Section 2 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 2 is the dictionary of the Act. This article covers the six definitions that decide what the Act protects and what counts as handling it: "automated", "data", "digital personal data", "personal data", "personal data breach" and "processing". The roles (Data Principal, Data Fiduciary and others) are in the next article, and the remaining terms follow after that. If you want your own records tested against these definitions, our legal consultation service can do that.
"Personal data" is any data about an individual who is identifiable by or in relation to that data (section 2(t)). The Act applies to it in digital form (section 2(n)), and "processing" is a wholly or partly automated operation performed on digital personal data, from collection to erasure (section 2(x)). A "personal data breach" is any unauthorised processing or accidental disclosure, loss of access and similar events that compromise confidentiality, integrity or availability (section 2(u)).
The six definitions at a glance
| Clause | Term | What the Act says |
|---|---|---|
| 2(b) | automated | Any digital process capable of operating automatically in response to instructions given or otherwise, for the purpose of processing data |
| 2(h) | data | A representation of information, facts, concepts, opinions or instructions in a manner suitable for communication, interpretation or processing by human beings or by automated means |
| 2(n) | digital personal data | Personal data in digital form |
| 2(t) | personal data | Any data about an individual who is identifiable by or in relation to such data |
| 2(u) | personal data breach | Any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data |
| 2(x) | processing | A wholly or partly automated operation or set of operations performed on digital personal data |
"Data" and "personal data"
Section 2(h) is deliberately wide. It covers information, facts, concepts, opinions and instructions, so long as they are in a form suitable for communication, interpretation or processing by people or by automated means. A spreadsheet of customer names, a database field, a scanned form and a chat message all fit.
Section 2(t) then narrows it: personal data is data about an individual who is identifiable by or in relation to that data. Three points follow from the wording.
- The data must be about an individual. Section 2(s) separately defines "person" more widely (company, firm and so on), but personal data concerns an individual.
- The individual need not be named. If the person can be identified by the data itself or in relation to it, the data qualifies. A customer ID plus an address that points to one person is an example of identification "in relation to" the data.
- The Act does not split personal data into ordinary and sensitive categories. The definition has no list of sensitive types. Where the type of data matters, the Act says so in the specific section, for example section 10(1)(a) refers to "volume and sensitivity" of personal data for notifying a Significant Data Fiduciary, and section 33(2)(b) refers to "the type and nature of the personal data" when setting a penalty.
"Digital personal data" and the reach of the Act
Section 2(n) says digital personal data is personal data in digital form. Section 3(a) extends the Act to personal data collected in non-digital form and digitised afterwards, which means paper records are caught once they are digitised. Until then, purely paper-based handling is outside the definition of processing in section 2(x), because processing is defined on "digital personal data". See the article on section 3 and the application of the Act for the territorial and format rules.
"Automated"
Section 2(b) defines "automated" as any digital process capable of operating automatically in response to instructions given or otherwise. It feeds into the definition of processing, which is "wholly or partly automated". An operation that is partly automated, such as an employee entering data that a system then indexes, is still processing. Because the definition says "wholly or partly", a business cannot avoid the Act by pointing to a manual step inside an otherwise digital workflow.
"Processing"
Section 2(x) lists the operations that count, using the word "includes", so the list is illustrative rather than closed: collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction.
Two practical readings matter. First, merely storing data is processing, so a company that holds old customer records and never uses them is still processing. Second, erasure and destruction are also processing, so deleting data is itself an operation the Act covers, which is relevant when you read the retention and erasure duties in section 8(7).
"Personal data breach"
Section 2(u) is broader than a hack. It includes:
- unauthorised processing of personal data; and
- accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access,
in either case where the event compromises the confidentiality, integrity or availability of the data. A ransomware lock that blocks access is covered because availability is compromised. An email sent to the wrong recipient with customer details is covered because of accidental disclosure. The duty to tell the Board and each affected Data Principal is in section 8(6), and the detail of form and manner is left to the Rules.
Practical examples
Example 1: a paper register. A clinic keeps a handwritten visitor register. Until the entries are digitised, they are not digital personal data under section 2(n). Once staff type them into a booking system, the Act applies under section 3(a)(ii).
Example 2: a retail database. A shop's loyalty system stores a phone number and purchase history against an ID. The data is about an individual who is identifiable in relation to it, so it is personal data, and keeping it in the system is processing.
Example 3: a misdirected file. An HR executive emails salary slips to the wrong employee. This is accidental disclosure compromising confidentiality, so it fits the definition of a personal data breach in section 2(u).
Common mistakes
- Thinking that data without a name is not personal data. The test is whether the individual is identifiable by or in relation to the data.
- Assuming storage alone is outside "processing". Section 2(x) includes storage and erasure.
- Reading "breach" as meaning only external hacking. Section 2(u) covers accidental events.
Need help with DPDP definitions and data mapping?
If you are not sure which of your records are personal data, or which of your operations count as processing, a structured review can settle that before you draft notices or contracts. Speak to us through our legal consultation service and we will map your records against these definitions.
Key takeaways
- "Personal data" means data about an individual who is identifiable by or in relation to that data.
- "Digital personal data" is personal data in digital form; digitised paper records are brought in by section 3(a).
- "Processing" is a wholly or partly automated operation and covers collection through to erasure.
- A "personal data breach" includes accidental events, not only attacks.
- The Act has no separate list of sensitive personal data in section 2.
Read next
- Key definitions under the DPDP Act: Data Principal, Fiduciary and personal data
- Section 2 of the DPDP Act, 2023: definitions of Data Principal, Data Fiduciary and Data Processor
- Section 3 of the DPDP Act, 2023: application inside and outside India
- Data breach notification obligation under the DPDP Act
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
