Data Protection

Non-Personal Data

Data not relating to identified or identifiable individuals.

Definitions (5)

Data that does not relate to an identified or identifiable natural person (including appropriately anonymised datasets); the Bill sets rules for its use, sharing and re-use, and coordinates those rules with the EU Data Act and national data-governance arrangements.

Datasets that are aggregated or de‑identified such that they do not permit re‑identification of individuals under standard tests; treated differently from personal data for access, licensing and governance purposes. The Committee distinguishes non‑personal data from personal and synthetic data to enable differentiated access controls and reuse conditions.

Datasets that, in their stored or released form, do not permit the identification of any natural person and therefore fall outside personal data protections; the draft treats such data as eligible for discovery and reuse subject to other restrictions. The classification guides whether datasets can be included in the India Datasets programme or shared under metadata/APIs.

Data that cannot be attributed to an identifiable natural person and therefore falls outside the scope of the GDPR (including appropriately anonymised datasets). The Strategy distinguishes non-personal data from personal data and signals the need for legal frameworks and contractual/technical building blocks to govern its secondary use and sharing.

Non-Personal Data (NPD) means data that is not related to an identified or identifiable natural person, including personal data that has been anonymised; the regime is bounded by identifiability and re-identification risk, and the Report proposes harmonised anonymisation standards to classify datasets reliably.