Live Founding Cohort open, limited seats remaining Back to main site →

Why you can trust this course

We don't ask you to take our word for it. Every claim in every lesson is anchored to a Section, Rule, or judgment. This page is the master register of every authority we cite.

Legal basis snapshot: DPDP Act 2023 (No. 22 of 2023) + DPDP Rules 2025 (G.S.R. 843(E)-846(E), notified 13 November 2025)

How this DPDP Act 2023: Professional Certification register is built

This trust page is the citation register for the DPDP Act 2023: Professional Certification course. It cites 33 authorities across 6 statutory instruments, drawn from the legal basis snapshot above (DPDP Act 2023 (No. 22 of 2023) + DPDP Rules 2025 (G.S.R. 843(E)-846(E), notified 13 November 2025)).

Primary sources: DPDP Act 2023 (18 entries), DPDP Rules 2025 (9 entries), EU AI Act (3 entries).

Every claim in every DPDP Act 2023: Professional Certification lesson traces back to a Section, Rule, or judgment listed below. If a lesson references a specific obligation, click the [Lx-Cy] marker in that lesson to jump to the verbatim text in the register.

Our verification promise

  1. Every factual claim has a source. If we say "Section 9 allows a three-month limitation period", you can click the [Lx-Cy] marker next to it and read the verbatim text of Section 9 of the Sexual Harassment of Women at Workplace Act, 2013.
  2. Every source is on this page. Below you will find every Section, Rule and judgment we have relied on, grouped by category, with the verbatim text we hold in our register.
  3. Every source has a public link. Wherever an authoritative public link exists (India Code, the official court website, a reputable law-reports portal), we link to it.
  4. Bug bounty for errors. If you find a factual error in any lesson, write to [email protected] with the lesson, the claim and the corrected source. We will credit your account ₹1,000 for the first report of any verifiable error, ₹5,000 for a substantial error.
8
modules
38
lessons
33
cited authorities
recent
last reviewed

The full citation register

Every authority used in any lesson appears below. Click a row to expand the verbatim text.

Schedule , Penalty ceilings 11 Aug 2023
Plain summary: Item 1: Failure to take reasonable security safeguards under Section 8(5) — up to two hundred and fifty crore rupees. Item 2: Failure to give breach intimation under Section 8(6) — up to two hundred crore rupees. Item 3: Failure of children's data obligations under Section 9 — up to two hundred crore rupees. Item 4: Failure of SDF obligations under Section 10 — up to one hundred and fifty crore rupees. Item 5: Data Principal duty breach under Section 15 — up to ten thousand rupees. Item 7: Residual — any other breach of Act or Rules — up to fifty crore rupees.
Schedule (Section 33): Item 1 (Section 8(5) reasonable security safeguards): may extend to two hundred and fifty crore rupees. Item 2 (Section 8(6) breach intimation to Board and affected Data Principals): may extend to two hundred crore rupees. Item 3 (Section 9 additional obligations for children's personal data): may extend to two hundred crore rupees. Item 4 (Section 10 additional obligations for Significant Data Fiduciary): may extend to one hundred and fifty crore rupees. Item 5 (Section 15 duties of Data Principal): may extend to ten thousand rupees. Item 6 (breach of any term of voluntary undertaking accepted by Board under Section 32): may extend to the extent applicable for the relevant Item. Item 7 (any other breach of the provisions of this Act or rules): may extend to fifty crore rupees.
Section 1 , Short title, extent, commencement 11 Aug 2023
Plain summary: The Act is called the Digital Personal Data Protection Act, 2023. It extends to the whole of India and comes into force on dates the Central Government appoints in the Official Gazette, and different dates may be appointed for different provisions.
1. (1) This Act may be called the Digital Personal Data Protection Act, 2023. (2) It shall come into force on such date as the Central Government may, by notification in the Official Gazette, appoint and different dates may be appointed for different provisions of this Act.
Section 10 , Additional obligations of Significant Data Fiduciary 11 Aug 2023
Plain summary: Central Government may notify any Data Fiduciary or class as Significant Data Fiduciary based on volume and sensitivity of personal data, risk to rights of Data Principals, potential impact on sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order. Every SDF must appoint an India-resident Data Protection Officer responsible to the Board of Directors, an independent Data Auditor, and undertake periodic DPIAs and audits.
10. (1) The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary, on the basis of an assessment of such relevant factors as it may determine, including (a) the volume and sensitivity of personal data processed; (b) risk to the rights of Data Principal; (c) potential impact on the sovereignty and integrity of India; (d) risk to electoral democracy; (e) security of the State; and (f) public order. (2) Every Significant Data Fiduciary shall (a) appoint a Data Protection Officer who shall (i) represent the Significant Data Fiduciary under the provisions of this Act; (ii) be based in India; (iii) be an individual responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary; (iv) be the point of contact for the grievance redressal mechanism under the provisions of this Act; (b) appoint an independent data auditor to carry out data audit; and (c) undertake (i) periodic Data Protection Impact Assessment; (ii) periodic audit; and (iii) such other measures as may be prescribed.
Section 11 , Right of Data Principal to access information 11 Aug 2023
Plain summary: Data Principal has the right to obtain from the Data Fiduciary a summary of personal data being processed and the processing activities undertaken with respect to it, identities of Fiduciaries and Processors with whom data has been shared, and any other prescribed information. Excludes disclosure to other Fiduciaries authorised by law to obtain the data for prevention, detection, investigation, prosecution or punishment of offences or cyber incidents.
11. (1) The Data Principal shall have the right to obtain from the Data Fiduciary to whom she has previously given consent, (a) a summary of personal data which is being processed by such Data Fiduciary and the processing activities undertaken by that Data Fiduciary with respect to such personal data; (b) the identities of all other Data Fiduciaries and Data Processors with whom the personal data has been shared by such Data Fiduciary, along with a description of the personal data so shared; and (c) any other information related to the personal data of such Data Principal and its processing, as may be prescribed.
Section 12 , Right to correction, completion, updating and erasure 11 Aug 2023
Plain summary: Data Principal has the right to correction, completion, updating and erasure of personal data for the processing of which she has previously given consent. Erasure must be honoured unless retention is required by law or for the specified purpose.
12. (1) A Data Principal shall have the right to correction, completion, updating and erasure of her personal data for the processing of which she has previously given consent. (2) A Data Fiduciary shall, upon receiving a request for such correction, completion or updating from a Data Principal, (a) correct the inaccurate or misleading personal data; (b) complete the incomplete personal data; and (c) update the personal data. (3) A Data Principal shall make a request in such manner as may be prescribed to the Data Fiduciary for erasure of her personal data, and upon receipt of such a request, the Data Fiduciary shall erase her personal data unless retention of the same is necessary for the specified purpose or for compliance with any law for the time being in force.
Section 13 , Right of grievance redressal 11 Aug 2023
Plain summary: Data Principal has the right to a readily available means of grievance redressal from the Data Fiduciary or Consent Manager. The Fiduciary or CM must respond to grievance within the prescribed period. The Data Principal must exhaust the internal grievance mechanism before approaching the Board.
13. (1) A Data Principal shall have the right to have readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager in respect of any act or omission regarding the performance of its obligations. (2) The Data Fiduciary or Consent Manager shall respond to any grievances referred to in sub-section (1) within such period as may be prescribed. (3) The Data Principal shall exhaust the opportunity of redressing her grievance under this section before approaching the Board.
Section 14 , Right to nominate 11 Aug 2023
Plain summary: Data Principal has the right to nominate any other individual to exercise her rights in the event of her death or incapacity. Incapacity means inability to exercise rights under the Act due to unsoundness of mind or infirmity of body.
14. (1) A Data Principal shall have the right to nominate, in such manner as may be prescribed, any other individual, who shall, in the event of death or incapacity of the Data Principal, exercise the rights of the Data Principal in accordance with the provisions of this Act. (2) For the purposes of this section, the expression "incapacity" means inability to exercise the rights of the Data Principal under the provisions of this Act due to unsoundness of mind or infirmity of body.
Section 15 , Duties of Data Principal 11 Aug 2023
Plain summary: Data Principal must comply with applicable law while exercising rights; must not impersonate another person while providing personal data; must not suppress material information; must not register a false or frivolous grievance or complaint with a Data Fiduciary or the Board; and must furnish only authentic information when exercising the right to correction or erasure. Breach attracts penalty up to ten thousand rupees under the Schedule.
15. A Data Principal shall (a) comply with the provisions of all applicable laws while exercising rights under the provisions of this Act; (b) ensure not to impersonate another person while providing her personal data; (c) ensure not to suppress any material information; (d) ensure not to register a false or frivolous grievance or complaint with a Data Fiduciary or the Board; and (e) furnish only such information as is verifiably authentic while exercising the right to correction or erasure.
Section 16 , Processing of personal data outside India 11 Aug 2023
Plain summary: The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary to countries or territories outside India. Nothing in this section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection or restriction on transfer.
16. (1) The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified. (2) Nothing contained in sub-section (1) shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data by a Data Fiduciary outside India in relation to any personal data or Data Fiduciary or class thereof.
Section 2 , Definitions 11 Aug 2023
Plain summary: Defines key terms including Data Principal, Data Fiduciary, Data Processor, personal data, personal data breach, processing, Significant Data Fiduciary, Consent Manager, child, and Board.
2. In this Act, unless the context otherwise requires (selected clauses): (f) "child" means an individual who has not completed the age of eighteen years; (i) "Data Fiduciary" means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data; (j) "Data Principal" means the individual to whom the personal data relates, and where such individual is (i) a child, includes the parents or lawful guardian; (ii) a person with disability, includes her lawful guardian; (k) "Data Processor" means any person who processes personal data on behalf of a Data Fiduciary; (t) "personal data" means any data about an individual who is identifiable by or in relation to such data; (u) "personal data breach" means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data; (x) "processing" means a wholly or partly automated operation or set of operations performed on digital personal data; (z) "Significant Data Fiduciary" means any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10.
Section 3 , Application of the Act 11 Aug 2023
Plain summary: The Act applies to processing of digital personal data within India collected in digital form or digitised subsequently; and to processing outside India if in connection with offering goods or services to Data Principals in India. It does not apply to personal or domestic use, or to data made publicly available by the Data Principal or under law.
3. Subject to the provisions of this Act, it shall (a) apply to the processing of digital personal data within the territory of India where the personal data is collected (i) in digital form; or (ii) in non-digital form and digitised subsequently; (b) also apply to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India; (c) not apply to (i) personal data processed by an individual for any personal or domestic purpose; and (ii) personal data that is made or caused to be made publicly available by (A) the Data Principal to whom such personal data relates; or (B) any other person under an obligation under any law for the time being in force in India to make such personal data publicly available.
Section 33 , Penalties for breach 11 Aug 2023
Plain summary: The Board may impose penalty as specified in the Schedule. Factors to consider include nature/gravity/duration of breach, type of data affected, repetitive nature, gain avoided or loss suffered, mitigation, proportionality and impact. Penalty is credited to the Consolidated Fund of India.
33. (1) If the Board determines on conclusion of an inquiry that non-compliance by a person is significant, it may, after giving the person a reasonable opportunity of being heard, impose such monetary penalty specified in the Schedule. (2) While determining the amount of monetary penalty, the Board shall have regard to (a) nature, gravity and duration of the non-compliance; (b) type and nature of personal data affected; (c) repetitive nature of the non-compliance; (d) whether the person, as a result of the non-compliance, has realised a gain or avoided any loss; (e) whether the person took any action to mitigate the effects and consequences and the timeliness and effectiveness of the action; (f) whether the monetary penalty is proportionate and effective; and (g) likely impact of the imposition on the person. (3) The amount so realised shall be credited to the Consolidated Fund of India.
Section 4 , Grounds for processing personal data 11 Aug 2023
Plain summary: Personal data may be processed only for a lawful purpose, either with the consent of the Data Principal, or for certain legitimate uses listed in Section 7.
4. (1) A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose, (a) for which the Data Principal has given her consent; or (b) for certain legitimate uses. (2) For the purposes of this section, the expression "lawful purpose" means any purpose which is not expressly forbidden by law.
Section 5 , Notice to Data Principal 11 Aug 2023
Plain summary: Every consent request must be accompanied or preceded by a notice describing the personal data, purpose of processing, how to exercise rights, and how to complain to the Board. Notice must be available in English or any language listed in the Eighth Schedule.
5. (1) Every request made to a Data Principal under section 6 for consent shall be accompanied or preceded by a notice given by the Data Fiduciary to the Data Principal, informing her (i) the personal data and the purpose for which the same is proposed to be processed; (ii) the manner in which she may exercise her rights under sub-section (4) of section 6 and section 13; and (iii) the manner in which the Data Principal may make a complaint to the Board. (3) The Data Fiduciary shall give the Data Principal the option to access the contents of the notice in English or any language specified in the Eighth Schedule to the Constitution of India.
Section 6 , Consent 11 Aug 2023
Plain summary: Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to personal data necessary for the specified purpose. Withdrawal must be as easy as giving consent. Consent may be given, managed, reviewed or withdrawn through a Consent Manager registered with the Board.
6. (1) The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose. (4) Where consent given by the Data Principal is the basis of processing of personal data, such Data Principal shall have the right to withdraw her consent at any time, with the ease of doing so being comparable to the ease with which such consent was given. (7) The Data Principal may give, manage, review or withdraw her consent to the Data Fiduciary through a Consent Manager. (8) The Consent Manager shall be accountable to the Data Principal and shall act on her behalf. (9) Every Consent Manager shall be registered with the Board. (10) In a dispute, the burden of proving valid notice and consent lies on the Data Fiduciary.
Section 7 , Certain legitimate uses 11 Aug 2023
Plain summary: Nine specific limbs allowing processing without explicit consent: voluntarily provided data used for the specified purpose; State subsidies/benefits/services/licences; State functions under law or in the interests of sovereignty/security; disclosures required by law; compliance with judgments; medical emergency; epidemic or public health measures; disaster response; and employment purposes including safeguarding employer from loss or liability.
7. A Data Fiduciary may process personal data of a Data Principal for any of the following uses, namely: (a) for the specified purpose for which the Data Principal has voluntarily provided her personal data; (b) for the State and its instrumentalities to provide or issue any subsidy, benefit, service, certificate, licence or permit; (c) for State functions under law or in the interest of sovereignty and integrity of India or security of the State; (d) for legal disclosure obligations; (e) for compliance with any judgment or order under law; (f) for a medical emergency involving threat to life or immediate threat to health; (g) for measures during an epidemic, outbreak of disease, or other threat to public health; (h) for measures during any disaster or breakdown of public order; (i) for the purposes of employment or those related to safeguarding the employer from loss or liability.
Section 8 , General obligations of Data Fiduciary 11 Aug 2023
Plain summary: The Data Fiduciary is responsible for compliance regardless of any agreement to the contrary or Data Principal duty failure. Must engage Processors only under a valid contract. Must ensure data quality where the data will affect the Data Principal. Must implement reasonable security safeguards. Must intimate personal data breaches to the Board and affected Data Principals. Must erase personal data when consent is withdrawn or the specified purpose is no longer served, unless retention is required by law. Must publish contact details of the Data Protection Officer or a designated person to answer queries.
8. (1) A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties, be responsible for complying with the provisions of this Act and the rules made thereunder. (2) A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf only under a valid contract. (5) A Data Fiduciary shall protect personal data in its possession or under its control by taking reasonable security safeguards to prevent personal data breach. (6) In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed. (7) A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force, erase personal data upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier. (9) A Data Fiduciary shall publish the business contact information of a Data Protection Officer or of such other person who is able to answer questions from the Data Principal.
Section 9 , Processing of personal data of children 11 Aug 2023
Plain summary: Before processing personal data of a child or a person with disability who has a lawful guardian, the Data Fiduciary must obtain verifiable consent of the parent or lawful guardian. Fiduciary shall not undertake processing likely to cause detrimental effect on well-being, tracking or behavioural monitoring, or targeted advertising directed at children. Central Government may notify exemptions for classes of Fiduciaries or purposes.
9. (1) The Data Fiduciary shall, before processing any personal data of a child or a person with disability who has a lawful guardian, obtain verifiable consent of the parent of such child or the lawful guardian. (2) A Data Fiduciary shall not undertake such processing of personal data that is likely to cause any detrimental effect on the well-being of a child. (3) A Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.

Rule 1 , Short title, commencement 13 Nov 2025
Plain summary: The Rules are called the Digital Personal Data Protection Rules, 2025. Commencement is phased: Rules 1, 2 and 17-21 come into force on publication (13 Nov 2025); Rule 4 (Consent Manager registration) on 13 November 2026; Rules 3, 5-16, 22-23 on 13 May 2027.
1. (1) These rules may be called the Digital Personal Data Protection Rules, 2025. (2) They shall come into force as follows: (a) rules 1, 2 and 17 to 21 on the date of their publication in the Official Gazette; (b) rule 4 on the expiry of one year from the date of publication; (c) rules 3, 5 to 16, 22 and 23 on the expiry of eighteen months from the date of publication.
Rule 10 , Verifiable consent for children 13 Nov 2025
Plain summary: Before processing personal data of a child, the Data Fiduciary must adopt appropriate technical and organisational measures to ensure verifiable consent of the parent is obtained. Verification may be by reference to reliable identity and age details already available with the Fiduciary, or voluntarily provided identity and age details or a virtual token mapped to such details issued by an entity entrusted by law or by a Digital Locker Service Provider.
10. (1) A Data Fiduciary shall, before processing personal data of a child, adopt appropriate technical and organisational measures to ensure that verifiable consent of the parent is obtained. (2) The verifiable consent shall be that the person identifying herself as the parent is an adult, either (a) by reference to reliable details of identity and age already available with the Data Fiduciary, or (b) by reference to identity and age details voluntarily provided by the parent, or by a virtual token mapped to such details, which is issued by an entity entrusted by law with maintaining such details, including a Digital Locker Service Provider.
Rule 12 , Exemptions from Section 9(1) and (3) for Fourth Schedule classes 13 Nov 2025
Plain summary: The provisions of sub-sections (1) and (3) of Section 9 do not apply to the classes of Data Fiduciary and purposes specified in the Fourth Schedule. Includes clinical and mental health establishments, allied healthcare professionals, educational institutions and creches/day-care centres. Restricted to specified purposes: child safety, welfare, transportation tracking, subsidies/benefits, obligation under law, and similar.
12. The provisions of sub-sections (1) and (3) of section 9 shall not apply to the classes of Data Fiduciaries specified in the Fourth Schedule and to the extent of the purposes specified therein.
Rule 13 , Additional obligations of Significant Data Fiduciary 13 Nov 2025
Plain summary: A Significant Data Fiduciary must (a) undertake a Data Protection Impact Assessment and independent audit at least once every 12 months from the date of notification as SDF, and shall submit the results of the DPIA and audit and observations to the Board; (b) exercise due diligence to verify that algorithmic software deployed for hosting, display, uploading, modification, publishing, transmission, storage or sharing of personal data is not likely to pose a risk to the rights of the Data Principal; (c) undertake such measures as the Central Government may specify, including in relation to certain classes of personal data or traffic data that shall not be transferred outside India.
13. (1) A Significant Data Fiduciary shall (a) undertake, at least once in a period of twelve months from the date of its notification as such, (i) a Data Protection Impact Assessment; and (ii) an audit; and (b) publish and submit to the Board a report containing significant observations arising from such Data Protection Impact Assessment and audit. (2) A Significant Data Fiduciary shall exercise due diligence to verify that algorithmic software deployed by it for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data managed or processed by it is not likely to pose a risk to the rights of Data Principals. (3) A Significant Data Fiduciary shall undertake such measures as the Central Government may specify from time to time to ensure that personal data and traffic data pertaining to its flow, as may be specified, is not transferred outside India.
Rule 3 , Notice by Data Fiduciary to Data Principal 13 Nov 2025
Plain summary: Notice under Section 5 must be presented independently of any other information or document. It must contain an itemised description of the personal data and an itemised description of the specified purpose including the goods or services enabled. Notice must set out how the Data Principal can withdraw consent, exercise rights and make a complaint to the Board. Notice must be available in English or any of the 22 Eighth Schedule languages on the Data Principal's option.
3. The notice given by a Data Fiduciary to a Data Principal under section 5 shall (a) be presented and be understandable independently of any other information that may be made available by such Data Fiduciary; (b) give in clear and plain language a fair account of the following details necessary to enable the Data Principal to give specific and informed consent for the processing of her personal data, namely: (i) an itemised description of such personal data; and (ii) the specified purpose of and an itemised description of the goods or services to be provided or uses to be enabled by such processing; (c) provide the communication link for accessing the website or app or both of the Data Fiduciary; and (d) the manner in which the Data Principal may withdraw her consent, exercise her rights and make a complaint to the Board.
Rule 4 , Registration and obligations of Consent Manager 13 Nov 2025
Plain summary: A person may apply to the Board for registration as a Consent Manager if it fulfils the conditions in Part A of the First Schedule (Indian company, net worth at least two crore rupees, technical/operational/financial capability, no conflict of interest, etc.). A registered Consent Manager shall comply with the obligations in Part B (data-blind pipe, ≥7-year consent-log retention, interoperability, audit, security). Rule 4 commences 13 November 2026.
4. (1) A person seeking to be registered as a Consent Manager shall make an application to the Board fulfilling the conditions specified in Part A of the First Schedule. (2) A Consent Manager shall comply with the obligations specified in Part B of the First Schedule. (3) The Board may register a Consent Manager fulfilling the conditions and may cancel or suspend registration for non-compliance.
Rule 6 , Reasonable security safeguards 13 Nov 2025
Plain summary: Data Fiduciary must protect personal data by taking reasonable security safeguards including: appropriate data security measures (encryption, obfuscation, masking, virtual tokens); appropriate access controls; visibility on access via logs and monitoring; measures to detect unauthorised access and take mitigation action; retention of logs and personal data for a period of one year unless a longer period is required by law, for the purpose of enabling investigation; contractual arrangements with Data Processors for equivalent measures; and appropriate technical and organisational measures to ensure effective observance of the safeguards.
6. (1) A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach, which shall include, at the minimum: (a) appropriate data security measures, including securing personal data through its encryption, obfuscation or masking or the use of virtual tokens mapped to personal data; (b) appropriate measures to control access to the computer resources used by the Data Fiduciary or the Data Processor; (c) visibility on access to such personal data, through appropriate logs, monitoring and review; (d) reasonable measures for detection of unauthorised access and its mitigation, including through appropriate measures for continued processing in the event of confidentiality, integrity or availability of personal data being compromised; (e) reasonable measures for continued processing in the event of a personal data breach and enabling the investigation, including through appropriate retention of logs and personal data for a period of one year unless a longer period is required by law; (f) appropriate provisions in the contract entered into between the Data Fiduciary and Data Processor for taking such reasonable security safeguards; and (g) appropriate technical and organisational measures to ensure that the reasonable security safeguards are effectively implemented.
Rule 7 , DPDP breach notification (parallel to CSCRF for personal data) 13 Nov 2025
Plain summary: DPDP Rules 2025 Rule 7: on becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay and intimate the Data Protection Board without delay. Detailed report to the Board within 72 hours of awareness (extendable on written request). For a SEBI RE handling personal data, this runs in parallel with the CSCRF 6-hour clock.
DPDP Rules 2025 Rule 7. On becoming aware of any personal data breach, the Data Fiduciary shall intimate each affected Data Principal in a concise, clear and plain manner and without delay; and shall intimate the Data Protection Board without delay of the initial description, followed by an updated and detailed report within seventy-two hours of becoming aware (extendable on written request to the Board).
Rule 8 , Time period for erasure 13 Nov 2025
Plain summary: For the classes of Data Fiduciary and purposes specified in the Third Schedule, personal data of a Data Principal who has not approached the Fiduciary for the specified purpose nor exercised her rights for the specified period, is deemed no longer needed for the specified purpose and shall be erased. The Fiduciary must inform the Data Principal at least 48 hours before erasure that the personal data will be erased. The Seventh Schedule permits state functions to retain personal data, traffic data and logs for at least one year for sovereignty, security, public order and related purposes.
8. (1) The Data Fiduciaries and purposes as specified in the Third Schedule shall be deemed to no longer be serving the specified purpose if the Data Principal has, for the time period specified therein, neither approached the Data Fiduciary for the performance of the specified purpose, nor exercised any of her rights in relation to such processing, and the Data Fiduciary shall erase such personal data unless retention is required for compliance with any law for the time being in force. (2) The Data Fiduciary shall, at least forty-eight hours before the time period specified in the Third Schedule expires, inform the Data Principal that unless she takes an action indicating continued use of the specified purpose or exercise of rights, her personal data will be erased. (3) Retention of personal data, traffic data and logs by the Government or its instrumentalities may be for a period as prescribed under the Seventh Schedule for purposes related to sovereignty and integrity of India, security of the State, public order or similar functions.

Article 5 , Prohibited AI practices 13 Jun 2024
Plain summary: Article 5 of Regulation (EU) 2024/1689 (the AI Act) lists AI practices that are prohibited outright in the Union, including social scoring by public authorities, real-time remote biometric identification in publicly accessible spaces for law enforcement (with narrow exceptions), predictive policing based solely on profiling, and untargeted scraping of facial images from the internet or CCTV to build facial-recognition databases. Prohibited practices carry the highest tier of penalties under Article 99 (up to EUR 35 million or 7 percent of worldwide annual turnover). The Article 5 prohibitions apply from 2 February 2025.
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), Article 5. Summary of prohibited practices (consult the Regulation for verbatim text): (a) AI systems that deploy subliminal techniques beyond a person's consciousness or purposefully manipulative or deceptive techniques, with the objective or effect of materially distorting the behaviour of a person or a group of persons in a manner that causes or is reasonably likely to cause significant harm. (b) AI systems that exploit vulnerabilities of a natural person or a specific group of persons due to age, disability or a specific social or economic situation, with the objective or the effect of materially distorting behaviour and causing or reasonably likely to cause significant harm. (c) AI systems for the evaluation or classification of natural persons or groups over a certain period based on their social behaviour or known, inferred or predicted personal or personality characteristics, where the social score leads to detrimental or unfavourable treatment (social scoring by public and private actors, with limited exceptions). (d) AI systems for making risk assessments of natural persons in order to assess or predict the risk of a natural person committing a criminal offence, based solely on the profiling of a natural person or on assessing their personality traits and characteristics (predictive policing based solely on profiling). (e) AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage. (f) AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use is for medical or safety reasons. (g) Biometric categorisation systems that categorise individual natural persons based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation (with certain law-enforcement exceptions). (h) The use of real-time remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement (with narrow, court-authorised exceptions). The Article 5 prohibitions apply from 2 February 2025, six months after the Regulation entered into force on 1 August 2024. Non-compliance is subject to the highest tier of administrative fines under Article 99: up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 percent of its total worldwide annual turnover for the preceding financial year, whichever is higher.
Article 50 , Transparency obligations for certain AI systems 13 Jun 2024
Plain summary: Article 50 of Regulation (EU) 2024/1689 imposes cross-cutting transparency obligations. Providers of AI systems intended to interact directly with natural persons (chatbots) must ensure that persons are informed that they are interacting with an AI. Providers of generative AI systems (including general-purpose AI) that generate synthetic audio, image, video or text content must mark the outputs in a machine-readable format detectable as artificially generated or manipulated. Deployers of emotion recognition, biometric categorisation, and deep fake systems have separate disclosure duties. Article 50 applies from 2 August 2026.
Regulation (EU) 2024/1689, Article 50. Summary of transparency duties (consult the Regulation for verbatim text): (1) Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, or unless the use is authorised by law to detect, prevent, investigate or prosecute criminal offences. (2) Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content shall ensure that the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Solutions shall be effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of different types of content, the costs of implementation, and the generally acknowledged state of the art. (3) Deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system and shall process the personal data in compliance with the applicable Union data protection law. (4) Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake shall disclose that the content has been artificially generated or manipulated (with narrow artistic, satirical, and law-enforcement exceptions). Where the content is part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosing the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work. (5) The information referred to in paragraphs (1) to (4) shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. Article 50 applies from 2 August 2026.
Article 6 , Classification of high-risk AI systems 13 Jun 2024
Plain summary: Article 6, read with Annex I and Annex III of Regulation (EU) 2024/1689, classifies certain AI systems as high-risk. Annex III lists eight domains where AI systems are treated as high-risk by default: biometrics, critical infrastructure, education and vocational training, employment (workers management and access to self-employment), access to essential private and public services and benefits, law enforcement, migration/asylum/border control, and administration of justice and democratic processes. High-risk systems carry substantial obligations under Chapter III, including risk management systems, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy/robustness/cybersecurity, and conformity assessment before market placement.
Regulation (EU) 2024/1689, Article 6 read with Annexes I and III. Summary of the classification rule (consult the Regulation and Annexes for verbatim text): An AI system is high-risk if either: (a) it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I, and is required to undergo third-party conformity assessment under that legislation (for example, machinery, toys, radio equipment, medical devices, in vitro diagnostic medical devices, civil aviation security, marine equipment, and other listed sectoral legislation); or (b) it is an AI system referred to in Annex III (the standalone high-risk list). Annex III lists the following categories as high-risk: 1. Biometrics (remote biometric identification, biometric categorisation according to sensitive attributes, and emotion recognition systems, except those prohibited under Article 5). 2. Critical infrastructure (AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity). 3. Education and vocational training (AI systems for determining access, admission, evaluation of learning outcomes, assessing appropriate level of education, and monitoring/detecting prohibited behaviour during tests). 4. Employment, workers management and access to self-employment (AI systems for recruitment or selection, decisions affecting terms of relationships, promotion and termination, task allocation based on behaviour or characteristics, and monitoring and evaluating performance and behaviour). 5. Access to essential private services and essential public services and benefits (AI systems used by public authorities to evaluate eligibility for benefits and services, credit scoring for natural persons (with limited exceptions), risk assessment and pricing for life and health insurance, and emergency call classification and dispatching). 6. Law enforcement (with a range of specific systems including risk assessments, polygraphs, evidence evaluation, profiling of persons, crime analytics). 7. Migration, asylum and border control management (risk assessments, examination of applications, and detection/recognition/identification systems in these contexts). 8. Administration of justice and democratic processes (AI systems to assist judicial authorities in research and interpretation of facts and law, and AI systems influencing the outcome of elections or referenda, or the voting behaviour of natural persons). High-risk systems carry the Chapter III obligations, including: risk management (Article 9); data and data governance (Article 10); technical documentation (Article 11); record-keeping (Article 12); transparency and provision of information to deployers (Article 13); human oversight (Article 14); accuracy, robustness and cybersecurity (Article 15); and conformity assessment before market placement (Article 43). The high-risk regime applies from 2 August 2026, twenty-four months after entry into force.

ISO/IEC 42001:2023 , AI management system standard 18 Dec 2023
Plain summary: ISO/IEC 42001:2023 is the first international standard for AI management systems, published by the International Organization for Standardization and the International Electrotechnical Commission in December 2023. It specifies requirements and provides guidance for establishing, implementing, maintaining and continually improving an AI management system within an organisation. It is certifiable (like ISO/IEC 27001 for information security) and offers a defensible governance backbone for organisations subject to DPDPA Rule 12(2) algorithmic diligence and cross-jurisdictional AI regulation.
ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system. Published December 2023 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Summary (consult the standard for full text): ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining and continually improving an AI management system (AIMS) within the context of the organisation. It is designed to help organisations responsibly develop and use AI systems. Structure follows the ISO harmonised management-system structure, with clauses on: (4) Context of the organisation, including AI-specific considerations of the internal and external environment. (5) Leadership, including AI policy and roles. (6) Planning, including AI risk assessment and AI risk treatment, and objectives. (7) Support, including resources, competence, awareness, communication and documented information. (8) Operation, covering operational planning and control, AI system impact assessment, and management of AI system life cycle. (9) Performance evaluation, including monitoring, measurement, analysis and evaluation, internal audit, and management review. (10) Improvement, including nonconformity, corrective action and continual improvement. Annex A lists reference controls for AI system life cycle stages, AI use, third-party relationships, and AI system data. ISO/IEC 42001 is certifiable. An organisation can be audited to the standard by a certification body and receive a certificate similar to ISO 27001 certification for information security. Certification does not by itself satisfy any statutory AI obligation but provides a defensible, internationally recognised governance framework that overlaps significantly with the diligence expected under DPDPA Rule 12(2) for Significant Data Fiduciaries deploying algorithmic systems.

AI RMF 1.0 , NIST AI Risk Management Framework 1.0 26 Jan 2023
Plain summary: The AI Risk Management Framework 1.0 was published by the United States National Institute of Standards and Technology in January 2023. It is a voluntary framework organised around four functions (Govern, Map, Measure, Manage) that operationalise trustworthy AI. AI RMF 1.0 is widely referenced as a general-purpose risk framework for AI systems and is compatible with sectoral and regional regulations, including the EU AI Act and, by translation, obligations under DPDPA Rule 12(2).
NIST AI Risk Management Framework (AI RMF 1.0), NIST AI 100-1, published January 2023 by the U.S. National Institute of Standards and Technology. Summary (consult the Framework for full text): The AI RMF is a voluntary framework that helps organisations and individuals design, develop, deploy and use AI systems in ways that are trustworthy. It is organised around four functions: (1) Govern. Culture, policies, processes and structures for AI risk management across the organisation. Includes accountability, roles, and integration with existing risk-management practices. (2) Map. Establishing the context in which the AI system operates: purpose, capabilities, benefits, risks, and the categories of persons potentially affected. Requires identifying interested parties and the specific tasks the system will perform. (3) Measure. Assessing, analysing and tracking AI risks and impacts using quantitative, qualitative or mixed-method tools. Covers dimensions such as accuracy, reliability, robustness, safety, security, resilience, accountability, transparency, explainability, interpretability, privacy, and fairness (managing harmful bias). (4) Manage. Prioritising and acting on risks. Allocating resources to risks based on impact and likelihood, applying mitigations, planning responses, and communicating with interested parties. The Framework is technology-neutral and sector-agnostic. It was developed through open consultation and is widely cited as a common vocabulary for AI risk in the enterprise. A Generative AI Profile (NIST AI 600-1) was released in July 2024, extending the framework to generative and dual-use foundation models. AI RMF is not law. It is a reference practice document. Adopting the Framework does not by itself satisfy any statutory obligation, but it provides a defensible baseline that regulators, auditors, and courts recognise.

Draft Guidance on Data Governance (July 2026) , RBI Draft Guidance on Regulatory Expectations for Data Governance 14 Jul 2026
Plain summary: The Reserve Bank of India released a Draft Guidance on Regulatory Expectations for Data Governance in July 2026 for stakeholder comments until 17 August 2026 through the RBI Connect 2 Regulate portal. It applies to Regulated Entities including commercial banks, small finance banks, payments banks, regional rural banks, cooperative banks, all-layer NBFCs, all-India financial institutions, asset reconstruction companies and credit information companies. The Guidance requires each Regulated Entity to establish a board-approved Data Governance Framework aligned with its enterprise risk management framework and with the Digital Personal Data Protection Act 2023 and DPDP Rules 2025. It mandates a Board-level Data Governance Committee, an Executive Data Governance Committee, a Data Function headed by an officer not below the rank of Chief General Manager or equivalent, and clearly defined roles of Data Owner, Data Steward and Data Custodian across the data lifecycle. Architectural asks include a Single Source of Truth (SSOT) for each data element, metadata management with tagging at the point of origination, end-to-end data lineage, data classification, data quality management, and strengthened controls over third-party data sharing including CERT-In empanelled audits and cascading accountability.
Reserve Bank of India, Draft Guidance on Regulatory Expectations for Data Governance, released July 2026 on the RBI Connect 2 Regulate portal for stakeholder comments until 17 August 2026. Summary of key provisions (consult the draft for verbatim text): Applicability. Commercial banks (including small finance banks, payments banks, regional rural banks), primary (urban) cooperative banks, state and district central cooperative banks, all-layer non-banking financial companies, all-India financial institutions, asset reconstruction companies, and credit information companies. Data Governance Framework. Every Regulated Entity shall put in place a comprehensive, board-approved Data Governance Framework aligned with its enterprise risk management framework and shall ensure compliance with the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. The Framework covers scope, data architecture, data risk management, ownership and RACI across the data lifecycle, data quality management, data classification, and third-party arrangements. Governance structure. A Board-level Data Governance Committee (either standalone or a delegated existing board committee) is responsible for approving the Framework and receiving periodic data quality and risk reports. An Executive Data Governance Committee implements the policy operationally and coordinates escalation and consent dispute resolution. Data Function. A dedicated Data Function is required, headed by an officer not below the rank of Chief General Manager or equivalent, coordinating across business, risk and technology. Organisational roles. Data Owner (defines and classifies data within a domain, designates the Single Source of Truth, approves sharing and usage rules, owns data quality outcomes, approves exceptions). Data Steward (day-to-day implementation, maintains data definitions and documentation, monitors flows, reports material issues). Data Custodian (technical enforcement of access controls, encryption, metadata and lineage systems, retention and disposal). Single Source of Truth. One authoritative source for each data element, with reconciliation controls. No parallel or competing SSOTs. Metadata and lineage. Foundational attributes (ownership, classification, usage intent, consent status) are stamped at the point of data origination and travel through downstream transformations. Reclassification is required when aggregation or enrichment changes the sensitivity or category of the data (for example, inferred health data derived from payment data). Data quality management. The Framework must address accuracy, consistency, confidentiality, integrity and traceability, with metrics reported to the Board Data Governance Committee. Third-party data sharing. Accountability remains with the Regulated Entity. Third-party access is on a need-to-know basis, subject to non-disclosure obligations, encryption, authentication, auto-deletion and de-duplication where applicable, CERT-In empanelled third-party audits, and full traceability back to the SSOT. The Regulated Entity retains cascading accountability across sub-processors. DPDP alignment. The Guidance is explicitly framed to operationalise the DPDP Act 2023 and the DPDP Rules 2025 for the financial sector, supporting obligations related to Significant Data Fiduciary designation under Section 10, Data Protection Impact Assessment under Rule 12, consent status tracking under Sections 5 and 6, personal data breach notification, and processor obligations under Sections 8(5) and 8(6). Status. Draft for comment. Comments are invited on the RBI Connect 2 Regulate portal until 17 August 2026. The final Guidance is expected to be notified as a Master Direction or a Notification. Regulated Entities are advised not to wait for the final Guidance but to undertake a comprehensive gap assessment covering governance structures, DPDPA compliance, data architecture, third-party arrangements, AI governance and operational resilience.

Found an error? We pay for it.

If you find a factual error in any lesson, write to [email protected] with the lesson title, the specific claim, and the corrected source.

  • ₹1,000 credit for the first report of any verifiable factual error.
  • ₹5,000 credit for a substantial error (e.g. a wrong section number, an obsolete ruling, a misrepresented holding).
  • Credit on your dcomply Academy account usable against any future course.

We pay because we'd rather know than not know. If the law changes (and it will), we want to be the first to fix our lessons.

On this page
  • 🟢 Our verification promise
  • 📊 Course statistics
  • 📚 Full citation register
  • 🐛 Bug bounty for errors

Maintained by the dcomply Academy editorial team. Last reviewed recently.