Skip to content
DPDP deadline in
Learn more →
PrivacySuraksha - Privacy. Trust. Compliance

India's DPDP privacy operations platform

Chapter I · Preliminary

Section 2 — Definitions

What this section requires

Section 2 defines the terms the rest of the Act uses — Data Fiduciary, Data Principal, Data Processor, personal data, consent, Consent Manager, Significant Data Fiduciary, and around two dozen others. It sets no obligation on its own; every substantive duty elsewhere in the Act depends on reading its terms through these definitions.

A few are worth knowing by heart because the rest of this guide leans on them: "Data Fiduciary" is any person who alone or with others determines the purpose and means of processing personal data (i.e., decides why and how — regardless of size or whether it also does the processing itself); "Data Principal" is the individual the data is about, extended to a parent or lawful guardian where she is a child, and to her lawful guardian where she is a person with disability; "personal data" is any data about an individual who is identifiable by or in relation to it; and "processing" is defined broadly enough to cover collection, storage, use, sharing, and erasure alike.

Who it applies to

Everyone the Act touches — every other section reads its own terms through these definitions, so this section applies wherever any other provision does.

Checklist

  • Not applicable — a definitions section has nothing to check against; the checklist lives in the sections that use these terms.

Penalty exposure

Not applicable — no obligation attaches to Section 2 itself, so no penalty in the Schedule to Section 33 does either.

Implementation timeline

In force since 13 November 2025.

Section 2

← Back to the DPDP guide index