A 30-module course on the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Plan on about 15 minutes a day. Passing earns a certificate of completion from Consent Guru. It is not a government, university, or Data Protection Board accreditation.
30 modules, about 15 minutes each
A video, a lesson, and a 15-question quiz in every module
Modules unlock in order, and your progress is saved
A 50-question final exam drawn from the module questions
A certificate when you pass
Modules
30
Duration
30 days, 15 min a day
Level
Foundation
Instructor
Consent Guru
Before you start
Read this before you enrol. It is the note from the first page of the programme, with what you need in place to begin.
Prerequisites
A Consent Guru account, so your progress, quizzes, and certificate stay with you.
No earlier DPDP module. This foundation programme begins with privacy, data protection, and the terms used in the Act.
About 15 minutes a day for 30 days.
A score of 60% or more on each module quiz and on the final exam.
Disclaimer
Legal status note: The Digital Personal Data Protection Rules, 2025 were notified by the Ministry of Electronics and Information Technology on 13 November 2025. The Act and Rules have a phased commencement structure. References in this programme should therefore be read subject to the applicable commencement date.
This training material is educational in nature and should be read with the official Gazette notifications and the final statutory text.
Verify a certificate
Enter the certificate ID printed on a Consent Guru DPDP certificate. A valid certificate is good for one year from the date it was issued.
Curriculum
30 modules, each with a video, a lesson, and a 15-question quiz. Sign in to enrol. Lessons stay private to your account.
0115 min
Introduction to Data Protection and Privacy
Privacy is about appropriate control and protection of information about individuals. Data protection is the organisational framework that turns that principle into rules, responsibilities, processes and safeguards. Cybersecurity is a major supporting layer, but it is not the whole of privacy compliance. A secure system can still misuse data if it collects information for an unclear purpose or retains it unnecessarily. Conversely, a well-written privacy policy is not sufficient if the underlying systems are insecure.