The DPDP Bible/ Glossary/ The Person
The Person

What is a Data Principal?

A Data Principal is the person whose personal data is being collected, used, stored, shared, or deleted.

In one line

A Data Principal is the person whose personal data is being collected, used, stored, shared, or deleted.

Simple example

A customer ordering food, a student using an EdTech app, a patient booking a test, and an employee in an HR system can all be Data Principals.

Why it matters

DPDP starts with the person. If your business cannot explain what happens to that person's data, your DPDP work is not ready.

What to check

1

Who are the people behind the data?

2

Are they customers, employees, students, patients, vendors, or leads?

3

Do any of them include children?

4

Can they access, correct, delete, or raise a grievance?

5

Can you respond without searching across ten disconnected tools?

Common mistake

Treating data as rows in a database and forgetting that each row belongs to a real person.

First useful action

Pick one type of person, such as customer or employee, and map their full data journey.

If this is still fuzzy, do this

Run one real data journey through your business. Do not start with legal language. Start with the person, the form, the tool, the vendor, the message, and the deletion point.

Related DPDP terms