Why you can trust this course
We don't ask you to take our word for it. Every claim in every lesson is anchored to a Section, Rule, or judgment. This page is the master register of every authority we cite.
How this DPDP Rules 2025 Deep Dive / DPO Practitioner register is built
This trust page is the citation register for the DPDP Rules 2025 Deep Dive / DPO Practitioner course. It cites 45 authorities across 9 statutory instruments, drawn from the legal basis snapshot above (DPDP Act 2023 (No. 22 of 2023, assented 11 August 2023). DPDP Rules 2025 notified 13 November 2025 via Gazette Notifications G.S.R. 843(E), 844(E), 845(E) and 846(E). Sectoral overlays as in force August 2026: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); RBI Draft Data Governance Framework (15 July 2026, consultation closed 17 August 2026); SEBI CSCRF (20 August 2024); IRDAI Information and Cyber Security Guidelines 2026 (6 April 2026); Telecom Cyber Security Rules 2024 (21 November 2024); Aadhaar Data Security Regulations 2016. Constitutional context: Puttaswamy v. Union of India (2017) 10 SCC 1.).
Primary sources: DPDP Act 2023 (21 entries), DPDP Rules 2025 (16 entries), DPDP Gazette 2025 (2 entries).
Every claim in every DPDP Rules 2025 Deep Dive / DPO Practitioner lesson traces back to a Section, Rule, or judgment listed below.
If a lesson references a specific obligation, click the [Lx-Cy] marker in that
lesson to jump to the verbatim text in the register.
Our verification promise
- Every factual claim has a source. If we say "Section 9 allows a three-month limitation period", you can click the
[Lx-Cy]marker next to it and read the verbatim text of Section 9 of the Sexual Harassment of Women at Workplace Act, 2013. - Every source is on this page. Below you will find every Section, Rule and judgment we have relied on, grouped by category, with the verbatim text we hold in our register.
- Every source has a public link. Wherever an authoritative public link exists (India Code, the official court website, a reputable law-reports portal), we link to it.
- Bug bounty for errors. If you find a factual error in any lesson, write to [email protected] with the lesson, the claim and the corrected source. We will credit your account ₹1,000 for the first report of any verifiable error, ₹5,000 for a substantial error.
The full citation register
Every authority used in any lesson appears below. Click a row to expand the verbatim text.
Direction (ii) , CERT-In 6-hour cyber incident reporting (parallel to CSCRF) 28 Apr 2022
Section 17 , Exemptions
Section 27 , Functions of Data Protection Board
Section 29 , Appeal to Appellate Tribunal
Section 36 , Power to call for information
Section 44(3) , Amendment to Right to Information Act
Schedule , Penalty ceilings 11 Aug 2023
Section 1 , Short title, extent, commencement 11 Aug 2023
Section 10 , Additional obligations of Significant Data Fiduciary 11 Aug 2023
Section 11 , Right of Data Principal to access information 11 Aug 2023
Section 12 , Right to correction, completion, updating and erasure 11 Aug 2023
Section 13 , Right of grievance redressal 11 Aug 2023
Section 14 , Right to nominate 11 Aug 2023
Section 15 , Duties of Data Principal 11 Aug 2023
Section 16 , Processing of personal data outside India 11 Aug 2023
Section 2 , Definitions 11 Aug 2023
Section 3 , Application of the Act 11 Aug 2023
Section 33 , Penalties for breach 11 Aug 2023
Section 4 , Grounds for processing personal data 11 Aug 2023
Section 5 , Notice to Data Principal 11 Aug 2023
Section 6 , Consent 11 Aug 2023
Section 8 , General obligations of Data Fiduciary 11 Aug 2023
G.S.R. 844(E) , Establishment of Data Protection Board of India 13 Nov 2025
G.S.R. 846(E) , Digital Personal Data Protection Rules, 2025 13 Nov 2025
First Schedule , Consent Manager conditions and obligations 13 Nov 2025
Rule 1 , Short title, commencement 13 Nov 2025
Rule 10 , Verifiable consent for children 13 Nov 2025
Rule 13 , Additional obligations of Significant Data Fiduciary 13 Nov 2025
Rule 14 , Rights of Data Principals — publication and response 13 Nov 2025
Rule 15 , Cross-border transfer restrictions 13 Nov 2025
Rule 16 , Exemption for research, archiving and statistical processing 13 Nov 2025
Rule 23 , Confidentiality of information sought under Section 36 13 Nov 2025
Rule 3 , Notice by Data Fiduciary to Data Principal 13 Nov 2025
Rule 4 , Registration and obligations of Consent Manager 13 Nov 2025
Rule 6 , Reasonable security safeguards 13 Nov 2025
Rule 7 , DPDP breach notification (parallel to CSCRF for personal data) 13 Nov 2025
Rule 8 , Time period for erasure 13 Nov 2025
Rule 9 , Contact information 13 Nov 2025
Seventh Schedule , Purposes for calling information under Section 36 13 Nov 2025
Third Schedule , Retention default periods 13 Nov 2025
April 2026 Guidelines , IRDAI Information and Cyber Security Guidelines 2026 06 Apr 2026
Puttaswamy v. UoI (2017) 10 SCC 1 , Right to privacy as a fundamental right 24 Aug 2017
Draft July 2026 , RBI Data Governance Framework Draft (15 July 2026) 15 Jul 2026
Incident Reporting , 6-hour incident reporting to SEBI + CERT-In 20 Aug 2024
Incident reporting , Telecom Cyber Security Rules 2024 — 6-hour + 24-hour follow-up 21 Nov 2024
Found an error? We pay for it.
If you find a factual error in any lesson, write to [email protected] with the lesson title, the specific claim, and the corrected source.
- ₹1,000 credit for the first report of any verifiable factual error.
- ₹5,000 credit for a substantial error (e.g. a wrong section number, an obsolete ruling, a misrepresented holding).
- Credit on your dcomply Academy account usable against any future course.
We pay because we'd rather know than not know. If the law changes (and it will), we want to be the first to fix our lessons.
- 🟢 Our verification promise
- 📊 Course statistics
- 📚 Full citation register
- 🐛 Bug bounty for errors
Maintained by the dcomply Academy editorial team. Last reviewed recently.