The person who breaks this is rarely the person who read the policy. It is whoever was handed the form, the email or the request.
Short sessions, built around what each group actually touches, delivered by people who work on this rather than read from a deck.
Usually more people than anyone expected, and rarely the ones on the org chart for it. The list itself is often the most useful thing that comes out of this.
Reception, support, HR, marketing, engineering, the board. Same Act, entirely different forty-five minutes, using your forms and your systems as the examples.
In person or remote, in the language the room actually works in, with a short assessment afterwards — because attendance and understanding are different things.
Who was trained, on what, when, and how they scored. Plus the decks, so you can run it again for joiners without paying us to come back.
Refreshers matter more than launches. A single all-hands session decays within months as people join and leave, which is why the material being yours to re-run is part of the deliverable rather than an upsell.
Not for individuals, not for organisations. Every badge on sale in this market is a private certificate, including ours.
The Act creates no accreditation scheme. It does require a Consent Manager to be registered with the Data Protection Board — but that is the registration of one particular kind of service provider, not a qualification anybody can study for. If a vendor implies their certificate carries statutory weight, ask them which provision creates it.
Industry bodies run respected privacy qualifications and they are worth having. None of them is a DPDP requirement either.
All three are about what happens on an ordinary Tuesday, not about what hangs on the wall.
The attachment sent to the wrong name, the login shared to get something done, the export taken home to work on. Rule 6’s safeguards are technical; the opening is usually not.
A rights request or a grievance does not turn up labelled. It reads like a complaint or an awkward email, and the ninety days runs from the day it landed — not from the day somebody realised what it was.
Section 33(2) makes your mitigation and its timeliness express factors in setting a penalty. A trained team that acted quickly and a confused one that did not are not read the same way.
Your notice can be flawless and your consent still void. Section 6(1) requires it to be free, specific and informed — and “just sign here, it’s a formality” at the counter undoes every word of the document.
A generic awareness deck is the reason most privacy training is forgotten by Friday. Nobody in the room could see themselves in it.
How consent is actually given or ruined at the counter, what a form has to say, and how to recognise a request when it arrives in person.
Spotting a rights request or grievance inside an ordinary complaint, and logging it the day it arrives, because that is when the period starts.
Employment data under section 7(i), what an ex-employee can and cannot require, candidate retention, and wellness data that must not reach managers.
Why section 7 offers no legitimate use for marketing, why optional toggles default off, and what makes a purpose new rather than adjacent.
The safeguards Rule 6 actually names, a year of logs, and what counts as a breach — including a lockout where nothing left the building.
Where the exposure sits, the decisions only they can make, and what a Significant Data Fiduciary designation would change. Thirty minutes, not an afternoon.
The front desk and the support inbox handle more personal data in a week than the leadership team touches in a year, and they are almost never trained first.
No. The Act creates no accreditation or certification scheme, for individuals or for organisations, so every "DPDP Certified" badge currently on sale in India is a private certificate issued by whoever printed it — ours included. The one registration the Act does require is of Consent Managers with the Data Protection Board, and that is the registration of a particular kind of service provider rather than a qualification anyone can study for. If a vendor implies otherwise, the fair question is which provision creates the scheme they are selling you into.
It records that a named person was trained on a stated syllabus on a given date, which is a real and useful thing. Section 33(2) makes what you did in advance an express factor when a penalty is set, so a training record is part of the evidence that you took the obligation seriously. It also answers the training question that appears in almost every customer due-diligence questionnaire, and it shows you who has not done it — which in practice is what most clients want it for.
You can, and it is the most common way privacy training is wasted. The person on reception and the person writing the database schema have almost nothing in common in what they need to know, and a session pitched to cover both is too abstract for either. Worse, generic awareness training teaches people that this is somebody else's job. Where budget is tight the better trade is fewer groups trained properly than everyone trained vaguely — and we would start with the front desk and the support inbox.
By saying the wrong thing while handing over the right form. Section 6(1) requires consent to be free, specific, informed and unambiguous. "Just sign here, it's a formality" makes it uninformed; "we can't admit you unless you tick all of these" makes it conditional, and section 6(2) voids any part of a consent that infringes the Act. Your notice can be perfectly drafted and the consent still fail, because the quality of consent is created at the counter rather than in the document.
Often enough to survive your staff turnover, which for a front desk or a support team can mean twice a year, and less for a stable engineering group. This is why the material is yours to keep and re-run: paying an outside firm to deliver the same forty-five minutes to each new joiner is a poor use of money. We would rather sell you a refresh when the law or your processes actually change than an annual repeat of the same session.
People who do this work rather than trainers who read a deck, which matters mostly because of the questions. The useful part of a session is almost always somebody describing a real situation from their own week and asking what they should have done — and answering that needs someone who has handled it, not someone with the next slide queued up. Sessions run in the language the room actually works in.
Real client quotes, attributed by role and sector — we never name a client.
Working across
Not with the board, not with a policy sign-off. With the desk where somebody is asked for their details forty times a day.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.