Home / Insights / Data Privacy Compliance: GDPR, DPDP and Beyond

Data Privacy Compliance: GDPR, DPDP and Beyond

Jan 1, 2026 • 5 min read

Data Privacy Compliance: GDPR, DPDP and Beyond

Cyber crime lawyer Delhi — IT Act, digital evidence, online fraud defence

Data privacy compliance has become a board-level concern for businesses operating in India. The Digital Personal Data Protection Act 2023, the EU General Data Protection Regulation, and cross-border data transfer rules create overlapping obligations that most organizations struggle to navigate. If your business collects, processes, or stores personal data, understanding these frameworks is no longer optional.

For Indian companies with EU customers or operations, GDPR compliance is a live requirement, not a future concern. For all businesses handling Indian personal data, the DPDP Act sets mandatory standards that carry penalties of up to INR 250 crore. The regulatory environment is evolving fast, and gaps in compliance carry real financial and reputational risk.

What the DPDP Act 2023 Requires

The Digital Personal Data Protection Act 2023 applies to the processing of personal data within India and to the processing of personal data outside India where it relates to offering goods or services to data principals in India. Key obligations include: lawful basis for processing (consent or legitimate use), transparency in data collection practices, purpose limitation (collect only what is needed), storage limitation (retain only as long as necessary), data breach notification within 72 hours, and appointment of a data protection officer for significant data fiduciaries.

The Data Protection Board of India has powers to investigate violations, issue directions, and impose penalties. Penalties for data breach failures can reach INR 200 crore. For failure to obtain valid consent, penalties can reach INR 250 crore. These are not theoretical risks — the Board has already begun accepting complaints.

GDPR and Indian Businesses

If your business offers goods or services to EU residents, or monitors the behavior of EU residents, GDPR applies regardless of where your business is based. Indian tech companies, SaaS platforms, BPOs, and e-commerce businesses with EU customers are all in scope.

GDPR obligations include: lawful basis for processing (consent, legitimate interest, contract performance), data subject rights (access, rectification, erasure, portability), privacy by design and by default, data protection impact assessments for high-risk processing, 72-hour breach notification to supervisory authorities, and appointment of a Data Protection Officer for public authorities or core activities involving large-scale monitoring.

Cross-Border Data Transfer Rules

Both GDPR and the DPDP Act restrict cross-border data transfers. Under GDPR, transfers to countries without adequacy decisions require appropriate safeguards: Standard Contractual Clauses, Binding Corporate Rules, or adequacy decisions. The EU’s Schrems II ruling invalidated the Privacy Shield framework and required companies to conduct transfer impact assessments for SCC-based transfers.

Under the DPDP Act, cross-border transfers of personal data are permitted only: to countries with adequate data protection (as determined by the Indian government), with informed consent from the data principal, under a legal instrument between India and the destination country, or for specified cases permitted by the government. Until the government publishes its adequacy list, most cross-border transfers rely on consent or contractual mechanisms.

Data Breach Response

A data breach is any unauthorized access, disclosure, alteration, or destruction of personal data. Breaches can result from cyber attacks, employee negligence, vendor failures, or system vulnerabilities. The DPDP Act requires data fiduciaries to notify the Data Protection Board and affected individuals within 72 hours of becoming aware of a breach.

A breach response plan should cover: identification and containment of the breach, assessment of the type and volume of data affected, notification to the Data Protection Board, notification to affected individuals, forensic investigation, remediation of vulnerabilities, and post-breach monitoring. For businesses subject to GDPR, parallel obligations to EU supervisory authorities may apply.

Practical Compliance Steps

Start with a data inventory. Map what personal data you collect, where it is stored, who has access to it, and how long you retain it. Without this map, compliance is guesswork. Next, review your privacy notices and consent mechanisms. Ensure they describe what data is collected, why it is collected, how it is used, and who it is shared with. Consent must be free, specific, informed, and unambiguous.

Third-party vendor management is another area where compliance often breaks down. Many data breaches originate from vendors — payment processors, hosting providers, SaaS platforms — rather than from the business itself. Vendor contracts must include data protection obligations, audit rights, and breach notification commitments. A cyber lawyer can help you draft and negotiate these provisions.

Common Questions

What is the difference between DPDP Act and GDPR?

DPDP Act is India’s domestic data protection framework, focused on Indian data principals. GDPR applies to EU residents’ data anywhere in the world. Both require lawful basis for processing, data subject rights, and breach notification. GDPR is generally stricter in its consent requirements and carries higher penalties. Businesses handling both EU and Indian personal data must comply with both frameworks.

Does DPDP Act apply to small businesses?

Yes, but with graduated obligations. Small businesses and startups have reduced compliance burdens compared to significant data fiduciaries. The Data Protection Board can issue different rules for different categories of data fiduciaries. However, the basic obligations — lawful processing, transparency, and breach notification — apply to all businesses processing personal data.

What are the penalties for DPDP Act violations?

Penalties range from INR 10,000 to INR 250 crore depending on the nature of the violation. Data breach failures: up to INR 200 crore. Failure to obtain valid consent: up to INR 250 crore. The Board also has powers to issue warnings, require remediation, and direct the suspension of data processing activities.

Do I need a Data Protection Officer?

Only if you are classified as a significant data fiduciary — typically large-scale processors of personal data, government entities, or businesses processing data of children. The DPDP Act empowers the government to designate categories of data fiduciaries that require a DPO. If not mandated, appointing a DPO voluntarily is good practice and signals commitment to compliance.

Related Practice Areas

Data privacy compliance requires legal expertise
Bijlani & Co advises businesses on DPDP Act compliance, GDPR obligations, and data breach response across Delhi NCR. Contact us at +91-96549-26593 or write@bijlani.in.



Chat on WhatsApp

Or call: 085958 09471
scale

Stay Ahead of Legal Trends

Authoritative analysis on corporate law and litigation delivered directly to your inbox. Curated by our partners.

Confidentiality maintained. Unsubscribe at any time.

§

Senior Partner

Specializes in complex corporate litigation and regulatory compliance with over 15 years of experience in high-stakes disputes.

View Full Profile arrow_forward