Compliance glossary:
DPDP, consent, GRC and AI governance terms.
79 terms defined in a sentence or two each, with the section, rule or article they come from and a link to the guide that goes further. Written for the people who have to implement the rules, not only read them.
Last updated Published by TryTrustableNot legal advice
What does this compliance glossary cover?
This glossary defines 79 terms used in India's DPDP Act and Rules, consent and cookie management, governance, risk and compliance (GRC) audits such as SOC 2 and ISO 27001, and AI governance under ISO 42001 and the EU AI Act. Each entry gives a short definition, the statutory reference, and a deeper guide.
Definitions come first and are written to stand alone, so any entry can be quoted without the ones around it. Where a term has a legal source, the reference names the section, rule or article so you can check it; where it is industry practice rather than law, the entry says so. Each term has a permanent link: use the # beside its name.
| Area | Terms | Start with |
|---|---|---|
| DPDP Act and Rules | 27 | Data Fiduciary, Consent Manager, Significant Data Fiduciary, the DPDP Act guide |
| Privacy and consent | 21 | Consent management platform, proof of consent, Global Privacy Control, the consent manager |
| GRC and audit | 18 | Control, evidence, SOC 2 Type 2, Statement of Applicability |
| AI governance | 13 | Provider, deployer, high-risk AI system, the ISO 42001 guide |
Terms are listed A to Z below. Section references are to the DPDP Act 2023 and the DPDP Rules 2025 unless another instrument is named.
A
Access review GRC#
An access review is a periodic, dated check by a named reviewer that each person's access to a system is still needed and appropriate, with every removal recorded. It is one of the first controls auditors test under SOC 2 and ISO 27001.
AI impact assessment AI governance#
An AI impact assessment is a documented evaluation of the consequences an AI system could have for individuals, groups and society, covering its intended use and foreseeable misuse. ISO/IEC 42001 requires one as part of an AI management system.
AI literacy AI governance#
AI literacy is the knowledge and skill staff need to use and oversee AI systems with an understanding of their risks. The EU AI Act, as amended by the Digital Omnibus, requires providers and deployers to take measures supporting their staff's AI literacy.
AI management system (AIMS) AI governance#
An AI management system is the set of policies, objectives, processes and controls an organisation uses to govern how it develops, provides or uses AI. ISO/IEC 42001:2023 specifies the requirements for one, and it can be certified.
Anonymisation Privacy & consent#
Anonymisation is processing data so the individual can no longer be identified by any means reasonably likely to be used, which takes it outside data protection law. Data that can be linked back to a person is pseudonymised, not anonymised.
Appellate Tribunal (TDSAT) DPDP#
The Telecom Disputes Settlement and Appellate Tribunal hears appeals against orders and directions of the Data Protection Board of India. An appeal must be filed within sixty days of receiving the order, though the Tribunal can admit a late one for sufficient cause.
B
Bridge letter GRC#
A bridge letter is a statement from a service organisation's management covering the gap between the end of its last SOC report period and today, confirming no material change to its controls. Management writes it, not the auditor, so it carries no audit assurance.
C
Certain legitimate uses DPDP#
Legitimate uses are the purposes listed in section 7 of the DPDP Act for which personal data can be processed without consent, such as data a person volunteers for a stated purpose, employment, legal obligations, court orders, medical emergencies and disasters. They are a closed list, narrower than the GDPR's legitimate interests.
CERT-In DPDP#
CERT-In, the Indian Computer Emergency Response Team, is the national agency for cyber incident response under section 70B of the IT Act, 2000. Its Directions of 28 April 2022 require specified cyber incidents to be reported within six hours of noticing them, separately from any DPDP breach notice.
Child DPDP#
Under the DPDP Act a child is anyone who has not completed eighteen years of age. Processing a child's personal data needs verifiable parental consent, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited.
Consent management platform (CMP) Privacy & consent#
A consent management platform is software a business runs on its own website or app to show notices, collect and enforce consent choices, hold back trackers until consent is given, and keep a record of each choice. Under the DPDP Act a CMP is not a Consent Manager and needs no registration.
Consent Manager DPDP#
A Consent Manager is a company registered with the Data Protection Board that gives individuals one interoperable platform to give, manage, review and withdraw consent across many Data Fiduciaries, acting on the individual's behalf. Registration opens on 13 November 2026 and is limited to Indian companies with a net worth of at least ₹2 crore.
Consent receipt Privacy & consent#
A consent receipt is a record of a consent given to the individual, stating what they agreed to, with whom, for which purposes, under which notice version and when. ISO/IEC TS 27560:2023 defines a standard structure for the consent record behind it.
Consent withdrawal Privacy & consent#
Consent withdrawal is an individual revoking consent given earlier. Under the DPDP Act it must be as easy as giving consent, processing by the business and its processors must stop within a reasonable time, and processing done before withdrawal stays lawful.
Continuous control monitoring GRC#
Continuous control monitoring is testing controls automatically and repeatedly against live systems, instead of sampling them once before an audit, so a control is seen to fail when it fails. Each result becomes dated evidence.
Control GRC#
A control is a specific safeguard, process or rule that reduces a risk or meets a requirement, such as enforcing multi-factor authentication or reviewing access every quarter. Frameworks state requirements; controls are what an organisation actually does to meet them.
Cross-border transfer (DPDP) DPDP#
Under the DPDP Act a Data Fiduciary may transfer personal data outside India except to countries the Central Government restricts by notification, subject to any requirements it sets on making data available to foreign states. Stricter sector rules, such as RBI's payment data storage direction, still apply.
Cross-framework mapping GRC#
Cross-framework mapping links one control to every requirement it satisfies across several frameworks, so evidence collected once answers SOC 2, ISO 27001, the DPDP Act and others together.
D
Dark patterns Privacy & consent#
Dark patterns are interface designs that mislead or pressure users into choices they would not otherwise make, such as a pre-selected option, a hidden reject button or false urgency. In India the Central Consumer Protection Authority's 2023 guidelines name thirteen specified dark patterns.
Data Fiduciary DPDP#
A Data Fiduciary is any person who, alone or with others, determines the purpose and means of processing personal data. It carries the DPDP Act's duties and stays responsible for processing done on its behalf by a Data Processor.
Data minimisation Privacy & consent#
Data minimisation is collecting and keeping only the personal data a stated purpose needs. The DPDP Act builds it into consent, which must be limited to the data necessary for the specified purpose.
Data Principal DPDP#
A Data Principal is the individual the personal data relates to. For a child it includes the parents or lawful guardian, and for a person with disability, the lawful guardian acting on their behalf.
Data processing agreement (DPA) Privacy & consent#
A data processing agreement is the contract under which a processor handles personal data for a controller or Data Fiduciary, setting its instructions, security measures, sub-processing rules, breach assistance and deletion at the end of the service.
Data Processor DPDP#
A Data Processor is any person who processes personal data on behalf of a Data Fiduciary. The Fiduciary may engage one only under a valid contract and stays responsible for what it does.
Data Protection Board of India DPDP#
The Data Protection Board of India is the body set up under the DPDP Act to inquire into breaches, direct urgent remedial measures, accept voluntary undertakings and impose penalties. It works as a digital office, and its provisions have applied since 13 November 2025.
Data Protection Impact Assessment (DPIA) Privacy & consent#
A Data Protection Impact Assessment is a structured assessment of a processing activity's purpose, necessity and risks to individuals, and of the controls that treat them. Under the DPDP Act only Significant Data Fiduciaries must carry one out, every twelve months; the GDPR requires one for likely high-risk processing.
Data Protection Officer (DPO) DPDP#
Under the DPDP Act a Data Protection Officer is an individual appointed by a Significant Data Fiduciary who is based in India, is responsible to its board and is the point of contact for grievances. Other Data Fiduciaries need only publish a contact who can answer questions about their processing.
Data subject access request (DSAR) Privacy & consent#
A data subject access request is an individual's request to see the personal data a business holds about them; the term is often stretched to cover correction and erasure requests. Under the DPDP Act access includes a summary of processing and the identities of everyone the data was shared with.
Deemed consent DPDP#
Deemed consent was a provision of the draft Digital Personal Data Protection Bill, 2022 under which consent was assumed in listed situations. The Act passed in 2023 dropped it and put "certain legitimate uses" in section 7 in its place, a narrower closed list.
Deployer AI governance#
A deployer is a person or organisation using an AI system under its own authority, other than for personal non-professional activity. Deployers of high-risk systems owe human oversight, monitoring and log keeping, and some owe a fundamental rights impact assessment.
Digital personal data DPDP#
Digital personal data is personal data in digital form. The DPDP Act covers only this, which includes data collected on paper and later digitised, but not paper records that are never digitised.
Duties of Data Principals DPDP#
The DPDP Act places duties on individuals as well: not to impersonate anyone, not to suppress material information for official identity documents, not to file false or frivolous complaints, and to give only verifiably authentic information when seeking correction or erasure. A breach can cost up to ₹10,000.
E
Eighth Schedule languages DPDP#
The Eighth Schedule to the Constitution of India lists 22 languages. The DPDP Act requires a Data Fiduciary to give people the option to read its notice and its consent request in English or any of them.
Erasure (DPDP) DPDP#
Erasure under the DPDP Act is deleting personal data once consent is withdrawn or the purpose is no longer served, unless a law requires it to be kept, and making processors delete it too. The Rules add a three-year inactivity limit for large platforms and a one-year minimum for keeping processing logs.
Evidence GRC#
Evidence is the dated, attributable record that shows a control operated, such as a configuration export, a signed review or a log extract. Auditors test evidence, not policies, and evidence created after the event reads as remediation rather than as a control.
F
Fundamental rights impact assessment (FRIA) AI governance#
A fundamental rights impact assessment is an assessment certain deployers of high-risk AI systems must complete before first use, covering who is affected, the specific risks of harm, and the oversight and mitigation measures. It applies to public bodies, private providers of public services, and deployers using AI for credit scoring or life and health insurance pricing.
G
General-purpose AI model (GPAI) AI governance#
A general-purpose AI model is an AI model, typically trained on large amounts of data, that can competently perform a wide range of distinct tasks and be integrated into many downstream systems. Its providers have had EU AI Act obligations since 2 August 2025, with extra duties for models with systemic risk.
Global Privacy Control (GPC) Privacy & consent#
Global Privacy Control is a browser signal telling websites that the user does not want their personal data sold or shared. California's CCPA regulations require businesses to treat it as a valid request to opt out of sale and sharing.
Google Consent Mode v2 Privacy & consent#
Google Consent Mode v2 is Google's interface for passing a visitor's consent choices to Google tags, adding the ad_user_data and ad_personalization signals to the earlier ad_storage and analytics_storage. Google makes it a condition of using its advertising features with visitors from the European Economic Area.
Granular consent Privacy & consent#
Granular consent is consent asked for and recorded separately for each purpose, rather than one acceptance covering everything. The DPDP Act requires consent to be specific to the specified purpose and limited to the data that purpose needs.
Grievance redressal DPDP#
Grievance redressal is the mechanism a Data Fiduciary or Consent Manager must provide for individuals to complain about how their data is handled. The response period must be published and cannot exceed 90 days, and a person must use the mechanism before going to the Board.
H
High-risk AI system AI governance#
A high-risk AI system under the EU AI Act is one used as a safety component of a regulated product, or in an Annex III area such as employment, credit, education, essential services or law enforcement. After the Digital Omnibus, Annex III obligations apply from 2 December 2027 and product-embedded ones from 2 August 2028.
Human oversight AI governance#
Human oversight is the requirement that a high-risk AI system be designed so people can understand, monitor, intervene in and stop it. Providers build the capability in; deployers must assign it to people with the competence and authority to use it.
I
Incident response plan GRC#
An incident response plan is the documented, rehearsed procedure naming who detects, decides, contains, investigates and notifies when a security incident happens. In India it has to meet both CERT-In's six-hour reporting rule and the DPDP Rules' 72-hour report to the Board.
Independent data auditor DPDP#
An independent data auditor is the auditor a Significant Data Fiduciary must appoint to evaluate its compliance with the DPDP Act. The audit runs every twelve months alongside a DPIA, and its significant observations are reported to the Board.
Information security management system (ISMS) GRC#
An information security management system is the organisation-wide set of policies, risk assessments, controls and reviews through which a company manages information security. ISO/IEC 27001 specifies its requirements, and certification is of the ISMS, not of a product.
Inherent risk GRC#
Inherent risk is the level of a risk before any controls are applied, usually scored on likelihood and impact. Comparing it with residual risk shows how much work the controls are actually doing.
L
Legitimate interests Privacy & consent#
Legitimate interests is the GDPR lawful basis that allows processing needed for a business's or a third party's legitimate interests unless the individual's rights override them. The DPDP Act has no equivalent general basis.
M
Model card AI governance#
A model card is a short document published with a machine learning model describing its intended use, training data, evaluation results across groups, limitations and ethical considerations. It is an industry practice rather than a legal term, but it feeds the technical documentation the EU AI Act requires.
N
NIST AI Risk Management Framework AI governance#
The NIST AI Risk Management Framework is a voluntary US framework, published in January 2023, for managing risks from AI systems through four functions: Govern, Map, Measure and Manage. It is guidance, not a certifiable standard.
Nomination DPDP#
Nomination is a Data Principal's right to name another individual to exercise their DPDP rights if they die or become incapable of doing so. The Rules let a person nominate one or more individuals through the process the Data Fiduciary publishes.
Notice (DPDP) DPDP#
A DPDP notice is the itemised statement a Data Fiduciary must give with or before a request for consent, setting out the personal data, each purpose, and how to withdraw consent, exercise rights and complain to the Board. It must make sense on its own, without reference to a privacy policy.
Notice versioning Privacy & consent#
Notice versioning is stamping each version of a consent notice with an identifier and storing that identifier on every consent record, so a business can show what a given person actually agreed to. Without it, old consents silently point at today's text.
O
Opt-in and opt-out Privacy & consent#
Opt-in means processing starts only after an affirmative choice; opt-out means it runs until the person objects. The DPDP Act and the GDPR are opt-in wherever consent is the basis, while most US state privacy laws are opt-out for the sale and sharing of data.
P
Personal data DPDP#
Personal data under the DPDP Act is any data about an individual who is identifiable by or in relation to that data. Unlike the GDPR, the Act has no separate category of sensitive personal data.
Personal data breach DPDP#
A personal data breach is any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises its confidentiality, integrity or availability. Under the DPDP Act every breach must be reported to the Board and to each affected person.
Prior blocking Privacy & consent#
Prior blocking is holding back non-essential cookies and trackers until the visitor has consented, instead of loading them while the banner is still on screen. It is the difference between a consent mechanism and a notification.
Privacy information management system (PIMS) GRC#
A privacy information management system is a management system for privacy that sets controls for organisations acting as controllers, processors or both. ISO/IEC 27701 specifies it, and the 2025 edition can be certified on its own rather than only as an extension of ISO 27001.
Prohibited AI practices AI governance#
Prohibited AI practices are uses the EU AI Act bans outright, including social scoring, manipulative techniques that cause significant harm, untargeted scraping of facial images, and emotion recognition at work or school. The bans have applied since 2 February 2025.
Proof of consent Privacy & consent#
Proof of consent is the record showing that a specific person was given a specific notice and agreed to specific purposes at a specific time. Under the DPDP Act the Data Fiduciary must prove it in any proceeding, so a stored true or false flag is not enough.
Provider AI governance#
A provider is a person or body that develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark. Providers of high-risk systems carry the heaviest EU AI Act obligations.
Pseudonymisation Privacy & consent#
Pseudonymisation is replacing direct identifiers with a key or token so data cannot be attributed to a person without separately held information. Pseudonymised data is still personal data; the DPDP Rules list masking and virtual tokens among the security safeguards.
Purpose limitation Privacy & consent#
Purpose limitation is the principle that personal data collected for one purpose is not used for another without a fresh basis. Under the DPDP Act consent covers only the specified purpose in the notice, so a new purpose needs a new notice and a new consent.
R
Reasonable security safeguards DPDP#
Reasonable security safeguards are the measures a Data Fiduciary must take to prevent a personal data breach. Rule 6 sets the minimum: encryption or masking, access control, logging and monitoring, backups, one-year log retention, and security clauses in processor contracts.
Record of processing activities (RoPA) Privacy & consent#
A record of processing activities is a register of the personal data an organisation processes: for which purposes, about whom, shared with whom, transferred where and kept for how long. The GDPR requires one; under the DPDP Act it is the practical basis for notice, rights and breach scoping.
Residual risk GRC#
Residual risk is the level of a risk that remains after controls are applied. It should move when a control fails, which is why it is better calculated from control results than typed into a spreadsheet.
Risk register GRC#
A risk register is the list of identified risks with an owner, inherent score, controls, residual score and treatment decision for each. ISO 27001 and SOC 2 both expect one, and it is the document that ties risks to the controls meant to treat them.
S
Significant Data Fiduciary (SDF) DPDP#
A Significant Data Fiduciary is a Data Fiduciary, or class of them, notified by the Central Government under section 10 of the DPDP Act on factors such as data volume and sensitivity, risk to people's rights and national interest. It must appoint a DPO in India and an independent auditor and run a DPIA and audit every twelve months.
SOC 2 GRC#
SOC 2 is an AICPA attestation in which an independent CPA firm reports on a service organisation's controls relevant to the Trust Services Criteria. It is an attestation report, not a certification, and it is shared with customers under NDA.
SOC 2 Type 1 GRC#
A SOC 2 Type 1 report assesses whether controls are suitably designed at a single point in time. It says nothing about whether they operated over a period.
SOC 2 Type 2 GRC#
A SOC 2 Type 2 report assesses both the design and the operating effectiveness of controls over a period, commonly three to twelve months, by testing samples of evidence. It is the report most enterprise buyers ask for.
Specified purpose DPDP#
The specified purpose is the purpose stated in the notice a Data Fiduciary gives the Data Principal. Consent covers only that purpose, and erasure falls due once it is no longer being served.
Statement of Applicability (SoA) GRC#
A Statement of Applicability is the ISO 27001 document listing every Annex A control, whether it is included or excluded and why, and whether it is implemented. It ties the risk treatment plan to the controls an auditor will test.
Strictly necessary cookies Privacy & consent#
Strictly necessary cookies are those without which a service the user asked for cannot be delivered, such as session, authentication, load-balancing and consent-choice cookies. Under the ePrivacy rules they are the only category that can be set without consent.
T
Transparency obligations (AI Act Article 50) AI governance#
Under Article 50 of the EU AI Act, people must be told when they are interacting with an AI system, synthetic content must be marked in a machine-readable way, and deepfakes must be labelled. These duties have applied since 2 August 2026.
Trust Services Criteria (TSC) GRC#
The Trust Services Criteria are the AICPA's criteria for SOC 2, grouped into five categories: security, availability, processing integrity, confidentiality and privacy. Security, the common criteria, is in every SOC 2; the others are chosen by scope.
V
Vendor risk assessment GRC#
A vendor risk assessment evaluates the security and privacy risk a supplier brings, before and during the relationship, usually through a security questionnaire, evidence review and contract terms. Under the DPDP Act a Data Fiduciary stays responsible for its processors, which makes this a control of its own.
Verifiable consent DPDP#
Verifiable consent is consent from a child's parent, or a disabled person's lawful guardian, that the Data Fiduciary has checked comes from an identifiable adult or a validly appointed guardian. Rule 10 allows the check against identity details already held or a token from an authorised entity such as DigiLocker.
Voluntary undertaking DPDP#
A voluntary undertaking is a commitment offered to the Data Protection Board at any stage of proceedings which, once accepted, bars proceedings on the matters it covers. Breaching it is penalised up to the amount the original breach could have attracted.
The things people ask us
What is the difference between a Data Fiduciary and a Data Processor?
A Data Fiduciary decides why and how personal data is processed and carries the DPDP Act's duties. A Data Processor processes data on the Fiduciary's behalf under a contract. The Fiduciary stays responsible for what its processors do, whatever the contract says, so the same company can be a Fiduciary for its own customer data and a Processor for data it hosts.
Is a consent management platform the same as a Consent Manager?
No. A consent management platform is software a business runs on its own site to collect and evidence its own consents, and needs no registration. A Consent Manager under the DPDP Act is a Board-registered Indian company acting for individuals across many businesses. Most companies need a CMP; very few will become a Consent Manager.
Did the final DPDP Act keep deemed consent?
No. Deemed consent appeared in the draft Digital Personal Data Protection Bill of 2022. The Act passed in August 2023 dropped the term and replaced it with certain legitimate uses in section 7: a closed list that includes voluntarily provided data, employment, legal obligations, medical emergencies and disasters.
What is the difference between SOC 2 Type 1 and Type 2?
A Type 1 report assesses whether controls are suitably designed at one point in time. A Type 2 report assesses design and operating effectiveness over a period, commonly three to twelve months, by testing samples of evidence. Type 1 is quicker to obtain; Type 2 is what most enterprise buyers ask for.
What is the difference between a provider and a deployer under the EU AI Act?
A provider develops an AI system or model, or has one developed, and places it on the market under its own name. A deployer uses an AI system under its own authority. Providers of high-risk systems carry most of the obligations; deployers owe oversight, monitoring and, in some cases, a fundamental rights impact assessment.
Can I link to a single definition?
Yes. Every term has a permanent anchor that will not change, such as trytrustable.com/glossary#consent-manager. Use the # beside a term's name to copy its link. If you quote a definition, a link back to the entry lets readers check the statutory reference beneath it.
Definitions are the easy part.
The platform keeps the evidence behind them: which notice each person saw, which control passed on which day, and which AI system sits in which risk tier.