DPDPA अब भारत में लागू है। अपनी वेबसाइट पर मुफ़्त प्राइवेसी स्कैन चलाएँ। अभी स्कैन करें

India / DPDPA

What is a Data Principal?

Also known as: DPDPA Data Principal, DPDP Act Data Principal, Data Subject in India

Under India's Digital Personal Data Protection Act, 2023 (DPDPA or DPDP Act), a Data Principal is the individual to whom personal data relates.

In simple terms, if an organisation collects or processes personal data about you, you are the Data Principal.

For a child, the term also includes the child's parent or lawful guardian. For a person with a disability, it includes the lawful guardian acting on that person's behalf.

Data principals have rights under the DPDPA and can exercise control over their personal data in accordance with the Act, including rights relating to access to information, correction and erasure, grievance redressal, and nomination.

What does Data Principal mean?

A Data Principal is the person whose personal data is being processed.

For example:

  • A customer whose name and email are collected by an online store
  • A user who creates an account on a SaaS platform
  • A patient whose digital information is processed by an online healthcare service
  • An employee whose personal information is processed digitally
  • A website visitor whose personal data is collected through an online form

In each case, the individual the data relates to may be the Data Principal.

The DPDPA defines a Data Principal as the individual to whom the personal data relates.

Who is a Data Principal under DPDPA?

A Data Principal is generally the individual whose personal data is collected, stored, used, shared, or otherwise processed.

For example, consider an e-commerce website:

Customer

Data Principal

The customer's name, address, phone number, and other personal data relate to that individual.

E-commerce company

Data Fiduciary

The company determines why and how the personal data is processed.

Cloud provider or service provider

Data Processor

The provider may process the personal data on behalf of the Data Fiduciary.

Understanding these roles is important because each has a different position under the DPDPA.

Data Principal vs Data Fiduciary

A Data Principal is the individual the personal data is about.

A Data Fiduciary is the person or organisation that determines the purpose and means of processing that personal data.

For example:

RoleExample
Data PrincipalA customer using an online shopping website
Data FiduciaryThe company operating the website
Data ProcessorA cloud provider processing data for the company

The Data Principal is the person whose privacy interests and rights are protected, while the Data Fiduciary is generally responsible for meeting applicable obligations relating to the processing.

What are the rights of a Data Principal?

The DPDPA provides Data Principals with rights relating to their personal data.

Depending on the applicable provisions, these include:

Right to access information

A Data Principal can seek certain information about the personal data being processed and related processing activities as provided under the DPDPA.

This can help individuals understand how their personal data is being handled.

Right to correction and erasure

A Data Principal may request correction, completion, updating, or erasure of personal data, subject to the applicable requirements and exceptions.

Organisations should have processes for receiving and responding to these requests.

Right of grievance redressal

A Data Principal has the right to access a grievance-redressal mechanism provided by the Data Fiduciary or Consent Manager.

This provides a process for raising concerns about personal-data processing or the handling of rights requests.

Right to nominate

A Data Principal can nominate another individual to exercise applicable rights in certain circumstances specified by the DPDPA.

Right to withdraw consent

Where personal data is processed based on consent, a Data Principal can withdraw that consent.

Withdrawal should be as easy as giving consent.

The DPDPA's consent framework therefore requires organisations to think beyond collecting a one-time “yes.” They also need a practical mechanism for managing withdrawal and applying that decision to relevant processing.

Data Principal and consent

Consent is one of the key ways personal data may be processed under the DPDPA.

Where consent is relied upon, it should meet the applicable requirements under the Act, including being:

  • Free
  • Specific
  • Informed
  • Unconditional
  • Unambiguous
  • Given through clear affirmative action

The Data Principal should understand the purpose for which consent is being requested.

A strong consent process should make it possible to:

  1. Inform
  2. Ask
  3. Capture
  4. Record
  5. Enforce
  6. Withdraw

This helps connect the user's decision with the actual processing of personal data.

How can a Data Principal withdraw consent?

Where processing is based on consent, a Data Principal should have access to an effective mechanism for withdrawing that consent.

A business should not make withdrawal unnecessarily difficult or materially more complicated than giving consent.

After consent is withdrawn, the Data Fiduciary should take the required steps to stop processing personal data where applicable and manage the consequences of withdrawal in accordance with the DPDPA and other applicable requirements.

For websites and applications, this may involve updating consent preferences and ensuring connected systems respect the revised choice.

Data Principal and children's data

The DPDPA provides additional protections for children's personal data.

A child means an individual who has not completed 18 years of age.

For the definition of Data Principal, where the individual is a child, the term includes the child's parent or lawful guardian.

The DPDPA also establishes specific requirements concerning the processing of children's personal data, including parental or lawful guardian consent requirements in applicable circumstances and restrictions relating to certain forms of processing.

Businesses that process children's personal data should review the specific requirements that apply to their services.

Data Principal and persons with disabilities

The statutory definition of Data Principal also addresses situations involving a person with a disability.

Where applicable under the definition, the term includes the person's lawful guardian acting on their behalf.

This ensures that the DPDPA's framework recognises situations in which personal-data rights and consent-related actions may need to be exercised through an authorised legal representative.

How can a Data Principal exercise their rights?

Businesses should provide accessible processes for Data Principals to exercise applicable rights.

A typical workflow may include:

01

Submit

Submit a request through the available privacy or grievance mechanism.

02

Verify

Verify the request where verification is necessary and appropriate.

03

Identify

Identify the relevant personal data and processing activity.

04

Assess

Assess the request under the applicable legal requirements.

05

Act

Take the required action, such as providing information, correcting data, or erasing data where applicable.

06

Record

Record the outcome and respond through the appropriate process.

The exact procedure depends on the type of request and the organisation's obligations under the DPDPA.

Data Principal requests for websites and apps

Websites and applications may process personal data through:

  • Account registration
  • Contact forms
  • Newsletter subscriptions
  • Purchases and payments
  • Customer-support systems
  • Mobile app usage
  • Cookies and online identifiers
  • Analytics tools
  • Advertising technologies
  • Other third-party services

Businesses should understand where this data is processed so they can respond effectively when a Data Principal exercises an applicable right.

A privacy request cannot be handled effectively if the organisation does not know where the relevant personal data is stored or which systems and service providers process it.

Data Principal vs Data Subject

The term Data Principal is used under India's DPDPA.

The term Data Subject is commonly used under privacy frameworks such as the GDPR.

Both terms generally refer to the individual the personal data relates to, but they belong to different legal frameworks.

DPDPAGDPR
Data PrincipalData Subject
Data FiduciaryData Controller
Data ProcessorData Processor
Consent ManagerNo direct equivalent

Businesses operating internationally should use the terminology and requirements applicable to each privacy framework.

Data Principal and a Consent Manager

The DPDPA defines a Consent Manager as a registered person that acts as a single point of contact to enable a Data Principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform.

This model is designed to give Data Principals greater control over their consent decisions.

Businesses should distinguish between the statutory concept of a Consent Manager and general consent-management software or a cookie consent banner.

Why is the Data Principal important?

The Data Principal is at the centre of the DPDPA's individual privacy framework.

The concept connects several key obligations:

  • Personal-data notices
  • Consent
  • Consent withdrawal
  • Access to information
  • Correction and erasure
  • Grievance redressal
  • Nomination
  • Children's data protections
  • Consent management

For organisations, identifying the Data Principal helps clarify whose data is being processed and whose rights and choices need to be respected.

Data Principal compliance checklist for businesses

Businesses processing personal data should consider whether they can:

  • Identify the relevant Data Principals
  • Provide clear privacy and consent notices
  • Explain applicable processing purposes
  • Capture valid consent where required
  • Record consent decisions
  • Support consent withdrawal
  • Locate relevant personal data
  • Correct or update data where required
  • Erase data where applicable
  • Provide grievance-redressal mechanisms
  • Handle children's personal data appropriately
  • Manage requests made through applicable representatives
  • Maintain records of requests and responses
  • Ensure connected systems respect updated privacy choices

Data Principal rights in ConsentX

ConsentX helps businesses operationalise consent and privacy choices across websites and applications.

ConsentX can support workflows such as:

Purpose-based consent collection

Clear consent notices

Recording consent decisions

Tamper-evident consent receipts

Consent review and withdrawal

Cookie and tracker discovery

Prior blocking of applicable non-essential trackers

Data Principal request workflows

Age-gating and parental consent flows

Audit-ready evidence

This helps organisations move from a static privacy policy to technical systems that can capture, manage, and demonstrate privacy choices.

Put Data Principal rights into practice

ConsentX helps businesses collect meaningful consent, manage privacy preferences, support withdrawal, and maintain evidence of Data Principal choices. Start free with ConsentX.

Frequently asked questions