Indian compliance glossary, for practitioners
Working definitions of the terms Indian compliance practitioners actually use — from Data Fiduciary to UPSI to BRSR Core to CERT-In 6-hour incident reporting. Every definition cites the exact Section, Rule or notification the term flows from.
Data Protection
Consent Manager
A person registered with the Data Protection Board of India who provides Data Principals with a consent-management interface under the DPDP Act 2023.
Data Fiduciary
Under the DPDP Act 2023, the person who determines the purpose and means of processing personal data — the Indian equivalent of a GDPR data controller.
Data Principal
The natural person to whom personal data relates under the DPDP Act 2023 — the Indian equivalent of a GDPR data subject.
Data Protection Impact Assessment (DPIA)
A structured assessment of the privacy risks of a processing activity, mandatory for Significant Data Fiduciaries under Section 10(2)(b) of the DPDP Act 2023.
Data Protection Officer (DPO)
The India-based officer appointed by a Significant Data Fiduciary under the DPDP Act 2023 to serve as the point of contact for grievance redressal.
Significant Data Fiduciary
A Data Fiduciary designated by the Central Government under Section 10 of the DPDP Act 2023, subject to enhanced compliance obligations.
Cybersecurity
Business Continuity Plan vs Disaster Recovery Plan
A BCP defines how the business keeps operating during a disruption; a DRP defines how IT systems and data are recovered after one.
CERT-In 6-Hour Incident Reporting
The obligation to report specified cyber incidents to CERT-In within six hours of noticing them, imposed by the 28 April 2022 CERT-In Directions.
Cyber Security Incident Response Team (CSIRT)
The dedicated team responsible for detecting, containing, eradicating and recovering from cyber security incidents, mandated by most Indian sectoral cyber frameworks.
ISO/IEC 27001:2022 Annex A Controls
The 93 information security controls listed in Annex A of ISO/IEC 27001:2022, organised into 4 themes: Organisational, People, Physical, and Technological.
SOC 2 Type 1 vs SOC 2 Type 2
A SOC 2 Type 1 report attests to control design at a point in time; a Type 2 report additionally attests to operating effectiveness over a period (typically 6–12 months).
Corporate Governance
BRSR Core
A subset of the Business Responsibility and Sustainability Report requiring reasonable assurance by an independent assessor, mandated by SEBI Circular 28 March 2025.
Related Party Transaction (RPT)
A transaction between a company and a related party, subject to approval and disclosure obligations under Companies Act Section 188 and SEBI LODR Regulation 23.
Trading Window Closure
The regulated period during which Designated Persons of a listed entity are prohibited from trading in its securities, imposed by SEBI PIT Regulation 4(1).
Unpublished Price Sensitive Information (UPSI)
Information relating to a listed company that is not generally available and, if generally available, would materially affect the price of its securities. Governed by SEBI PIT Regulations 2015.
Labour & Workplace
Internal Committee (IC) — POSH
The statutory committee constituted under Section 4 of the POSH Act 2013 to receive and inquire into complaints of sexual harassment at the workplace.
Occupational Safety Committee
The safety committee required in establishments with 10 or more workers under the OSH&WC Code 2020 to ensure compliance with occupational safety, health and working conditions.