📱Test our Android app — free beta!Join Beta GroupYou'll receive the install link by email after joining.

Differences

This shows you the differences between two versions of the page.


courses:dpdp:module-02 [2026/06/03 17:01] (current) – created - external edit 127.0.0.1
Line 1: Line 1:
 +{{htmlmetatags>metatag-keywords=(dpdp module 02, data principal rights + fiduciary obligations)&metatag-description=(DPDP Act 2023 + Rules 2026 Crash Course — Module 02: Data principal rights + Fiduciary obligations. Map every right + obligation to a practical action.)}}
 +
 +====== Module 02 — Data principal rights + Fiduciary obligations ======
 +
 +{{ :social:auto:dpdp-module-02.png?direct&1200 |DPDP Act 2023 + Rules 2026 Crash Course Module 02}}
 +
 +<WRAP center round info 95%>
 +**Goal:** Map every right + obligation to a practical action.
 +</WRAP>
 +
 +===== Rights of data principals (§11-§14) =====
 +
 +  - **§11 — Right to information** about processing (similar to GDPR Art. 15)
 +  - **§12 — Right to correction + erasure** (similar to Art. 16-17, but with limits)
 +  - **§13 — Right to grievance redressal** — file with Fiduciary first; escalate to DPB
 +  - **§14 — Right to nominate** — appoint another individual to exercise rights upon death/incapacity
 +
 +Notably absent: data portability, right to object to processing (compared to GDPR).
 +
 +===== Obligations of fiduciaries (§8) =====
 +
 +Every Fiduciary must:
 +  - Process for lawful purpose only
 +  - Implement reasonable security safeguards
 +  - Notify the DPB + affected data principals of breaches
 +  - Erase data when purpose is fulfilled (and inform Processors)
 +  - Publish business contact for grievance officer
 +
 +===== Significant Data Fiduciary additional obligations =====
 +
 +SDFs (notified by Government):
 +  - Appoint **Data Protection Officer** (DPO) based in India
 +  - Conduct **Data Protection Impact Assessment** (DPIA) for high-risk processing
 +  - Conduct **periodic audits** by independent Data Auditors
 +
 +Likely SDFs: large e-commerce, healthcare aggregators, banking, telco.
 +
 +===== Children's data (§9) =====
 +
 +  - Verifiable parental consent required for processing children's data (<18)
 +  - Cannot do **tracking, behavioural monitoring, targeted advertising** at children
 +  - Cannot cause **harm** to children
 +  - DPB can exempt platforms that demonstrate verifiable safe processing
 +
 +===== Cross-border transfer (§16) =====
 +
 +Default: data can flow to **any country EXCEPT those notified as restricted** by Central Government.
 +
 +This is more permissive than GDPR's adequacy decisions. The restricted list (when notified) becomes the bottleneck.
 +
 +===== ✅ Quiz =====
 +
 +Quiz available from your [[:courses:dpdp:app|course dashboard]].
 +
 +===== Next =====
 +
 +  * [[:courses:dpdp:start|← Course overview]]
 +  * Next: [[:courses:dpdp:final]]
 +
 +//Last reviewed: 24 April 2026.//
 +
 +{{tag>course dpdp module-02}}