EU · Data Protection

GDPR:
Compliance for global companies serving EU residents

"We're already GDPR compliant, so DPDP should be easy" is the assumption that gets companies into trouble. GDPR is the most consequential data protection regulation in the world — and the frameworks it resembles share a family resemblance, not an identical rulebook.

2018

In force since

EU Regulation 2016/679

4%

Max fine

of global annual turnover, or €20M

72 hrs

Breach notification

to the supervisory authority

6

Lawful bases

incl. consent, contract, legitimate interest

What is GDPR?

The General Data Protection Regulation governs how organisations collect, process, and store personal data of individuals in the EU — and it applies regardless of where the organisation processing that data is incorporated. Any company with EU customers, EU employees, or EU website visitors it profiles is very likely in scope.

Core data subject rights

Right to access
Right to rectification
Right to erasure ("right to be forgotten")
Right to restrict processing
Right to data portability
Right to object

GDPR vs. DPDP — where they diverge

DimensionGDPRDPDP
Primary lawful basis6 bases incl. broad "legitimate interest"Consent-led, narrower enumerated "legitimate uses"
Breach notification72 hours, to EU supervisory authorityTo India's Data Protection Board, DPDP timeline
Max penalty€20M or 4% global turnoverUp to ₹250 crore per instance
Extraterritorial reachYes — any EU resident's dataYes — any Indian resident's data
DPO requirementMandatory for certain processing typesMandatory for Significant Data Fiduciaries

Full breakdown of legal-basis structure, consent mechanics, and breach-routing differences:GDPR vs. DPDP: Key Differences for Global Companies →

Frequently Asked Questions

If we're already GDPR compliant, are we automatically DPDP compliant too?
No — the two frameworks share conceptual DNA but differ in specific mechanics that matter operationally: consent structure, the legal basis model, breach notification timelines, and enforcement structure all diverge in ways that require their own gap assessment. GDPR compliance is a strong starting foundation, not a substitute for a dedicated DPDP review.
Does DPDP recognise the same 'legitimate interest' legal basis GDPR does?
Not in the same broad form. DPDP's structure leans more heavily on consent as the primary lawful basis for processing, with a narrower, more specifically defined set of "legitimate uses" than GDPR's broader legitimate interest category.
How do breach notification timelines compare between GDPR and DPDP?
Both frameworks require prompt notification, but the specific timelines, thresholds, and notified party differ — DPDP notification goes to India's Data Protection Board, distinct from GDPR's notification path to the relevant EU supervisory authority within 72 hours.
Does a company need separate compliance programs for GDPR and DPDP, or can they be unified?
They can and generally should be unified at the evidence and control level — much of the underlying work (data discovery, classification, access governance) serves both frameworks simultaneously. What can't be unified is the framework-specific layer: consent mechanics, legal basis categorisation, and breach notification routing.

Not sure if GDPR applies to your organisation?

Our compliance team scopes applicability in a 30-minute call — no charge.

Book a scoping call