AMLEGALS — Strategic Lawyering
EU GDPR
+
India DPDPA

Operating under both GDPR and India's DPDPA?
We navigate both.

Organisations with operations spanning the EU and India face the world's two most consequential data privacy regimes simultaneously. AMLEGALS specialises in dual GDPR-DPDPA compliance architecture — building unified programmes that satisfy both frameworks without duplicating cost or creating compliance conflicts.

Overview

Two of the world's most demanding data privacy regimes — and you need to comply with both

The EU General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act 2023 (DPDPA) are the two most significant data privacy laws affecting organisations with cross-border operations involving Europe and India. For EU companies with Indian operations, Indian companies with EU customers, and global multinationals operating in both jurisdictions — dual compliance is not optional. It is mandatory.

While the GDPR and DPDPA share a common philosophy — giving individuals control over their personal data — they differ significantly in their specific requirements, definitions, enforcement mechanisms, and cross-border transfer rules. Organisations that attempt to apply their GDPR programme to India without India-specific adaptation consistently find compliance gaps at the precise points where the two frameworks diverge.

AMLEGALS delivers dual GDPR-DPDPA compliance programmes that are unified, efficient, and legally defensible under both frameworks. Our approach eliminates duplication, resolves conflicts, and builds a single governance architecture that meets both sets of obligations — reducing cost, reducing risk, and positioning your organisation for enforcement readiness in both jurisdictions.


Who Needs Dual Compliance?

If any of the following describe your organisation, you need a dual GDPR-DPDPA programme

EU/UK Company with India Operations

  • EU company with Indian subsidiary
  • EU company with Indian outsourcing / BPO
  • EU SaaS / platform with Indian users
  • EU e-commerce with Indian customers
  • EU pharma / healthcare with India clinical operations

Indian Company with EU Operations

  • Indian IT/ITES company processing EU client data
  • Indian SaaS / product company with EU customers
  • Indian company with EU subsidiary or staff
  • Indian fintech / payment company with EU users
  • Indian pharma with EU clinical trial participants
Gated Reference Material

GDPR–DPDPA Dual Compliance Reference Card

Structured mapping of 12 conflict zones, resolution pathways, and a unified compliance architecture for organisations operating under both GDPR and DPDPA simultaneously.

Reference Card Includes
GDPR vs DPDPA conflict zone mapping
Consent architecture dual-compliance model
Cross-border transfer mechanism comparison
DPO vs SDF obligation reconciliation
Breach notification timeline comparison
Unified compliance programme blueprint

Reference material delivered to your email. No spam.

Insights & Answers

What practitioners and boards are asking

How does India's DPDPA differ from the EU GDPR?

DPDPA and GDPR are structurally independent. DPDPA uses a negative-list model for cross-border transfers under Section 16 rather than GDPR's adequacy regime; it has no right to data portability; it relies on a single Data Protection Board rather than multiple supervisory authorities; it prescribes fixed penalty maximums (up to ₹250 crore) rather than turnover percentages; and it applies only to digital personal data, not paper records.

If we are already GDPR compliant, are we DPDPA compliant?

No. GDPR compliance is a strong foundation but not sufficient. DPDPA requires India-specific notice and consent (Sections 5-6), Section 8(2) processor contracts framed to Indian law, Significant Data Fiduciary duties under Section 10 and Rule 13, breach notification under Rule 7, and cross-border handling under Section 16 alongside sectoral localisation. A gap assessment against DPDPA is essential.

Can one compliance programme cover both GDPR and DPDPA?

Yes, with a mapped control framework. Shared controls — data mapping, consent records, security safeguards, breach processes — can be harmonised, while India-specific requirements (DPO based in India for SDFs, Section 16 transfer rules, Rule 7 breach form) are layered on. An integrated programme avoids duplicate effort while satisfying both regimes.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to GDPR DPDPA?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on GDPR DPDPA under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on GDPR DPDPA under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on GDPR DPDPA?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for GDPR DPDPA rather than a generic checklist.

How do I get a first view of my DPDPA exposure on GDPR DPDPA?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.