Back to Certification
Essential Study Guide

Certification Study Guide

A curated, high-yield distillation of what you must actually know to pass the DPDPA Professional Certification. Every point below is drawn from the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Master these and the examination becomes a demonstration of knowledge — not a test of luck.

How to Use This Guide

The examination is deliberately rigorous. Distractors are drawn from genuinely adjacent provisions — a neighbouring section, a near-miss figure, a plausible misconception — so shallow familiarity will not carry you through. This guide isolates the concepts that recur most across all three phases. Read it end to end, then attempt the phases in order.

For deeper reading, cross-reference the Codex, DPDP Rules 2025, and FAQ.

1. Foundations & Timeline

The Act
Digital Personal Data Protection Act, 2023 — enacted 11 August 2023. India’s first comprehensive personal-data protection statute.
The Rules
Digital Personal Data Protection Rules, 2025 — notified 13 November 2025 by MeitY.
Enforcement
Full enforcement begins 13 May 2027, following an 18-month transition window from notification.
What it governs
Processing of digital personal data — data collected digitally, or collected physically and later digitised.
Extra-territorial reach
Applies outside India where processing relates to offering goods or services to Data Principals in India.
What it does NOT cover
Personal data processed for purely personal/domestic purposes, and data made publicly available by the Data Principal or under a legal obligation.

2. Key Roles & Definitions

Data Principal
The individual to whom the personal data relates. For a child, includes parents/lawful guardian; for a person with disability, includes the lawful guardian.
Data Fiduciary
Any person who alone or with others determines the purpose and means of processing personal data.
Data Processor
A person who processes personal data on behalf of a Data Fiduciary, under a valid contract.
Significant Data Fiduciary (SDF)
A Data Fiduciary (or class) notified by the Central Government based on volume/sensitivity of data, risk to rights, sovereignty, electoral democracy, security and public order.
Consent Manager
A registered entity, accountable to the Data Principal, enabling consent to be given, managed, reviewed and withdrawn through an interoperable platform. Registered with the Board.
Data Protection Officer (DPO)
Mandatory for SDFs — based in India, reports to the Board of Directors/governing body, and is the point of contact for grievance redressal.
Board
The Data Protection Board of India (DPBI) — the adjudicatory regulator that inquires into breaches and imposes penalties.

3. Consent, Notice & Legitimate Uses

Consent standard (S. 6)
Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and limited to the personal data necessary for the specified purpose.
Right to withdraw
Consent can be withdrawn at any time, and the ease of withdrawal must be comparable to the ease of giving it. Withdrawal does not affect prior lawful processing.
Notice
On or before seeking consent, the Data Fiduciary must give an itemised notice: the personal data sought, the purpose, how to exercise rights, and how to complain to the Board. Must be available in English or any language in the Eighth Schedule of the Constitution.
Legitimate uses (S. 7)
Processing without fresh consent is permitted only for specified legitimate uses — e.g. voluntary provision for a specified purpose, State provision of benefits/services, medical emergency, employment purposes, disaster/epidemic response. (Note: the Act uses “legitimate uses,” not “deemed consent.”)

4. Data Principal Rights & Duties

Right to access
Summary of personal data being processed, the processing activities, and the identities of other Data Fiduciaries/Processors with whom it has been shared.
Right to correction & erasure
Correction, completion, updating and erasure of personal data — erasure unless retention is required for a legal purpose.
Right to grievance redressal
A readily available means of grievance redressal from the Data Fiduciary/Consent Manager, to be exhausted before approaching the Board.
Right to nominate
To nominate another individual to exercise rights in the event of death or incapacity.
Duties (S. 15)
Data Principals must not impersonate, suppress material information, file false/frivolous complaints, or register false particulars. Breach of duties is penalisable up to ₹10,000.

5. Children's Data (Section 9)

Definition of child
An individual below 18 years of age. (Note: this differs from GDPR’s 16, and 13 under COPPA — a common trap.)
Parental consent
Verifiable consent of a parent or lawful guardian is required before processing a child’s personal data.
Prohibitions
No tracking or behavioural monitoring of children, and no targeted advertising directed at children.
Exemptions
The Central Government may exempt certain classes of Data Fiduciaries or purposes (e.g. health, education) from some obligations, subject to conditions.

6. Fiduciary Obligations, Breach & SDFs

Accountability
The Data Fiduciary is responsible for compliance for all processing it or its Processor undertakes, regardless of any agreement or Data Principal default.
Security safeguards
Reasonable technical and organisational measures must be implemented to prevent personal data breaches.
Accuracy & retention
Ensure accuracy/completeness where data is used to make a decision or is disclosed; erase data once the purpose is served and retention is no longer necessary or legally required.
Breach notification
On a personal data breach, notify the Board and each affected Data Principal in the form and manner prescribed by the Rules.
SDF additional duties
Appoint a DPO in India; appoint an independent data auditor; conduct periodic Data Protection Impact Assessments (DPIA) and audits; observe other measures the Government prescribes.

7. Cross-Border Transfer & Exemptions

Transfer model (S. 16)
A “negative-list” (blacklist) approach — transfer of personal data outside India is permitted except to countries the Central Government restricts by notification. (Contrast GDPR’s adequacy/whitelist model.)
Sectoral overlay
Sector regulators may impose stricter localisation (e.g. RBI for payment data) — the DPDPA does not override such stricter requirements.
Exemptions (S. 17)
Certain provisions may not apply — e.g. enforcement of legal rights/claims, judicial/regulatory functions, prevention/investigation of offences, and processing of non-residents’ data under foreign contract.
State exemptions
The Government may exempt notified State instrumentalities in the interests of sovereignty, security, public order, and friendly foreign relations, subject to safeguards.

8. Penalties & Enforcement

The Schedule prescribes ceilings per instance. Know the ladder — the figures are a frequent source of near-miss distractors.

Security safeguards failure
Up to ₹250 crore — the highest ceiling, for failure to take reasonable security safeguards to prevent a breach.
Breach-notification failure
Up to ₹200 crore — for failure to notify the Board/Data Principals of a personal data breach.
Children’s-data obligations
Up to ₹200 crore — for breach of additional obligations regarding children.
SDF additional duties
Up to ₹150 crore — for breach of the additional obligations of a Significant Data Fiduciary.
Residual / other
Up to ₹50 crore — for breach of any other provision or Rule.
Data Principal duties
Up to ₹10,000 — for breach of the Data Principal’s duties.
Adjudication & appeal
The Data Protection Board adjudicates and imposes penalties; appeals lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days.

Quick-Recall Checklist

  • Act 2023 — Rules notified 13 Nov 2025 — enforcement 13 May 2027.
  • Lawful bases: consent (S.6) + legitimate uses (S.7) — not “deemed consent.”
  • Child = under 18; verifiable parental consent; no tracking/targeted ads (S.9).
  • Four rights: access; correction/erasure; grievance redressal; nomination.
  • SDF extras: DPO in India + independent auditor + DPIA/audit.
  • Cross-border = negative list (S.16); sector rules can be stricter.
  • Penalty ladder: 250 / 200 / 200 / 150 / 50 crore; ₹10,000 for Principal duties.
  • Regulator = Data Protection Board; appeal to TDSAT within 60 days.

This study guide is educational reference material derived from the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. It is not legal advice and does not create an attorney-client relationship.