Who is a Data Principal?
A plain-language guide to one of the most foundational concepts under India's Digital Personal Data Protection Act, 2023 β and why it matters to every individual in the digital age.

Understanding the Data Principal
Before you can understand rights, obligations, or penalties under the DPDP Act, you need to know one thing: whose data are we talking about? The answer to that question is the Data Principal β and it is the cornerstone around which the entire Act is built.
ποΈ The Foundation
Every right, protection, and obligation in the Act exists to safeguard the Data Principal's personal data.
βοΈ The Rights Holder
Only the Data Principal can exercise rights like access, correction, erasure, and consent withdrawal.
π The Starting Point
Understanding this concept unlocks every other provision β from consent to grievance redressal.
What Does βData Principalβ Mean?
Section 2(j), DPDP Act, 2023: βData Principal means the individual to whom the personal data relates.β
In plain English: you are the Data Principal for your own personal data. Whenever an organization collects, stores, or uses information that identifies you or relates to you β you become the Data Principal. It is that simple.
Examples of a Data Principal
The concept comes to life in situations you encounter every day. In each case below, the individual whose data is collected is the Data Principal β regardless of the setting.
π₯ Patient at a Hospital
Data Principal: The patient
Collector: Hospital
Data: Name, age, health records, Aadhaar
π¦ Bank Account Opening
Data Principal: The customer
Collector: Bank
Data: PAN, address, mobile number, photo
π College Admission
Data Principal: The student
Collector: College/University
Data: DOB, marks, Aadhaar, address
πΌ Employee Joining a Company
Data Principal: The employee
Collector: Employer/HR
Data: PAN, bank details, biometrics, records

Data Principals Are Everywhere
Data Principals are everywhere β shopping online, booking a flight, or simply using a government portal. The setting changes, but the principle remains the same.
π Online Shopping
Data Principal: The customer
Collector: E-commerce platform
Data: Address, payment info, purchase history
ποΈ Government Portal
Data Principal: The citizen
Collector: Government department
Data: Aadhaar, address, income details
βοΈ Flight Booking
Data Principal: The traveller
Collector: Airline
Data: Passport, email, phone, payment info
π± Mobile Application
Data Principal: The app user
Collector: App developer/company
Data: Location, contacts, IP address, device ID
What Counts as Personal Data?
Personal data is any information that identifies or can be used to identify a Data Principal. It covers a surprisingly wide range β from the obvious to the less obvious.

Any one of these β or a combination β can make a piece of information βpersonal dataβ under the DPDP Act. If it relates to an identifiable individual, that individual is the Data Principal.
Only an Individual Can Be a Data Principal
This is one of the most important β and most misunderstood β aspects of the definition. The DPDP Act is designed to protect people, not entities.
β Who IS a Data Principal
- A patient whose medical records are stored
- An employee whose HR files are maintained
- A customer whose purchase history is tracked
- A student whose academic data is held
- A citizen whose Aadhaar is linked to services
β Who is NOT a Data Principal
- A hospital or clinic (it is a Data Fiduciary)
- A company or corporation
- A government department or agency
- An AI system or software application
- A partnership firm or LLP
Organizations can collect, process, and store data β but they are never the subject of that data. Only natural persons (human beings) qualify as Data Principals.
Children Are Data Principals Too
The DPDP Act explicitly recognizes that children β individuals under 18 years of age β are also Data Principals. Because of their vulnerability, the Act provides them with significantly stronger protections.
Verifiable Parental Consent
Before collecting any personal data of a child, a Data Fiduciary must obtain verifiable consent from a parent or legal guardian.
No Tracking or Targeted Advertising
Data Fiduciaries are prohibited from tracking, behaviorally monitoring, or targeting children with advertising based on their personal data.
Age-Appropriate Processing Only
Processing of children's data must not cause any detrimental effect on their well-being β a uniquely strong standard in the Act.
Data Principal vs. Data Fiduciary vs. Data Processor
The DPDP Act defines three distinct roles. Understanding these at a high level will help you follow the rest of the Act with clarity. Full definitions will be covered in separate modules.
| Role | Who They Are | What They Do | Example |
|---|---|---|---|
| Data Principal | The individual whose data it is | Provides data, gives or withdraws consent, exercises rights | A patient at a hospital |
| Data Fiduciary | Entity that decides why and how data is processed | Collects data, determines its purpose and means of processing | The hospital collecting patient records |
| Data Processor | Entity that processes data on behalf of the Fiduciary | Processes data as instructed β no independent decision-making | A lab that processes test reports for the hospital |
What the Act Actually Says
Several myths about the Data Principal concept circulate among professionals and businesses. Here is what the Act actually says.
β Myth: βThe hospital owns my medical data.β
β Fact: The hospital is the Data Fiduciary β it processes your data. But the data relates to you, making you the Data Principal. You retain rights over it, including the right to access and correct it.
β Myth: βMy company is the Data Principal for employee data.β
β Fact: The employees are the Data Principals. The company is the Data Fiduciary that collects and processes the data, and it bears legal obligations toward its employees under the Act.
β Myth: βIf I don't use the internet, the Act doesn't apply to me.β
β Fact: Personal data can be collected offline too β think hospital forms, bank KYC, college registrations. You become a Data Principal the moment your data is collected in digital form, regardless of the channel.
Why Understanding This Concept Comes First
The entire architecture of the DPDP Act is built to protect the Data Principal. Every obligation placed on businesses, every right granted to individuals, and every penalty prescribed by the Act flows from this single definition.
If you skip this concept, the rest of the Act will not make sense. Understanding who is being protected is the prerequisite for understanding how that protection works.

Data Principal at a Glance
01. You Are the Data Principal
Any individual whose personal data is collected, stored, or processed is a Data Principal β regardless of the context or organization involved.
02. Only Individuals Qualify
Companies, hospitals, and government agencies are never Data Principals. Only natural persons β human beings β can hold this status.
03. Personal Data Is Broad
Names, phone numbers, health records, biometrics, IP addresses β any information that identifies or relates to you counts as your personal data.
04. Children Receive Extra Protection
Children under 18 are also Data Principals, with stronger safeguards including mandatory parental consent and a ban on behavioral tracking.
05. The Foundation of the Act
Every right, obligation, and enforcement mechanism in the DPDP Act exists to protect Data Principals. This is where your study of the Act must begin.
Who is a Data Fiduciary?
Now that you understand who the Data Principal is, the next critical question is: who is responsible for protecting that data?
In the next module, we will explore the concept of a Data Fiduciary β the entity that decides why and how personal data is processed. We will cover:
The legal definition of a Data Fiduciary
Straight from Section 2(i) of the DPDP Act, 2023, explained in plain English.
Real-world examples across industries
Hospitals, banks, employers, schools, government agencies, and tech platforms β who qualifies and why.
Obligations placed on Data Fiduciaries
What the law requires them to do β and the consequences of non-compliance.
DPDP Act 2023 Series Β· Module 2 β DPDP #08 - Who is a Data Fiduciary?
Disclaimer

This presentation is intended solely for educational and professional awareness purposes. It provides a general overview of the subject matter discussed. While every effort has been made to ensure the accuracy of the information presented, the content should be read in conjunction with the applicable laws, rules, regulations, official guidance, and judicial developments. The application of law and professional practices may vary depending on the specific facts and circumstances of each case.