Section 2 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
The obligations in the Act fall on identified roles. Section 2 defines them: the individual whose data it is (Data Principal), the person who decides why and how it is processed (Data Fiduciary), the person who processes it on the fiduciary's behalf (Data Processor), and a few related roles. Getting the role right is the first step in working out who owes what, and it is a point we check first in any legal due diligence that involves customer or employee data.
A Data Fiduciary is any person who alone or with others determines the purpose and means of processing; a Data Processor only processes on behalf of a Data Fiduciary. A Data Principal is the individual the data relates to, and for a child or a person with disability it includes the parent or lawful guardian. A child is anyone under eighteen years. "Person" is defined widely and includes the State.
The roles in section 2 at a glance
| Clause | Term | Definition in brief |
|---|---|---|
| 2(f) | child | An individual who has not completed the age of eighteen years |
| 2(g) | Consent Manager | A person registered with the Board who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform |
| 2(i) | Data Fiduciary | Any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data |
| 2(j) | Data Principal | The individual to whom the personal data relates; includes the parents or lawful guardian of a child, and the lawful guardian of a person with disability acting on her behalf |
| 2(k) | Data Processor | Any person who processes personal data on behalf of a Data Fiduciary |
| 2(l) | Data Protection Officer | An individual appointed by the Significant Data Fiduciary under section 10(2)(a) |
| 2(s) | person | Includes an individual, a Hindu undivided family, a company, a firm, an association of persons or body of individuals (incorporated or not), the State, and every other artificial juristic person |
| 2(z) | Significant Data Fiduciary | Any Data Fiduciary or class notified by the Central Government under section 10 |
Data Fiduciary: the decision-maker
Section 2(i) turns on one test: who determines the purpose and means of processing. It does not matter whether the person owns the software or holds the servers. A company that decides to collect customer phone numbers for marketing is a Data Fiduciary for that data, even if a vendor runs the database.
Because "person" in section 2(s) includes the State, a company, a firm, an HUF and an association of persons, the same test applies to a government department and to a neighbourhood shop. Two or more persons can be Data Fiduciaries for the same data, because the definition says "alone or in conjunction with other persons". Section 8(1) then makes the Data Fiduciary responsible for compliance, regardless of any agreement to the contrary.
Data Processor: the agent
Section 2(k) defines a Data Processor as a person who processes personal data on behalf of a Data Fiduciary. A payroll vendor, a cloud storage provider or an SMS gateway that acts only on the fiduciary's instructions fits. If the vendor starts deciding its own purposes, it moves towards being a Data Fiduciary in its own right, because it would be determining purpose and means. Section 8(2) allows a Data Fiduciary to involve a Data Processor for activities related to offering goods or services only under a valid contract; the article on section 8(1) and (2) covers that.
Data Principal: the individual, and who acts for her
Section 2(j) starts with the individual to whom the data relates. It adds two extensions:
- where the individual is a child, the term includes the parents or lawful guardian; and
- where the individual is a person with disability, it includes her lawful guardian, acting on her behalf.
This matters for rights and consent. A parent exercising a right for a child, or giving consent under section 9(1), does so as the Data Principal's extension under section 2(j). The Act does not define "person with disability" in section 2. It does not define "lawful guardian" either, so read the provisions together with the law that appoints guardians. Section 14 separately lets a Data Principal nominate another individual for death or incapacity.
Child
Section 2(f) fixes the age at eighteen years: a child is an individual who has not completed eighteen years. This is a single statutory line, and it is what triggers section 9. Section 9(4) and 9(5) allow exemptions and an age threshold to be notified, but those are matters for the notification and the Rules and are covered in the articles on section 9.
Consent Manager
Section 2(g) describes a Consent Manager as a person registered with the Board who acts as a single point of contact for the Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. Note that it is a registered role: registration conditions are left to the Rules under section 6(9). The mechanics are in the article on section 6(7) to (9).
Significant Data Fiduciary and Data Protection Officer
Section 2(z) does not define a Significant Data Fiduciary by size. It says any Data Fiduciary or class the Central Government notifies under section 10. The factors in section 10(1) include the volume and sensitivity of data, risk to Data Principals' rights, and the potential impact on the sovereignty and integrity of India. A Data Protection Officer under section 2(l) exists only in that setting; ordinary Data Fiduciaries have a duty to publish contact details of "a Data Protection Officer, if applicable, or a person who is able to answer" under section 8(9).
Practical examples
Example 1: hospital and lab. A hospital collects patient data and sends samples to a diagnostic lab that reports only to the hospital. The hospital decides purpose and means, so it is the Data Fiduciary. The lab, acting on the hospital's behalf, is a Data Processor, unless it also uses the data for its own purposes.
Example 2: a parent and a minor's account. A seventeen-year-old signs up to a learning app. The teenager is a "child" under section 2(f). The parent is included in "Data Principal" under section 2(j)(i) for the purpose of the Act.
Example 3: two companies sharing a customer list. Two group companies jointly decide to run a combined loyalty programme and determine its purposes and means together. Each is a Data Fiduciary "in conjunction with" the other.
Common mistakes
- Calling every vendor a Data Fiduciary. The test is who decides purpose and means.
- Assuming a company is not covered because it is small. "Person" in section 2(s) includes firms, HUFs and companies of any size; size matters only for notified exemptions and Significant Data Fiduciary status.
- Forgetting that a child is anyone below eighteen, not a lower age.
Need help with working out your DPDP role?
If your business handles customer, employee or vendor data and you are unsure whether you sit as a Data Fiduciary, a Data Processor or both, the answer affects your contracts and notices. Our legal due diligence service can review your data flows and vendor arrangements against these definitions.
Key takeaways
- A Data Fiduciary decides the purpose and means of processing, alone or with others.
- A Data Processor processes only on behalf of a Data Fiduciary.
- The Data Principal is the individual, and for a child or a person with disability includes the parent or lawful guardian.
- A child is anyone who has not completed eighteen years.
- "Person" includes the State, companies, firms, HUFs and other bodies.
Read next
- Key definitions under the DPDP Act: Data Principal, Fiduciary and personal data
- Section 2 of the DPDP Act, 2023: definitions of data and processing
- Section 2 of the DPDP Act, 2023: other definitions, Board, gain, loss and specified purpose
- Data processing agreement template for DPDP compliance
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
