Glossary

Compliance glossary:
DPDP, consent, GRC and AI governance terms.

79 terms defined in a sentence or two each, with the section, rule or article they come from and a link to the guide that goes further. Written for the people who have to implement the rules, not only read them.

Last updated Published by TryTrustableNot legal advice

01

What does this compliance glossary cover?

This glossary defines 79 terms used in India's DPDP Act and Rules, consent and cookie management, governance, risk and compliance (GRC) audits such as SOC 2 and ISO 27001, and AI governance under ISO 42001 and the EU AI Act. Each entry gives a short definition, the statutory reference, and a deeper guide.

Definitions come first and are written to stand alone, so any entry can be quoted without the ones around it. Where a term has a legal source, the reference names the section, rule or article so you can check it; where it is industry practice rather than law, the entry says so. Each term has a permanent link: use the # beside its name.

Terms are listed A to Z below. Section references are to the DPDP Act 2023 and the DPDP Rules 2025 unless another instrument is named.

A

Access review GRC#

An access review is a periodic, dated check by a named reviewer that each person's access to a system is still needed and appropriate, with every removal recorded. It is one of the first controls auditors test under SOC 2 and ISO 27001.

Reference: ISO/IEC 27001:2022 Annex A 5.18; SOC 2 CC6 · Read more: Compliance programme

AI impact assessment AI governance#

An AI impact assessment is a documented evaluation of the consequences an AI system could have for individuals, groups and society, covering its intended use and foreseeable misuse. ISO/IEC 42001 requires one as part of an AI management system.

Reference: ISO/IEC 42001:2023, clause 6.1.4 · Read more: ISO 42001 guide

AI literacy AI governance#

AI literacy is the knowledge and skill staff need to use and oversee AI systems with an understanding of their risks. The EU AI Act, as amended by the Digital Omnibus, requires providers and deployers to take measures supporting their staff's AI literacy.

Reference: EU AI Act Art. 4, applying since 2 February 2025 · Read more: EU AI Act guide

AI management system (AIMS) AI governance#

An AI management system is the set of policies, objectives, processes and controls an organisation uses to govern how it develops, provides or uses AI. ISO/IEC 42001:2023 specifies the requirements for one, and it can be certified.

Reference: ISO/IEC 42001:2023 · Read more: ISO 42001 guide

Anonymisation Privacy & consent#

Anonymisation is processing data so the individual can no longer be identified by any means reasonably likely to be used, which takes it outside data protection law. Data that can be linked back to a person is pseudonymised, not anonymised.

Reference: GDPR Recital 26; DPDP Act s.2(t) covers only identifiable data · Read more: Data discovery and DSAR

Appellate Tribunal (TDSAT) DPDP#

The Telecom Disputes Settlement and Appellate Tribunal hears appeals against orders and directions of the Data Protection Board of India. An appeal must be filed within sixty days of receiving the order, though the Tribunal can admit a late one for sufficient cause.

Reference: DPDP Act s.2(a), s.29; DPDP Rules 2025, Rule 22 · Read more: Data Protection Board guide

B

Bridge letter GRC#

A bridge letter is a statement from a service organisation's management covering the gap between the end of its last SOC report period and today, confirming no material change to its controls. Management writes it, not the auditor, so it carries no audit assurance.

Read more: SOC 2 guide

C

Certain legitimate uses DPDP#

Legitimate uses are the purposes listed in section 7 of the DPDP Act for which personal data can be processed without consent, such as data a person volunteers for a stated purpose, employment, legal obligations, court orders, medical emergencies and disasters. They are a closed list, narrower than the GDPR's legitimate interests.

Reference: DPDP Act s.2(d), s.4(1)(b), s.7 · Read more: DPDP Act guide

CERT-In DPDP#

CERT-In, the Indian Computer Emergency Response Team, is the national agency for cyber incident response under section 70B of the IT Act, 2000. Its Directions of 28 April 2022 require specified cyber incidents to be reported within six hours of noticing them, separately from any DPDP breach notice.

Reference: Information Technology Act, 2000, s.70B; CERT-In Directions under s.70B(6), 28 April 2022 · Read more: CERT-In Directions guide

Child DPDP#

Under the DPDP Act a child is anyone who has not completed eighteen years of age. Processing a child's personal data needs verifiable parental consent, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited.

Reference: DPDP Act s.2(f), s.9 · Read more: Children's data under DPDP

Consent management platform (CMP) Privacy & consent#

A consent management platform is software a business runs on its own website or app to show notices, collect and enforce consent choices, hold back trackers until consent is given, and keep a record of each choice. Under the DPDP Act a CMP is not a Consent Manager and needs no registration.

Read more: Consent by TryTrustable

Consent withdrawal Privacy & consent#

Consent withdrawal is an individual revoking consent given earlier. Under the DPDP Act it must be as easy as giving consent, processing by the business and its processors must stop within a reasonable time, and processing done before withdrawal stays lawful.

Reference: DPDP Act s.6(4)–(6); GDPR Art. 7(3) · Read more: Consent and cookie manager

Continuous control monitoring GRC#

Continuous control monitoring is testing controls automatically and repeatedly against live systems, instead of sampling them once before an audit, so a control is seen to fail when it fails. Each result becomes dated evidence.

Read more: Compliance as code

Control GRC#

A control is a specific safeguard, process or rule that reduces a risk or meets a requirement, such as enforcing multi-factor authentication or reviewing access every quarter. Frameworks state requirements; controls are what an organisation actually does to meet them.

Read more: Compliance programme

Cross-border transfer (DPDP) DPDP#

Under the DPDP Act a Data Fiduciary may transfer personal data outside India except to countries the Central Government restricts by notification, subject to any requirements it sets on making data available to foreign states. Stricter sector rules, such as RBI's payment data storage direction, still apply.

Reference: DPDP Act s.16; DPDP Rules 2025, Rule 15 · Read more: DPDP cross-border transfer guide

Cross-framework mapping GRC#

Cross-framework mapping links one control to every requirement it satisfies across several frameworks, so evidence collected once answers SOC 2, ISO 27001, the DPDP Act and others together.

Read more: Cross-framework mapping

D

Dark patterns Privacy & consent#

Dark patterns are interface designs that mislead or pressure users into choices they would not otherwise make, such as a pre-selected option, a hidden reject button or false urgency. In India the Central Consumer Protection Authority's 2023 guidelines name thirteen specified dark patterns.

Reference: Guidelines for Prevention and Regulation of Dark Patterns, 2023 (CCPA, India); EU Digital Services Act Art. 25 · Read more: Consent and cookie manager

Data Fiduciary DPDP#

A Data Fiduciary is any person who, alone or with others, determines the purpose and means of processing personal data. It carries the DPDP Act's duties and stays responsible for processing done on its behalf by a Data Processor.

Reference: DPDP Act s.2(i), s.8(1) · Read more: DPDP Act guide

Data minimisation Privacy & consent#

Data minimisation is collecting and keeping only the personal data a stated purpose needs. The DPDP Act builds it into consent, which must be limited to the data necessary for the specified purpose.

Reference: DPDP Act s.6(1); GDPR Art. 5(1)(c) · Read more: DPDP consent notice template

Data Principal DPDP#

A Data Principal is the individual the personal data relates to. For a child it includes the parents or lawful guardian, and for a person with disability, the lawful guardian acting on their behalf.

Reference: DPDP Act s.2(j) · Read more: DPDP Act guide

Data processing agreement (DPA) Privacy & consent#

A data processing agreement is the contract under which a processor handles personal data for a controller or Data Fiduciary, setting its instructions, security measures, sub-processing rules, breach assistance and deletion at the end of the service.

Reference: DPDP Act s.8(2); DPDP Rules 2025, Rule 6(1)(f); GDPR Art. 28 · Read more: DPDP data processing agreement template

Data Processor DPDP#

A Data Processor is any person who processes personal data on behalf of a Data Fiduciary. The Fiduciary may engage one only under a valid contract and stays responsible for what it does.

Reference: DPDP Act s.2(k), s.8(1)–(2) · Read more: DPDP data processing agreement template

Data Protection Board of India DPDP#

The Data Protection Board of India is the body set up under the DPDP Act to inquire into breaches, direct urgent remedial measures, accept voluntary undertakings and impose penalties. It works as a digital office, and its provisions have applied since 13 November 2025.

Reference: DPDP Act s.2(c), s.18, s.27–28; DPDP Rules 2025, Rules 17–21 · Read more: Data Protection Board guide

Data Protection Impact Assessment (DPIA) Privacy & consent#

A Data Protection Impact Assessment is a structured assessment of a processing activity's purpose, necessity and risks to individuals, and of the controls that treat them. Under the DPDP Act only Significant Data Fiduciaries must carry one out, every twelve months; the GDPR requires one for likely high-risk processing.

Reference: DPDP Act s.10(2)(c); DPDP Rules 2025, Rule 13(1); GDPR Art. 35 · Read more: DPIA template

Data Protection Officer (DPO) DPDP#

Under the DPDP Act a Data Protection Officer is an individual appointed by a Significant Data Fiduciary who is based in India, is responsible to its board and is the point of contact for grievances. Other Data Fiduciaries need only publish a contact who can answer questions about their processing.

Reference: DPDP Act s.2(l), s.8(9), s.10(2)(a) · Read more: Significant Data Fiduciary guide

Data subject access request (DSAR) Privacy & consent#

A data subject access request is an individual's request to see the personal data a business holds about them; the term is often stretched to cover correction and erasure requests. Under the DPDP Act access includes a summary of processing and the identities of everyone the data was shared with.

Reference: DPDP Act s.11–12; GDPR Art. 15 · Read more: Data discovery and DSAR

Deployer AI governance#

A deployer is a person or organisation using an AI system under its own authority, other than for personal non-professional activity. Deployers of high-risk systems owe human oversight, monitoring and log keeping, and some owe a fundamental rights impact assessment.

Reference: EU AI Act Art. 3(4), Art. 26, Art. 27 · Read more: EU AI Act guide

Digital personal data DPDP#

Digital personal data is personal data in digital form. The DPDP Act covers only this, which includes data collected on paper and later digitised, but not paper records that are never digitised.

Reference: DPDP Act s.2(n), s.3(a) · Read more: DPDP applicability checker

Duties of Data Principals DPDP#

The DPDP Act places duties on individuals as well: not to impersonate anyone, not to suppress material information for official identity documents, not to file false or frivolous complaints, and to give only verifiably authentic information when seeking correction or erasure. A breach can cost up to ₹10,000.

Reference: DPDP Act s.15 and the Schedule · Read more: DPDP penalties guide

E

Eighth Schedule languages DPDP#

The Eighth Schedule to the Constitution of India lists 22 languages. The DPDP Act requires a Data Fiduciary to give people the option to read its notice and its consent request in English or any of them.

Reference: DPDP Act s.5(3), s.6(3) · Read more: DPDP consent notice template

Erasure (DPDP) DPDP#

Erasure under the DPDP Act is deleting personal data once consent is withdrawn or the purpose is no longer served, unless a law requires it to be kept, and making processors delete it too. The Rules add a three-year inactivity limit for large platforms and a one-year minimum for keeping processing logs.

Reference: DPDP Act s.8(7)–(8); DPDP Rules 2025, Rule 8 · Read more: DPDP retention and erasure guide

Evidence GRC#

Evidence is the dated, attributable record that shows a control operated, such as a configuration export, a signed review or a log extract. Auditors test evidence, not policies, and evidence created after the event reads as remediation rather than as a control.

Read more: Automated evidence and ledger

F

Fundamental rights impact assessment (FRIA) AI governance#

A fundamental rights impact assessment is an assessment certain deployers of high-risk AI systems must complete before first use, covering who is affected, the specific risks of harm, and the oversight and mitigation measures. It applies to public bodies, private providers of public services, and deployers using AI for credit scoring or life and health insurance pricing.

Reference: EU AI Act Art. 27 · Read more: EU AI Act guide

G

General-purpose AI model (GPAI) AI governance#

A general-purpose AI model is an AI model, typically trained on large amounts of data, that can competently perform a wide range of distinct tasks and be integrated into many downstream systems. Its providers have had EU AI Act obligations since 2 August 2025, with extra duties for models with systemic risk.

Reference: EU AI Act Art. 3(63), Arts. 51–55 · Read more: EU AI Act guide

Global Privacy Control (GPC) Privacy & consent#

Global Privacy Control is a browser signal telling websites that the user does not want their personal data sold or shared. California's CCPA regulations require businesses to treat it as a valid request to opt out of sale and sharing.

Reference: GPC specification; California Code of Regulations, title 11, §7025 · Read more: Consent and cookie manager

Grievance redressal DPDP#

Grievance redressal is the mechanism a Data Fiduciary or Consent Manager must provide for individuals to complain about how their data is handled. The response period must be published and cannot exceed 90 days, and a person must use the mechanism before going to the Board.

Reference: DPDP Act s.8(10), s.13; DPDP Rules 2025, Rule 14(3) · Read more: DPDP Act guide

H

High-risk AI system AI governance#

A high-risk AI system under the EU AI Act is one used as a safety component of a regulated product, or in an Annex III area such as employment, credit, education, essential services or law enforcement. After the Digital Omnibus, Annex III obligations apply from 2 December 2027 and product-embedded ones from 2 August 2028.

Reference: EU AI Act Art. 6, Annexes I and III; Regulation (EU) 2026/1744 · Read more: EU AI Act guide

Human oversight AI governance#

Human oversight is the requirement that a high-risk AI system be designed so people can understand, monitor, intervene in and stop it. Providers build the capability in; deployers must assign it to people with the competence and authority to use it.

Reference: EU AI Act Art. 14, Art. 26(2) · Read more: AI governance

I

Incident response plan GRC#

An incident response plan is the documented, rehearsed procedure naming who detects, decides, contains, investigates and notifies when a security incident happens. In India it has to meet both CERT-In's six-hour reporting rule and the DPDP Rules' 72-hour report to the Board.

Reference: CERT-In Directions, 28 April 2022; DPDP Rules 2025, Rule 7 · Read more: Incident response plan template

Independent data auditor DPDP#

An independent data auditor is the auditor a Significant Data Fiduciary must appoint to evaluate its compliance with the DPDP Act. The audit runs every twelve months alongside a DPIA, and its significant observations are reported to the Board.

Reference: DPDP Act s.10(2)(b); DPDP Rules 2025, Rule 13 · Read more: Significant Data Fiduciary guide

Information security management system (ISMS) GRC#

An information security management system is the organisation-wide set of policies, risk assessments, controls and reviews through which a company manages information security. ISO/IEC 27001 specifies its requirements, and certification is of the ISMS, not of a product.

Reference: ISO/IEC 27001:2022 · Read more: ISO 27001 on the platform

Inherent risk GRC#

Inherent risk is the level of a risk before any controls are applied, usually scored on likelihood and impact. Comparing it with residual risk shows how much work the controls are actually doing.

Read more: Risk assessment and register

L

Legitimate interests Privacy & consent#

Legitimate interests is the GDPR lawful basis that allows processing needed for a business's or a third party's legitimate interests unless the individual's rights override them. The DPDP Act has no equivalent general basis.

Reference: GDPR Art. 6(1)(f) · Read more: DPDP to GDPR mapping

M

Model card AI governance#

A model card is a short document published with a machine learning model describing its intended use, training data, evaluation results across groups, limitations and ethical considerations. It is an industry practice rather than a legal term, but it feeds the technical documentation the EU AI Act requires.

Reference: Mitchell et al., Model Cards for Model Reporting (2019); compare EU AI Act Annex IV · Read more: AI governance

N

NIST AI Risk Management Framework AI governance#

The NIST AI Risk Management Framework is a voluntary US framework, published in January 2023, for managing risks from AI systems through four functions: Govern, Map, Measure and Manage. It is guidance, not a certifiable standard.

Reference: NIST AI 100-1 · Read more: NIST AI RMF guide

Nomination DPDP#

Nomination is a Data Principal's right to name another individual to exercise their DPDP rights if they die or become incapable of doing so. The Rules let a person nominate one or more individuals through the process the Data Fiduciary publishes.

Reference: DPDP Act s.14; DPDP Rules 2025, Rule 14(4) · Read more: DPDP Act guide

Notice (DPDP) DPDP#

A DPDP notice is the itemised statement a Data Fiduciary must give with or before a request for consent, setting out the personal data, each purpose, and how to withdraw consent, exercise rights and complain to the Board. It must make sense on its own, without reference to a privacy policy.

Reference: DPDP Act s.5; DPDP Rules 2025, Rule 3 · Read more: DPDP consent notice template

Notice versioning Privacy & consent#

Notice versioning is stamping each version of a consent notice with an identifier and storing that identifier on every consent record, so a business can show what a given person actually agreed to. Without it, old consents silently point at today's text.

Read more: DPDP consent notice template

O

Opt-in and opt-out Privacy & consent#

Opt-in means processing starts only after an affirmative choice; opt-out means it runs until the person objects. The DPDP Act and the GDPR are opt-in wherever consent is the basis, while most US state privacy laws are opt-out for the sale and sharing of data.

Read more: Consent and cookie manager

P

Personal data DPDP#

Personal data under the DPDP Act is any data about an individual who is identifiable by or in relation to that data. Unlike the GDPR, the Act has no separate category of sensitive personal data.

Reference: DPDP Act s.2(t) · Read more: DPDP Act guide

Personal data breach DPDP#

A personal data breach is any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises its confidentiality, integrity or availability. Under the DPDP Act every breach must be reported to the Board and to each affected person.

Reference: DPDP Act s.2(u), s.8(6); DPDP Rules 2025, Rule 7 · Read more: CERT-In vs DPDP breach reporting

Prior blocking Privacy & consent#

Prior blocking is holding back non-essential cookies and trackers until the visitor has consented, instead of loading them while the banner is still on screen. It is the difference between a consent mechanism and a notification.

Reference: ePrivacy Directive 2002/58/EC, Art. 5(3) · Read more: Free cookie scanner

Privacy information management system (PIMS) GRC#

A privacy information management system is a management system for privacy that sets controls for organisations acting as controllers, processors or both. ISO/IEC 27701 specifies it, and the 2025 edition can be certified on its own rather than only as an extension of ISO 27001.

Reference: ISO/IEC 27701:2025 · Read more: ISO 27701 guide

Prohibited AI practices AI governance#

Prohibited AI practices are uses the EU AI Act bans outright, including social scoring, manipulative techniques that cause significant harm, untargeted scraping of facial images, and emotion recognition at work or school. The bans have applied since 2 February 2025.

Reference: EU AI Act Art. 5 · Read more: EU AI Act penalties

Provider AI governance#

A provider is a person or body that develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark. Providers of high-risk systems carry the heaviest EU AI Act obligations.

Reference: EU AI Act Art. 3(3), Art. 16 · Read more: EU AI Act guide

Pseudonymisation Privacy & consent#

Pseudonymisation is replacing direct identifiers with a key or token so data cannot be attributed to a person without separately held information. Pseudonymised data is still personal data; the DPDP Rules list masking and virtual tokens among the security safeguards.

Reference: GDPR Art. 4(5); DPDP Rules 2025, Rule 6(1)(a) · Read more: Data discovery and DSAR

Purpose limitation Privacy & consent#

Purpose limitation is the principle that personal data collected for one purpose is not used for another without a fresh basis. Under the DPDP Act consent covers only the specified purpose in the notice, so a new purpose needs a new notice and a new consent.

Reference: DPDP Act s.2(za), s.6(1); GDPR Art. 5(1)(b) · Read more: DPDP consent notice template

R

Reasonable security safeguards DPDP#

Reasonable security safeguards are the measures a Data Fiduciary must take to prevent a personal data breach. Rule 6 sets the minimum: encryption or masking, access control, logging and monitoring, backups, one-year log retention, and security clauses in processor contracts.

Reference: DPDP Act s.8(5); DPDP Rules 2025, Rule 6; penalty up to ₹250 crore · Read more: DPDP penalties guide

Record of processing activities (RoPA) Privacy & consent#

A record of processing activities is a register of the personal data an organisation processes: for which purposes, about whom, shared with whom, transferred where and kept for how long. The GDPR requires one; under the DPDP Act it is the practical basis for notice, rights and breach scoping.

Reference: GDPR Art. 30 · Read more: RoPA template

Residual risk GRC#

Residual risk is the level of a risk that remains after controls are applied. It should move when a control fails, which is why it is better calculated from control results than typed into a spreadsheet.

Read more: Risk assessment and register

Risk register GRC#

A risk register is the list of identified risks with an owner, inherent score, controls, residual score and treatment decision for each. ISO 27001 and SOC 2 both expect one, and it is the document that ties risks to the controls meant to treat them.

Reference: ISO/IEC 27001:2022 clause 6.1; SOC 2 CC3 · Read more: Risk register template

S

Significant Data Fiduciary (SDF) DPDP#

A Significant Data Fiduciary is a Data Fiduciary, or class of them, notified by the Central Government under section 10 of the DPDP Act on factors such as data volume and sensitivity, risk to people's rights and national interest. It must appoint a DPO in India and an independent auditor and run a DPIA and audit every twelve months.

Reference: DPDP Act s.2(z), s.10; DPDP Rules 2025, Rule 13 · Read more: Significant Data Fiduciary guide

SOC 2 GRC#

SOC 2 is an AICPA attestation in which an independent CPA firm reports on a service organisation's controls relevant to the Trust Services Criteria. It is an attestation report, not a certification, and it is shared with customers under NDA.

Reference: AICPA Trust Services Criteria · Read more: SOC 2 guide

SOC 2 Type 1 GRC#

A SOC 2 Type 1 report assesses whether controls are suitably designed at a single point in time. It says nothing about whether they operated over a period.

Read more: SOC 2 Type 1 vs Type 2

SOC 2 Type 2 GRC#

A SOC 2 Type 2 report assesses both the design and the operating effectiveness of controls over a period, commonly three to twelve months, by testing samples of evidence. It is the report most enterprise buyers ask for.

Read more: SOC 2 Type 1 vs Type 2

Specified purpose DPDP#

The specified purpose is the purpose stated in the notice a Data Fiduciary gives the Data Principal. Consent covers only that purpose, and erasure falls due once it is no longer being served.

Reference: DPDP Act s.2(za), s.8(7) · Read more: DPDP consent notice template

Statement of Applicability (SoA) GRC#

A Statement of Applicability is the ISO 27001 document listing every Annex A control, whether it is included or excluded and why, and whether it is implemented. It ties the risk treatment plan to the controls an auditor will test.

Reference: ISO/IEC 27001:2022 clause 6.1.3(d) · Read more: ISO 27001 SoA template

Strictly necessary cookies Privacy & consent#

Strictly necessary cookies are those without which a service the user asked for cannot be delivered, such as session, authentication, load-balancing and consent-choice cookies. Under the ePrivacy rules they are the only category that can be set without consent.

Reference: ePrivacy Directive 2002/58/EC, Art. 5(3) · Read more: Cookie policy generator

T

Transparency obligations (AI Act Article 50) AI governance#

Under Article 50 of the EU AI Act, people must be told when they are interacting with an AI system, synthetic content must be marked in a machine-readable way, and deepfakes must be labelled. These duties have applied since 2 August 2026.

Reference: EU AI Act Art. 50 · Read more: EU AI Act guide

Trust Services Criteria (TSC) GRC#

The Trust Services Criteria are the AICPA's criteria for SOC 2, grouped into five categories: security, availability, processing integrity, confidentiality and privacy. Security, the common criteria, is in every SOC 2; the others are chosen by scope.

Reference: AICPA 2017 Trust Services Criteria, revised points of focus 2022 · Read more: SOC 2 guide

V

Vendor risk assessment GRC#

A vendor risk assessment evaluates the security and privacy risk a supplier brings, before and during the relationship, usually through a security questionnaire, evidence review and contract terms. Under the DPDP Act a Data Fiduciary stays responsible for its processors, which makes this a control of its own.

Reference: DPDP Act s.8(1)–(2); ISO/IEC 27001:2022 Annex A 5.19; SOC 2 CC9 · Read more: Vendor risk management guide

Voluntary undertaking DPDP#

A voluntary undertaking is a commitment offered to the Data Protection Board at any stage of proceedings which, once accepted, bars proceedings on the matters it covers. Breaching it is penalised up to the amount the original breach could have attracted.

Reference: DPDP Act s.32 and the Schedule · Read more: DPDP penalties guide

Questions

The things people ask us

What is the difference between a Data Fiduciary and a Data Processor?

A Data Fiduciary decides why and how personal data is processed and carries the DPDP Act's duties. A Data Processor processes data on the Fiduciary's behalf under a contract. The Fiduciary stays responsible for what its processors do, whatever the contract says, so the same company can be a Fiduciary for its own customer data and a Processor for data it hosts.

Is a consent management platform the same as a Consent Manager?

No. A consent management platform is software a business runs on its own site to collect and evidence its own consents, and needs no registration. A Consent Manager under the DPDP Act is a Board-registered Indian company acting for individuals across many businesses. Most companies need a CMP; very few will become a Consent Manager.

Did the final DPDP Act keep deemed consent?

No. Deemed consent appeared in the draft Digital Personal Data Protection Bill of 2022. The Act passed in August 2023 dropped the term and replaced it with certain legitimate uses in section 7: a closed list that includes voluntarily provided data, employment, legal obligations, medical emergencies and disasters.

What is the difference between SOC 2 Type 1 and Type 2?

A Type 1 report assesses whether controls are suitably designed at one point in time. A Type 2 report assesses design and operating effectiveness over a period, commonly three to twelve months, by testing samples of evidence. Type 1 is quicker to obtain; Type 2 is what most enterprise buyers ask for.

What is the difference between a provider and a deployer under the EU AI Act?

A provider develops an AI system or model, or has one developed, and places it on the market under its own name. A deployer uses an AI system under its own authority. Providers of high-risk systems carry most of the obligations; deployers owe oversight, monitoring and, in some cases, a fundamental rights impact assessment.

Can I link to a single definition?

Yes. Every term has a permanent anchor that will not change, such as trytrustable.com/glossary#consent-manager. Use the # beside a term's name to copy its link. If you quote a definition, a link back to the entry lets readers check the statutory reference beneath it.

Book a walkthrough

Definitions are the easy part.

The platform keeps the evidence behind them: which notice each person saw, which control passed on which day, and which AI system sits in which risk tier.