Glossary

Plain-language explanation of DPDP, data discovery and AI terms.

Core DPDP terms

Personal data
Data about an individual who can be identified by or in relation to that data.
Digital personal data
Personal data in digital form, including paper data that is later digitised.
Data Principal
The individual to whom the personal data relates.
Data Fiduciary
The organisation or person that decides why and how personal data is processed.
Data Processor
A vendor or service provider that processes personal data on behalf of a Data Fiduciary.
Processing
Any operation on personal data, such as collection, storage, use, sharing, disclosure, deletion or destruction.
Consent
Clear, informed and affirmative agreement for processing personal data for a specified purpose.
Notice
Information given to an individual explaining what data is processed, why and how rights may be exercised.
Specified purpose
The specific purpose stated for which personal data will be processed.
Certain legitimate uses
Situations where processing may be permitted without consent under the Act. Legal review is recommended before relying on this.
Personal data breach
Unauthorised processing, disclosure, acquisition, sharing, use, alteration, destruction or loss of access affecting personal data.
Consent Manager
A Board-registered entity enabling individuals to give, manage, review or withdraw consent.
Significant Data Fiduciary
A Data Fiduciary or class of Data Fiduciaries notified by the Government for additional obligations.
Child
An individual below 18 years of age.
Verifiable consent
Consent verifiable in the manner required by the Rules, especially for children or persons with disabilities.

Data discovery terms

Data discovery
Identifying what data exists, where it comes from, where it is stored, who uses it and where it goes.
Data-flow map
A map showing movement of data between people, teams, systems, vendors, repositories and locations.
Process owner
The person responsible for explaining and validating how a business process actually works.
Data source
The point where data is first collected, received, created or imported.
Repository
Any place where data is stored, such as an app, database, shared drive, email inbox, spreadsheet or paper file.
Working copy
A copy of data used for day-to-day work, often outside the main system.
Shadow data
Data stored or used outside formal systems, such as local downloads, personal drives or unofficial spreadsheets.
Informal channel
A non-standard data-sharing channel, such as WhatsApp, personal email or personal cloud storage.
Data category
A type of personal data, such as identity, contact, financial, HR or health data.
Data Principal category
The group of individuals whose data is processed, such as employees, customers, vendors or visitors.
Retention period
How long data is kept before deletion, archival or anonymisation.
Vendor access
A situation where an external vendor can view, receive, store or process personal data.
Evidence
Documents, screenshots, contracts, system extracts, logs or confirmations supporting the information provided.
Gap
A difference between current practice and expected DPDP-ready practice.
Readiness roadmap
A prioritised action plan showing what should be fixed, by whom and in what sequence.

AI-specific terms

AI tool
A tool such as ChatGPT, Claude, Gemini, Grok or Copilot used to generate, analyse, summarise or transform content.
Official AI account
An AI account provided, paid for or administered by the organisation for business use.
Personal AI account
An AI account created personally by an employee, even if used for official work.
Free AI account
A non-paid AI account, often with fewer enterprise controls.
Enterprise AI account
Organisation-managed AI account with administrative controls and potentially stronger privacy settings.
Prompt
Text, question, instruction or data entered into an AI tool.
Uploaded file
A file submitted to an AI tool for summarisation, extraction, analysis or drafting.
AI output
Content generated by an AI tool, such as text, tables, summaries, code or reports.
Prompt history
Stored records of prompts, uploaded files and AI-generated outputs.
AI data exposure
Entry of personal, confidential or client data into an AI tool without adequate controls.
AI acceptable-use policy
Internal rules defining permitted and prohibited use of AI tools.

NPV Group’s DPDP diagnostic tools and website resources are intended for awareness and readiness planning. They do not constitute legal advice, audit assurance, certification or confirmation of DPDP compliance.