Table of Contents
Module 03 — DPDP Rules 2026 — operational details
Notice format (Rule 3)
Privacy notice must:
- Be in English + at least one schedule language preferred by data principal
- State purpose in clear, plain language
- List categories of personal data processed
- State rights + how to exercise
- Include link to Fiduciary's contact + grievance officer
- Include withdrawal mechanism
Format: maximum 1 page; readable on a phone.
Consent records (Rule 4)
Each consent must be logged with:
- Identity of data principal
- Date + time + IP / device fingerprint
- Purpose for which consent given
- Verbatim notice text version-stamped
Retention: until consent is withdrawn + 2 years for compliance audit.
Breach notification (Rule 7)
Personal data breach → notify within 72 hours:
- To DPB: incident details, scope, mitigation
- To affected data principals: nature of breach, expected harm, mitigation steps
- Even if low-risk, log internally
Failure to notify = penalty up to ₹250 crore (per §33 Schedule).
Children's consent (Rule 10)
Verifiable parental consent methods:
- Aadhaar-linked OTP to parent
- DigiLocker-issued parent ID
- Video-call verification + signed consent form
No single method mandated; Fiduciary picks 'reasonable' method.
Cross-border restricted list (Rule 12)
Central Government can notify restricted countries. Until notified — all destinations open.
For a Fiduciary: monitor MeitY notifications; tag data flows by destination country in your data inventory; have a contingency plan for re-routing if a destination is restricted.
✅ Quiz
Quiz available from your course dashboard.
Next
Last reviewed: 24 April 2026.

