Why you can trust this course
We don't ask you to take our word for it. Every claim in every lesson is anchored to a Section, Rule, or judgment. This page is the master register of every authority we cite.
How this DPDP Implementation Practitioner — 90 Days to Audit-Ready register is built
This trust page is the citation register for the DPDP Implementation Practitioner — 90 Days to Audit-Ready course. It cites 38 authorities across 7 statutory instruments, drawn from the legal basis snapshot above (DPDP Act 2023 (No. 22 of 2023, assented 11 August 2023). DPDP Rules 2025 notified 13 November 2025 via Gazette Notifications G.S.R. 843(E), 844(E), 845(E) and 846(E). Sectoral overlays as in force on 5 October 2026: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); RBI Draft Data Governance Framework (15 July 2026, consultation closed 17 August 2026); SEBI CSCRF (20 August 2024, SEBI AI Vulnerability Detection Advisory 5 May 2026); IRDAI Information and Cyber Security Guidelines 2026 (6 April 2026); Telecom Cyber Security Rules 2024 (21 November 2024); Aadhaar Data Security Regulations 2016. Constitutional context: Puttaswamy v. Union of India (2017) 10 SCC 1.).
Primary sources: DPDP Act 2023 (21 entries), DPDP Rules 2025 (10 entries), CERT-In Directions 2022 (2 entries).
Every claim in every DPDP Implementation Practitioner — 90 Days to Audit-Ready lesson traces back to a Section, Rule, or judgment listed below.
If a lesson references a specific obligation, click the [Lx-Cy] marker in that
lesson to jump to the verbatim text in the register.
Our verification promise
- Every factual claim has a source. If we say "Section 9 allows a three-month limitation period", you can click the
[Lx-Cy]marker next to it and read the verbatim text of Section 9 of the Sexual Harassment of Women at Workplace Act, 2013. - Every source is on this page. Below you will find every Section, Rule and judgment we have relied on, grouped by category, with the verbatim text we hold in our register.
- Every source has a public link. Wherever an authoritative public link exists (India Code, the official court website, a reputable law-reports portal), we link to it.
- Bug bounty for errors. If you find a factual error in any lesson, write to [email protected] with the lesson, the claim and the corrected source. We will credit your account ₹1,000 for the first report of any verifiable error, ₹5,000 for a substantial error.
The full citation register
Every authority used in any lesson appears below. Click a row to expand the verbatim text.
CERT-In 6-hour Rule , CERT-In Directions 2022 six-hour incident reporting 28 Apr 2022
Direction (ii) , CERT-In 6-hour cyber incident reporting (parallel to CSCRF) 28 Apr 2022
Section 17 , Exemptions
Section 2(u) , Definition of personal data breach
Section 27 , Functions of Data Protection Board
Section 29 , Appeal to Appellate Tribunal
Section 36 , Power to call for information
Schedule , Penalty ceilings 11 Aug 2023
Section 10 , Additional obligations of Significant Data Fiduciary 11 Aug 2023
Section 11 , Right of Data Principal to access information 11 Aug 2023
Section 12 , Right to correction, completion, updating and erasure 11 Aug 2023
Section 13 , Right of grievance redressal 11 Aug 2023
Section 15 , Duties of Data Principal 11 Aug 2023
Section 16 , Processing of personal data outside India 11 Aug 2023
Section 2 , Definitions 11 Aug 2023
Section 3 , Application of the Act 11 Aug 2023
Section 33 , Penalties for breach 11 Aug 2023
Section 4 , Grounds for processing personal data 11 Aug 2023
Section 5 , Notice to Data Principal 11 Aug 2023
Section 6 , Consent 11 Aug 2023
Section 7 , Certain legitimate uses 11 Aug 2023
Section 8 , General obligations of Data Fiduciary 11 Aug 2023
Section 9 , Processing of personal data of children 11 Aug 2023
G.S.R. 843(E) , Commencement of specific Sections of the DPDP Act 13 Nov 2025
Fourth Schedule , Exemptions from Section 9(1)/(3) for classes of Data Fiduciary and purposes 13 Nov 2025
Rule 13 , Additional obligations of Significant Data Fiduciary 13 Nov 2025
Rule 14 , Rights of Data Principals — publication and response 13 Nov 2025
Rule 15 , Cross-border transfer restrictions 13 Nov 2025
Rule 3 , Notice by Data Fiduciary to Data Principal 13 Nov 2025
Rule 4 , Registration and obligations of Consent Manager 13 Nov 2025
Rule 7 , DPDP breach notification (parallel to CSCRF for personal data) 13 Nov 2025
Seventh Schedule , Purposes for calling information under Section 36 13 Nov 2025
Third Schedule , Retention default periods 13 Nov 2025
Rule 8 , DPDP Rules 2025 Rule 8 (Log Retention and Third Schedule Sector Defaults) 14 Nov 2025
April 2026 Guidelines , IRDAI Information and Cyber Security Guidelines 2026 06 Apr 2026
Draft July 2026 , RBI Data Governance Framework Draft (15 July 2026) 15 Jul 2026
Cyber Audit , Cyber audit cadence and scope 20 Aug 2024
Master Circular 2024/113 , Cybersecurity and Cyber Resilience Framework for SEBI Regulated Entities 20 Aug 2024
Found an error? We pay for it.
If you find a factual error in any lesson, write to [email protected] with the lesson title, the specific claim, and the corrected source.
- ₹1,000 credit for the first report of any verifiable factual error.
- ₹5,000 credit for a substantial error (e.g. a wrong section number, an obsolete ruling, a misrepresented holding).
- Credit on your dcomply Academy account usable against any future course.
We pay because we'd rather know than not know. If the law changes (and it will), we want to be the first to fix our lessons.
- 🟢 Our verification promise
- 📊 Course statistics
- 📚 Full citation register
- 🐛 Bug bounty for errors
Maintained by the dcomply Academy editorial team. Last reviewed recently.