Glossary
Plain-language explanation of DPDP, data discovery and AI terms.
Core DPDP terms
- Personal data
- Data about an individual who can be identified by or in relation to that data.
- Digital personal data
- Personal data in digital form, including paper data that is later digitised.
- Data Principal
- The individual to whom the personal data relates.
- Data Fiduciary
- The organisation or person that decides why and how personal data is processed.
- Data Processor
- A vendor or service provider that processes personal data on behalf of a Data Fiduciary.
- Processing
- Any operation on personal data, such as collection, storage, use, sharing, disclosure, deletion or destruction.
- Consent
- Clear, informed and affirmative agreement for processing personal data for a specified purpose.
- Notice
- Information given to an individual explaining what data is processed, why and how rights may be exercised.
- Specified purpose
- The specific purpose stated for which personal data will be processed.
- Certain legitimate uses
- Situations where processing may be permitted without consent under the Act. Legal review is recommended before relying on this.
- Personal data breach
- Unauthorised processing, disclosure, acquisition, sharing, use, alteration, destruction or loss of access affecting personal data.
- Consent Manager
- A Board-registered entity enabling individuals to give, manage, review or withdraw consent.
- Significant Data Fiduciary
- A Data Fiduciary or class of Data Fiduciaries notified by the Government for additional obligations.
- Child
- An individual below 18 years of age.
- Verifiable consent
- Consent verifiable in the manner required by the Rules, especially for children or persons with disabilities.
Data discovery terms
- Data discovery
- Identifying what data exists, where it comes from, where it is stored, who uses it and where it goes.
- Data-flow map
- A map showing movement of data between people, teams, systems, vendors, repositories and locations.
- Process owner
- The person responsible for explaining and validating how a business process actually works.
- Data source
- The point where data is first collected, received, created or imported.
- Repository
- Any place where data is stored, such as an app, database, shared drive, email inbox, spreadsheet or paper file.
- Working copy
- A copy of data used for day-to-day work, often outside the main system.
- Shadow data
- Data stored or used outside formal systems, such as local downloads, personal drives or unofficial spreadsheets.
- Informal channel
- A non-standard data-sharing channel, such as WhatsApp, personal email or personal cloud storage.
- Data category
- A type of personal data, such as identity, contact, financial, HR or health data.
- Data Principal category
- The group of individuals whose data is processed, such as employees, customers, vendors or visitors.
- Retention period
- How long data is kept before deletion, archival or anonymisation.
- Vendor access
- A situation where an external vendor can view, receive, store or process personal data.
- Evidence
- Documents, screenshots, contracts, system extracts, logs or confirmations supporting the information provided.
- Gap
- A difference between current practice and expected DPDP-ready practice.
- Readiness roadmap
- A prioritised action plan showing what should be fixed, by whom and in what sequence.
AI-specific terms
- AI tool
- A tool such as ChatGPT, Claude, Gemini, Grok or Copilot used to generate, analyse, summarise or transform content.
- Official AI account
- An AI account provided, paid for or administered by the organisation for business use.
- Personal AI account
- An AI account created personally by an employee, even if used for official work.
- Free AI account
- A non-paid AI account, often with fewer enterprise controls.
- Enterprise AI account
- Organisation-managed AI account with administrative controls and potentially stronger privacy settings.
- Prompt
- Text, question, instruction or data entered into an AI tool.
- Uploaded file
- A file submitted to an AI tool for summarisation, extraction, analysis or drafting.
- AI output
- Content generated by an AI tool, such as text, tables, summaries, code or reports.
- Prompt history
- Stored records of prompts, uploaded files and AI-generated outputs.
- AI data exposure
- Entry of personal, confidential or client data into an AI tool without adequate controls.
- AI acceptable-use policy
- Internal rules defining permitted and prohibited use of AI tools.
NPV Group’s DPDP diagnostic tools and website resources are intended for awareness and readiness planning. They do not constitute legal advice, audit assurance, certification or confirmation of DPDP compliance.