Personal Data –
GDPR - applies to any Any information relating to an identified or identifiable natural person. Includes
digital data as well as non-digital data which is a part of a filing system.
DPDPA - applies only to “digital personal data”, which means personal data collected in digital form
and personal data collected or stored in a non-digital form that is subsequently digitised.
Also excludes the personal data that is made publicly available by the data principals or pursuant to a
legal requirement.
Sensitive Data –
GDPR – higher protections to sensitive data and special categories of data
DPDPA - the DPDPA does not differentiate between personal data and sensitive personal data /
special categories of data.
Significant Data Fiduciaries –
GDPR – No such concept is recognized
DPDPA – SDF’s are recognized by the Govt. based on volume and sensitivity of personal data
processed; (b) risk to the rights of the data principal; (c) potential impact on the sovereignty and
integrity of India; (d) risk to electoral democracy; (e) security of the State; and (f) public order.
Additional compliance obligations will apply, such as appointing a resident data protection officer
(DPO) who reports to the board of directors, conducts periodic audits, carries out periodic DPIAs, and
deploys risk mitigation measures.
Consent Managers –
GDPR – No such concept is recognized
DPDPA – Consent managers are entities registered with the Data Protection Board under the DPDPA and act
on behalf of data principals to review, provide, manage, and withdraw consent.
Organisations may be required to either: (i) register as consent managers (subject to additional guidance
provided by the rules framed pursuant to the DPDPA), or (ii) give data principals the option (through their user
interface) to nominate a registered consent manager on their platform, app, website, etc.
Children’s Data –
GDPR – Age limit is 16 which varies across the EU States up to 13 years. Verifiable Parental consent
required.
DPDPA – Age limit is 18; includes person with disability. Verifiable Parental Consent. For children’s
data processing no data processing that is detrimental to children, or processing of data that in any
manner would aid targeted advertising directed at children should be undertaken.
Privacy Policy Disclosures–
GDPR – More detailed requirements for privacy notices (Data Controller Details, DPO Details, lawful
basis of processing, categories of personal data, recipients of personal data, cross border data
transfer, retention period, sources of personal data, automated decision making, profiling)
DPDPA – Fewer requirements comparatively (1. the personal data and the purpose for which it is
being processed; 2. the manner in which they may exercise their rights under the DPDPA; 3. manner
in which they may make a complaint to the Data Protection Board)
Language Requirements–
GDPR – Provides for info in native language of subject is required)
DPDPA – English or 22 languages of the Constitution (Practical implementation difficult)