The Practitioner Track
The full, practitioner-grade certification. Eight section-mapped modules take you across the whole Act and Rules, then a timed exam from a 272-question bank earns you a verifiable Certified DPDP Practitioner certificate.
Outcomes
Concrete capabilities you carry away - not just knowledge, but what to do with it.
Build a defensible inventory of personal-data flows
Operate lawful notice, consent and withdrawal
Run rights and grievances within statutory timelines
Stand up a 72-hour breach response with evidence
The curriculum
About 205 minutes of focused study, each module tied to the sections it draws from.
Set the scope precisely - most compliance errors trace back to a wrong call made right here.
The Act governs digital personal data processed in India, and processing outside India where it's tied to offering goods or services to Data Principals in India (Section 3).
Distinguish the Data Principal, the Data Fiduciary (determines purpose and means) and the Data Processor (acts on the Fiduciary's instructions). Accountability sits with the Fiduciary, always.
Digital - or digitised - personal data is in scope; purely personal or domestic processing and certain published data sit outside it (Section 3).
Takeaway - Pin down who the Fiduciary is and whether the processing is in scope before designing a single control.
Learn by doing
Pressure-test your judgement the way an audit would. Call compliance gaps, decide your SDF status, and keep the vocabulary sharp.
Read each practice and make the call an auditor would.
A fiduciary keeps closed-account KYC documents for ten years “just in case”, with no legal requirement to.
Run DPDP compliance end to end.
From a free DPDP risk check to a board-ready roadmap, Anix TrustStack helps you manage AI and DPDP together - securely and sustainably.