Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 42 weeks awayRead handbook →

Glossary

Plain-language definitions of the DPDP Act and DPDP Guard terms used throughout these docs.

Data Principal — the individual a piece of personal data is about. In DPDP Guard, this is the “consumer” role: someone with a consent history and the right to file requests.

Data Fiduciary — the organization that determines the purpose and means of processing personal data (roughly, “the company collecting the data”). In DPDP Guard, Fiduciary Admins and DPOs act on the Data Fiduciary’s behalf.

DPO (Data Protection Officer) — the individual an organization designates to be accountable for data-protection compliance. Has access to Rights & Grievances and Risk & Governance, but not Setup, in the Fiduciary dashboard.

DSR (Data Subject Request) — a request from a Data Principal to access, correct, or erase their personal data, or to learn who it’s shared with. See Exercise your rights and Process Data Subject Requests.

DPIA (Data Protection Impact Assessment) — a structured assessment of the privacy risk posed by a specific processing activity, done before (or during) that activity. See DPIA Workflow.

RoPA (Record of Processing Activities) — a maintained inventory of what personal data an organization processes, why, and how. See RoPA.

SDF (Significant Data Fiduciary) — a Data Fiduciary designated by the government as significant based on volume/sensitivity of data processed, subject to extra obligations (e.g. mandatory DPO, periodic audits). See SDF Readiness.

DPBI (Data Protection Board of India) — the regulatory body that adjudicates DPDP Act complaints and can impose penalties. See DPBI Complaints.

Grievance — a complaint a Data Principal raises about how their request or data was handled, distinct from the request itself. See Raising a grievance.

Consent Manager (CM) — in DPDP Guard, the page where you configure the consent banner (/docs/fiduciary/consent/consent-manager). Also, separately, a statutory intermediary role defined under the DPDP Rules for managing consent on a Data Principal’s behalf — see CM Readiness for the latter.