Two different words, same meaning, yet very different legal identities.
When Europe’s GDPR came into effect, it termed the individual whose personal data is collected and used as the “Data Subject.” India’s Digital Personal Data Protection Act, 2023 (DPDPA) chose a different word: “Data Principal.”
Why the change? In theory, both terms refer to the same person. It is the individual whose data is being collected, stored, or processed. But they carry different weights:
- ‘Subject’ : implies the information is held under someone else’s authority. The law works as traditional regulations where the individual is being regulated around.
- ‘Principal’ : implies the individual’s control and ownership. The person has the central authority over their data.
In this blog, we will point out why the two terms differ, and why the wording shift matters more than it looks.
In this blog, we will point out why the two terms differ, and why the wording shift matters more than it looks.
Why did India use ‘Data Principal’ instead of ‘Data Subject’?
India chose the term Data Principal (DP) to reflect individual agency, ownership, and control rather than passivity. The following are the details about this shift from Subject to Principal-
- Ownership- The Data Principal is the primary key. DP is not just a subject of data processing bodies. They have full control over their personal data that a company holds. In comparison, a Data Subject is a more passive party whose data is processed under a controller’s authority.
- Active Participation – A Data Principal can actively give, manage, review, and withdraw consent for your data.
- Responsibilities- When an individual becomes a ‘Principal,’ they have significant duties like providing accurate information.

Who is a “Data Principal” Under the DPDP Act?
Under the Section 2 (j) of the DPDP Act introduces the term ‘Data Principal.’ A Data Principal (DP) is an individual to whom the personal data relates.
Data Principal-
- Must be a natural person (no corporate or government bodies)
- Can be parents or lawful guardians of a child.
- Is a lawful guardian acting on behalf of a disabled person.
What is a “Data Subject” Under GDPR?
A Data Subject (DS) under the GDPR Act is any living person whose personal data is collected, held, and processed by an organisation.
Data Subject –
- Is a real, living human being. Deceased persons, animals, and corporate entities are excluded.
- Can be identified directly by name, ID number, or location data.
- Is someone who is located within the EU (European Union) when their data is processed.
What This Means for Indian Businesses ?
1. How is the law structured for both?
GDPR is broader than DPDP. It is more focused on empowering individuals by giving them finer control over their data.
DPDP is narrower than GDPR. The law is lighter on compliance. It is built around consent and data fiduciaries’ duties.
2. Core definitions in the official documents
Data Subject (GDPR) Article 4(1)
An identified or identifiable natural person, i.e., one who can be identified directly or indirectly via an identifier such as a name, ID number, location data, or online identifier. That individual can also be identified by factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity.
Data Principal (DPDP Act, 2023) Section 2(j)
The individual to whom the personal data relates — and if that individual is a child, includes their parent/lawful guardian; if a person with disability, includes their lawful guardian acting on their behalf.
Comparison table for both Data Subject and Data Principal
| S. No. | Right to | Data Subject (GDPR) | Data Principal (DPDP) |
|---|---|---|---|
| 1. | Access the data | Right to obtain confirmation of whether their data is processed. They can access it along with specified details like purpose, categories, recipients, retention period, etc. (Article 15) |
Right to obtain a summary of personal data being processed, the identities of other fiduciaries/processors it’s been shared with, and other prescribed info. (Section 11) |
| 2. | Being informed | The controller must inform the individual what data is collected, why, and for how long. (Article 13 and 14) | Data Fiduciary must give notice describing the data collected and the purpose of processing, at or before the consent request. (Section 5) |
| 3. | Correction / Rectification | Right to have inaccurate data rectified and incomplete data completed. (Article 16) | Right to correction, completion and updating of inaccurate, incomplete, or outdated personal data. [Section 12(1)–(2)] |
| 4. | Erasure | “Right to be forgotten” — right to erasure under specific grounds, unless it is subject to exceptions. (Article 17) | Right to request erasure of personal data, unless retention is needed for the specified purpose. [Section 12(3)] |
| 5. | Grievance redressal / Complaints | Right to lodge a complaint with a supervisory authority. (It is not a fiduciary, which is the first requirement like DPDP). (Article 77) | Right to accessible grievance redressal from the Data Fiduciary/Consent Manager. If there is no solution, then they can approach the Data Protection Board. (Section 13) |
| 6. | Nomination (death/incapacity) | No direct equivalent. | Right to nominate another individual to exercise the Data Principal’s rights in the event of death or incapacity. (Section 14) |
| 7. | Objecting to processing | Right to object to processing, in particular for direct marketing or processing based on legitimate interest/public task. (Article 21) | No particular “objection” right. The closest is consent withdrawal and duty-based exceptions. [Section 6(4)] |
| 8. | Restriction of processing | Right to obtain restriction of processing under specific conditions (e.g., while accuracy is contested). (Article 18) | No standalone equivalent. |
| 9. | Data portability | Right to receive personal data in a structured, commonly used, machine-readable format and transmit it to another controller. (Article 20) | No standalone equivalent. |
| 10. | Automated decision-making | Right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. (Article 22) | No standalone equivalent. |
| 11. | Consent withdrawal | Right to withdraw consent at any time (part of the conditions for consent). [Article 7(3)] | Right to withdraw consent at any time, as easily as it was given. [Section 6(4)] |
DPDP consolidates rights into four broad categories (access, correction/erasure, grievance, nomination), while GDPR grants eight separate, more detailed rights including these as well (portability, restriction, automated decision-making protection) that DPDP doesn’t provide as independent rights.
What This Means for Indian Businesses ?
The DPDP Act isn’t just another compliance checkbox for the business, it changes how Indian businesses think about personal data. DPDP pushes data protection from a legal afterthought into a core part of product and operations.
This shift from older regulations to DPDP Act brings-
- Consent can no longer be an afterthought. The consent has to be specified, informed, and easy to withdraw.
- Data minimization is the main principle of this act. Collecting more than necessary data now is a liability.
- Companies need systems that are placed to detect and report breaches quickly. This is because now, the breach reporting timelines are tight.
- Significant Data Fiduciaries face extra examinations, like audits, DPO appointments, and impact assessments.
- In a case of non-compliance, the company is penalized with heavy fines.
Businesses that treat data protection as a core business part early will have a real advantage over those scrambling to catch up later.

Simplify DPDP Compliance with DPDP.ai
Tracking consent, mapping data flows, monitoring breach timelines, preparing documentation and more, keeping up with all of these is a lot to manage on the top of running a business. This is where DPDP.ai comes in.
DPDP.ai helps Indian businesses navigate the DPDP Act without the guesswork:
- Automated Consent Management keeps records audit-ready and withdrawal requests frictionless. Multiple Indian languages are supported on the platform.
- Data mapping and classification know what personal data you hold and why through the PII Discovery Platform.
- Real-time Compliance Monitoring catches gaps before they become violations. It reduces manual work and responds faster.
- Breach Alert Workflows are built around the Act’s reporting timelines.
- Ready-to-use documentation for audits, DPO requirements, and regulatory reviews.
Instead of piecing the compliance across different spreadsheets, legal advice, and manual process, DPDP.ai provides the businesses a single system that keeps up with the regulations.
Conclusion
Fundamentally, ‘Data Principal’ and ‘Data Subject’ are the same. It is a person whose personal data is being collected and processed. The difference between both lies in authority and terminology. The EU’s GDPR uses ‘Data Subject,’ while India’s DPDPA uses ‘Data Principal.’
Data Subject’ rules focus on individual protection against data processing activities. Here, the individual is passive, denoting that the person is under the rule or authority of the data controller.
Whereas, Data Principal has the ownership and authority of their personal data. Here, the individual has an active role in the driver’s seat to manage, review, or withdraw consent.
FAQs
Ques: What does “data subject” mean?
Ans: Data Subject is an individual who is a living person whose personal data is collected or processed under GDPR.
Ques: Who is “data principal?”
Ans: Data Principal is the individual to whom personal data is related, under India’s DPDP Act.
Ques: Are data principal and data subject the same?
Ans: Yes, conceptually both the terms mean the person whose data is being processed. But the terminology and jurisdiction differ.
Ques: Does the DPDP Act apply to businesses outside India?
Ans: Yes, the act applies to any entity, in India or abroad, that processes the personal data of Indian residents.
Ques: Are there any penalties if a business doesn’t comply with the DPDP Act?
Ans: Yes, the business can face huge financial penalties, which can go up to ₹250 crore per instance depending on the violation.
Ques: When will the DPDP Act be fully enforceable?
Ans: Full compliance is required by 13 May 2027.
