Home/Key Roles
Section 2 · Section 10 · Sections 18–26

Six Defined Roles Carry Every Obligation

Get the roles right and the rest of the Act reads itself: duties attach to the Data Fiduciary, rights attach to the Data Principal, and everything else is machinery around those two.

§ 2(j)Data PrincipalThe individual the personal data is about. Where she is a child, the expression includes her parents or lawful guardian; where she is a person with disability, her lawful guardian acting on her behalf.
§ 2(i)Data FiduciaryWhoever determines the purpose and means of processing, alone or with others. Accountability sits here — irrespective of any agreement to the contrary, and irrespective of what a Data Principal does or fails to do.
§ 2(k) · § 8(2)Data ProcessorProcesses personal data on behalf of a Data Fiduciary, and may only be engaged for offering goods or services under a valid contract. When the Fiduciary must erase data, it must cause its processors to erase too.
§ 2(g) · § 6(7)–(9)Consent ManagerA single point of contact, registered with the Board, through which a Data Principal can give, manage, review and withdraw consent on an accessible, transparent and interoperable platform. Accountable to her, not to the Fiduciary.
§ 10Significant Data FiduciaryNotified by the Central Government on volume and sensitivity of data, risk to rights, sovereignty, electoral democracy, security of the State and public order. Owes a DPO in India, an independent data auditor, and periodic DPIA and audit.
§§ 18–26Data Protection Board of IndiaA body corporate established by the Central Government, with a Chairperson and Members appointed for two-year terms, functioning as far as practicable as a digital office. Its officers are deemed public servants.

Definitions that decide exam questions

Personal dataAny data about an individual who is identifiable by or in relation to such data. § 2(t)
ProcessingA wholly or partly automated operation on digital personal data — collection, storage, use, sharing, erasure and more. § 2(x)
Personal data breachAny unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises confidentiality, integrity or availability. § 2(u)
ChildAn individual who has not completed the age of eighteen years. § 2(f)
Specified purposeThe purpose stated in the notice given by the Data Fiduciary to the Data Principal. § 2(za)
Digital officeAn office conducting proceedings online end to end, from intimation to disposal. § 2(m)
Roles are the most tested topic on the exam.Run a practice set now while the definitions are fresh.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 2 August 2026 against the DPDP Act, 2023 and notified DPDP Rules, 2025. Educational information, not legal advice.

Review standards and attribution →