What is a Data Principal?
Also known as: DPDPA Data Principal, DPDP Act Data Principal, Data Subject in India
In simple terms, if an organisation collects or processes personal data about you, you are the Data Principal.
For a child, the term also includes the child's parent or lawful guardian. For a person with a disability, it includes the lawful guardian acting on that person's behalf.
Data principals have rights under the DPDPA and can exercise control over their personal data in accordance with the Act, including rights relating to access to information, correction and erasure, grievance redressal, and nomination.
What does Data Principal mean?
A Data Principal is the person whose personal data is being processed.
For example:
- A customer whose name and email are collected by an online store
- A user who creates an account on a SaaS platform
- A patient whose digital information is processed by an online healthcare service
- An employee whose personal information is processed digitally
- A website visitor whose personal data is collected through an online form
In each case, the individual the data relates to may be the Data Principal.
The DPDPA defines a Data Principal as the individual to whom the personal data relates.
Who is a Data Principal under DPDPA?
A Data Principal is generally the individual whose personal data is collected, stored, used, shared, or otherwise processed.
For example, consider an e-commerce website:
Customer
Data PrincipalThe customer's name, address, phone number, and other personal data relate to that individual.
E-commerce company
Data FiduciaryThe company determines why and how the personal data is processed.
Cloud provider or service provider
Data ProcessorThe provider may process the personal data on behalf of the Data Fiduciary.
Understanding these roles is important because each has a different position under the DPDPA.
Data Principal vs Data Fiduciary
A Data Principal is the individual the personal data is about.
A Data Fiduciary is the person or organisation that determines the purpose and means of processing that personal data.
For example:
| Role | Example |
|---|---|
| Data Principal | A customer using an online shopping website |
| Data Fiduciary | The company operating the website |
| Data Processor | A cloud provider processing data for the company |
The Data Principal is the person whose privacy interests and rights are protected, while the Data Fiduciary is generally responsible for meeting applicable obligations relating to the processing.
What are the rights of a Data Principal?
The DPDPA provides Data Principals with rights relating to their personal data.
Depending on the applicable provisions, these include:
Right to access information
A Data Principal can seek certain information about the personal data being processed and related processing activities as provided under the DPDPA.
This can help individuals understand how their personal data is being handled.
Right to correction and erasure
A Data Principal may request correction, completion, updating, or erasure of personal data, subject to the applicable requirements and exceptions.
Organisations should have processes for receiving and responding to these requests.
Right of grievance redressal
A Data Principal has the right to access a grievance-redressal mechanism provided by the Data Fiduciary or Consent Manager.
This provides a process for raising concerns about personal-data processing or the handling of rights requests.
Right to nominate
A Data Principal can nominate another individual to exercise applicable rights in certain circumstances specified by the DPDPA.
Right to withdraw consent
Where personal data is processed based on consent, a Data Principal can withdraw that consent.
Withdrawal should be as easy as giving consent.
The DPDPA's consent framework therefore requires organisations to think beyond collecting a one-time “yes.” They also need a practical mechanism for managing withdrawal and applying that decision to relevant processing.
Data Principal and consent
Consent is one of the key ways personal data may be processed under the DPDPA.
Where consent is relied upon, it should meet the applicable requirements under the Act, including being:
- Free
- Specific
- Informed
- Unconditional
- Unambiguous
- Given through clear affirmative action
The Data Principal should understand the purpose for which consent is being requested.
A strong consent process should make it possible to:
- Inform
- Ask
- Capture
- Record
- Enforce
- Withdraw
This helps connect the user's decision with the actual processing of personal data.
How can a Data Principal withdraw consent?
Where processing is based on consent, a Data Principal should have access to an effective mechanism for withdrawing that consent.
A business should not make withdrawal unnecessarily difficult or materially more complicated than giving consent.
After consent is withdrawn, the Data Fiduciary should take the required steps to stop processing personal data where applicable and manage the consequences of withdrawal in accordance with the DPDPA and other applicable requirements.
For websites and applications, this may involve updating consent preferences and ensuring connected systems respect the revised choice.
Data Principal and children's data
The DPDPA provides additional protections for children's personal data.
A child means an individual who has not completed 18 years of age.
For the definition of Data Principal, where the individual is a child, the term includes the child's parent or lawful guardian.
The DPDPA also establishes specific requirements concerning the processing of children's personal data, including parental or lawful guardian consent requirements in applicable circumstances and restrictions relating to certain forms of processing.
Businesses that process children's personal data should review the specific requirements that apply to their services.
Data Principal and persons with disabilities
The statutory definition of Data Principal also addresses situations involving a person with a disability.
Where applicable under the definition, the term includes the person's lawful guardian acting on their behalf.
This ensures that the DPDPA's framework recognises situations in which personal-data rights and consent-related actions may need to be exercised through an authorised legal representative.
How can a Data Principal exercise their rights?
Businesses should provide accessible processes for Data Principals to exercise applicable rights.
A typical workflow may include:
Submit
Submit a request through the available privacy or grievance mechanism.
Verify
Verify the request where verification is necessary and appropriate.
Identify
Identify the relevant personal data and processing activity.
Assess
Assess the request under the applicable legal requirements.
Act
Take the required action, such as providing information, correcting data, or erasing data where applicable.
Record
Record the outcome and respond through the appropriate process.
The exact procedure depends on the type of request and the organisation's obligations under the DPDPA.
Data Principal requests for websites and apps
Websites and applications may process personal data through:
- Account registration
- Contact forms
- Newsletter subscriptions
- Purchases and payments
- Customer-support systems
- Mobile app usage
- Cookies and online identifiers
- Analytics tools
- Advertising technologies
- Other third-party services
Businesses should understand where this data is processed so they can respond effectively when a Data Principal exercises an applicable right.
A privacy request cannot be handled effectively if the organisation does not know where the relevant personal data is stored or which systems and service providers process it.
Data Principal vs Data Subject
The term Data Principal is used under India's DPDPA.
The term Data Subject is commonly used under privacy frameworks such as the GDPR.
Both terms generally refer to the individual the personal data relates to, but they belong to different legal frameworks.
| DPDPA | GDPR |
|---|---|
| Data Principal | Data Subject |
| Data Fiduciary | Data Controller |
| Data Processor | Data Processor |
| Consent Manager | No direct equivalent |
Businesses operating internationally should use the terminology and requirements applicable to each privacy framework.
Data Principal and a Consent Manager
The DPDPA defines a Consent Manager as a registered person that acts as a single point of contact to enable a Data Principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform.
This model is designed to give Data Principals greater control over their consent decisions.
Businesses should distinguish between the statutory concept of a Consent Manager and general consent-management software or a cookie consent banner.
Why is the Data Principal important?
The Data Principal is at the centre of the DPDPA's individual privacy framework.
The concept connects several key obligations:
- Personal-data notices
- Consent
- Consent withdrawal
- Access to information
- Correction and erasure
- Grievance redressal
- Nomination
- Children's data protections
- Consent management
For organisations, identifying the Data Principal helps clarify whose data is being processed and whose rights and choices need to be respected.
Data Principal compliance checklist for businesses
Businesses processing personal data should consider whether they can:
- Identify the relevant Data Principals
- Provide clear privacy and consent notices
- Explain applicable processing purposes
- Capture valid consent where required
- Record consent decisions
- Support consent withdrawal
- Locate relevant personal data
- Correct or update data where required
- Erase data where applicable
- Provide grievance-redressal mechanisms
- Handle children's personal data appropriately
- Manage requests made through applicable representatives
- Maintain records of requests and responses
- Ensure connected systems respect updated privacy choices
Data Principal rights in ConsentX
ConsentX helps businesses operationalise consent and privacy choices across websites and applications.
ConsentX can support workflows such as:
Purpose-based consent collection
Clear consent notices
Recording consent decisions
Tamper-evident consent receipts
Consent review and withdrawal
Cookie and tracker discovery
Prior blocking of applicable non-essential trackers
Data Principal request workflows
Age-gating and parental consent flows
Audit-ready evidence
This helps organisations move from a static privacy policy to technical systems that can capture, manage, and demonstrate privacy choices.
Put Data Principal rights into practice
ConsentX helps businesses collect meaningful consent, manage privacy preferences, support withdrawal, and maintain evidence of Data Principal choices. Start free with ConsentX.
Related Terms
A Data Fiduciary is the person or organisation that determines the purpose and means of processing personal data.
A Data Processor processes personal data on behalf of a Data Fiduciary.
India's data-protection framework governing applicable processing of digital personal data.
A registered platform through which a Data Principal can give, manage, review, and withdraw consent.
Software that helps organisations collect, manage, enforce, and document privacy and consent choices.
A consent receipt is a record of a user's consent decision and related information.
Rights available to individuals under the DPDPA, including applicable rights relating to information, correction, erasure, grievance redressal, and nomination.
Cookie consent helps websites collect and manage a user's permission for applicable cookies and tracking technologies.
Prior blocking is the technical process of keeping applicable non-essential trackers inactive until the required consent has been obtained.