Boardroom Answers · Security & Compliance · Compliance, Regulatory & Legal
Everyone claims GDPR readiness and assumes India's DPDP Act is the same thing with a different name. It isn't. What have you actually done for DPDP?
The question a Chief Privacy Officer / DPO asks.
The short answer
DPDP is engineered-for by name — consent trails in an immutable log, the same executed erasure pipeline, breach-deadline tracking, Japan hosting currently permissible under s.16, and an India cell coded and waiting for the day localisation demands it.
The full executive answer
Agreed — and the differences you're alluding to are the ones we've engineered around. DPDP is consent-centric in a way GDPR isn't (no legitimate-interests catch-all), it introduces the Data Fiduciary/Data Processor split with duties weighted onto the fiduciary, and its transfer regime is a government blacklist rather than an adequacy whitelist. In that structure, our customers are typically the Data Fiduciary and we are the Data Processor under Section 8 — so our job is to make YOUR fiduciary duties dischargeable: verifiable consent trails (our append-only audit log timestamps consent events immutably), erasure that actually executes (Section 12 rights ride the same shipped pipeline as GDPR Article 17 — export, scheduled deletion, cascade), and breach intimation support, where DPDP is stricter than GDPR: notification to the Data Protection Board and affected individuals, with our incident module's jurisdiction-aware deadline tracking built for exactly this multi-regime reality.
DPDP is a named jurisdiction in our compliance catalogue, our data-protection registry, and our retention policy — the code comments cite it alongside GDPR explicitly, which tells you it was designed-for, not retrofitted. On transfers: hosting in Japan is currently permissible under Section 16 since Japan isn't on any restriction list, and the India cell is coded and configuration-ready for the day localisation rules tighten or a customer's sectoral regulator (RBI-adjacent entities, for instance, carry their own localisation expectations) requires in-country hosting. Same honest gating as Europe: we don't claim Indian residency until the cell is live.
What's honestly open: DPDP's subordinate rules are still crystallising — Significant Data Fiduciary designations, consent-manager interoperability specifics — and no vendor can truthfully claim final-form compliance with rules not yet notified. Our position is architecture that tracks the statute's structure (consent evidence, erasure, breach intimation, transfer readiness) plus the regulatory-horizon monitoring to move when the rules do. If your DPO team maintains a DPDP control checklist, mapping it against our implementation is an exercise we'd welcome — gaps found now are cheaper than gaps found in an audit.
Grounded in: India DPDP Act 2023 ss.4–8 (consent, fiduciary/processor duties), s.8(6) (breach intimation), s.12 (erasure), s.16 (transfers); GDPR contrast (Art. 6 lawful bases).
The natural next questions
Related governed answers
- You've clearly built for GDPR and you talk about India. What about California — does CCPA even apply to you, and are you ready for the US state-law patchwork?
- GDPR Articles 15 and 17 — access and erasure. Not your policy: your implementation. What happens, in your system, when I exercise those rights?
- Under Article 30 I must maintain records of processing, and as my processor you feed those records. Can you actually tell me what personal data you process, where, and why — or will I get a shrug?
Want this answered live, on your data?