Does complying with the DPDP Act mean we comply with the GDPR?
No. The structures overlap but the obligations are separate. The DPDP Act rests on consent and legitimate uses, while the GDPR has six legal bases, portability and objection rights, and mandatory impact assessments for high-risk processing. Each has to be discharged on its own terms.
What has to be done
- Sign the Commission's Standard Contractual Clauses and select the module that matches the real roles: controller to processor for most IT services and BPO work, controller to controller where the Indian entity decides purposes of its own.
- Complete a transfer impact assessment covering Indian government access powers, including the Information Technology Act section 69 interception route and the Telecommunications Act, and record what you concluded.
- Document supplementary measures concretely: encryption in transit and at rest, keys held in the EU, field minimisation, pseudonymisation of production data used in development, and a documented process for handling government access requests.
Citations
- GDPR Article 44: general principle for transfers
- GDPR Article 45: transfers on an adequacy decision
- GDPR Article 46: transfers subject to appropriate safeguards
- GDPR Article 47: binding corporate rules
- GDPR Article 48: transfers not authorised by Union law
- GDPR Article 49: derogations for specific situations
- GDPR Article 28: processor obligations
Full requirement
Source and version
- Read date
- 2026-08-26
- Address
- /in/questions/dpdp-and-gdpr
Continue
Nästa steg
Vill ni använda registret i eget arbete finns tre vägar in.
Börja med din uppgift
Advokat, tvist
Hitta stöd i avgörande
Sök i vägledande domar, se vad som vunnit laga kraft och följ ändringar i rättsläget.
Bolagsjurist, transaktion
Kartlägg regelverket i affären
Gå från tema till rättsakt och vidare till artikeln som bär kravet.
Compliance
Bedöm risken i en behandling
Riskklassning per rättsområde, med källorna bakom varje poäng.