Certification Study Guide
A curated, high-yield distillation of what you must actually know to pass the DPDPA Professional Certification. Every point below is drawn from the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Master these and the examination becomes a demonstration of knowledge — not a test of luck.
How to Use This Guide
The examination is deliberately rigorous. Distractors are drawn from genuinely adjacent provisions — a neighbouring section, a near-miss figure, a plausible misconception — so shallow familiarity will not carry you through. This guide isolates the concepts that recur most across all three phases. Read it end to end, then attempt the phases in order.
For deeper reading, cross-reference the Codex, DPDP Rules 2025, and FAQ.
1. Foundations & Timeline
2. Key Roles & Definitions
3. Consent, Notice & Legitimate Uses
4. Data Principal Rights & Duties
5. Children's Data (Section 9)
6. Fiduciary Obligations, Breach & SDFs
7. Cross-Border Transfer & Exemptions
8. Penalties & Enforcement
The Schedule prescribes ceilings per instance. Know the ladder — the figures are a frequent source of near-miss distractors.
Quick-Recall Checklist
- Act 2023 — Rules notified 13 Nov 2025 — enforcement 13 May 2027.
- Lawful bases: consent (S.6) + legitimate uses (S.7) — not “deemed consent.”
- Child = under 18; verifiable parental consent; no tracking/targeted ads (S.9).
- Four rights: access; correction/erasure; grievance redressal; nomination.
- SDF extras: DPO in India + independent auditor + DPIA/audit.
- Cross-border = negative list (S.16); sector rules can be stricter.
- Penalty ladder: 250 / 200 / 200 / 150 / 50 crore; ₹10,000 for Principal duties.
- Regulator = Data Protection Board; appeal to TDSAT within 60 days.
This study guide is educational reference material derived from the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. It is not legal advice and does not create an attorney-client relationship.