GDPR:
Compliance for global companies serving EU residents
"We're already GDPR compliant, so DPDP should be easy" is the assumption that gets companies into trouble. GDPR is the most consequential data protection regulation in the world — and the frameworks it resembles share a family resemblance, not an identical rulebook.
2018
In force since
EU Regulation 2016/679
4%
Max fine
of global annual turnover, or €20M
72 hrs
Breach notification
to the supervisory authority
6
Lawful bases
incl. consent, contract, legitimate interest
What is GDPR?
The General Data Protection Regulation governs how organisations collect, process, and store personal data of individuals in the EU — and it applies regardless of where the organisation processing that data is incorporated. Any company with EU customers, EU employees, or EU website visitors it profiles is very likely in scope.
Core data subject rights
GDPR vs. DPDP — where they diverge
| Dimension | GDPR | DPDP |
|---|---|---|
| Primary lawful basis | 6 bases incl. broad "legitimate interest" | Consent-led, narrower enumerated "legitimate uses" |
| Breach notification | 72 hours, to EU supervisory authority | To India's Data Protection Board, DPDP timeline |
| Max penalty | €20M or 4% global turnover | Up to ₹250 crore per instance |
| Extraterritorial reach | Yes — any EU resident's data | Yes — any Indian resident's data |
| DPO requirement | Mandatory for certain processing types | Mandatory for Significant Data Fiduciaries |
Full breakdown of legal-basis structure, consent mechanics, and breach-routing differences:GDPR vs. DPDP: Key Differences for Global Companies →
Frequently Asked Questions
If we're already GDPR compliant, are we automatically DPDP compliant too?
Does DPDP recognise the same 'legitimate interest' legal basis GDPR does?
How do breach notification timelines compare between GDPR and DPDP?
Does a company need separate compliance programs for GDPR and DPDP, or can they be unified?
Not sure if GDPR applies to your organisation?
Our compliance team scopes applicability in a 30-minute call — no charge.
Explore Related
Multi-framework compliance programs with shared controls — DPDP, GDPR, HIPAA, ISO 27001, SOC 2, PCI DSS.
Discovery and classification work that underpins both GDPR and DPDP obligations.
Multi-jurisdiction consent (DPDP, GDPR, CPRA) from a single console.
Unified governance platform with GDPR, ISO 27001, and ISO 27701 compliance packs.