope?

If it contains personal data in digital form, it is in scope. If it starts on paper and you digitise it, it becomes in scope upon digitisation. Aggregated or anonymised datasets fall out of scope only if individuals are not identifiable by or in relation to the data.

Is an activity “processing”?

If the action touches digital personal data and uses any automated means, it is processing. Collection, storage, indexing, sharing, and deletion all qualify.

A flowchart illustrating the decision process for determining if a dataset is in scope of DPDPA Section 2.

Operational implications

The strength of your compliance program depends on alignment with these definitions. They determine who is on the hook, what data is regulated, and which actions trigger obligations. Get the vocabulary right, and execution becomes a matter of disciplined process and engineering.

  • Map your data: Map personal data and digital personal data across systems, including logs and backups. Classify uses against the specified purpose communicated in your notices.
  • Establish a single source of truth: Identify all Data Fiduciaries and Processors in your ecosystem. Align contracts, instructions, and technical controls with those roles. A contract that says you are a Processor does not save you if your engineering team acts like a Fiduciary.
  • Prepare for children’s data: Implement age checks, guardian workflows, and restrictions for tracking or targeted activities that involve minors.
  • Triage incidents correctly: Incidents must be triaged against the breach definition. Include confidentiality, integrity, and availability in your risk scoring. Define clear criteria for notifying the Board and Data Principals within prescribed timelines once Rules specify them.
  • Watch for designation: If notified as a Significant Data Fiduciary, appoint a Data Protection Officer and be prepared for impact assessments and audits under section 10.
  • Design for Consent Managers: Support interoperable consent capture and withdrawal where relevant. Engineer for verifiable provenance and revocation across integrated systems.

Real-world compliance is not theory. It is notices that match reality, processing inventories that stay current, and incident response that measures confidentiality, integrity, and availability without guesswork.

At Regodit, we built a platform to help you map roles, data, and processing against every DPDPA core definition. If you are ready to stop managing privacy on spreadsheets and start running compliance like an operating system, schedule a call to discuss your current state and what good execution actually looks like.

Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.

Keep reading

All blogs →