Primary sources first
Statutory claims start with the Gazette of India, MeitY publications, notified Rules, corrigenda, commencement notifications and official decisions.
DPDP Academy is an independent educational website for reading the Digital Personal Data Protection Act, 2023, understanding the notified Rules, and translating them into practical implementation work.
Statutory claims start with the Gazette of India, MeitY publications, notified Rules, corrigenda, commencement notifications and official decisions.
Pages distinguish enacted requirements from implementation suggestions. Practical guidance is labelled as guidance and never presented as a government direction.
The site is educational, not a law firm, regulator, accredited university or government certification authority. It does not claim a named advocate has reviewed material unless that person is identified.
Everything is free to read, with no account and no paywall. The statutory text is reproduced verbatim; everything built on top of it is labelled as editorial explanation.
All 44 sections and the Schedule of penalties, reproduced as published in the Gazette. Every provision has its own page and its own stable URL, so a specific section can be cited directly.
Open the Act reader →Chapter-level explanations, a provision-level DPDP-versus-GDPR comparison, the notified Rules 2025 with their phased commencement dates, and 9 sector implementation guides anchored to the provisions that single each sector out.
Browse the guides →An applicability checker, a penalty calculator built on the Schedule and the section 33(2) factors, a 24-control readiness checklist, and editable consent and breach templates in open formats.
Open the checklist →A 10-question practice test with explanations after every answer, and a graded 15-question exam at 70% to pass. Both are free, with no sign-up and no card.
See the certification →A site that reproduces a statute is only worth reading if the reproduction can be checked. Three mechanisms make that possible, and all three are visible in the public repository.
The transcription was compared paragraph by paragraph against the Act as published by MeitY on 9 August 2026. All 365 paragraphs matched, the only differences being page furniture the PDF extractor pulled out of the Gazette margins. Read the source PDF and check any provision yourself.
The file holding the Act is fixed to a SHA-256 hash. Any edit to the statutory text, deliberate or accidental, fails the build until the change has been verified against the MeitY publication and the hash updated in the same commit. Prose can be improved; the Act cannot be quietly reworded.
Section references in the industry guides are checked against the sections that actually exist in the Act each time the site is built. A guide citing a provision that is not there does not ship. Where a claim rests on the Rules rather than the Act, it is reported as unverified rather than presented as checked.
A site teaching a data protection law should be legible under that law. There is no account and no sign-up, so there is no user record to hold. Checklist progress, reading position and exam results are stored in your own browser and are never transmitted to the site. Analytics load only after you consent to them, and the consent banner is served from this domain rather than a third-party network, so asking you about tracking does not itself hand you to another party.
Most sites that reproduce an Act retype it once and never check it again. Reproducing a statute incorrectly is the worst thing a resource like this can do, because a reader has no way to catch it, so the text here is held to a mechanical check rather than to good intentions.
The transcription was compared against the MeitY publication paragraph by paragraph on 9 August 2026: 365 of 365 paragraphs matched, the only differences being page furniture the PDF extractor pulled out of the Gazette margins. The file holding that text is then pinned by a SHA-256 hash recorded in the build scripts. If a single character of the Act changes — deliberately, or through a stray find-and-replace across the repository — the build fails until someone re-verifies the text against the Government's own document and updates the hash in the same commit.
Explanatory pages carry no such guarantee and do not pretend to. They are editorial summaries, they cite the provision they rest on, and they are the part of the site most worth arguing with.
Content is currently published under the organisation-level bylines DPDP Academy Editorial and DPDP Academy Source Review. Those labels describe the work performed; they are not a claim that a named lawyer or other credentialed professional has reviewed it. A personal byline will be added only with the contributor's approval, biography and relevant credentials.
This is DPDP Academy, at dpdpact.net. It is not affiliated with, endorsed by or operated by the Ministry of Electronics and Information Technology, the Data Protection Board of India, or any other government body, law firm, university or compliance vendor. Several unrelated sites use similar names and near-identical domains; a page is part of this resource only if its address begins https://dpdpact.net.
Nothing here is a government-issued qualification. The certification is an educational assessment produced by this site, is not accredited by the Data Protection Board, and confers no legal or professional status. Where you need the authoritative text, the official source register links to the Gazette and MeitY publications directly.
Review standards, source hierarchy and correction handling are published. The application source is public so technical implementation and content changes can be inspected. If you have found an error, write to sam@faceoff.world.
No. It is an independent educational website, not affiliated with, endorsed by or operated by the Ministry of Electronics and Information Technology, the Data Protection Board of India, or any other government body. The Act's authoritative text is published by MeitY, and every page here links to it so you can check the reproduction against the original.
It is not a government-issued qualification and is not accredited by the Data Protection Board. It is an educational assessment produced by this site: it evidences that you sat a graded test on the Act and scored above the pass mark, and nothing more. Treat it as study evidence rather than as a professional credential.
Content is published under the organisation-level bylines DPDP Academy Editorial and DPDP Academy Source Review. Those labels describe the work performed and are not a claim that a named lawyer has reviewed it. A personal byline will be added only with the contributor's approval, biography and relevant credentials.
No. Nothing here is legal advice and no lawyer-client relationship arises from reading it. The statutory text is reproduced faithfully and the explanations cite the provisions they rest on, but applying the Act to a specific organisation needs a qualified practitioner who can take instructions and carry professional liability.
Everything is free to use with no account, no card and no paywall. There are no advertisements, no sponsored placements and no affiliate links, so no page is written to sell anything.
Email sam@faceoff.world or open an issue in the public repository. Errors in the Act's text are corrected as soon as they are verified against the Gazette or the MeitY publication; every correction is recorded in the open.
DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 9 August 2026 against the DPDP Act, 2023 and notified DPDP Rules, 2025. Educational information, not legal advice.