Live 17 practitioner certifications live · First lesson free on every course Back to main site →
Data Protection

DPDP Implementation Practitioner — 90 Days to Audit-Ready

The exact 90-day playbook used to take an Indian company from zero to DPDP audit-ready

₹14,999 incl. 18% GST Intermediate 13.8 hours 12 modules
12
Modules
63
Lessons
45
Exam questions
75%
Pass mark

A hands-on, artifact-first practitioner course that teaches you how to actually run a DPDP compliance programme in a live Indian company. Where our two existing DPDP courses teach the law and the rules, this course teaches the operational 90-day engagement: scoping, data discovery, RoPA, retention, notice and consent wire-up, DSAR workflow, vendor and cross-border register, Rule 7 breach and CERT-In parallel, DPIA for high-risk and SDF programmes, DPO operations and board reporting, and the leadership craft of making engineering, marketing and vendors cooperate. Every module produces a deliverable (template, SOP, SQL query, email script, filled example). The capstone runs the full programme end-to-end on a fictional Indian company. Written for in-house implementers, CAs and CSs adding a DPDP service line, DPOs and consultants. Updated through 5 October 2026.

What you will learn
  • Scope and sell a 90-day DPDP engagement to an Indian SME or mid-market company
  • Run a data-discovery sprint that finds personal data engineering forgot existed
  • Build a Records of Processing (RoPA) that survives an auditor and a Section 8 inquiry
  • Design a retention schedule that layers DPDP, RBI, SEBI, IRDAI and Seventh Schedule exceptions
  • Draft a Rule 3 standalone notice and wire a Section 6 consent flow Consent Manager-ready
  • Operate a DSAR workflow inside the 90-day hard cap without over-collecting identity data
  • Run a vendor risk register with Section 8(2) DPAs and Rule 15 cross-border decisions
  • Fire a Rule 7 Stage 1 and Stage 2 breach report while the CERT-In 6-hour clock runs in parallel
  • Run a DPIA for a high-risk processing activity and the Rule 13 SDF programme
  • Operate the DPO function on a 12-month calendar with board-ready metrics
  • Get engineering, marketing and vendors to actually say yes to compliance asks
  • Deliver a complete, audit-ready programme file for a client at the end of 90 days
Prerequisites
  • Familiarity with how a company collects, stores and processes digital information. If you have ever been in a company data-flow conversation, you are fine.
  • The DPDP Act 2023 free course or the DPDP Rules 2025 Deep Dive course on dcomply Academy is a helpful primer but not required. This course assumes legal literacy and teaches operational craft.
  • No programming background required. Where SQL and code snippets appear, they are explained line by line.
Who this is for
  • In-house compliance, HR, IT and legal managers at Indian SMEs and mid-market firms told to "handle DPDP" with no consulting budget
  • Chartered Accountants, Company Secretaries and advocates adding DPDP implementation as a service line
  • DPOs at mid-market Indian firms who have passed the DPDP Rules exam and now need to actually run the programme
  • Consultants and freelancers serving Indian SMEs on DPDP, cyber, or governance
  • dcomply Privacy Suite subscribers who want to self-serve more of their implementation
  • CISOs and heads of information security who own breach readiness and vendor risk
  • Founders and operators of Indian SaaS, fintech, healthtech and D2C companies
About the author
AJ
Course Author. Advocate; author of "DPDP Compliance for Indian Businesses".

Advocate Joginder Poswal is the founder of Poswal Law Office and the author of "DPDP Compliance for Indian Businesses: A Practical Guide for SMEs, Startups, and Founders". His eighteen years running IT operations before practising law give this course the perspective most compliance training lacks. It is not a reading list of Sections and Rules. It is the actual 90-day engagement playbook used on real Indian clients, with the templates, the SQL queries, the vendor emails, the breach runbooks and the board-deck language that get the work done. This course assumes you know what DPDP requires. It teaches you how to get it done. It is practitioner training, not legal advice.

inclusive of 18% GST
No account to create. We email you a one-click link.
How we use your personal data DPDP notice
  • What we collect: name, email, IP address (for security logging), and course progress.
  • Why: to email you the one-click access link, deliver lessons, issue your certificate, and (with your consent) send course updates plus a Day-7 follow-up about dcomply.
  • How long: kept until you unsubscribe or request erasure.
  • Your rights under the DPDP Act 2023: access, correction, erasure, and grievance redressal. Write to [email protected] to exercise any of them.
  • Unsubscribe any time using the link in every email we send you.
Certificate on completion. Pass mark 75%.
Curriculum

Syllabus

12 modules, 63 lessons. Click any module to expand.

A working picture of the entire 90-day programme in one module. Who the stakeholders are, how to scope the engagement so it finishes on time, how to secure the budget and the political cover, and how the three deliverables of this module (scope doc, stakeholder RACI, 90-day Gantt) become the spine every later module hangs off. This module is free preview so buyers can validate the depth and the voice before purchasing.

  1. 1. The shape of a DPDP engagement, before anyone opens a Section 11 min
  2. 2. The one-page scope document a founder will sign in a single meeting 11 min
  3. 3. The stakeholder RACI that actually works (and the trap in a six-column RACI) 10 min
  4. 4. The 90-day Gantt with four checkpoint reviews baked in 11 min
  5. 5. Three programme killers that sink DPDP in week 2 — and the two-minute CFO pitch 12 min

The first two weeks of a real engagement. Running the discovery interviews that get engineering, marketing, HR and support to actually tell you where personal data lives. The two scanner outputs you must have (file-share grep + database schema diff). The four hiding places that never make the first list: ad-platform audience uploads, support-ticket attachments, legacy backups, and spreadsheets on individual laptops. The deliverable is a draft data inventory good enough to anchor the RoPA in Module 3.

  1. 1. Discovery interview questions that get engineering to actually tell you where data lives 12 min
  2. 2. Reading a database schema the way an auditor reads it 11 min
  3. 3. The four hiding places engineering always forgets to mention 12 min
  4. 4. File-share and cloud-storage scanning without buying a six-figure DLP 11 min
  5. 5. Building the draft data inventory that will survive Day 15 11 min
  6. 6. Discovery sign-off and the Day-15 stop-or-go decision pack 12 min

The RoPA is the one artifact an auditor will ask for first. Most RoPAs fail because they are built as checklists, not as a map of how the company actually works. This module teaches the eight columns a RoPA must have, how to source each column from the Module 2 inventory, the three "red flag" cells that indicate a problem the moment they are filled, and how to walk a Data Protection Board inquiry through your RoPA without flinching. One fully-worked example (ABC Tyres) is built step by step.

  1. 1. The eight columns of a DPDP RoPA, and why no ninth belongs 12 min
  2. 2. Filling the RoPA from the Module 2 inventory, column by column 12 min
  3. 3. The three red-flag cells an auditor spots in the first sixty seconds 12 min
  4. 4. The twenty-minute RoPA walkthrough a DPB officer will ask you to run 12 min
  5. 5. ABC Tyres worked example: four RoPA rows, filled column by column 12 min
  6. 6. RoPA sign-off, the Day-30 Board update, and setting up Module 4 11 min

Lawful basis under DPDP is binary in theory and messy in practice. Retention is where theory and practice collide hardest. This module teaches the lawful-basis test as a decision tree, the retention matrix as a layered artifact (DPDP floor, sectoral overlay, government-security exception, contractual necessity), the Third Schedule 3-year inactivity rule with the 48-hour pre-erasure notice, and how to defend a 7-year retention cell to a Data Principal who asks for erasure.

  1. 1. The lawful basis decision tree, and why "legitimate interest" is not an answer 12 min
  2. 2. The retention matrix, layered by sector, that defends every cell 12 min
  3. 3. The Third Schedule three-year inactivity rule and the 48-hour pre-erasure notice 11 min
  4. 4. Erasure requests and the "unless required by law" response 12 min
  5. 5. Getting the retention schedule signed off by Day 30 11 min

The privacy-facing surface of the company. Drafting a Rule 3 standalone notice that itemises data categories and purposes without turning into a wall of text. Wiring a Section 6 consent flow that will route through a registered Consent Manager when the Rule 4 regime goes live in November 2026. Handling cookies and tracking pixels (DPDP is silent, but the direction of travel is clear). Multilingual delivery under the Eighth Schedule. The deliverable is a live notice, a working consent flow in staging, and a Consent Manager integration plan.

  1. 1. Drafting the Rule 3 standalone notice without turning it into a wall of text 12 min
  2. 2. The Section 6 consent flow and the auditable consent record 13 min
  3. 3. Cookies and tracking under DPDP, when the Act does not mention cookies 12 min
  4. 4. Multilingual notice under the Eighth Schedule: 22 languages, Claude AI, not Bhashini 12 min
  5. 5. The Rule 4 Consent Manager integration plan: live-frontier work 12 min
  6. 6. Going live: the Day-45 checklist that keeps the notice from embarrassing you 12 min

Data Principal rights are the first place a company gets publicly embarrassed. This module teaches the DSAR intake form that minimises identity over-collection, the internal SLA design that stays comfortably inside the 90-day hard cap, the four response templates (grant, partial, refuse-with-reason, escalate) and the Section 13 grievance workflow that keeps a request out of the DPB. Includes the Section 15 Data Principal duties and the ₹10,000 Schedule penalty, because every DSAR workflow leaks requests from bad-faith requesters.

  1. 1. The DSAR intake form that collects what you need and nothing more 11 min
  2. 2. Identity verification without over-collection — three tiers, one decision tree 11 min
  3. 3. The 90-day clock, and why you must beat it, not touch it 11 min
  4. 4. The four response templates — grant, carve-out, refuse, escalate 11 min
  5. 5. Section 13 grievance and the Section 15 duty that handles bad-faith requests 11 min

A DPDP programme is only as strong as its weakest Data Processor. This module teaches the vendor risk register (one row per vendor, nine columns), the Section 8(2) DPA with the ten clauses that are non-negotiable, the Rule 15 cross-border decision log for the negative-list regime, and the three "difficult vendor" scripts (big US SaaS vendor, small Indian vendor who will not sign anything, legacy vendor whose contract was signed in 2019). Includes the Section 17 exemptions and when they actually apply.

  1. 1. The vendor risk register — ten columns, one row per vendor, nothing more 12 min
  2. 2. The ten DPA clauses you do not negotiate away 13 min
  3. 3. The Rule 15 cross-border decision log — four columns and the empty negative list 12 min
  4. 4. Three vendor conversations that go sideways — and the exact scripts 13 min
  5. 5. Section 17 exemptions — when they genuinely apply and when founders only think they do 11 min
  6. 6. The Day-75 cutoff — accept the risk, or kill-switch the vendor 12 min

The lesson practitioners get called about at 2 AM. The Rule 7 Stage 1 "without delay" intimation to Data Principals and the Board. The Rule 7 Stage 2 72-hour detailed report. The parallel CERT-In 6-hour clock under the April 2022 Directions. The breach runbook that lets a company fire both without missing either. A tabletop exercise with a plausible breach scenario. The Star Health late-reporting pattern as a cautionary case.

  1. 1. Classifying an incident as a personal data breach under Section 2(u) 11 min
  2. 2. Rule 7 Stage 1 — the "without delay" intimation to Data Principals and the Board 12 min
  3. 3. Rule 7 Stage 2 — the 72-hour detailed report to the Data Protection Board 11 min
  4. 4. The CERT-In six-hour parallel clock — filing twice without duplicating effort 11 min
  5. 5. The two-hour tabletop that turns a paper runbook into a tested one 12 min

What changes when the company either designs a high-risk processing activity or gets notified as a Significant Data Fiduciary. The DPIA scoping template, the risk-rating methodology, the algorithmic due diligence checklist for AI/ML systems, the Rule 13 independent audit on a 12-month clock, and the DPO role (qualifications, reporting line, salary band, independence protections). One fully-worked DPIA on a case-study processing activity.

  1. 1. Scoping a DPIA before Legal is the one asking you to run one 12 min
  2. 2. A risk-rating methodology that survives a Board meeting 11 min
  3. 3. Algorithmic due diligence for AI systems, worked on a credit-scoring model 13 min
  4. 4. The Rule 13 independent audit on a 12-month clock 12 min
  5. 5. The DPO role that survives a change of CEO 12 min

Day 91 is the hardest day of a DPDP programme. The engagement is "over" but the programme must now run forever. This module teaches the 12-month DPO calendar (monthly, quarterly, half-yearly, annual cadences), the five KPIs that actually indicate programme health, the board-reporting cadence and deck template, the budget-ask language that gets a renewal through CFO, and the handover document a departing DPO owes a successor.

  1. 1. The 12-month DPO calendar that keeps a programme alive after Day 91 12 min
  2. 2. Five KPIs that indicate programme health — and the gaming behaviour that corrupts each 12 min
  3. 3. Board reporting cadence and the six-slide deck that gets fifteen minutes well-spent 11 min
  4. 4. The budget renewal ask — how to argue for a 10 percent increase, not accept a 10 percent cut 11 min
  5. 5. The DPO handover document — what a departing DPO owes a successor 12 min

The reason most DPDP programmes stall is not legal, not technical, and not budgetary. It is cross-functional friction. This module teaches the leadership craft: how to run a steering committee, how to turn an engineering No into a scheduled Yes, how to handle a marketing team that has already shipped the pixel you now need to remove, how to brief a Board that does not understand DPDP, and the three conversations that unblock 90% of implementations. Six lessons, six real scripts, zero generic advice.

  1. 1. Running a steering committee that decides, not one that updates 12 min
  2. 2. Converting an engineering "no, not this quarter" into a scheduled Yes 11 min
  3. 3. Handling the marketing pixel removal fight without losing the CMO 12 min
  4. 4. Briefing a Board on DPDP risk in ten minutes and six slides 11 min
  5. 5. The three recurring cross-functional disputes and how to mediate each 13 min
  6. 6. When to escalate to the CEO, when to absorb, and how to escalate once 12 min

The capstone walks you through a complete 90-day DPDP engagement on ABC Tyres, a fictional Indian tyre-manufacturing company (modelled on the dcomply Decipher demo tenant). You produce every artifact from Modules 1-11 on this one company, and submit a complete programme file. The final exam is 45 questions drawn from a 70-item pool, covering every module, with each question anchored to a specific Section, Rule, Schedule or regulator circular cited in the course.

  1. 1. ABC Tyres — the client brief and your Day-0 engagement plan 13 min
  2. 2. Walking the full ABC Tyres programme file end to end 15 min
  3. 3. Submitting your capstone and preparing for the final exam 11 min
Frequently Asked

Everything a buyer usually asks

Who is this course for?
In-house compliance, HR, IT and legal managers at Indian SMEs and mid-market firms told to "handle DPDP" with no consulting budget Full audience list is on the course page below.
Is there a free preview?
Yes. Module 1 is a free preview: read every lesson in it without payment and without an account.
What do I get when I enrol?
Access to all 12 modules covering 63 lessons, the full citation register, the final exam (45 question bank with unlimited retakes at 75% pass mark), and a verifiable certificate with a public verify URL on completion.
Is there a certificate on completion?
Yes. Pass the final exam and you receive a certificate with a public verify URL that recruiters can validate in one click. LinkedIn-shareable.
How much does the course cost?
₹14,999 (inclusive of 18% GST). Lifetime access. One-time payment. Lifetime access including future updates.
How long do I have to complete the course?
Lifetime access. Self-paced. You can start, pause, and resume any time from any device.
Can I retake the final exam?
Yes, unlimited retakes. Options are shuffled per attempt and questions are drawn from a larger question bank, so each attempt is a fresh test of judgement.
How do you keep the course current when the law changes?
Every course carries a Legal Basis Version listing the exact instruments it teaches to. When a material instrument is amended or superseded, we update the affected lessons and email all enrolled learners.
Is this course legal advice?
No. This is an educational and awareness training programme. Nothing in the course creates a lawyer-client relationship. For specific compliance decisions, consult a qualified advocate or a regulator-empanelled auditor.
Educational content, not legal advice.

This course is a paid practitioner training programme. Every statutory claim is anchored to a primary source (statute, rule, schedule, gazette notification, or sectoral regulator circular) cited in the lesson. As of 5 October 2026 several items are still in motion: the Data Protection Board of India is constituted but its Chairperson is not yet appointed under the MeitY Search Committee circular F.No. 2(1)/2026-Pers.I; no entity has yet been notified as a Significant Data Fiduciary; no Consent Manager has registered under Rule 4 (registration opens 13 November 2026); no country has been placed on the negative list under Rule 15; and a batch of writ petitions challenging Section 36, Rules 22-23 and Section 44(3) is pending before the Supreme Court after referral to a larger bench on 16 February 2026.

The course flags each live-frontier item in the lesson where it appears. This course is not legal advice. For specific compliance decisions on your organisation, retain a qualified data protection advocate.