Skip to main content

Boardroom Answers · Security & Compliance · Compliance, Regulatory & Legal

Everyone claims GDPR readiness and assumes India's DPDP Act is the same thing with a different name. It isn't. What have you actually done for DPDP?

The question a Chief Privacy Officer / DPO asks.

The short answer

DPDP is engineered-for by name — consent trails in an immutable log, the same executed erasure pipeline, breach-deadline tracking, Japan hosting currently permissible under s.16, and an India cell coded and waiting for the day localisation demands it.

The full executive answer

Agreed — and the differences you're alluding to are the ones we've engineered around. DPDP is consent-centric in a way GDPR isn't (no legitimate-interests catch-all), it introduces the Data Fiduciary/Data Processor split with duties weighted onto the fiduciary, and its transfer regime is a government blacklist rather than an adequacy whitelist. In that structure, our customers are typically the Data Fiduciary and we are the Data Processor under Section 8 — so our job is to make YOUR fiduciary duties dischargeable: verifiable consent trails (our append-only audit log timestamps consent events immutably), erasure that actually executes (Section 12 rights ride the same shipped pipeline as GDPR Article 17 — export, scheduled deletion, cascade), and breach intimation support, where DPDP is stricter than GDPR: notification to the Data Protection Board and affected individuals, with our incident module's jurisdiction-aware deadline tracking built for exactly this multi-regime reality.

DPDP is a named jurisdiction in our compliance catalogue, our data-protection registry, and our retention policy — the code comments cite it alongside GDPR explicitly, which tells you it was designed-for, not retrofitted. On transfers: hosting in Japan is currently permissible under Section 16 since Japan isn't on any restriction list, and the India cell is coded and configuration-ready for the day localisation rules tighten or a customer's sectoral regulator (RBI-adjacent entities, for instance, carry their own localisation expectations) requires in-country hosting. Same honest gating as Europe: we don't claim Indian residency until the cell is live.

What's honestly open: DPDP's subordinate rules are still crystallising — Significant Data Fiduciary designations, consent-manager interoperability specifics — and no vendor can truthfully claim final-form compliance with rules not yet notified. Our position is architecture that tracks the statute's structure (consent evidence, erasure, breach intimation, transfer readiness) plus the regulatory-horizon monitoring to move when the rules do. If your DPO team maintains a DPDP control checklist, mapping it against our implementation is an exercise we'd welcome — gaps found now are cheaper than gaps found in an audit.

Grounded in: India DPDP Act 2023 ss.4–8 (consent, fiduciary/processor duties), s.8(6) (breach intimation), s.12 (erasure), s.16 (transfers); GDPR contrast (Art. 6 lawful bases).

Want this answered live, on your data?