Why This Training Matters
DPDPA is not simply a legal or compliance requirement. It is gradually changing the way organizations collect, use, store, share, retain and dispose of personal data.
For professionals across IT, Cybersecurity, HR, Finance, Sales & Marketing, Operations, Procurement and Business Management, understanding DPDPA is becoming an important part of their professional responsibility.
The objective of this training is therefore not merely to explain the Act, but to help participants understand:
- What DPDPA means for their organization and their specific role
- How personal data moves through an organization and where privacy risks arise
- What changes may be required in existing business processes
- How consent, notices, data retention, deletion and Data Principal rights affect day-to-day operations
- How employees and vendors can create privacy and compliance risks
- How cybersecurity and data protection work together
- How organizations can prepare for data breaches and privacy incidents
- How to contribute to their organization’s DPDPA readiness rather than treating it as only a legal department’s responsibility
What Participants Will Take Back
At the end of the two-day program, participants should be able to:
- Identify personal-data exposure
Understand where personal data exists within their function and how it is collected, processed, shared and retained. - Recognize privacy risks in everyday work
Identify common practices that may create DPDPA risks, including excessive data collection, inappropriate sharing, uncontrolled retention and inadequate security. - Understand their professional responsibility
Clearly understand how DPDPA impacts different functions and what is expected from them in their respective roles. - Participate effectively in compliance initiatives
Be better prepared to work with their organization’s IT, Security, Legal, HR, Compliance and Business teams during DPDPA implementation. - Make better business decisions involving personal data
Understand the privacy implications before introducing new applications, processes, vendors, marketing initiatives or data-driven services. - Contribute to organizational readiness
Take away practical checklists and implementation guidance that can be applied within their own organization.
In short, the objective is that participants should not leave the session simply knowing “what DPDPA says,” but should understand “what I need to do differently in my professional role because of DPDPA.”
Contents :
Day 1 – Understanding DPDPA & Its Business Impact
- Introduction to Data Privacy & Protection in India
- DPDPA 2023 – regulatory landscape and business context
- Key terminology – Data Principal, Data Fiduciary, Data Processor, Consent Manager, etc.
- Applicability of DPDPA to organizations
- Understanding Personal Data and Processing Activities
- Lawful Processing, Notice and Consent
- Rights of Data Principals
- Obligations of Data Fiduciaries
- Children’s Personal Data
- Data Retention, Erasure and Purpose Limitation
- Data Breach Management and Incident Response
- Cross-border transfer and third-party/vendor considerations
- Significant Data Fiduciaries and additional obligations
- Penalties, risks and business implications
- Practical case studies and interactive discussion
Day 2 – From Compliance Understanding to Implementation
- Building a DPDPA Compliance Framework
- Data Discovery, Inventory & Classification
- Data Flow Mapping and Records of Processing
- Data Protection Impact Assessment
- Consent Management Framework
- Data Principal Request & Grievance Management
- Data Retention & Secure Disposal
- Vendor & Third-Party Data Protection
- Privacy Policies, Notices, SOPs and Governance
- Technical & Organizational Security Measures
- Data Breach Response & Regulatory Readiness
- Employee Awareness & Privacy Culture
- DPDPA Compliance Roadmap – 30/60/90-day approach
- Practical DPDPA Readiness Checklist
- Interactive Q&A and participant-specific scenarios
Training Approach
The program will be designed as a business-oriented and practical learning session, rather than a purely legal or theoretical training.
The sessions will use:
- Real-world business scenarios
- Industry examples
- Practical exercises
- Data-flow and processing examples
- Role-based discussions
- Compliance checklists
- Implementation guidance
- Interactive Q&A
This approach will help participants connect the regulatory requirements with their actual professional responsibilities and day-to-day business decisions.
Speaker Profile: Jayesh Ghotkar is a seasoned Corporate Trainer and Technology Educator with over 10 years of dedicated training experience, backed by a further 15+ years as a practicing cybersecurity and IT governance professional. Brings the rare combination of deep hands-on domain expertise and the proven ability to communicate complex technical and regulatory concepts clearly and engagingly to diverse audiences — from fresh graduates to senior enterprise professionals.
Currently specialises exclusively in four high-demand compliance and governance training domains: ISO 27001:2022 Information Security Management Systems, ISO 27701 Privacy Information Management Systems, ISO 42001:2023 AI Management Systems, and DPDPA 2023 Data Privacy compliance delivering as a Certified Lead Auditor and Certified Data Protection Officer. These are among the most strategically relevant frameworks for regulated enterprises in India today, particularly across BFSI, IT/ITeS, healthcare, and manufacturing sectors navigating rapidly evolving information security and privacy obligations.
Brings a rich earlier career in technology training spanning networking, cybersecurity, software programming, databases, hardware, load balancing, and Web Application Firewalls providing a broad technical foundation that enriches the depth and contextual relevance of current governance and compliance training. Has successfully delivered corporate training programs for international audiences in Dubai and Egypt, demonstrating cross-cultural adaptability and professional delivery at a global level.

