Picture a sales executive on a Friday evening. She wants to finish her follow-ups from home, so she exports the customer list and emails it to her personal Gmail account. Nothing about this feels wrong to her. She has done it before, and so have half her colleagues.
Under the Digital Personal Data Protection Act, 2023, that email is the organisation's problem. Section 8(1) makes the Data Fiduciary, the organisation that decides why and how personal data is processed, responsible for complying with the Act “irrespective of any agreement to the contrary”. If that spreadsheet leaks, the Data Protection Board will not ask what the executive knew. It will ask what the organisation did to make sure she knew.
So this guide treats training as part of compliance, with the same seriousness as encryption or a vendor contract. It is written for the people who have to make it happen: compliance heads, and the leaders deciding what to budget for before 2027.
Does the DPDP Act require training?
The honest answer is that the Act never uses the word. Neither do the DPDP Rules, 2025. No provision says that every employee must attend a session every year.
But look at what the Act does say. Section 8(4) requires a Data Fiduciary to “implement appropriate technical and organisational measures to ensure effective observance” of the Act and the Rules. Rule 6(1)(g) repeats the phrase for security safeguards. Technical measures are things like encryption and access controls. Organisational measures are about people: who can do what, and whether anyone has told them the rules.
We would argue that training is the most basic organisational measure there is. It is hard to show the Board that your measures were “appropriate” if the people who handle personal data every day were never told what the law expects of them.
The Schedule to the Act shows what is at stake. Failing to take reasonable security safeguards under Section 8(5) can attract a penalty of up to ₹250 crore. Failing to tell the Board and affected individuals about a breach can attract up to ₹200 crore. Many breaches begin with an ordinary mistake by someone who did not know better.
Why a privacy policy is not enough
Many organisations will respond to the DPDP Act by rewriting their privacy policy, naming someone to own compliance, and moving on. The policy matters; it tells people what you do with their data. But a policy does not change what happens at a desk on a Friday evening.
Data protection failures are rarely dramatic. An email goes to the wrong recipient. A team shares one login to the CRM. A vendor gets onboarded because the business needed it this week, with the contract to follow. A customer asks for her data to be deleted and gets passed between departments for a month. Each of these is a people problem before it becomes a legal one.
We saw how wide the gap can be at a recent CADP workshop for the leadership of a Bengaluru college. Before the session, only a third of participants felt confident about sharing data safely with vendors or responding to a breach. Afterwards, more than four in five did. These were principals and senior administrators, the people who sign contracts and approve systems. If they were unsure, the gap further down the organisation is probably wider.
Who needs training, and what each role needs
The most common mistake is one generic session for everyone. The board does not need to know how to redact a spreadsheet, and the customer support team does not need a lecture on Significant Data Fiduciaries. This is how we would divide it.
Board and senior leadership
Leadership needs to understand accountability. Section 8(1) puts responsibility on the organisation, and the Schedule puts a price on failure. Leaders also approve the budgets and vendors that decide whether compliance is possible at all. A half-day session on their obligations and the decisions only they can make is usually enough.
The Data Protection Officer or compliance lead
If the government notifies your organisation as a Significant Data Fiduciary, Section 10(2) requires a Data Protection Officer who is based in India, answers to the board and handles grievances. Even if you are not notified, Section 8(9) requires you to publish the contact details of someone who can answer people's questions about their data. Whoever holds that role needs the deepest training: the full Act and Rules, and a sense of how the Board is likely to read them.
Sales, marketing and customer-facing teams
These teams collect most of the personal data an organisation holds, and they are usually the first to hear a complaint. They need to know what a valid notice and consent look like under Sections 5 and 6, and that withdrawing consent must be as easy as giving it. They also need to know how to route a request to access, correct or erase data under Sections 11 and 12, and how to recognise a grievance when it arrives as an angry phone call.
Human resources
HR holds some of the most sensitive data in the building: salaries, medical records, bank details and background checks. Section 7 lets an employer process personal data for employment purposes without consent, but the rest of the Act still applies, including security safeguards and erasure. HR teams need to know what they collect, how long they keep it, and what they may share with payroll providers and insurers.
IT and security
Rule 6 sets the minimum security safeguards: encryption or masking, access controls, logs that can detect unauthorised access, backups, and retention of those logs for at least a year. IT teams usually know the technology. What they often lack is the legal reading: which of these are now mandatory, what “reasonable” is likely to mean before the Board, and what the breach clock requires of them.
Procurement and vendor managers
Section 8(2) lets you use a Data Processor, a vendor that processes personal data on your behalf, only under a valid contract. Section 8(1) keeps you responsible for whatever that vendor does, and Rule 6(1)(f) requires the contract to cover security safeguards. The people who onboard vendors need to know what the contract must say and what to ask before anyone signs. At our college workshop, this was the topic participants most wanted to learn next.
What good DPDP training looks like
Most compliance training fails in the same way. People sit through slides about the law and go back to work unchanged. Good training differs in a few specific ways.
It starts from your own data. Before any session, map what personal data the team actually handles. At the college workshop, we followed a student's data from admission day to graduation. Participants recognised their own forms and spreadsheets, and the law stopped being abstract.
It works through scenarios. “A caller says he is a customer's husband and wants her order history. What do you do?” teaches more than any slide defining a Data Principal, the person the data is about.
It is short, and it repeats. A two-hour session every six months will do more than a full day once. The obligations are new, and habits change slowly.
It measures something. Ask participants the same questions before and after, anonymously. The answers show where confidence is still low, and they give you a record of what you did, which will matter if the Board ever asks.
A training timeline to May 2027
The DPDP Rules come into force in phases. Rules 1, 2 and 17 to 21 took effect on publication on 13 November 2025. Rule 4, on Consent Managers, takes effect on 13 November 2026. Everything else, including security safeguards and breach intimation, takes effect on 13 May 2027. Our implementation roadmap sets out the wider compliance work; working back from that date, training fits in like this.