Skip to main content

Glossary

This glossary defines important terms used across SAHAJ and the DPDPA (Digital Personal Data Protection Act, 2023) compliance ecosystem.
The terms are organized alphabetically.


πŸ…±οΈβ€‹

Breach Management​

Processes and procedures for detecting, reporting, investigating, and mitigating personal data breaches. Under DPDPA, data fiduciaries must notify the Data Protection Board of India and affected data principals promptly.


πŸ…²β€‹

Collection Point​

The specific interface or touchpoint (web form, mobile app, call center, IoT device, etc.) where personal data is first collected from the data principal.

A freely given, specific, informed, and unambiguous indication of a data principal’s agreement to the processing of their personal data for a stated purpose.

A digital or physical record that evidences consent given by a data principal. Includes timestamp, purpose, scope, and revocation details.

A commercial or open-source platform providing tools for obtaining, storing, and managing consent across different systems and jurisdictions.

The technical and organizational infrastructure enabling organizations to collect, store, and process consent in compliance with privacy regulations.
(SAHAJ is an open-source CMS built for DPDPA compliance.)

The clearly defined objective for which a data fiduciary collects and processes personal data (e.g., billing, marketing, fraud detection). Consent must be purpose-specific.

A mechanism to inform users and obtain consent for cookies or similar tracking technologies on websites or apps.


πŸ…³β€‹

Data Elements​

Individual units of personal information collected or processed (e.g., name, email address, Aadhaar number). Each element may have its own sensitivity and legal implications.

Data Fiduciary​

The entity (person, company, state body, or organization) that determines the purpose and means of processing personal data. Similar to β€œdata controller” under GDPR.

Data Processor​

Any person or entity that processes personal data on behalf of a data fiduciary. They cannot process data beyond the fiduciary’s instructions.

DPAR (Data Principal Access Request)​

A request made by the data principal to access, correct, delete, or port their personal data held by a data fiduciary.


πŸ…Άβ€‹

Grievance​

Any complaint or issue raised by a data principal regarding the processing of their personal data, including misuse, unauthorized access, or lack of response to DPARs.


πŸ…½β€‹

Notice​

The disclosure provided by a data fiduciary to a data principal before or at the time of data collection, explaining the purposes of processing, retention period, and rights available.

Notice Orchestration​

Coordinating, standardizing, and delivering notices across multiple channels (SMS, email, app notification, web UI) to ensure data principals are informed consistently.


πŸ…ΏοΈβ€‹

Personal Data Breach Artefact​

A digital record detailing the nature, scope, and impact of a personal data breach. Includes when and how the breach was discovered, affected data subjects, and remediation measures.