Live Founding Cohort open, limited seats remaining Back to main site →
Data Protection

DPDP Rules 2025 Deep Dive / DPO Practitioner

The 23 Rules that make you audit-ready by 13 May 2027

₹4,999 Intermediate 5.4 hours 8 modules Founding Cohort: 836 seats left
Founding Cohort, DPDP Class of 2026. The first 1,000 learners to pass the final exam receive a permanent "Founding #N" badge on their certificate. 836 seats remaining.
8
Modules
28
Lessons
40
Exam questions
75%
Pass mark

A citation-anchored, exam-backed practitioner course on the Digital Personal Data Protection Rules, 2025 notified by MeitY on 13 November 2025. Rule-by-rule teaching of all 23 Rules and 7 Schedules, with lesson-level anchors to the DPDP Act 2023 Sections they operationalise. Covers the three-phase commencement calendar (13 Nov 2025 / 13 Nov 2026 / 13 May 2027), Notice + Consent + Consent Manager registration, RoPA + retention under the Third Schedule, Data Principal rights, DPIA + independent audit + algorithmic due diligence for Significant Data Fiduciaries, the Rule 7 breach two-stage clock and its parallel with CERT-In, cross-border transfer under the negative-list regime, and the RBI Data Governance Framework (July 2026 draft), IRDAI Cyber Security Guidelines 2026 (April 2026), SEBI CSCRF (August 2024) and Telecom Cyber Security Rules 2024 sector overlays. Updated through August 2026.

What you will learn
  • Read and apply every one of the 23 DPDP Rules 2025 as they stand today
  • Operate the three-phase commencement calendar and build a May 2027 readiness plan
  • Draft a Rule 3-compliant standalone notice with 22-language rendering
  • Design a Section 6 consent flow ready for Consent Manager routing under Rule 4
  • Build a Rule 8 + Third Schedule retention regime with the 48-hour pre-erasure notice
  • Run a Rule 7 breach playbook and reconcile it with the CERT-In 6-hour clock
  • Structure a Rule 13 SDF DPIA + independent audit + algorithmic due diligence programme
  • Handle Data Principal access, correction, erasure, grievance and nomination inside the 90-day cap
  • Draft a Section 8(2) DPA that survives a DPB inquiry
  • Map the RBI DGF, SEBI CSCRF, IRDAI and Telecom overlays to DPDP obligations for BFSI, insurance and telecom DPOs
Prerequisites
  • Basic familiarity with how an organisation collects, stores and processes digital information
  • No prior legal background required. Practitioners in privacy, compliance, DPO, in-house counsel and consulting roles are the natural audience
  • DPDP Act 2023 free course from dcomply Academy is a helpful but not required primer
Who this is for
  • Data Protection Officers and privacy leads at mid to large Indian firms
  • In-house counsel and compliance officers preparing for the May 2027 substantive-obligation cut-off
  • CISOs and heads of information security responsible for Rule 7 breach readiness
  • BFSI second-line-of-defence teams facing the RBI Data Governance Framework
  • Insurance and web-aggregator compliance teams under IRDAI Cyber Guidelines 2026
  • Consultants, auditors and legaltech founders serving Indian Data Fiduciaries
  • DPO aspirants stacking IAPP CIPP/A, CIPM, DSCI DCDPO with an India-specific practitioner cert
About the author
AJ
Advocate Joginder Poswal
Course Author. Advocate; author of "DPDP Compliance for Indian Businesses".

Advocate Joginder Poswal is the founder of Poswal Law Office and the author of "DPDP Compliance for Indian Businesses: A Practical Guide for SMEs, Startups, and Founders". His 18 years of IT operations experience before legal practice give this course a perspective most DPO training material lacks: it explains not only what the Rules say, but how a working DPO builds a compliance programme against them. This paid course is based on the DPDP Rules 2025 (notified 13 November 2025) read alongside the DPDP Act 2023 and the sectoral overlays from RBI, SEBI, IRDAI, DoT and UIDAI as they stand in August 2026. It is intended as practitioner training and does not constitute legal advice or solicitation.

No account to create. We email you a one-click link.
How we use your personal data DPDP notice
  • What we collect: name, email, IP address (for security logging), and course progress.
  • Why: to email you the one-click access link, deliver lessons, issue your certificate, and (with your consent) send course updates plus a Day-7 follow-up about dcomply.
  • How long: kept until you unsubscribe or request erasure.
  • Your rights under the DPDP Act 2023: access, correction, erasure, and grievance redressal. Write to [email protected] to exercise any of them.
  • Unsubscribe any time using the link in every email we send you.
Certificate on completion. Pass mark 75%.
Curriculum

Syllabus

8 modules, 28 lessons. Click any module to expand.

A working model of the entire DPDP regime in one module. Where the law came from, how the Act and the Rules fit together, the three commencement dates that structure every compliance decision, and how DPDP compares with GDPR. This module is available as a free preview so buyers can validate the depth before purchasing.

  1. 1. Where DPDP came from and why the 2025 Rules matter now 10 min
  2. 2. The three-phase commencement calendar 8 min
  3. 3. Reading the Act and Rules as one instrument 10 min
  4. 4. DPDP vs GDPR: the four key differences 9 min

The privacy-facing surface of every product in India. How to write a Rule 3 standalone notice that survives an audit, how the Section 6 consent test actually works in practice, why cookies remain a grey zone, and how Consent Manager registration under Rule 4 changes the consent architecture from November 2026.

  1. 1. Notice under Section 5 and Rule 3 11 min
  2. 2. The Section 6 consent test and withdrawal architecture 10 min
  3. 3. Cookies and the India grey zone 8 min
  4. 4. Consent Manager registration under Rule 4 and the MeitY six 10 min

Data discovery, records of processing, and the retention regime introduced by Rule 8 and the Third Schedule. The specific-purpose test for erasure, the 3-year inactivity clock for e-commerce, gaming and social media platforms, the 48-hour pre-erasure notice, and how to layer retention across DPDP, sectoral rules and the Seventh Schedule government-security exception.

  1. 1. Data discovery and classification 9 min
  2. 2. Building a DPDP-fit Record of Processing Activities 10 min
  3. 3. Rule 8 retention and the Third Schedule 12 min
  4. 4. Layered retention across DPDP and sectoral rules 8 min

Access, correction, erasure, grievance and nomination as an operational workflow. Identity verification without over-collection, the internal SLA design that stays inside the 90-day hard cap, the escalation path from Fiduciary to Board, and Section 15 Data Principal duties that carry their own penalty.

  1. 1. Section 11 access and Rule 14 workflow 9 min
  2. 2. Section 12 correction, completion and erasure 9 min
  3. 3. Section 13 grievance mechanism and escalation to the Board 9 min
  4. 4. Section 14 nomination and Section 15 Data Principal duties 7 min

What changes the day your entity is notified as a Significant Data Fiduciary. Structuring a Data Protection Impact Assessment and independent audit on a 12-month clock; the Rule 13(3) algorithmic due diligence duty for AI/ML systems; the DPO role, qualifications, salary bands and reporting line; and the DPB adjudication and TDSAT appeal path.

  1. 1. SDF designation under Section 10 and the Rule 13 programme 11 min
  2. 2. Running a DPIA in practice 10 min
  3. 3. The DPO role in detail: qualifications, salary bands, reporting line 10 min
  4. 4. DPB adjudication and TDSAT appeal 9 min

The Rule 7 breach playbook read carefully. What triggers a personal data breach, what goes in the Stage 1 without-delay intimation, what goes in the Stage 2 72-hour detailed report, and how a single incident affecting personal data runs both the DPDP clock and the CERT-In 6-hour clock in parallel. Includes the Item 2 Schedule penalty exposure and the Star Health late-reporting pattern.

  1. 1. What counts as a personal data breach 8 min
  2. 2. Rule 7 Stage 1 and Stage 2 mechanics 10 min
  3. 3. Parallel clocks: DPDP Rule 7 and CERT-In 6-hour 9 min
  4. 4. Rule 6 security safeguards 9 min

The outward-facing surface of a DPO programme. Section 8(2) valid-contract requirement and the DPA clauses you cannot negotiate away; Section 16 + Rule 15 negative-list cross-border regime; and how the RBI Data Governance Framework (July 2026 draft), IRDAI Cyber Guidelines 2026, SEBI CSCRF and Telecom Cyber Security Rules layer over DPDP for BFSI, insurance and telecom DPOs. Includes Section 17 exemptions and the pending constitutional challenges before the Supreme Court and Delhi High Court.

  1. 1. Section 8(2) DPA and the ten non-negotiable clauses 11 min
  2. 2. Section 16 and Rule 15 cross-border transfer 9 min
  3. 3. Sector overlays: RBI, SEBI, IRDAI, Telecom, Aadhaar 10 min
  4. 4. Section 17 exemptions and the constitutional challenge 9 min

Final certification exam covering all seven content modules. Every question is anchored to a specific Rule, Schedule, Section, DPB rule, or sectoral overlay cited in the course. Randomised order, shuffled options, explanations shown after each question.

Lessons coming soon.

Sister Academy · VakeelSaathi Academy

Litigation angle on this? Our sister academy covers it.

VakeelSaathi Academy is our sister site for practice training aimed at corporate advocates and litigators. Separate login. Same group. You will sign in there with a fresh account.

Frequently Asked

Everything a buyer usually asks

Who is this course for?
Data Protection Officers and privacy leads at mid to large Indian firms Full audience list is on the course page below.
Is there a free preview?
Yes. Module 1 is a free preview: read every lesson in it without payment and without an account.
What do I get when I enrol?
Access to all 8 modules covering 28 lessons, the full citation register, the final exam (40 question bank with unlimited retakes at 75% pass mark), and a verifiable certificate with a public verify URL on completion.
Is there a certificate on completion?
Yes. Pass the final exam and you receive a certificate with a public verify URL that recruiters can validate in one click. LinkedIn-shareable.
How much does the course cost?
₹4,999 founding-cohort price (list price ₹14,999) One-time payment. Lifetime access including future updates.
How long do I have to complete the course?
Lifetime access. Self-paced. You can start, pause, and resume any time from any device.
Can I retake the final exam?
Yes, unlimited retakes. Options are shuffled per attempt and questions are drawn from a larger question bank, so each attempt is a fresh test of judgement.
How do you keep the course current when the law changes?
Every course carries a Legal Basis Version listing the exact instruments it teaches to. When a material instrument is amended or superseded, we update the affected lessons and email all enrolled learners.
Is this course legal advice?
No. This is an educational and awareness training programme. Nothing in the course creates a lawyer-client relationship. For specific compliance decisions, consult a qualified advocate or a regulator-empanelled auditor.
Educational content, not legal advice.

This course is a paid practitioner training programme. Every claim is anchored to a primary source (statute, rule, schedule, gazette notification, or sectoral regulator circular) cited in the lesson. As of August 2026 several critical items are pending: the Data Protection Board is constituted but its Chairperson and Members are not fully appointed; no entity has been formally designated a Significant Data Fiduciary; no Consent Manager has been registered under Rule 4 (registration window opens 13 November 2026); no country has been notified as restricted under Rule 15; and a batch of writ petitions challenging Section 36, Rule 22-23 and Section 44(3) is pending before the Supreme Court after referral to a larger bench on 16 February 2026. The course flags each of these live-frontier items in the lesson where they appear.

It is not legal advice. For specific compliance decisions, consult a qualified data protection lawyer.