DPDP Rules 2025 Deep Dive / DPO Practitioner
The 23 Rules that make you audit-ready by 13 May 2027
A citation-anchored, exam-backed practitioner course on the Digital Personal Data Protection Rules, 2025 notified by MeitY on 13 November 2025. Rule-by-rule teaching of all 23 Rules and 7 Schedules, with lesson-level anchors to the DPDP Act 2023 Sections they operationalise. Covers the three-phase commencement calendar (13 Nov 2025 / 13 Nov 2026 / 13 May 2027), Notice + Consent + Consent Manager registration, RoPA + retention under the Third Schedule, Data Principal rights, DPIA + independent audit + algorithmic due diligence for Significant Data Fiduciaries, the Rule 7 breach two-stage clock and its parallel with CERT-In, cross-border transfer under the negative-list regime, and the RBI Data Governance Framework (July 2026 draft), IRDAI Cyber Security Guidelines 2026 (April 2026), SEBI CSCRF (August 2024) and Telecom Cyber Security Rules 2024 sector overlays. Updated through August 2026.
What you will learn
- Read and apply every one of the 23 DPDP Rules 2025 as they stand today
- Operate the three-phase commencement calendar and build a May 2027 readiness plan
- Draft a Rule 3-compliant standalone notice with 22-language rendering
- Design a Section 6 consent flow ready for Consent Manager routing under Rule 4
- Build a Rule 8 + Third Schedule retention regime with the 48-hour pre-erasure notice
- Run a Rule 7 breach playbook and reconcile it with the CERT-In 6-hour clock
- Structure a Rule 13 SDF DPIA + independent audit + algorithmic due diligence programme
- Handle Data Principal access, correction, erasure, grievance and nomination inside the 90-day cap
- Draft a Section 8(2) DPA that survives a DPB inquiry
- Map the RBI DGF, SEBI CSCRF, IRDAI and Telecom overlays to DPDP obligations for BFSI, insurance and telecom DPOs
Prerequisites
- Basic familiarity with how an organisation collects, stores and processes digital information
- No prior legal background required. Practitioners in privacy, compliance, DPO, in-house counsel and consulting roles are the natural audience
- DPDP Act 2023 free course from dcomply Academy is a helpful but not required primer
Who this is for
- Data Protection Officers and privacy leads at mid to large Indian firms
- In-house counsel and compliance officers preparing for the May 2027 substantive-obligation cut-off
- CISOs and heads of information security responsible for Rule 7 breach readiness
- BFSI second-line-of-defence teams facing the RBI Data Governance Framework
- Insurance and web-aggregator compliance teams under IRDAI Cyber Guidelines 2026
- Consultants, auditors and legaltech founders serving Indian Data Fiduciaries
- DPO aspirants stacking IAPP CIPP/A, CIPM, DSCI DCDPO with an India-specific practitioner cert
- What we collect: name, email, IP address (for security logging), and course progress.
- Why: to email you the one-click access link, deliver lessons, issue your certificate, and (with your consent) send course updates plus a Day-7 follow-up about dcomply.
- How long: kept until you unsubscribe or request erasure.
- Your rights under the DPDP Act 2023: access, correction, erasure, and grievance redressal. Write to [email protected] to exercise any of them.
- Unsubscribe any time using the link in every email we send you.
Syllabus
8 modules, 28 lessons. Click any module to expand.
A working model of the entire DPDP regime in one module. Where the law came from, how the Act and the Rules fit together, the three commencement dates that structure every compliance decision, and how DPDP compares with GDPR. This module is available as a free preview so buyers can validate the depth before purchasing.
The privacy-facing surface of every product in India. How to write a Rule 3 standalone notice that survives an audit, how the Section 6 consent test actually works in practice, why cookies remain a grey zone, and how Consent Manager registration under Rule 4 changes the consent architecture from November 2026.
- 1. Notice under Section 5 and Rule 3 11 min
- 2. The Section 6 consent test and withdrawal architecture 10 min
- 3. Cookies and the India grey zone 8 min
- 4. Consent Manager registration under Rule 4 and the MeitY six 10 min
Data discovery, records of processing, and the retention regime introduced by Rule 8 and the Third Schedule. The specific-purpose test for erasure, the 3-year inactivity clock for e-commerce, gaming and social media platforms, the 48-hour pre-erasure notice, and how to layer retention across DPDP, sectoral rules and the Seventh Schedule government-security exception.
- 1. Data discovery and classification 9 min
- 2. Building a DPDP-fit Record of Processing Activities 10 min
- 3. Rule 8 retention and the Third Schedule 12 min
- 4. Layered retention across DPDP and sectoral rules 8 min
Access, correction, erasure, grievance and nomination as an operational workflow. Identity verification without over-collection, the internal SLA design that stays inside the 90-day hard cap, the escalation path from Fiduciary to Board, and Section 15 Data Principal duties that carry their own penalty.
- 1. Section 11 access and Rule 14 workflow 9 min
- 2. Section 12 correction, completion and erasure 9 min
- 3. Section 13 grievance mechanism and escalation to the Board 9 min
- 4. Section 14 nomination and Section 15 Data Principal duties 7 min
What changes the day your entity is notified as a Significant Data Fiduciary. Structuring a Data Protection Impact Assessment and independent audit on a 12-month clock; the Rule 13(3) algorithmic due diligence duty for AI/ML systems; the DPO role, qualifications, salary bands and reporting line; and the DPB adjudication and TDSAT appeal path.
- 1. SDF designation under Section 10 and the Rule 13 programme 11 min
- 2. Running a DPIA in practice 10 min
- 3. The DPO role in detail: qualifications, salary bands, reporting line 10 min
- 4. DPB adjudication and TDSAT appeal 9 min
The Rule 7 breach playbook read carefully. What triggers a personal data breach, what goes in the Stage 1 without-delay intimation, what goes in the Stage 2 72-hour detailed report, and how a single incident affecting personal data runs both the DPDP clock and the CERT-In 6-hour clock in parallel. Includes the Item 2 Schedule penalty exposure and the Star Health late-reporting pattern.
- 1. What counts as a personal data breach 8 min
- 2. Rule 7 Stage 1 and Stage 2 mechanics 10 min
- 3. Parallel clocks: DPDP Rule 7 and CERT-In 6-hour 9 min
- 4. Rule 6 security safeguards 9 min
The outward-facing surface of a DPO programme. Section 8(2) valid-contract requirement and the DPA clauses you cannot negotiate away; Section 16 + Rule 15 negative-list cross-border regime; and how the RBI Data Governance Framework (July 2026 draft), IRDAI Cyber Guidelines 2026, SEBI CSCRF and Telecom Cyber Security Rules layer over DPDP for BFSI, insurance and telecom DPOs. Includes Section 17 exemptions and the pending constitutional challenges before the Supreme Court and Delhi High Court.
- 1. Section 8(2) DPA and the ten non-negotiable clauses 11 min
- 2. Section 16 and Rule 15 cross-border transfer 9 min
- 3. Sector overlays: RBI, SEBI, IRDAI, Telecom, Aadhaar 10 min
- 4. Section 17 exemptions and the constitutional challenge 9 min
Final certification exam covering all seven content modules. Every question is anchored to a specific Rule, Schedule, Section, DPB rule, or sectoral overlay cited in the course. Randomised order, shuffled options, explanations shown after each question.
Lessons coming soon.
Litigation angle on this? Our sister academy covers it.
VakeelSaathi Academy is our sister site for practice training aimed at corporate advocates and litigators. Separate login. Same group. You will sign in there with a fresh account.
Everything a buyer usually asks
Who is this course for?
Is there a free preview?
What do I get when I enrol?
Is there a certificate on completion?
How much does the course cost?
How long do I have to complete the course?
Can I retake the final exam?
How do you keep the course current when the law changes?
Is this course legal advice?
This course is a paid practitioner training programme. Every claim is anchored to a primary source (statute, rule, schedule, gazette notification, or sectoral regulator circular) cited in the lesson. As of August 2026 several critical items are pending: the Data Protection Board is constituted but its Chairperson and Members are not fully appointed; no entity has been formally designated a Significant Data Fiduciary; no Consent Manager has been registered under Rule 4 (registration window opens 13 November 2026); no country has been notified as restricted under Rule 15; and a batch of writ petitions challenging Section 36, Rule 22-23 and Section 44(3) is pending before the Supreme Court after referral to a larger bench on 16 February 2026. The course flags each of these live-frontier items in the lesson where they appear.
It is not legal advice. For specific compliance decisions, consult a qualified data protection lawyer.
DPDP Act 2023 (No. 22 of 2023, assented 11 August 2023). DPDP Rules 2025 notified 13 November 2025 via Gazette Notifications G.S.R. 843(E), 844(E), 845(E) and 846(E). Sectoral overlays as in force August 2026: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); RBI Draft Data Governance Framework (15 July 2026, consultation closed 17 August 2026); SEBI CSCRF (20 August 2024); IRDAI Information and Cyber Security Guidelines 2026 (6 April 2026); Telecom Cyber Security Rules 2024 (21 November 2024); Aadhaar Data Security Regulations 2016.
Constitutional context: Puttaswamy v. Union of India (2017) 10 SCC 1.