The key stakeholders, and every term the Act defines
Verified August 2026 · Checked monthly
The Act creates one regulator, one ministry with the power to notify, four roles that organisations and people fall into, and an appeal route through the courts. Section 2 then defines twenty-eight terms, from clause (a) to clause (zb). This page holds both, because the roles and the definitions describe the same small set of things. Section 2 came into force on 14 November 2025 and is one of the few parts of the Act that is already law.
The key stakeholders
Ministry of Electronics and Information Technology
MeitY makes the Rules under section 40 and appoints commencement dates under section 1(2). It holds the power to designate Significant Data Fiduciaries, to restrict destination countries, and to exempt classes of startup. It answers questions about the Act in Parliament.
What it has done. It notified the commencement dates and the DPDP Rules on 13 November 2025. It sought nominations to the Board in May 2026 and advertised the posts in June 2026. It consulted in early 2026 on compressing the compliance window for Significant Data Fiduciaries and has not notified that change. It has used none of the six powers listed on the status tracker.
The Data Protection Board of India
The Board is the only body that can impose a penalty under the Act. It receives complaints from Data Principals and decides them. Sections 18 to 26 of the Act and Rules 17 to 21 govern it, and both are in force. Its powers and procedure, in sections 27 to 28, are not: those start in May 2027.
What it has done. Nothing. It has no appointed chairperson and no appointed members. See the full answer.
Data Fiduciary
Section 2(i) defines a Data Fiduciary as any person who alone or together with others determines the purpose and the means of processing personal data. The test is control over the decision, not contact with the data.
The first official statement about Common Service Centres. A written answer in the Lok Sabha on 12 August 2026 states that Village Level Entrepreneurs at Common Service Centres are not authorised to collect or store citizen data. The answer does not say whether they are Data Fiduciaries. India has more than 5.8 lakh Common Service Centres. The operators are not authorised to collect or store Aadhaar records, banking records or health records. On the section 2(i) test, an operator who decides nothing about the purpose or the means is not a Data Fiduciary. The obligations then sit with the government department whose service the centre delivers. That is a reading of the Act and not a statement by the Government.
Data Processor
Section 2(k) defines a Data Processor as any person who processes personal data on behalf of a Data Fiduciary. It does not decide the purpose. Section 8(2) requires the Data Fiduciary to hold a valid contract with every processor it uses. The parliamentary answer of 12 August 2026 lists that contract among the obligations falling due by May 2027.
Consent Manager
Section 2(g) defines a Consent Manager as a person registered with the Board who gives a Data Principal one place to give, manage, review and withdraw consent. Rule 4 and Part A of the First Schedule set the conditions: incorporation in India, a net worth of at least two crore rupees, and independent certification of the platform. Part B then sets the continuing duties, including keeping consent records for at least seven years.
How many are registered. None. Registration opens on 13 November 2026. See the full conditions.
Significant Data Fiduciary
Section 10(1) lets the Central Government notify a Data Fiduciary, or a class of them, as significant. It decides on factors including the volume and sensitivity of the data processed, the risk to the rights of Data Principals, the potential impact on the sovereignty and integrity of India, the risk to electoral democracy, the security of the State, and public order.
Section 10(2) then adds three duties: appoint a Data Protection Officer based in India who answers to the board of directors, appoint an independent data auditor, and carry out periodic data protection impact assessments and audits. Rule 13 adds the detail, and Rule 13(4) allows the Government to require a class of personal data to stay inside India.
How many are designated. None. Until MeitY names one, no Data Fiduciary carries these duties.
The Supreme Court, the High Courts and the Appellate Tribunal
Appeals from the Board will go to the Telecom Disputes Settlement and Appellate Tribunal. Section 44(1), which puts these appeals in that Tribunal’s jurisdiction, is in force. Section 29, which creates the right of appeal, starts on 13 May 2027. Rule 22, which sets the procedure, starts on the same date. No appeal can be brought today. Section 39 bars the civil courts from any matter the Board is empowered to decide, and is also in force. Section 35 is a different provision. It protects action taken in good faith.
The Supreme Court referred the challenges to the Act and the Rules to a larger bench on 16 February 2026. It refused an interim stay on the same date and has not announced the size of the larger bench. Section 44(3) substitutes section 8(1)(j) of the Right to Information Act, 2005 and is in force.
The Madhya Pradesh High Court at Indore directed a petitioner to file a representation before the Board in Parth Sharma v. Union of India, although the Board was not functioning.
Every term the Act defines
Each entry gives the plain meaning and the clause number. The wording is a restatement and is not the statutory text.
| Term | What it means | Clause |
|---|---|---|
| Appellate Tribunal | The Telecom Disputes Settlement and Appellate Tribunal established under section 14 of the Telecom Regulatory Authority of India Act, 1997. | 2(a) |
| Automated | Any digital process able to operate automatically in response to instructions given, or otherwise, for the purpose of processing data. | 2(b) |
| Board | The Data Protection Board of India, established by the Central Government under section 18. | 2(c) |
| Certain Legitimate Uses | The uses set out in section 7. These are the grounds on which personal data may be processed without consent. | 2(d) |
| Chairperson | The Chairperson of the Board. | 2(e) |
| Child | An individual who has not completed the age of eighteen years. | 2(f) |
| Consent Manager | A person registered with the Board who acts as a single point of contact, so that a Data Principal can give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. | 2(g) |
| Data | A representation of information, facts, concepts, opinions or instructions, in a form suitable for communication, interpretation or processing by a human being or by automated means. | 2(h) |
| Data Fiduciary | Any person who, alone or together with other persons, determines the purpose and means of processing personal data. This is the test that decides who carries the obligations. | 2(i) |
| Data Principal | The individual the personal data relates to. Where that individual is a child, it includes the parents or lawful guardian. Where that individual is a person with disability, it includes the lawful guardian acting on her behalf. | 2(j) |
| Data Processor | Any person who processes personal data on behalf of a Data Fiduciary. | 2(k) |
| Data Protection Officer | The individual a Significant Data Fiduciary appoints under section 10(2)(a). | 2(l) |
| Digital Office | An office that adopts an online mechanism, in which proceedings are conducted in online or digital mode. | 2(m) |
| Digital Personal Data | Personal data in digital form. | 2(n) |
| Gain | A gain in property or in the supply of services, whether temporary or permanent. It also covers an opportunity to earn remuneration or greater remuneration, or to gain a financial advantage otherwise than by legitimate remuneration. | 2(o) |
| Loss | A loss in property, or an interruption in the supply of services, whether temporary or permanent. It also covers the loss of an opportunity to earn remuneration or greater remuneration, or to gain a financial advantage otherwise than by legitimate remuneration. | 2(p) |
| Member | A Member of the Board, which includes the Chairperson. | 2(q) |
| Notification | A notification published in the Official Gazette. The words notify and notified are read accordingly. | 2(r) |
| Person | Includes an individual, a Hindu undivided family, a company, a firm, an association of persons or body of individuals whether incorporated or not, the State, and every artificial juristic person not already covered. | 2(s) |
| Personal Data | Any data about an individual who is identifiable by that data or in relation to it. | 2(t) |
| Personal Data Breach | Any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data. | 2(u) |
| Prescribed | Prescribed by rules made under the Act. | 2(v) |
| Proceeding | Any action taken by the Board under the Act. | 2(w) |
| Processing | A wholly or partly automated operation, or set of operations, performed on digital personal data. It includes collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission or dissemination, restriction, erasure and destruction. | 2(x) |
| She | A reference to an individual includes that individual whatever their gender. The Act uses the female pronoun throughout. | 2(y) |
| Significant Data Fiduciary | Any Data Fiduciary, or class of Data Fiduciaries, that the Central Government notifies under section 10. | 2(z) |
| Specified Purpose | The purpose stated in the notice the Data Fiduciary gives to the Data Principal under the Act and the Rules. | 2(za) |
| State | The State as defined in article 12 of the Constitution of India. | 2(zb) |
What the Act does not define
The Act leaves three terms undefined.
Harm is not defined. The draft Digital Personal Data Protection Bill, 2022 defined it. The enacted Act does not. Any guidance that cites a definition of harm from this Act is citing something that is not there.
Sensitive personal data is not defined, and the category does not exist in this Act. There is no special class of health, financial, biometric or caste data with heavier duties attached, which is a deliberate departure from the Information Technology rules of 2011 and from the General Data Protection Regulation of the European Union.
Profiling is not defined and the word does not appear as a defined term. Nor is cross-border transfer. Section 16 restricts transfer by notification rather than by definition. See the status tracker for the position on section 16.
The two definitions that carry the obligations
Section 2(i), Data Fiduciary, is the test that decides who carries every obligation in the Act. It turns on who determines the purpose and means, not on who holds the data. See who the Act applies to.
Section 2(z), Significant Data Fiduciary, defines nothing on its own. It means whoever the Central Government notifies under section 10. Nobody has been notified, so the class is currently empty.
An appointment to the Board. The first designation of a Significant Data Fiduciary, which would also fill the empty class at clause 2(z). The first Consent Manager registration. A judgment of the larger bench on section 44(3). An amendment to section 2. Any further official statement about who is or is not a Data Fiduciary.
Source. Section 2 of the Act as published by India Code and by MeitY. The wording above is a plain restatement and is not the statutory text. Read the section itself where exact words matter.