Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026in 2 days 15 OCTPF & ESI · Contributions · Sep 2026in 6 days 20 OCTGSTR-3B · Summary return · Sep 2026in 11 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 12 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 21 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 29 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 43 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 51 days
All due dates

Section 2 of the Digital Personal Data Protection Act, 2023: Definitions of data, personal data and processing

"Personal data" is any data about an individual who is identifiable by or in relation to that data (section 2(t)). The Act applies to it in digital form (section 2(n)), and...

Published
Updated
Reading time
7 min
Views
15
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
Topic
Data Protection
Published
September 30, 2026
Last updated
Oct 9, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Section 2 is the dictionary of the Act. This article covers the six definitions that decide what the Act protects and what counts as handling it: "automated", "data", "digital personal data", "personal data", "personal data breach" and "processing". The roles (Data Principal, Data Fiduciary and others) are in the next article, and the remaining terms follow after that. If you want your own records tested against these definitions, our legal consultation service can do that.

The six definitions at a glance

ClauseTermWhat the Act says
2(b)automatedAny digital process capable of operating automatically in response to instructions given or otherwise, for the purpose of processing data
2(h)dataA representation of information, facts, concepts, opinions or instructions in a manner suitable for communication, interpretation or processing by human beings or by automated means
2(n)digital personal dataPersonal data in digital form
2(t)personal dataAny data about an individual who is identifiable by or in relation to such data
2(u)personal data breachAny unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data
2(x)processingA wholly or partly automated operation or set of operations performed on digital personal data

"Data" and "personal data"

Section 2(h) is deliberately wide. It covers information, facts, concepts, opinions and instructions, so long as they are in a form suitable for communication, interpretation or processing by people or by automated means. A spreadsheet of customer names, a database field, a scanned form and a chat message all fit.

Section 2(t) then narrows it: personal data is data about an individual who is identifiable by or in relation to that data. Three points follow from the wording.

  • The data must be about an individual. Section 2(s) separately defines "person" more widely (company, firm and so on), but personal data concerns an individual.
  • The individual need not be named. If the person can be identified by the data itself or in relation to it, the data qualifies. A customer ID plus an address that points to one person is an example of identification "in relation to" the data.
  • The Act does not split personal data into ordinary and sensitive categories. The definition has no list of sensitive types. Where the type of data matters, the Act says so in the specific section, for example section 10(1)(a) refers to "volume and sensitivity" of personal data for notifying a Significant Data Fiduciary, and section 33(2)(b) refers to "the type and nature of the personal data" when setting a penalty.

"Digital personal data" and the reach of the Act

Section 2(n) says digital personal data is personal data in digital form. Section 3(a) extends the Act to personal data collected in non-digital form and digitised afterwards, which means paper records are caught once they are digitised. Until then, purely paper-based handling is outside the definition of processing in section 2(x), because processing is defined on "digital personal data". See the article on section 3 and the application of the Act for the territorial and format rules.

"Automated"

Section 2(b) defines "automated" as any digital process capable of operating automatically in response to instructions given or otherwise. It feeds into the definition of processing, which is "wholly or partly automated". An operation that is partly automated, such as an employee entering data that a system then indexes, is still processing. Because the definition says "wholly or partly", a business cannot avoid the Act by pointing to a manual step inside an otherwise digital workflow.

"Processing"

Section 2(x) lists the operations that count, using the word "includes", so the list is illustrative rather than closed: collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction.

Two practical readings matter. First, merely storing data is processing, so a company that holds old customer records and never uses them is still processing. Second, erasure and destruction are also processing, so deleting data is itself an operation the Act covers, which is relevant when you read the retention and erasure duties in section 8(7).

"Personal data breach"

Section 2(u) is broader than a hack. It includes:

  • unauthorised processing of personal data; and
  • accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access,

in either case where the event compromises the confidentiality, integrity or availability of the data. A ransomware lock that blocks access is covered because availability is compromised. An email sent to the wrong recipient with customer details is covered because of accidental disclosure. The duty to tell the Board and each affected Data Principal is in section 8(6), and the detail of form and manner is left to the Rules.

Practical examples

Example 1: a paper register. A clinic keeps a handwritten visitor register. Until the entries are digitised, they are not digital personal data under section 2(n). Once staff type them into a booking system, the Act applies under section 3(a)(ii).

Example 2: a retail database. A shop's loyalty system stores a phone number and purchase history against an ID. The data is about an individual who is identifiable in relation to it, so it is personal data, and keeping it in the system is processing.

Example 3: a misdirected file. An HR executive emails salary slips to the wrong employee. This is accidental disclosure compromising confidentiality, so it fits the definition of a personal data breach in section 2(u).

Common mistakes

  • Thinking that data without a name is not personal data. The test is whether the individual is identifiable by or in relation to the data.
  • Assuming storage alone is outside "processing". Section 2(x) includes storage and erasure.
  • Reading "breach" as meaning only external hacking. Section 2(u) covers accidental events.

Need help with DPDP definitions and data mapping?

If you are not sure which of your records are personal data, or which of your operations count as processing, a structured review can settle that before you draft notices or contracts. Speak to us through our legal consultation service and we will map your records against these definitions.

Key takeaways

  • "Personal data" means data about an individual who is identifiable by or in relation to that data.
  • "Digital personal data" is personal data in digital form; digitised paper records are brought in by section 3(a).
  • "Processing" is a wholly or partly automated operation and covers collection through to erasure.
  • A "personal data breach" includes accidental events, not only attacks.
  • The Act has no separate list of sensitive personal data in section 2.

Read next

Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.

Quick recapKey facts & short answers

Key Facts About Section 2

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

What is personal data under the DPDP Act?

Section 2(t) defines it as any data about an individual who is identifiable by or in relation to such data.

Is paper data covered?

Section 3(a) covers personal data collected in non-digital form and digitised subsequently. Purely paper handling is outside the definition of processing in section 2(x).

Ask the question before you sign — it is always cheaper than asking it afterwards.

— TaxClue Compliance Desk

Section 2: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

Section 2(t) defines it as any data about an individual who is identifiable by or in relation to such data.

Section 3(a) covers personal data collected in non-digital form and digitised subsequently. Purely paper handling is outside the definition of processing in section 2(x).

Not in section 2. The Act refers to the sensitivity or type of data only where a particular section needs it, such as section 10(1)(a) and section 33(2)(b).

Yes. Section 2(x) lists storage among the operations, and the list is introduced by the word "includes".

Under section 2(u), unauthorised processing or accidental disclosure, loss of access and similar events that compromise confidentiality, integrity or availability of the personal data.

Section 8(6) requires intimation to the Board and each affected Data Principal in the form and manner prescribed. Check the DPDP Rules, 2025 for the detail.