← The DPDP BiblePlain-English DPDP Library
Short, practical explanations for people who need to understand India’s data protection law without legal jargon.
- What is Personal Data under DPDP?Personal data is information about a person who can be identified from that data or together with other information.
- What does Processing mean under DPDP?Processing means almost anything a business does with personal data, including collecting, storing, using, sharing and deleting it.
- What is a Consent Manager under DPDP?A Consent Manager is a registered service that helps a person give, manage, review and withdraw consent through an accessible platform.
- What is the Data Protection Board of India?The Data Protection Board is the body created under the DPDP Act to handle complaints, inquire into breaches and impose penalties.
- What is a Personal Data Breach?A personal data breach is an unauthorised use, disclosure, loss, alteration or access that harms the confidentiality, integrity or availability of personal data.
- What is the Right to Erasure under DPDP?Erasure lets a person ask a business to delete personal data when retention is no longer required by the purpose or by law.
- What is the Right to Correction under DPDP?Correction lets a person ask a business to fix inaccurate or misleading personal data and complete data that is incomplete.
- What is the Right to Access under DPDP?Access lets a person ask for a summary of personal data being processed, the activities performed and the parties it was shared with.
- What is the Right to Nominate under DPDP?Nomination lets a person name someone who may exercise their DPDP rights if the person dies or becomes unable to act.
- What is Children’s Data under DPDP?Children’s data is personal data about a person under 18 and receives stronger protection under the DPDP framework.
- What is Verifiable Parental Consent?Verifiable parental consent is a checked permission from a parent or lawful guardian before processing a child’s personal data where required.
- What is Legitimate Use under DPDP?Legitimate use is a limited situation where personal data may be processed without relying on ordinary consent, subject to the Act and Rules.
- What is Voluntarily Provided Personal Data?This is personal data a person gives for a clear purpose without indicating that they do not agree to its use for that purpose.
- What is Purpose Limitation?Purpose limitation means using personal data only for the clear purpose explained to the person or otherwise permitted by law.
- What is Data Minimisation?Data minimisation means collecting and keeping only the personal data that is genuinely needed for the stated purpose.
- What is Storage Limitation?Storage limitation means personal data should not be kept forever when the purpose is complete and no law requires retention.
- What is a Cross-Border Data Transfer?A cross-border transfer happens when personal data is stored, accessed or processed outside India.
- What is a Data Processing Agreement?A data processing agreement is a contract that tells a processor how it may handle personal data for the business using it.
- What is a Subprocessor?A subprocessor is another vendor used by a processor to help deliver the service while handling personal data.
- What is Privacy by Design?Privacy by design means building privacy checks into a product or workflow before launch instead of repairing harm later.
- What is a Data Protection Officer?A Data Protection Officer is a privacy leader who advises, monitors and acts as a contact for data protection matters where the role is required or chosen.
- What is a Data Protection Impact Assessment?A DPIA is a structured review of a data activity, its risks to people and the controls needed before or during processing.
- What is a Record of Processing Activities?A ROPA is an organised record of what personal data a business processes, why, where, with whom and for how long.
- What is a Personal Data Inventory?A personal data inventory lists the data fields, systems, owners and vendors involved across the organisation.
- What is a Data Flow Map?A data flow map shows how personal data moves from collection through systems, teams, vendors and deletion.
- What is a Consent Log?A consent log is evidence of who agreed, what they saw, which purpose they accepted, when they acted and how they withdrew.
- What is Withdrawal of Consent?Withdrawal means a person can take back consent through a method that should be as easy as giving it.
- What is Grievance Redressal?Grievance redressal is the process for receiving, investigating, answering and closing a person’s privacy complaint.
- What is a Data Breach Register?A breach register records security incidents involving personal data, their impact, decisions, notifications and corrective actions.
- What is DPDP Vendor Due Diligence?Vendor due diligence checks whether a supplier can handle personal data securely, lawfully and according to your instructions.
- What is a Data Retention Schedule?A retention schedule says how long each kind of personal data is kept, why, who owns deletion and what law may require longer storage.
- What is Role-Based Access Control?Role-based access gives people system permissions based on their job instead of giving everyone broad access.
- What is Encryption?Encryption changes readable data into protected data that needs the right key to be understood.
- What is Pseudonymisation?Pseudonymisation replaces direct identifiers with a code while keeping the ability to reconnect the data using separate information.
- What is Anonymisation?Anonymisation removes or changes identifying details so a person cannot reasonably be identified again.
- What is a Website Cookie?A cookie is a small value stored by a browser to remember sessions, settings, measurement or advertising information.
- What is a Tracking Pixel?A tracking pixel is code or a tiny resource that sends an event to another service when a page, email or action occurs.
- What is Session Replay?Session replay records page interactions such as clicks, scrolling and field activity so a team can watch a visit later.
- What is Device Fingerprinting?Device fingerprinting combines browser and device signals to recognise a device even without a normal login.
- What is a Data Broker?A data broker collects, combines or sells information about people, often from many sources and without a direct relationship.
- What is Identity Resolution?Identity resolution links different signals to decide that they belong to the same person or household.
- What is First-Party Data?First-party data is information a business collects directly through its own customer, user or employee relationship.
- What is Zero-Party Data?Zero-party data is information a person intentionally shares about preferences or plans, often through a quiz or profile.