
Explore the concept of intermediaries under the Indian IT act, tracing 2000 to 2021 updates, including cyber cafes, ISPs, and the pass through role to avoid content modification.
Illustrate privacy by design through a restaurant payment example, showing how embedding privacy at the center guides business decisions, product design, and service rollout.
Organizations manage confidential, personal, and sensitive personal data and protect them with consent-based safeguards and contractual measures under the information technology act.
India lacks a comprehensive data protection law; the IT Act and 2011 privacy rules govern sensitive data under section 43A and general data under section 72A, plus sectoral regulations.
Explain section 43 and 43A of the IT act, and define sensitive personal data, reasonable security practices, and uncapped damages, with examples like passwords, biometric data, health and financial information.
Analyze a data privacy case: Amit Patwardhan vs Route India Chains, involving bank data. The court treats bank statements as sensitive personal data and supports purposive interpretation of financial information.
Navigate sensitive personal data rules by implementing security practices, defining collection purposes, managing consent, disclosures, transfers, data retention, and establishing a grievance officer.
Explore section 72A of the IT act, governing personal data in services under lawful contracts, excluding sensitive data, with penalties up to 3 years or Rs 5 lakh for disclosure.
Explore the Personal Data Protection Bill journey, from the 2017 Justice Srikrishna Committee to the Joint Parliamentary Committee, and Parliament's path to debate and rollout.
Explore the Personal Data Protection Bill, 2019 highlights, including extraterritorial jurisdiction, data localization, cross-border transfers, new compliances, data subject rights, penalties, and the proposed data protection authority.
Identify two penalty buckets under the PDP Bill 2019: 15 crore rupees or 4% of worldwide turnover, whichever higher, and five crore rupees or 2% plus imprisonment and compensation.
Understand the proposed rollout timeline for the Personal Data Protection Bill 2019, with a two-year, phase-wise implementation similar to the GDPR.
Define data fiduciary and data principal, noting the trust relationship with data processors under the PDP bill and sensitive data scope including financial, health, official identifiers, biometric and genetic data.
Explore the grounds of processing data, starting with consent and including function of state, reasonable purposes, employment, compliance with law, and court prompt action.
Explain grounds for processing under the PDP, focusing on consent as a basis with affirmative, informed, specific, and withdrawable elements, plus explicit consent for sensitive data.
Identify non-consensual processing grounds under the PDP bill, including government orders, health services in epidemics, and disaster responses. Examine employment-related grounds and future reasonable purposes for data processing.
Explore the essential elements of a privacy policy under the personal data protection bill, including data categories, purpose, consent withdrawal, cross-border transfer, retention, data trust score, and rights.
Understand the rights of individuals under the Personal Data Protection Bill 2019, including access, correction, erasure, data portability, and the right to be forgotten against further disclosure.
Discover the rights of data principals under the Personal Data Protection Bill, including access, correction, erasure, data portability, and the right to be forgotten, with data fiduciary duties and enforcement.
Identify general and significant data fiduciary compliances under the PDP bill, including privacy by design, transparency, security safeguards, breach notification, grievance redressal, impact assessments, records, data audits, and DPO requirements.
The PDP bill adopts a graded breach notification approach, requiring a notice detailing the nature of personal data breached, affected individuals, consequences, remedies, and authority notification, with data subject disclosure.
Understand data localization under the PDP bill, where personal data may transfer abroad, sensitive data stays in India, and critical data rarely leaves, highlighting organizational challenges and evolving rules.
Explore the obligations of a data fiduciary under the PDP Bill 2019, including purpose limitation, fair processing, and comprehensive notice to data principals.
Educate every level to build privacy champions and demonstrate PDP bill compliance. Perform gap analysis, map a route to staged, customized implementation for each entity.
Explore the intermediary concept under the IT act, tracing changes from 2000 through the 2021 guidelines and emphasizing pass-through roles of ISPs, cyber cafes, and online platforms.
Clarifies why intermediaries enjoy safe harbour under section 79, requiring compliance with either 2A or 2B and 2C, plus due diligence and central guidelines under 2021 IT intermediary guidelines.
Explain how the 2011 IT intermediaries guidelines evolved into the 2021 rules, defining social media intermediary and significant social media intermediary, with a 50 lakh user threshold and related obligations.
Outline the due diligence obligations for intermediaries, including publishing privacy policy and user agreement, handling prohibited information, takedown timelines, data retention, security rules, and a graded grievance redressal mechanism.
Appoint a chief compliance officer, a nodal contact person, and a resident grievance officer in India to enforce IT act compliance and enable first originator identification under section 69.
Learn how India's information technology act defines cyber security incidents and mandates reporting to CERT-In, including annexure items like targeted scanning, unauthorized access, malware, phishing, with timing and format obligations.
SkillxPro brings to you the most encompassing, up-to-date and sought-after training and certification program for privacy and data protection. This course will arm you with the insight and skill needed to handle data privacy-related issues and advisory, which you will handle as a transactional or data-privacy lawyer. DPP is a practical-oriented course to equip you with and help you understand the real-time issues and works around data privacy as a data privacy or transactional lawyer.
As skilled privacy data privacy lawyers are in high demand, this certification is what recruiters and employers are looking for. When you earn a DPP credential, you earn the right to be recognized as part of a group of knowledgeable, capable and dedicated privacy professionals. DPP is a pioneer credentialing program that empowers you with knowledge and equips you with the necessary skills to advance your career in the field of data privacy.
Gain the required skills to conduct a baseline review of your client/ organisation’s current position and report issues or the effectiveness of the Indian legal framework related to the IT Act and GDPR. Using a step-by-step approach, you’ll learn the very basics to advanced level of data protection and the legal framework.