Rule 4

Consent Manager registration opens — 13 Nov 2026

myconsent+
Glossary

The person the data is about, and what she can ask of you

Last updated

7 October 2026

Sec. 2(j) defines the Data Principal as the individual the personal data is about, and includes a child's parent. The four rights, and the five duties.

Every duty in the Digital Personal Data Protection Act, 2023 is owed to someone, and the Act names that someone itself rather than borrowing a word from European law. She is the Data Principal, and her definition does one unusual thing: for two kinds of individual it reaches past her.

The definition, in the Act's words

"Data Principal" means the individual to whom the personal data relates and where such individual is— (i) a child, includes the parents or lawful guardian of such a child; (ii) a person with disability, includes her lawful guardian, acting on her behalf.

That is Sec. 2(j). A child, under Sec. 2(f), is an individual who has not completed eighteen years, so for a sixteen-year-old the Data Principal is the teenager and her parent or lawful guardian — which is why Sec. 9(1) requires verifiable consent of the parent before a child's data is processed at all. What attaches to her is Sec. 2(t) personal data: any data about an individual identifiable by or in relation to it.

The same thing, in one sentence

A Data Principal is the individual the personal data is about — and where she is a child or has a guardian, the person acting for her counts too.

A worked example

A woman in Jaipur opens a demat account with an online broker. She is the Data Principal for her PAN, her bank details and her trading history. The broker is her Data Fiduciary; the KYC agency it uses is a Data Processor.

Six months later she asks the broker what it holds. Sec. 11(1) entitles her to a summary of the personal data being processed and the processing activities undertaken on it, and Sec. 11(1)(b) to the identities of every other Data Fiduciary and Data Processor it was shared with — so the KYC agency has to be named.

She also asks for an old address to be corrected: Sec. 12(2) requires the broker to correct what is inaccurate or misleading, complete what is incomplete and update what is stale. When she closes the account and asks for erasure, Sec. 12(3) requires it unless retention is necessary for the specified purpose or for compliance with law — and for a broker it usually is.

What a Data Principal is not

She is not necessarily your customer. The definition turns on whose data it is, not on whether there is an account or a contract — a rejected job applicant and a patient's next of kin are both Data Principals.

She is not any legal person. Sec. 2(s) defines "person" widely enough to include companies and firms, but Sec. 2(j) says individual. A company is never a Data Principal, and its registered office address is not personal data.

She is not an owner of the data. The Act grants rights against a Data Fiduciary and creates no property in personal data; Sec. 6(5) makes the point sharply — the consequences of withdrawal are borne by her, and it does not make earlier processing unlawful.

And the rights are not unconditional. Sec. 11(1) and Sec. 12(1) both run against a Data Fiduciary to whom she has previously given consent, including consent referred to in Sec. 7(a). Processing resting only on employment under Sec. 7(i) is outside the reach of those two; Sec. 13 and Sec. 14 carry no such limit.

What follows from being one

Four rights, each with a provision behind it.

Access, Sec. 11. The summary, the processing activities and the recipients, as above. Sec. 11(2) withholds the recipient list in one narrow case: sharing with another Data Fiduciary authorised by law, on a written request, for the prevention, detection or investigation of offences or cyber incidents.

Correction and erasure, Sec. 12. Correction, completion, updating and erasure of data she previously consented to.

Grievance redressal, Sec. 13. Sec. 13(1) entitles her to readily available means of grievance redressal from a Data Fiduciary or a Consent Manager, and Rule 14(3) of the DPDP Rules, 2025 fixes the outer limit for a response at a reasonable period not exceeding ninety days. Sec. 13(3) requires her to exhaust that route before approaching the Board.

Nomination, Sec. 14. She may nominate another individual to exercise her rights on death or incapacity, which Sec. 14(2) defines as inability arising from unsoundness of mind or infirmity of body.

Alongside them sits the Sec. 6(4) right to withdraw consent at any time, and the Sec. 6(7) option to give, manage, review or withdraw it through a Consent Manager rather than dealing with each Data Fiduciary separately. Rule 14(1) puts the burden of reach on you: a Data Fiduciary, and where applicable a Consent Manager, must prominently publish the means of making a request and the particulars needed to identify her.

She owes something back. Sec. 15 places five duties on her, among them not impersonating another person and not registering a false or frivolous grievance. The asymmetry is deliberate: entry 5 of the Schedule caps a breach of Sec. 15 at ten thousand rupees, against ceilings in the crores for your own failures.

Where to go next

The Act, from the beginning sets these rights beside the grounds and the dates they commence on; the provision map pairs each with the control that answers it. Rights and grievance is where these requests land here, each on its own clock — Sec. 11, Sec. 12 and Sec. 13 do not share one.