DPDP Act 2023: Professional Certification
India's Digital Personal Data Protection Act 2023 and DPDP Rules 2025
A structured, citation-backed course covering the full Digital Personal Data Protection Act 2023 and the operational DPDP Rules 2025 notified by MeitY in November 2025. Lessons are written from the statutory text and triple-verified for accuracy.
Who this is for. The programme is built for compliance and privacy professionals, in-house counsel and DPOs, founders, product managers and engineering leads, and auditors, consultants and policy researchers who need a working command of DPDP rather than a marketing overview. If you sit on the accountability side of a Data Fiduciary — or you audit one — this is the reference stack.
What you will learn. You will understand the constitutional and policy origins of the DPDP Act, identify the five roles the Act defines and place your organisation inside them, and operationalise the rights of Data Principals across access, correction, erasure, grievance and nomination. You will implement notice, consent, security, retention and children's data obligations end-to-end, build a Record of Processing Activities, a DPIA, a consent register and a breach response runbook, apply the AI-compliance principles introduced by the 2025 Rules, and navigate the Data Protection Board of India, the penalty matrix and the appeals process.
Legal basis. The course is anchored to the DPDP Act 2023 (No. 22 of 2023) read together with the DPDP Rules 2025 notified via G.S.R. 843(E)-846(E) on 13 November 2025. Every module lesson cites the specific Section, sub-section or Rule it teaches, and references are re-verified against the primary sources before publication. If you also need a rule-by-rule operational deep dive, the dcomply Academy DPDP Rules 2025 Practitioner course is the natural next step.
How the course is graded and the certificate. Learning is self-paced. A final exam checks working knowledge across the full syllabus; the pass mark is applied uniformly and the certificate issued on pass is verifiable via a public URL. Retakes are unlimited so learners can revisit and improve.
What you will learn
- Understand the constitutional and policy origins of the DPDP Act
- Identify the five roles defined by the Act and your organisation's position
- Operationalise the rights of data principals across access, correction, erasure, grievance, and nomination
- Implement notice, consent, security, retention, and children's data obligations
- Build a RoPA, DPIA, consent register, and breach response runbook
- Apply the AI compliance principles introduced by the 2025 Rules
- Navigate the Data Protection Board, penalty matrix, and appeals process
Prerequisites
- No prior legal background required
- Basic familiarity with how organisations collect and use personal data is helpful
Who this is for
- Compliance and privacy professionals
- In-house counsel and DPOs
- Founders, product managers, engineering leads
- Auditors, consultants, and policy researchers
How this fits your compliance stack
The DPDP Act 2023 is the enabling statute, but the operational obligations sit in the DPDP Rules 2025 notified by MeitY in November 2025. Most Data Protection Officers pair this course with the deeper DPDP Rules 2025 / DPO Practitioner Certification for the consent-manager registration, breach reporting mechanics and Significant Data Fiduciary triggers. Teams selling to European customers additionally take the GDPR + DPDP Crosswalk to run one privacy programme across both regimes.
- What we collect: name, email, IP address (for security logging), and course progress.
- Why: to email you the one-click access link, deliver lessons, issue your certificate, and (with your consent) send course updates plus a Day-7 follow-up about dcomply.
- How long: kept until you unsubscribe or request erasure.
- Your rights under the DPDP Act 2023: access, correction, erasure, and grievance redressal. Write to [email protected] to exercise any of them.
- Unsubscribe any time using the link in every email we send you.
Syllabus
8 modules, 38 lessons. Click any module to expand.
Where India's data protection law came from, why it took six years, and how to read it.
- 1. Why this law, why now 8 min
- 2. How to read the law 7 min
- 3. Key definitions you must know 10 min
- 4. When does the Act apply to you? 8 min
Who is who, and why the role you sit in changes everything.
- 1. The Data Principal 7 min
- 2. The Data Fiduciary 9 min
- 3. The Data Processor 7 min
- 4. Significant Data Fiduciary and Consent Manager 9 min
Access, correction, erasure, grievance redressal, nomination, and the duties of a Data Principal.
- 1. Right to access information about personal data (Section 11) 7 min
- 2. Right to correction and erasure (Section 12) 8 min
- 3. Right of grievance redressal (Section 13) 6 min
- 4. Right to nominate (Section 14) 5 min
- 5. Duties of Data Principal (Section 15) 5 min
Notice, consent, security, retention, and the special rules for children's data and SDFs.
- 1. Lawful grounds for processing (Section 4) 6 min
- 2. Notice (Section 5 and Rule 3) 8 min
- 3. Certain legitimate uses (Section 7) 7 min
- 4. General obligations: security, breach, erasure, DPO contact (Section 8) 9 min
- 5. Children's data (Section 9 and Rule 10) 7 min
The practical artefacts every compliance program needs, with templates and worked examples.
- 1. Data mapping 8 min
- 2. Record of Processing Activities (RoPA) 7 min
- 3. Consent architecture 8 min
- 4. Breach response runbook 9 min
- 5. Retention design 7 min
When you become a Significant Data Fiduciary, how to scope and run a DPIA, and how to structure the DPO function.
- 1. Becoming a Significant Data Fiduciary 6 min
- 2. The Data Protection Officer 6 min
- 3. Data Protection Impact Assessment 8 min
- 4. Independent audit and algorithmic diligence 6 min
How the Board works, how investigations unfold, the penalty matrix, and the appeals path.
- 1. The Data Protection Board of India 6 min
- 2. The Schedule penalty matrix 6 min
- 3. Handling a Board inquiry 6 min
- 4. Voluntary undertakings, ADR, and the appeals path 5 min
How DPDPA principles apply to machine learning and generative AI, and how the RBI July 2026 draft Data Governance Guidance operationalises DPDPA for banks, NBFCs and other Regulated Entities.
- 1. The AI lifecycle under DPDPA 8 min
- 2. Data minimisation for AI systems 8 min
- 3. Notice and consent design for AI 7 min
- 4. Fairness, bias, and explainability 8 min
- 5. EU AI Act risk tiers mapped to DPDPA 10 min
- 6. Machine unlearning and the right to erasure 9 min
- 7. RBI Data Governance Framework for BFSI (July 2026 draft) 12 min
Litigation angle on this? Our sister academy covers it.
VakeelSaathi Academy is our sister site for practice training aimed at corporate advocates and litigators. Separate login. Same group. You will sign in there with a fresh account.
Everything a buyer usually asks
Who is this course for?
Is there a free preview?
What do I get when I enrol?
Is there a certificate on completion?
How much does the course cost?
How long do I have to complete the course?
Can I retake the final exam?
How do you keep the course current when the law changes?
Is this course legal advice?
This course is for educational and awareness purposes only. It does not constitute legal advice. The content is based on the Digital Personal Data Protection Act 2023 and DPDP Rules 2025 as published by the Government of India. For specific compliance decisions, organisations and individuals should consult a qualified data protection lawyer.
DPDP Act 2023 (No. 22 of 2023) + DPDP Rules 2025 (G.S.R. 843(E)-846(E), notified 13 November 2025)