Module 03 — DPDP Rules 2026 — operational details
Goal: Master the practical implementation rules.
Privacy notice must:
Be in English + at least one schedule language preferred by data principal
State purpose in clear, plain language
List categories of personal data processed
State rights + how to exercise
Include link to Fiduciary's contact + grievance officer
Include withdrawal mechanism
Format: maximum 1 page; readable on a phone.
Consent records (Rule 4)
Each consent must be logged with:
Identity of data principal
Date + time + IP / device fingerprint
Purpose for which consent given
Verbatim notice text version-stamped
Retention: until consent is withdrawn + 2 years for compliance audit.
Breach notification (Rule 7)
Personal data breach → notify within 72 hours:
To DPB: incident details, scope, mitigation
To affected data principals: nature of breach, expected harm, mitigation steps
Even if low-risk, log internally
Failure to notify = penalty up to ₹250 crore (per §33 Schedule).
Children's consent (Rule 10)
Verifiable parental consent methods:
Aadhaar-linked OTP to parent
-
Video-call verification + signed consent form
No single method mandated; Fiduciary picks 'reasonable' method.
Cross-border restricted list (Rule 12)
Central Government can notify restricted countries. Until notified — all destinations open.
For a Fiduciary: monitor MeitY notifications; tag data flows by destination country in your data inventory; have a contingency plan for re-routing if a destination is restricted.
✅ Quiz
Next
Last reviewed: 24 April 2026.