DPDP Learning Series Β· #07 Β· Module 2

Who is a Data Principal?

A plain-language guide to one of the most foundational concepts under India's Digital Personal Data Protection Act, 2023 β€” and why it matters to every individual in the digital age.

Individual represented as a Data Principal under the DPDP Act
Why This Concept Matters

Understanding the Data Principal

Before you can understand rights, obligations, or penalties under the DPDP Act, you need to know one thing: whose data are we talking about? The answer to that question is the Data Principal β€” and it is the cornerstone around which the entire Act is built.

πŸ›οΈ The Foundation

Every right, protection, and obligation in the Act exists to safeguard the Data Principal's personal data.

βš–οΈ The Rights Holder

Only the Data Principal can exercise rights like access, correction, erasure, and consent withdrawal.

πŸ”‘ The Starting Point

Understanding this concept unlocks every other provision β€” from consent to grievance redressal.

The Legal Definition

What Does β€œData Principal” Mean?

Section 2(j), DPDP Act, 2023: β€œData Principal means the individual to whom the personal data relates.”

In plain English: you are the Data Principal for your own personal data. Whenever an organization collects, stores, or uses information that identifies you or relates to you β€” you become the Data Principal. It is that simple.

The Act is entirely centred around protecting the rights and interests of Data Principals β€” real people whose personal information is at stake.
Everyday Examples

Examples of a Data Principal

The concept comes to life in situations you encounter every day. In each case below, the individual whose data is collected is the Data Principal β€” regardless of the setting.

πŸ₯ Patient at a Hospital

Data Principal: The patient
Collector: Hospital
Data: Name, age, health records, Aadhaar

🏦 Bank Account Opening

Data Principal: The customer
Collector: Bank
Data: PAN, address, mobile number, photo

πŸŽ“ College Admission

Data Principal: The student
Collector: College/University
Data: DOB, marks, Aadhaar, address

πŸ’Ό Employee Joining a Company

Data Principal: The employee
Collector: Employer/HR
Data: PAN, bank details, biometrics, records

Everyday people whose personal data is collected
More Everyday Examples

Data Principals Are Everywhere

Data Principals are everywhere β€” shopping online, booking a flight, or simply using a government portal. The setting changes, but the principle remains the same.

πŸ›’ Online Shopping

Data Principal: The customer
Collector: E-commerce platform
Data: Address, payment info, purchase history

πŸ›οΈ Government Portal

Data Principal: The citizen
Collector: Government department
Data: Aadhaar, address, income details

✈️ Flight Booking

Data Principal: The traveller
Collector: Airline
Data: Passport, email, phone, payment info

πŸ“± Mobile Application

Data Principal: The app user
Collector: App developer/company
Data: Location, contacts, IP address, device ID

Personal Data

What Counts as Personal Data?

Personal data is any information that identifies or can be used to identify a Data Principal. It covers a surprisingly wide range β€” from the obvious to the less obvious.

Examples of information that can identify a Data Principal

Any one of these β€” or a combination β€” can make a piece of information β€œpersonal data” under the DPDP Act. If it relates to an identifiable individual, that individual is the Data Principal.

Who Qualifies?

Only an Individual Can Be a Data Principal

This is one of the most important β€” and most misunderstood β€” aspects of the definition. The DPDP Act is designed to protect people, not entities.

βœ… Who IS a Data Principal

  • A patient whose medical records are stored
  • An employee whose HR files are maintained
  • A customer whose purchase history is tracked
  • A student whose academic data is held
  • A citizen whose Aadhaar is linked to services

❌ Who is NOT a Data Principal

  • A hospital or clinic (it is a Data Fiduciary)
  • A company or corporation
  • A government department or agency
  • An AI system or software application
  • A partnership firm or LLP

Organizations can collect, process, and store data β€” but they are never the subject of that data. Only natural persons (human beings) qualify as Data Principals.

Special Protection

Children Are Data Principals Too

The DPDP Act explicitly recognizes that children β€” individuals under 18 years of age β€” are also Data Principals. Because of their vulnerability, the Act provides them with significantly stronger protections.

Verifiable Parental Consent

Before collecting any personal data of a child, a Data Fiduciary must obtain verifiable consent from a parent or legal guardian.

No Tracking or Targeted Advertising

Data Fiduciaries are prohibited from tracking, behaviorally monitoring, or targeting children with advertising based on their personal data.

Age-Appropriate Processing Only

Processing of children's data must not cause any detrimental effect on their well-being β€” a uniquely strong standard in the Act.

Detailed provisions on children's data protection will be covered in a dedicated module. This slide provides a high-level overview only.
Three Key Roles

Data Principal vs. Data Fiduciary vs. Data Processor

The DPDP Act defines three distinct roles. Understanding these at a high level will help you follow the rest of the Act with clarity. Full definitions will be covered in separate modules.

RoleWho They AreWhat They DoExample
Data PrincipalThe individual whose data it isProvides data, gives or withdraws consent, exercises rightsA patient at a hospital
Data FiduciaryEntity that decides why and how data is processedCollects data, determines its purpose and means of processingThe hospital collecting patient records
Data ProcessorEntity that processes data on behalf of the FiduciaryProcesses data as instructed β€” no independent decision-makingA lab that processes test reports for the hospital
Think of it this way: the Data Principal owns the story. The Data Fiduciary decides how to tell it. The Data Processor is the one who types it up.
Common Misconceptions β€” Busted

What the Act Actually Says

Several myths about the Data Principal concept circulate among professionals and businesses. Here is what the Act actually says.

❌ Myth: β€œThe hospital owns my medical data.”

βœ… Fact: The hospital is the Data Fiduciary β€” it processes your data. But the data relates to you, making you the Data Principal. You retain rights over it, including the right to access and correct it.

❌ Myth: β€œMy company is the Data Principal for employee data.”

βœ… Fact: The employees are the Data Principals. The company is the Data Fiduciary that collects and processes the data, and it bears legal obligations toward its employees under the Act.

❌ Myth: β€œIf I don't use the internet, the Act doesn't apply to me.”

βœ… Fact: Personal data can be collected offline too β€” think hospital forms, bank KYC, college registrations. You become a Data Principal the moment your data is collected in digital form, regardless of the channel.

Why It Comes First

Why Understanding This Concept Comes First

The entire architecture of the DPDP Act is built to protect the Data Principal. Every obligation placed on businesses, every right granted to individuals, and every penalty prescribed by the Act flows from this single definition.

If you skip this concept, the rest of the Act will not make sense. Understanding who is being protected is the prerequisite for understanding how that protection works.

The Data Principal at the centre of DPDP Act protections
Key Takeaways

Data Principal at a Glance

01. You Are the Data Principal

Any individual whose personal data is collected, stored, or processed is a Data Principal β€” regardless of the context or organization involved.

02. Only Individuals Qualify

Companies, hospitals, and government agencies are never Data Principals. Only natural persons β€” human beings β€” can hold this status.

03. Personal Data Is Broad

Names, phone numbers, health records, biometrics, IP addresses β€” any information that identifies or relates to you counts as your personal data.

04. Children Receive Extra Protection

Children under 18 are also Data Principals, with stronger safeguards including mandatory parental consent and a ban on behavioral tracking.

05. The Foundation of the Act

Every right, obligation, and enforcement mechanism in the DPDP Act exists to protect Data Principals. This is where your study of the Act must begin.

Coming Next in the DPDP Series

Who is a Data Fiduciary?

Now that you understand who the Data Principal is, the next critical question is: who is responsible for protecting that data?

In the next module, we will explore the concept of a Data Fiduciary β€” the entity that decides why and how personal data is processed. We will cover:

The legal definition of a Data Fiduciary

Straight from Section 2(i) of the DPDP Act, 2023, explained in plain English.

Real-world examples across industries

Hospitals, banks, employers, schools, government agencies, and tech platforms β€” who qualifies and why.

Obligations placed on Data Fiduciaries

What the law requires them to do β€” and the consequences of non-compliance.

DPDP Act 2023 Series Β· Module 2 β†’ DPDP #08 - Who is a Data Fiduciary?

⚠️ Important Notice

Disclaimer

Legal disclaimer illustration with documents and scales

This presentation is intended solely for educational and professional awareness purposes. It provides a general overview of the subject matter discussed. While every effort has been made to ensure the accuracy of the information presented, the content should be read in conjunction with the applicable laws, rules, regulations, official guidance, and judicial developments. The application of law and professional practices may vary depending on the specific facts and circumstances of each case.