Practical Guide

DPDP Act Training
for Organisations

The DPDP Act makes your organisation answer for what your people do with personal data. This guide sets out who needs training before the core obligations apply on 13 May 2027, and what that training should cover.

Core obligations apply from 13 May 2027
Up to ₹250 crore for weak security safeguards
72 hours for a detailed breach report to the Board
Section 8(4): organisational measures

Picture a sales executive on a Friday evening. She wants to finish her follow-ups from home, so she exports the customer list and emails it to her personal Gmail account. Nothing about this feels wrong to her. She has done it before, and so have half her colleagues.

Under the Digital Personal Data Protection Act, 2023, that email is the organisation's problem. Section 8(1) makes the Data Fiduciary, the organisation that decides why and how personal data is processed, responsible for complying with the Act “irrespective of any agreement to the contrary”. If that spreadsheet leaks, the Data Protection Board will not ask what the executive knew. It will ask what the organisation did to make sure she knew.

So this guide treats training as part of compliance, with the same seriousness as encryption or a vendor contract. It is written for the people who have to make it happen: compliance heads, and the leaders deciding what to budget for before 2027.

Does the DPDP Act require training?

The honest answer is that the Act never uses the word. Neither do the DPDP Rules, 2025. No provision says that every employee must attend a session every year.

But look at what the Act does say. Section 8(4) requires a Data Fiduciary to “implement appropriate technical and organisational measures to ensure effective observance” of the Act and the Rules. Rule 6(1)(g) repeats the phrase for security safeguards. Technical measures are things like encryption and access controls. Organisational measures are about people: who can do what, and whether anyone has told them the rules.

We would argue that training is the most basic organisational measure there is. It is hard to show the Board that your measures were “appropriate” if the people who handle personal data every day were never told what the law expects of them.

The Schedule to the Act shows what is at stake. Failing to take reasonable security safeguards under Section 8(5) can attract a penalty of up to ₹250 crore. Failing to tell the Board and affected individuals about a breach can attract up to ₹200 crore. Many breaches begin with an ordinary mistake by someone who did not know better.

Why a privacy policy is not enough

Many organisations will respond to the DPDP Act by rewriting their privacy policy, naming someone to own compliance, and moving on. The policy matters; it tells people what you do with their data. But a policy does not change what happens at a desk on a Friday evening.

Data protection failures are rarely dramatic. An email goes to the wrong recipient. A team shares one login to the CRM. A vendor gets onboarded because the business needed it this week, with the contract to follow. A customer asks for her data to be deleted and gets passed between departments for a month. Each of these is a people problem before it becomes a legal one.

We saw how wide the gap can be at a recent CADP workshop for the leadership of a Bengaluru college. Before the session, only a third of participants felt confident about sharing data safely with vendors or responding to a breach. Afterwards, more than four in five did. These were principals and senior administrators, the people who sign contracts and approve systems. If they were unsure, the gap further down the organisation is probably wider.

Who needs training, and what each role needs

The most common mistake is one generic session for everyone. The board does not need to know how to redact a spreadsheet, and the customer support team does not need a lecture on Significant Data Fiduciaries. This is how we would divide it.

Board and senior leadership

Leadership needs to understand accountability. Section 8(1) puts responsibility on the organisation, and the Schedule puts a price on failure. Leaders also approve the budgets and vendors that decide whether compliance is possible at all. A half-day session on their obligations and the decisions only they can make is usually enough.

The Data Protection Officer or compliance lead

If the government notifies your organisation as a Significant Data Fiduciary, Section 10(2) requires a Data Protection Officer who is based in India, answers to the board and handles grievances. Even if you are not notified, Section 8(9) requires you to publish the contact details of someone who can answer people's questions about their data. Whoever holds that role needs the deepest training: the full Act and Rules, and a sense of how the Board is likely to read them.

Sales, marketing and customer-facing teams

These teams collect most of the personal data an organisation holds, and they are usually the first to hear a complaint. They need to know what a valid notice and consent look like under Sections 5 and 6, and that withdrawing consent must be as easy as giving it. They also need to know how to route a request to access, correct or erase data under Sections 11 and 12, and how to recognise a grievance when it arrives as an angry phone call.

Human resources

HR holds some of the most sensitive data in the building: salaries, medical records, bank details and background checks. Section 7 lets an employer process personal data for employment purposes without consent, but the rest of the Act still applies, including security safeguards and erasure. HR teams need to know what they collect, how long they keep it, and what they may share with payroll providers and insurers.

IT and security

Rule 6 sets the minimum security safeguards: encryption or masking, access controls, logs that can detect unauthorised access, backups, and retention of those logs for at least a year. IT teams usually know the technology. What they often lack is the legal reading: which of these are now mandatory, what “reasonable” is likely to mean before the Board, and what the breach clock requires of them.

Procurement and vendor managers

Section 8(2) lets you use a Data Processor, a vendor that processes personal data on your behalf, only under a valid contract. Section 8(1) keeps you responsible for whatever that vendor does, and Rule 6(1)(f) requires the contract to cover security safeguards. The people who onboard vendors need to know what the contract must say and what to ask before anyone signs. At our college workshop, this was the topic participants most wanted to learn next.

What good DPDP training looks like

Most compliance training fails in the same way. People sit through slides about the law and go back to work unchanged. Good training differs in a few specific ways.

It starts from your own data. Before any session, map what personal data the team actually handles. At the college workshop, we followed a student's data from admission day to graduation. Participants recognised their own forms and spreadsheets, and the law stopped being abstract.

It works through scenarios. “A caller says he is a customer's husband and wants her order history. What do you do?” teaches more than any slide defining a Data Principal, the person the data is about.

It is short, and it repeats. A two-hour session every six months will do more than a full day once. The obligations are new, and habits change slowly.

It measures something. Ask participants the same questions before and after, anonymously. The answers show where confidence is still low, and they give you a record of what you did, which will matter if the Board ever asks.

A training timeline to May 2027

The DPDP Rules come into force in phases. Rules 1, 2 and 17 to 21 took effect on publication on 13 November 2025. Rule 4, on Consent Managers, takes effect on 13 November 2026. Everything else, including security safeguards and breach intimation, takes effect on 13 May 2027. Our implementation roadmap sets out the wider compliance work; working back from that date, training fits in like this.

  1. Now to December 2026

    Brief the board and senior leadership. Map the personal data each team handles. Decide who will be your Data Protection Officer or contact person under Section 8(9).

  2. January to March 2027

    Run role-based sessions for the teams described above. Start with vendor management and customer-facing staff, where most mistakes happen.

  3. April 2027

    Run a breach drill against the Rule 7 timelines: notice to the Board without delay, and a detailed report within 72 hours.

  4. From 13 May 2027

    Hold refresher sessions every six months, and train every new joiner who will handle personal data before they start.

These dates could still change. MeitY has reportedly considered a shorter window for Significant Data Fiduciaries, and our implementation tracker follows what is still pending.

How CADP runs DPDP training

CADP is a research centre at KLE Law College, Bengaluru. Our sessions are designed by lawyers who work on the DPDP Act every day, and each one is built around the organisation's own data flows. We run executive seminars for leadership, role-specific sessions for teams, and preparation for the Data Protection Officer function. You can read more on our DPDP training page, or see how a recent session went in our workshop report from KLE Degree College, Nagarabhavi.

So, go back to the sales executive and her Friday evening email. She was not careless; nobody had told her. One scenario in one session, “can I email customer data to my personal account?”, would have stopped her before she clicked send. That is what training does under the DPDP Act, and it costs far less than the alternative.

Common Questions

Frequently Asked Questions

Is DPDP training mandatory?

Neither the DPDP Act nor the DPDP Rules, 2025 use the word "training". But Section 8(4) of the Act requires every Data Fiduciary to implement appropriate organisational measures to ensure compliance, and Rule 6(1)(g) repeats this for security safeguards. Training the people who handle personal data is the most basic organisational measure, and it is hard to show the Data Protection Board that your measures were appropriate without it.

Who in an organisation needs DPDP training?

Anyone who collects, uses, shares or makes decisions about personal data. In practice that means the board and senior leadership, the Data Protection Officer or compliance lead, sales, marketing and customer-facing teams, HR, IT and security, and the people who onboard vendors. Each group needs different content.

When should organisations complete DPDP training?

Before 13 May 2027, when the core obligations under the DPDP Rules, 2025 take effect, including notice, security safeguards and breach intimation. Leadership briefings and data mapping should happen first, followed by role-based sessions and a breach drill in the months before the deadline.

How often should DPDP training be repeated?

We recommend short refresher sessions every six months, and training for every new joiner who will handle personal data. The obligations are new, and habits change slowly.

Does training reduce penalties under the DPDP Act?

The Act does not list training as a mitigating factor. However, Section 33(2) asks the Board to consider whether an organisation acted to mitigate a breach, and how quickly and effectively it did so. Staff who have practised a breach response are far more likely to act in time.

Train Your Teams

Plan your DPDP training before May 2027

Tell us who handles personal data in your organisation, and we will propose sessions built around your own data flows.