The DPDP Act assigns specific legal labels to entities based on how they handle data. Your obligations—and your potential fines—depend entirely on which category you fall into.
Any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data.
An E-commerce company collecting customer emails to sell shoes.
Any person who processes personal data on behalf of a Data Fiduciary.
A cloud hosting provider (AWS) or a third-party payroll agency processing the E-commerce company's data.
A subset of Data Fiduciaries notified by the Central Government based on the volume and sensitivity of data processed, risk to democracy, etc.
Large social media platforms, major banks, or massive telecom operators.
The Data Principal is the individual to whom the personal data relates. In the context of children or persons with disabilities, it includes their parents or lawful guardians. The entire Act is designed to protect the rights of the Data Principal.
A new class of entity introduced by the DPDP Act. A Consent Manager is an entity registered with the Board that acts as a single point of contact to enable a Data Principal to give, manage, review, and withdraw her consent through an accessible, transparent, and interoperable platform.
The regulatory body established by the Central Government under this Act. The DPB functions as a digital office to direct data fiduciaries in the event of a breach, conduct inquiries, and impose massive financial penalties for non-compliance.