India’s DPDP framework in comparison with the GDPR and the CCPA

Nine years ago today, a nine-Judge Bench of the Supreme Court of India decided that privacy is not a concession granted by the State but a right that belongs to the person. The Court located it in the guarantee of life and personal liberty under Article 21 and in the freedoms running through Part III of the Constitution, and in doing so it moved privacy out of the realm of polite expectation and into the realm of enforceable right. Privacy became a question of dignity, autonomy and choice rather than of confidentiality alone.

That was the principle. What has taken the intervening nine years, and what is still taking shape, is the far less romantic work of turning the principle into something a compliance team can actually do on a Tuesday morning. India now has the statute, the rules and the dates. What it does not yet have, and this is the part worth watching is a regulator with people in the chairs.

From Puttaswamy to the DPDP Act

Following Puttaswamy, the Committee of Experts chaired by Justice B.N. Srikrishna examined India’s framework and recommended a comprehensive law, publishing its report and a draft Bill in July 2018. Several rounds of consultation, one withdrawn Bill and five years later, the Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023.

The Act chose its own vocabulary. An organisation that determines the purpose and means of processing is a Data Fiduciary, not a controller; the individual is a Data Principal, not a data subject. The choice is not cosmetic. Fiduciary language imports an idea of trust and of duties owed, and it will matter when the Board and the courts come to interpret what a Data Fiduciary ought to have done in a given case.

The framework became operational on 13 November 2025, when the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025. Crucially, the Act and the Rules do not commence on a single date. The provisions establishing the Data Protection Board took effect immediately; the Consent Manager registration regime follows at the twelve-month mark in November 2026; and the substantive obligations, notice, consent, security, breach reporting, retention and the rights of Data Principals take effect eighteen months from notification, which points to around 13 May 2027. Any advice that treats the DPDP Act as either fully in force or not in force at all is wrong in both directions.

What the Rules actually ask of a business

The Rules are where broad statutory principle becomes operational detail, and the detail is mostly unglamorous.

Notice comes first. A privacy notice must be a standalone, intelligible document that gives a fair account of what is being processed and why, itemised rather than gestured at, with a working link through which consent can be withdrawn and rights exercised. Anyone who has drafted one of these knows that the hard part is not the drafting; it is persuading the business to describe what it is actually doing.

The Rules then build infrastructure that has no real analogue in either Europe or California: a register of Consent Managers, intermediaries through which an individual can give, review, manage and withdraw consent across multiple Data Fiduciaries from a single interface. If this works, it is genuinely interesting, a structural answer to consent fatigue rather than a rhetorical one. If it does not, it becomes another layer between the individual and the organisation holding their data.

Security is prescribed with unusual specificity: encryption, masking, tokenisation, role-based access control, monitoring, and log retention for at least a year. This is a drafting choice with consequences. Prescription gives certainty today and dates badly tomorrow.

Breach management deserves a correction that has been repeated wrongly often enough to have hardened into received wisdom. India does not have a simple seventy-two-hour breach rule. On becoming aware of a personal data breach, a Data Fiduciary must inform affected Data Principals without delay and give the Board an initial intimation without delay, with a fuller report following within seventy-two hours or such longer period as the Board may allow. The first obligation is immediate; the seventy-two hours attaches to the detail, not the disclosure. The difference is the difference between a compliant response and a penalty.

Retention is now a hard number for some. Large e-commerce entities and social media intermediaries with at least two crore registered users, and online gaming intermediaries with at least fifty lakh, must erase personal data three years after the Data Principal last approached them, subject to exceptions and to retention required by other law. And before erasure, the individual gets at least forty-eight hours’ notice and an opportunity to keep the account alive. For a platform with crores of users, that is not a policy question. It is an engineering programme.

For Significant Data Fiduciaries, designated by the Government by reference to volume, sensitivity and risk, the burden rises again: an annual Data Protection Impact Assessment, an annual audit, and due diligence to verify that the technical measures used, expressly including algorithmic software do not pose a risk to the rights of Data Principals. That last obligation is the one to watch. It is a statutory hook for algorithmic accountability sitting inside a data protection rule, and it will bite precisely as organisations move decision-making into models they did not build and cannot fully explain. The same rule reserves a localisation power: the Government may specify categories of personal data that a Significant Data Fiduciary must not transfer out of India at all. Nothing has been specified yet, which is not the same as nothing being coming.

India and the GDPR

The General Data Protection Regulation remains the reference point against which every newer regime is read, built on lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. The similarities with the DPDP framework are real: individual rights, transparency, security obligations, regulated international transfers, and a designated regulator.

The differences are more instructive than the similarities.

The first is the basis for processing. The GDPR offers six lawful bases, including contract, legal obligation, vital interests, public task and the workhorse of European practice, legitimate interests. The DPDP Act is consent-centric, supplemented by an enumerated list of ‘legitimate uses’ rather than an open-textured balancing test. In practice this means an Indian compliance programme cannot lean on a documented legitimate interests assessment the way a European one does. The consent flow has to carry weight that, in Europe, is distributed across six bases.

The second is the catalogue of rights. The GDPR gives portability, a right to object, and protection against solely automated decisions with legal or similarly significant effects. The DPDP Act gives access, correction, erasure, grievance redressal and nomination, the last being a genuinely thoughtful addition, allowing an individual to appoint someone to exercise their rights on death or incapacity, but it does not replicate the European list. There is no DPDP equivalent of Article 22.

The third is children. The GDPR sets sixteen as the default age for consent in relation to information society services, with Member States free to go as low as thirteen. India takes a single, higher line: anyone under eighteen is a child, verifiable parental consent is required, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited, subject to narrow carve-outs for health, education and child-safety contexts. This is the single largest operational lift in the Indian framework for any consumer-facing platform, and the one where enforcement is most likely to be early and public.

The fourth is cross-border transfer, where India is the more liberal regime. The GDPR conditions transfers on adequacy or appropriate safeguards. The DPDP Act permits transfer to any country except those the Central Government restricts by notification, a negative list rather than a positive one, and no restricted list exists yet. For once, the Indian position is the easier one to advise on. It is also the one most exposed to sudden change by executive notification, which is why cross-border architecture should be built to be restriction-ready rather than merely compliant today.

It is also worth saying plainly that the GDPR is not a fixed point of comparison at the moment. The European Commission’s Digital Omnibus proposal of November 2025 would amend the GDPR itself, including the definition of personal data and aspects of breach reporting and impact assessment. The EDPB and EDPS have supported simplification while warning against narrowing the concept of personal data, and the data-side amendments remain under negotiation. India is converging on a moving target.

India and the CCPA

The California Consumer Privacy Act, as amended by the California Privacy Rights Act, proceeds from a different premise altogether. It is not a comprehensive, federal-style data protection law but a consumer protection statute that applies to businesses meeting revenue or data-volume thresholds, and it is organised around transparency and control over commercial uses, particularly the sale and sharing of personal information.

California residents have rights to know, delete and correct, to opt out of sale and sharing, and, in specified circumstances, to limit the use and disclosure of sensitive personal information. California also does something neither India nor Europe has yet done at scale: it requires businesses to honour a machine-readable opt-out preference signal, such as Global Privacy Control, as a valid request. That is privacy expressed as a setting rather than as a series of clicks, and it is the most quietly consequential idea in American privacy law.

The conceptual distinction is this. The GDPR and DPDP frameworks regulate the lawfulness of processing from the outset; the CCPA concentrates on giving the consumer meaningful control over particular commercial uses after collection. India sits closer to Brussels than to Sacramento in architecture, but closer to Sacramento than one might expect in its instinct for prescriptive, operational rules.

The convergence is happening at the algorithm. California’s regulations on automated decision-making technology, risk assessments and cybersecurity audits took effect on 1 January 2026, with obligations phasing in through 2030: risk assessments for processing from 2026 with first attestations due in April 2028, cybersecurity audits by revenue tier from 2028, and compliance for significant automated decisions by January 2027. California has separately built a centralised deletion mechanism, through which a consumer makes one request that registered data brokers must act on.

Read those alongside Rule 13 of the Indian Rules and the pattern is unmistakable. Three very different legal systems have independently arrived at the same three instruments: mandatory assessment of high-risk processing, independent verification of security, and scrutiny of algorithmic decision-making. The labels differ. The compliance artefacts are increasingly the same document with a different cover page.

The real test is implementation

India now has the foundations of a modern privacy regime, with penalties to match up to two hundred and fifty crore rupees for a failure to take reasonable security safeguards. But legislation does not create privacy, and neither do penalties on paper.

The uncomfortable fact, as at the date of writing, is that the enforcer is not yet in place. The provisions constituting the Data Protection Board of India came into force on 13 November 2025. The Government has visibly worked the process, a communication of 6 May 2026 seeking nominations for the posts of Chairperson and Members, a further notification in June and yet, on the public record, the Search-cum-Selection Committees appear still to be soliciting names, and no Chairperson or Member has been appointed. A Board that exists in law but not in fact cannot receive a breach intimation, cannot hear a grievance, and cannot give the framework the interpretive content that only adjudication supplies. Meanwhile, courts have begun directing litigants towards it.

For organisations, the phased timeline is not a reprieve; it is a runway, and it is shorter than it looks. The work that has to happen before May 2027 is the work that always takes longest: knowing what data you hold, why you hold it, who inside and outside the organisation can reach it, where it travels, how long it stays, and what happens operationally when someone asks for it to be corrected or erased. Vendor and processor contracts have to be reopened, because the Act makes the Data Fiduciary answerable for its processor. Consent journeys have to be redesigned rather than relabelled. Retention has to become a configuration rather than an aspiration.

Privacy notices have to become documents a person can read and act on, not disclaimers drafted to be survived. Security has to be owned as an operational responsibility of the business rather than parked with IT. And for anyone building or buying algorithmic decision-making, the assessment obligations arriving in India, Europe and California within roughly the same eighteen months should be read as one signal rather than three.

India need not reproduce either the European or the Californian model, and it has not. Its framework is consent-forward like Europe’s, prescriptive like California’s, and more permissive than both on cross-border flows, a genuinely distinct settlement rather than a translation. Whether it succeeds will depend on whether it can hold the balance between innovation, the legitimate business use of data, and the dignity and autonomy of the individual, and on whether the institution meant to hold that balance is actually staffed and working.

Because in the end, data privacy is not really about protecting information. It is about protecting the person behind the information.