Glossary
Child — an individual who has not completed eighteen years of age under the Act.
Consent — the Data Principal’s indication that is free, specific, informed, unconditional and unambiguous with clear affirmative action, signifying agreement to processing for the specified purpose and limited to necessary personal data.
Consent Manager — a person registered with the Board who enables a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. Ordinary consent tooling is not automatically a Consent Manager.
Control plane — OpenDPDP services holding legal configuration, metadata, workflows, pseudonymous references and evidence; designed to avoid raw customer PII.
Data — a representation of information, facts, concepts, opinions or instructions suitable for communication, interpretation or processing by humans or automated means.
Data Fiduciary — a person who alone or with others determines purpose and means of processing personal data.
Data Principal — the individual to whom personal data relates; includes the parent or lawful guardian in the Act’s specified contexts.
Data Processor — a person who processes personal data on behalf of a Data Fiduciary.
Data Protection Board of India (DPBI/Board) — the body established under section 18 and G.S.R. 844(E). Establishment does not by itself prove staffing or portal availability.
Data Protection Impact Assessment (DPIA) — for an SDF, the statutory periodic process described by section 10 and Rules; OpenDPDP also supports it as a recommended high-risk control.
Evidence artefact — a bounded record, reference, test result or receipt supporting a control or event. It does not alone prove overall compliance.
Grievance — a complaint to a Data Fiduciary or Consent Manager about performance of obligations; the Act expects the grievance route to be exhausted before a Board complaint.
Legal hold — a scoped preservation instruction preventing disposal for an identified matter and authority. It does not permit unrelated use.
Notice — information given by a Data Fiduciary enabling informed consent and routes to withdraw/rights/Board complaint; Rule 3 specifies content and independent comprehensibility.
Personal data — any data about an individual who is identifiable by or in relation to such data.
Personal data breach — unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises confidentiality, integrity or availability of personal data.
Processing — wholly or partly automated operation or set of operations performed on digital personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment/combination, indexing, sharing, disclosure, dissemination, restriction, erasure or destruction.
Purpose version — immutable approved specification of why data is processed, route, data, Principals, recipients, owner, retention and effective period.
Significant Data Fiduciary (SDF) — a Data Fiduciary/class notified by Central Government under section 10. A risk candidate is not legally designated without notification.
Specified legitimate use — one of the exact uses in Act section 7. It is not a general “legitimate interests” basis.
Statutory clock — a deadline/sequence derived from one exact legal, sector or contractual regime. Multiple clocks can attach to one incident or case.
Subject reference — tenant-scoped pseudonymous reference for a Data Principal, normally derived through a tenant-secret HMAC in a customer boundary.
System of record — customer system authoritative for the underlying data. OpenDPDP orchestrates and evidences; it does not silently become that system.
Withdrawal propagation — instruction and reconciliation that stops consent-based processing in relevant systems/processors after withdrawal, subject to authorised/legal continuation.