DPDP Act 2023: Building Employee Data-Privacy Awareness Training for Indian Companies

Neither the DPDP Act nor the Rules 2025 contains an express employee-training requirement. What rule 6 does require, which roles need which training, what happens in the first hour of a breach, and what an LMS has to be able to prove.

ET
EdzLMS Team
·15 September 2026·22 min read
⚡ Quick answer

Neither the Digital Personal Data Protection Act, 2023 nor the Digital Personal Data Protection Rules, 2025 contains a provision that requires an organisation to run employee privacy training. What rule 6 does require of a Data Fiduciary is “appropriate technical and organisational measures to ensure effective observance” of the Act, alongside named safeguards such as access control, logging and monitoring. Awareness training is one of the ordinary ways the organisational half of that phrase is put into practice and evidenced, which is a different claim from a statutory training mandate, and the difference matters when a programme is being justified internally. Rule 6 sits in the eighteen-month phase and commences in May 2027. Because obligations attach to roles rather than to headcount, the training that organisations are building tends to be split by what a role actually touches — HR with employee records, sales with customer data, engineering with logs and backups, and frontline staff who collect consent — rather than delivered as one generic module.

This is general information, not legal advice.

DPDP obligations depend on the facts of your organisation and how it processes personal data. The Rules are phased and some provisions have not yet commenced. Before you act on anything here, take advice from a qualified professional on your own circumstances.

13 Nov 2025
DPDP Rules, 2025 published in the Official Gazette
May 2027
Rule 6 security safeguards commence, eighteen months from publication
72 hours
To file the detailed breach report with the Board under rule 7
6 hours
CERT-In cyber incident reporting window, in force since 2022

Key takeaways

  • There is no express employee-training requirement anywhere in the DPDP Act, 2023 or the DPDP Rules, 2025. Rule 6(g) requires “appropriate technical and organisational measures to ensure effective observance”, and awareness training is one of the ways the organisational half of that is commonly implemented and demonstrated.
  • Rule 6 is in the eighteen-month phase under rule 1(4) and commences in May 2027. Rule 4, on Consent Manager registration, commences one year from publication in November 2026. Sources differ by a day on the exact commencement dates, because they turn on how the publication date is counted; the months are not in dispute.
  • Obligations under the Act attach to the Data Fiduciary, which determines the purpose and means of processing. A Data Processor acts on a Fiduciary's behalf under contract, and rule 6(f) addresses that relationship through contractual provision rather than by placing the same duties on the processor directly.
  • Rule 7 addresses breach intimation in two parts: the affected Data Principal is told without delay, and a detailed report reaches the Data Protection Board within seventy-two hours. Separately, the CERT-In directions of 2022 carry a six-hour reporting window and are already in force, independent of the DPDP timeline.
  • The Schedule to the Act sets penalty ceilings: up to two hundred and fifty crore rupees for a breach of the security-safeguards obligation, and up to two hundred crore rupees for a breach of the obligation to give notice of a personal data breach.
  • As of the most recent public reporting, the Data Protection Board's Chairperson and Members had not assumed office, no Consent Manager had been registered, and no enforcement action had been published. The framework's substantive obligations are approaching rather than operating.

What the Rules actually say about training

A great deal of published commentary states that the DPDP framework mandates employee privacy training. It is worth being precise about this, because the claim does not survive a reading of the text. Neither the Digital Personal Data Protection Act, 2023 nor the Digital Personal Data Protection Rules, 2025 — notified on 13 November 2025 — contains a provision directing a Data Fiduciary to train its staff.

What rule 6 does is set a floor for reasonable security safeguards. It requires a Data Fiduciary to protect personal data in its possession or under its control by taking reasonable security safeguards to prevent a personal data breach, which shall include, at the minimum, securing of personal data through encryption, obfuscation, masking or the use of virtual tokens; appropriate measures to control access to the computer resources used; appropriate logs, monitoring and review to enable detection of unauthorised access; reasonable measures for continued processing, such as data backups; retention of logs and personal data for a period of one year; appropriate provision in the contract between the Data Fiduciary and any Data Processor; and appropriate technical and organisational measures to ensure effective observance of the Act.

That last clause is where training sits. “Organisational measures” is not defined in the Rules, and it is the phrase under which awareness programmes, role-based access discipline, internal policy and escalation routes are conventionally grouped in practice. The honest position is therefore narrower than the boilerplate and more useful: training is not a named statutory requirement, but it is one of the ordinary means by which the organisational half of rule 6(g) is implemented and evidenced. An organisation building a programme on that basis is on firmer ground than one told it is legally compelled to, and the distinction tends to survive scrutiny better when a budget is being defended.

Rule 6 does not yet apply. Rule 1(4) places rules 3, 5 to 16, 22 and 23 in force eighteen months after the date of publication, which falls in May 2027. Rule 1(3) places rule 4, on Consent Manager registration, in force one year after publication, in November 2026. Published sources differ by a day on both dates — 12 or 13 November 2026, 12 or 13 May 2027 — because they count the publication date differently. That ambiguity is real and it is not resolved here; it makes no practical difference to a training plan measured in quarters. The phasing is set out in full in our guide to what the DPDP Rules say and when they apply.

Who the obligations fall on

The Act distributes duties by role, not by size, and the roles are worth separating before any training is designed, because who in the organisation needs to know what follows directly from them.

A Data Fiduciary is whoever determines the purpose and means of processing personal data. Almost every obligation in the Act attaches here: notice, consent, purpose limitation, security safeguards, retention and erasure, breach intimation and the handling of data principal rights.

A Significant Data Fiduciary is a Data Fiduciary, or class of them, notified as such by the Central Government on the basis of factors including the volume and sensitivity of data processed and the risk to the rights of Data Principals. Rule 13 adds duties: a Data Protection Impact Assessment and an audit once in every period of twelve months, with significant observations furnished to the Board; due diligence to verify that technical measures including algorithmic software are not likely to pose a risk to the rights of Data Principals; and, for personal data specified by the Central Government, a restriction against transfer outside India. No class had been notified as Significant at the time of writing.

A Data Processor processes personal data on a Data Fiduciary's behalf. The Act does not replicate the Fiduciary's duties onto the processor. Rule 6(f) instead addresses the relationship through appropriate provision in the contract between them. In practice this means a processor's staff are usually trained against contractual commitments their employer has made, rather than against a direct statutory duty — a distinction that changes what the training content can honestly assert.

Which roles need what

This is the part that general privacy-awareness content tends to skip, and it is the part that determines whether a programme holds up when someone asks to see it. Because obligations follow what a role touches, a single all-staff module covers the concepts and leaves the specifics unaddressed for every role that has any. A programme that reflects the structure of the Rules is usually split roughly as follows.

RoleWhat that role touchesWhat the training addresses
HR and people operations Employee and candidate records, payroll inputs, background checks, exit files That employee data is personal data like any other; the purpose for which each field was collected; how long records are kept and on what basis; what happens to candidate data for applicants who were not hired; and how an access or erasure request from an employee is routed rather than answered ad hoc
Sales and marketing Customer and prospect records, CRM exports, campaign lists, enrichment tools Purpose limitation as it applies to a list collected for one purpose and used for another; what a notice covered at the point of collection; why exporting a CRM segment to a personal spreadsheet or an unvetted tool is the common failure; and the status of purchased or enriched contact data
Engineering and IT Production databases, application logs, backups, staging environments, third-party APIs That logs and backups contain personal data and fall inside the same obligations; rule 6's named safeguards — encryption, masking, tokenisation, access control, monitoring — as engineering work rather than policy language; the one-year log retention provision; why copying production data into staging is a processing decision; and how erasure interacts with backup media
Frontline and field staff Consent at the point of collection, forms, kiosks, walk-in and doorstep interactions What a notice has to convey and in which languages it is available; that consent is for a specified purpose rather than a signature to be obtained; how to answer a question about why the data is being collected; and what to do when someone declines or later withdraws
Managers and process owners New tools, vendors, and processes that create or move personal data That introducing a tool is a processing decision; when a processor contract needs the rule 6(f) provision; and who inside the organisation is told before data moves somewhere new
Everyone Email, shared drives, messaging, devices What counts as personal data; the first-hour breach route; and the fact that the reporting clock starts at suspicion rather than at confirmation

Consent, purpose and rights, in language an employee can use

Three ideas carry most of the day-to-day weight, and they translate into employee language reasonably cleanly.

Notice and consent. Under the Act, a request for consent is accompanied by a notice describing the personal data and the purpose for which it is proposed to be processed, and consent is limited to what is necessary for that specified purpose. The employee-facing version is that the form is the promise: whatever the notice said the data was for is what it can be used for.

Purpose limitation. The commonest breach of this in practice is not malicious. It is a list collected for one thing being reused for another because it was available. A recognisable version for training is that data collected for a service is not automatically available for a campaign.

Data principal rights. The Act gives individuals rights of access, correction, completion, updating, erasure and grievance redressal, exercisable against the Data Fiduciary. What staff need is not the jurisprudence but the route: recognising that a request has been made — including when it arrives informally, as most do, by email or in conversation — and knowing where it goes, because an unrecognised request is the one that becomes a grievance.

The first hour of a breach

Breach response is the part of privacy training most often left as a policy document nobody has read. The employee-facing portion is small and specific, and rule 7 sets out what the organisation then has to be able to do.

Rule 7 requires the Data Fiduciary to inform each affected Data Principal, in a concise, clear and plain manner and without delay, of the nature, extent and timing of the breach, the consequences likely to arise, the mitigation measures implemented, the safety measures the individual may take, and contact details for queries. In parallel, the Board is given a description without delay, and a detailed report — covering the events leading to the breach, the measures implemented, findings on the cause, remedial measures and a report on the intimations given to Data Principals — within seventy-two hours, or a longer period the Board allows in writing.

Two points are worth stating plainly in any training that covers this. The first is that those clocks are measured from the organisation becoming aware, which makes the interval between an employee noticing something and telling someone the only part of the timeline an individual controls. The second is that rule 7 has not commenced — it sits in the May 2027 phase — whereas the CERT-In directions of 2022, with their six-hour reporting window for specified cyber incidents, are already in force and independent of the DPDP timeline. An organisation that trains only against the 72-hour figure is training against the slower of two clocks, and the one that does not yet apply.

  1. 1
    Notice, and say so immediately

    The part an individual controls is the gap between seeing something and reporting it. Programmes that work set the threshold at suspicion, not confirmation, and say explicitly that a false alarm carries no consequence — otherwise the first hour is spent by an employee privately checking whether it is real.

  2. 2
    Report to one named route

    One address or channel, published in the training itself, that does not depend on knowing who the right person is or on that person being at their desk. Escalation paths that require judgement about severity tend to fail at the moment they matter.

  3. 3
    Preserve rather than tidy

    Rule 7(2) requires a report to the Board on the events leading to the breach and findings on its cause. Deleting the suspicious message, clearing a mailbox or reinstalling a laptop removes what that report is assembled from. Rule 6(c) and 6(e) address logs and their retention for the same reason.

  4. 4
    Do not notify anyone externally

    Intimation to Data Principals and to the Board under rule 7 is an organisational act with prescribed content. Training generally makes clear that individual staff do not contact affected people, customers or the press, and where questions are directed instead.

  5. 5
    Record the time

    Both the DPDP clocks and the CERT-In six-hour window run from awareness. The time something was first noticed, and by whom, is the fact the whole subsequent timeline is reconstructed against, and it is the one most reliably lost.

Where an off-the-shelf privacy module tends to be sufficient

  • The population is broad and the obligation is general awareness — what personal data is, what the Act covers, where to report a suspicion
  • The organisation is a Data Processor whose staff are trained against contractual commitments rather than direct statutory duties
  • Headcount is modest and no role handles a materially different category of data from any other
  • The requirement is to stand something up before a deadline and refine it afterwards
  • No sector regulator layers its own training expectations on top of the DPDP position
  • The evidence needed is completion by name and date, and the module's own reporting produces it

Where it tends not to be

  • Roles diverge sharply — engineering with production data and logs, frontline staff collecting consent — and a single module addresses neither specifically
  • The organisation has been notified as a Significant Data Fiduciary, or expects to be, and rule 13's assessment and audit duties need a documented training position
  • Consent is collected in person, in languages the workforce actually uses, and generic English content does not reach the people doing it
  • Processes are specific enough that generic examples are visibly not about this organisation, which is what makes staff disengage
  • The evidence has to show per-role assignment and refresher cadence, not a single completion list
  • A sector regulator's expectations have to be reconciled with the DPDP position in one coherent curriculum

The evidence trail

The question a training programme ultimately has to answer is not whether it ran but whether it can be shown to have run, per person, per role, on a date, against a version of the content. Rule 6(g)'s “organisational measures” and rule 13's assessment and audit duties for Significant Data Fiduciaries both point at records rather than intentions. Framed as what a system has to be able to prove rather than as a feature list, that comes to five things.

Who was assigned what, and why. Not a completion list for a single module, but a record showing that a person in a given role was assigned the curriculum that role's processing activity calls for. The “and why” matters: the mapping from role to content is the part that demonstrates the programme was designed rather than distributed.

Completion, with the version attached. A completion record that does not say which version of the content was completed cannot establish what somebody was actually told. Where content changes as the phases commence — and between now and May 2027 it will — version-stamped completion is the difference between a record and an assertion.

Refresher cadence, and what happens when it lapses. A one-off completion in 2027 says progressively less each year. The evidence a system needs to produce is the schedule, the re-assignment and the exception list of people who did not complete, which is the part that shows the cadence is enforced rather than aspirational.

Movement between roles. Someone who moves from sales into an engineering-adjacent role acquires a different processing surface. A system that assigns training at induction and never again produces an evidence trail that was accurate on someone's first day and has been drifting since.

An export that can be handed over. The practical test is whether the whole picture — assignment, completion, version, date, role — can be produced as a single coherent export without somebody reconciling spreadsheets for a week. A learning platform that can do this turns a training programme into documentation. One that cannot leaves an organisation asserting that training happened.

Delivery in the languages the workforce uses

Consent collection at the point of contact is frequently done by people whose working language is not English, and a privacy module in English delivered to that population produces completion records without producing comprehension — which is the failure mode that matters, because the record then evidences something that did not occur.

The problem is not specific to privacy training. It is the same delivery constraint that arises in statutory workplace training generally, and the approaches that work are the same: translated rather than transliterated content, audio for staff who read less comfortably than they listen, mobile delivery for people who are not at a desk, and assessment in the same language as the instruction. We have written about this in the context of POSH training in our guide to building versus buying POSH training modules, and the reasoning transfers directly. Where content has to be produced rather than licensed, the practicalities are set out in our course development work.

Where this sits in the wider picture

Two things are worth holding together. The substantive obligations are approaching rather than operating: rule 6 and rule 7 commence in May 2027, and as of the most recent public reporting the Data Protection Board's Chairperson and Members had not assumed office, no Consent Manager had been registered, and no enforcement action of any kind had been published. At the same time the Schedule to the Act sets the ceilings that will apply when they do — up to two hundred and fifty crore rupees for a breach of the obligation to take reasonable security safeguards, up to two hundred crore rupees for a breach of the obligation to give notice of a personal data breach, up to two hundred crore rupees in relation to the additional obligations concerning children under section 9, and up to one hundred and fifty crore rupees in relation to a Significant Data Fiduciary's additional obligations under section 10.

That gap between a distant commencement date and a long lead time is the substance of the planning problem, and it is not specific to training. For organisations weighing platforms against that timeline, our 2026 buyer's guide to compliance training software covers the evaluation in general terms, and the DPDP pillar covers the phasing and the Fiduciary/Processor question in more depth. Where learner data belongs to children, the education provisions post sets out what the Fourth Schedule does and does not cover.

💡

The dates are not the hard part — the inventory is

Every account of DPDP readiness that reports a ranked list of obstacles puts the legacy-environment problem at or near the top, ahead of interpreting the Act. The reason is that a role-based training matrix cannot be built until somebody knows which systems hold personal data and which roles reach them, and in most organisations of any age that map does not exist in written form. Organisations working to the May 2027 date have generally started there rather than with the curriculum, because the inventory is the input the curriculum is derived from.

Frequently asked questions

Does the DPDP Act require employee privacy training?

Not in express terms. Neither the Act nor the DPDP Rules, 2025 contains a provision requiring a Data Fiduciary to train its employees. Rule 6 requires reasonable security safeguards which shall include, at the minimum, a list of named measures ending with “appropriate technical and organisational measures to ensure effective observance” of the Act. Awareness training is one of the ordinary ways the organisational component of that is implemented and evidenced. The distinction between that and a statutory training mandate is worth preserving, because the two support different claims.

When does this actually apply?

Rule 1(4) brings rules 3, 5 to 16, 22 and 23 — which include the rule 6 security safeguards and the rule 7 breach intimation provisions — into force eighteen months after the date of publication of the Rules on 13 November 2025, which falls in May 2027. Rule 1(3) brings rule 4, on Consent Manager registration, into force one year after publication, in November 2026. Rules 1, 2 and 17 to 21 took effect on publication. Published sources differ by a day on the two computed dates because they count the publication date differently; the months are not in dispute.

Is a single all-staff privacy module enough?

It depends on what the roles in the organisation actually touch. Obligations under the Act attach to processing activity, so an organisation where every role handles broadly the same data may be adequately served by one module, while one where engineering holds production data and logs, HR holds employee records and frontline staff collect consent has three materially different processing surfaces and a generic module addresses none of them specifically. The question to test a programme against is whether the content a given person received corresponds to what that person can actually reach.

What is the difference between a Data Fiduciary and a Data Processor for training purposes?

A Data Fiduciary determines the purpose and means of processing and carries almost all the obligations in the Act. A Data Processor processes on a Fiduciary's behalf; the Act does not replicate those duties onto it, and rule 6(f) addresses the relationship through appropriate provision in the contract between the two instead. The practical consequence is that a processor's staff are generally trained against commitments their employer has made contractually rather than against direct statutory duties, and training content that asserts otherwise is overstating the position. The classification follows the facts of who decides what, not the label used in an agreement.

What does an employee need to do in the first hour of a suspected breach?

The part an individual controls is reporting, promptly, through a route that does not require judgement about severity, while preserving rather than deleting whatever was noticed, and recording when it was first seen. Rule 7 then requires the organisation to inform each affected Data Principal without delay with prescribed content, and to give the Data Protection Board a description without delay and a detailed report within seventy-two hours or a longer period the Board allows in writing. Rule 7 has not commenced. The CERT-In directions of 2022, with a six-hour reporting window for specified cyber incidents, are already in force and run on a separate track.

What records should a training programme be able to produce?

Framed as what has to be demonstrable rather than as features: which curriculum each person was assigned and on what basis in their role; completion with the content version attached, so the record establishes what was actually covered; the refresher schedule together with the exception list of non-completions; reassignment when someone changes role and their processing surface changes with it; and the ability to export all of that as one coherent record rather than reconciled spreadsheets. Rule 13 requires a Significant Data Fiduciary to undertake a Data Protection Impact Assessment and an audit once in every period of twelve months and to furnish significant observations to the Board, which is the setting in which such records are typically produced.

Is it too early to start, given that the obligations commence in 2027?

That is a judgement for each organisation against its own facts, and both positions are defensible. The observation most commonly made is that the binding input is not the curriculum but the data inventory it is derived from — which systems hold personal data and which roles reach them — and that in organisations running accumulated legacy estates this is reported as the slowest part of readiness rather than the fastest. Against that, the content itself will need revision as the phases commence, so material written now is unlikely to be the material delivered in 2027.

Mapping training to the roles that hold the data

If you are working out what a role-based privacy curriculum looks like in your organisation, and what your learning platform would need to evidence when somebody asks, we are happy to walk through it against your actual role structure rather than a template.

Book a Free Demo

Related reading: DPDP for LMS and Edtech: what the Rules say and when they apply · Children's data under DPDP · POSH training modules: build vs buy · Compliance training software: the 2026 buyer's guide · Course development

Sources: the Digital Personal Data Protection Act, 2023 and the Schedule thereto; the Digital Personal Data Protection Rules, 2025, published in the Official Gazette on 13 November 2025, rules 1, 6, 7 and 13; the CERT-In Directions of 28 April 2022 under section 70B(6) of the Information Technology Act, 2000. Positions stated were verified against these sources in September 2026.

Tags

DPDPcomplianceIndiaemployee trainingdata protectionprivacy

See EdzLMS in action.

Book a 45-minute demo tailored to your industry.

Book a Free Demo →