Personal Data: Art.4(1) prevent reidentification.
It ensures that the data cannot be traced
back to any individual, providing a higher level of privacy.
Any information relating to an identified or identifiable living
R. 26: Discusses the concept of anonymization and its role in ensuring that
individual.
data cannot be traced back to any individual.
R.26 [Discusses the principles of data protection and the concept of
identifiable natural persons.]
Big Data
Sensitive Personal Data: Art. 9 Big data refers to extremely large data sets that may be analysed
computationally to reveal patterns and trends and associations used to
If my personal data comes in someone else’s hand and that data can
identify human behaviour, interests and interactions.
harm me or have a negative effect. Any data which has the potential to
R. 6: Highlights the challenges posed by rapid technological developments
harm an individual if got into wrong hands, can lead to negative
and globalization, including the increased scale of data collection and
impact on a person’s well-being etc. is called SPD.
sharing.
R. 51: Explains the need for specific protection for sensitive personal data
Types of Privacy
due to the significant risks to fundamental rights and freedoms.
1. Territorial Privacy: Limits intrusions into physical or virtual
Public Data: environments, including homes, workplaces, and public spaces. R.
4: Balances the right to data protection with other fundamental
Widely shared data, which is difficult to categorize and no legal
rights, including respect for private and family life.
protection would be provided against such data is called Public Data.
2. Communications Privacy: Ensures the privacy of all forms of
R. 14: States that the GDPR does not apply to data concerning legal
communication, such as telephone, email, and postal systems. R. 4:
persons, which can be considered public data.
Includes the protection of communications as part of fundamental
rights.
Aggregated and anonymized Data:
3. Bodily Privacy: Protects a person's physical being from invasive
Data that has been collected and combined from multiple sources, procedures and tests. R. 4: Protects a person's physical being from
often in a way that individual data points are summarized or grouped invasive procedures.
together. This process helps to ensure that the data is less likely to be 4. Information Privacy: Governs the collection, handling, and
traced back to any specific individual, thereby enhancing privacy. protection of personal data. Art. 5: Sets out principles relating to the
R. 26: Clarifies that the principles of data protection do not apply to processing of personal data, including data minimization and
anonymous information that cannot be traced back to an individual. integrity.
1. Pseudonymization Art.4(5): This technique involves removing
direct identifiers (such as names, addresses, and dates of birth) and Roles in Data Protection
replacing them with artificial identifiers like numbers, letters, or
1. Data Subjects (Data Principal in India) [Art. 4(1)]: Individuals
symbols. This helps protect individual identities while still allowing
whose personal data is collected and processed by entities.
data analysis.
R. 28: Discusses the benefits of pseudonymization in reducing risks to data 2. Data Controller [Art.4(7)] : Entities or individuals who determine
the purposes and means of processing personal data.
subjects.
2. Anonymization: This technique goes a step further by removing
both direct and indirect identifiers and using technical processes to
3. Data Processor [Art.4(8)] : Organizations or individuals that o Importance: Ensuring data security upholds its confidentiality,
process data on behalf of the data controller, following their integrity, and availability. R. 83: Discusses the importance of data
instructions. security measures.
4. Regulators (Data Protection Board of India) [Art.51]: o Application: Implement encryption, access controls, and regular
Supervisory authorities that enforce data protection laws and security audits. For example, if a system containing patient data
regulations. lacks encryption and uses outdated software, contact supervisors and
Managing Data Lifecycle privacy offices to address the security risks.
1. Data Minimization(R.39)/Collection Limitation: Art.5(1)(c) Individual Rights
o Definition: Collect only the minimum amount of personal data 4. Notice/Openness: Art.12
necessary for the intended purpose, obtain it lawfully and fairly, and o Definition: Be transparent about data management practices and
retain it only for as long as needed. policies, informing data subjects about how their personal data is
o Importance: Minimizing data collection reduces the risk of data collected, used, and shared.
breaches and ensures that outdated or unnecessary data does not o Importance: Transparency builds trust and allows individuals to
compromise privacy. make informed decisions about their personal data. R. 58:
o Application: Regularly review data collection practices to avoid Emphasizes the principle of transparency.
gathering excessive information. For example, asking for a o Application: Provide clear and accessible privacy notices. For
recipient's mailing address when only an email is needed for a example, if a new advertising tool is used, update the privacy notice
newsletter is unnecessary and should be avoided. immediately to reflect this change.
Integrity and Protection of Information
2. Use Limitation: Art.5(1)(b) 5. Access/Individual Participation: Art.15
o Definition: Use personal data only for the (specified, explicit and
o Definition: Allow data subjects to access, review, and correct their
legitimate) purposes specified at the time of collection, unless the personal data, ensuring accuracy and fairness in data handling.
o Importance: Empowering individuals to manage their data helps
data subject consents to alternate uses or legal exceptions apply.
o Importance: Limiting data use to specified purposes helps maintain maintain data integrity and protects their privacy. R. 63: Discusses
trust and ensures compliance with privacy laws. R. 50: Discusses the the right of access.
o Application: Establish processes for individuals to request access to
compatibility of further processing with the original purposes.
o Application: Clearly communicate the intended use of data to data their data and make corrections if needed. For example, if an
subjects and adhere to those purposes. For instance, using human applicant requests their data, provide all relevant information unless
resources data for marketing without prior notice and consent is legally restricted.
inappropriate. Management-Level Controls
6. Accountability: Art.24
3. Safeguards/Security: Art.32 o Definition: Ensure organizations are responsible for complying with
o Definition: Protect personal data with reasonable physical, data protection principles and can demonstrate their compliance.
technical, and administrative security mechanisms against risks such o Importance: Accountability ensures that data protection obligations
as loss, unauthorized access, destruction, use, modification, or are taken seriously and that organizations can be held accountable
disclosure.
for breaches or non-compliance. R. 74: Discusses the responsibility Fiduciary in India)
and liability of controllers. Data Processor Article 4(8) Section 2(k)
o Application: Establish clear policies and procedures, conduct Regulators (Data Protection Article 51 Section 18
regular audits, and maintain documentation. Training programs and Board of India)
role-based training help ensure everyone understands their privacy Managing Data Lifecycle
obligations. For example, appointing a data protection officer can Data Article 5(1)(c), Section 4(1), Rule
oversee compliance efforts. Minimization/Collection Recital 39 8
These principles collectively ensure that personal data is handled Limitation
responsibly, transparently, and securely throughout its lifecycle. Use Limitation Article 5(1)(b), Section 4(1), Rule
Recital 50 5
Head GDPR DPDPA Safeguards/Security Article 32, Recital Section 8(5), Rule
Personal Data Article 4(1), Section 2(t) 83 6
Recital 26 Individual Rights
Sensitive Personal Data Article 9, Recital Section 2(u) Notice/Openness Article 12, Recital Section 5, Rule 3
(SPD) 51 58
Public Data Recital 14 Section 3(c) Access/Individual Article 15, Recital Section 11,
Aggregated and Anonymized Recital 26 Section 2(x) Participation 63 Section 12, Rule
Data 13
Pseudonymization Article 4(5), Rule 6(1)(a) Management-Level Controls
Recital 28 Accountability Article 24, Recital Section 8(1), Rule
Anonymization Recital 26 Rule 6(1)(a) 74 12
Big Data Recital 6 Section 2(h)
Types of Privacy Data Subject Rights/Subject Access Rights
Territorial Privacy Not explicitly Not explicitly
covered covered
Communications Privacy Not explicitly Not explicitly
covered covered
Bodily Privacy Not explicitly Not explicitly
covered covered
Information Privacy Article 5, Recital Covered
39 throughout
DPDPA and
DPDP Rules
Roles in Data Protection
Data Subjects (Data Article 4(1) Section 2(j)
Principal in India)
Data Controller (Data Article 4(7) Section 2(i)
Operational Impact GDPR DPDPA US Laws
Security Standard Article 32 (Recitals 83, Section 8 (General obligations of HIPAA Security Rule (45 CFR Part 160, 164), GLBA
84), Article 25 (Recital Data Fiduciary), Rule 3 Safeguards Rule (16 CFR Part 314)
78)
Personal Data Breach Articles 33, 34 (Recitals Section 9 (Processing of personal State Data Breach Notification Laws (e.g., California Civil
Notification 85-89) data of children), Section 10, Rule 4 Code § 1798.82), HIPAA Breach Notification Rule (45 CFR
§§ 164.400-414)
Mandatory DPO Articles 37-39 (Recitals Section 10 (Additional obligations of CCPA (California Consumer Privacy Act, Cal. Civ. Code §
97, 98) Significant Data Fiduciary), Rule 5 1798.100 et seq.)
Data Subject Rights Articles 7, 12-15 Sections 6 (Consent), 11-15 (Rights COPPA (Children's Online Privacy Protection Act, 15 U.S.C.
(Consent) (Recitals 32, 33, 42, 43, and Duties of Data Principal), Rule 6 §§ 6501-6506), CCPA
58-64)
Transborder Data Flow Articles 44-49 (Recitals Section 16 (Processing of personal Privacy Shield Framework, Standard Contractual Clauses
101-114) data outside India), Rule 7
Right to be Forgotten / Article 17 (Recitals 65, Section 12 (Right to correction and CCPA (California Consumer Privacy Act, Cal. Civ. Code §
Erasure 66) erasure of personal data), Rule 8 1798.105)
Data Portability Article 20 (Recital 68) Section 11 (Right to access CCPA (California Consumer Privacy Act, Cal. Civ. Code §
information about personal data), 1798.100(d))
Rule 9
Profiling or Automated Article 22 (Recitals 71, Section 7 (Certain legitimate uses), No specific federal law, but covered under various state laws
Processing 72) Rule 10
Code of Conduct and Articles 40-43 (Recitals Section 8 (General obligations of No specific federal law, but industry standards like ISO/IEC
Certification 98-101) Data Fiduciary), Rule 11 27001
Fines (Administrative Articles 83, 84 (Recitals Sections 33-34 (Penalties and CCPA (California Consumer Privacy Act, Cal. Civ. Code §
Procedures) 148-152) Adjudication), Rule 12 1798.155), FTC Act (15 U.S.C. § 45)
Pseudonymization Articles 4, 6 (Recitals Section 8 (General obligations of No specific federal law, but covered under various state laws
26, 29) Data Fiduciary), Rule 13
Risk Assessment Articles 35, 36 (Recitals Section 8 (General obligations of HIPAA Security Rule (45 CFR Part 160, 164), GLBA
84, 90-93) Data Fiduciary), Rule 14 Safeguards Rule (16 CFR Part 314)
Category Digital Personal Data Protection Act, 2023 EU General Data Protection US California Consumer Privacy Act
(DPDPA) & DPDP Rules, 2025 Regulation (GDPR) (CCPA)
Applicability Only on digital personal data Applies to all personal data Applies to personal data of California
residents
Sensitive Personal Treats all personal data uniformly, without Special categories of personal data (e.g., Sensitive personal information includes
Data separately classifying special or sensitive health, racial, biometric data) data like SSN, financial information, etc.
categories of personal data
Data Data Principal Data Subject Consumer
Principal/Subject
Data Significant Data Fiduciary (SDF), classified Data Controller Business
Fiduciary/Controller based on volume and sensitivity of personal
data, having higher compliance burden
Data Processor Obligation only on data fiduciaries to ensure Obligation directly on processor Service Provider
compliance, requiring valid contracts
Data Inventories Map how a data principal's personal data is Data mapping and records of processing Data mapping and records of processing
stored within their organizations, details of activities required activities required
each third-party data is shared with and
purposes for processing
Data Applies uniformly to all kinds of personal Special category of data as expressly Applies to personal information as
data mentioned in GDPR defined by the CCPA
Grounds for CONSENT: Free, Specific, Informed, Contractual necessity, Legitimate Consent, Contractual necessity,
Processing Unambiguous, Unconditional, Clear interests, Consent Legitimate interests
affirmative action, Not bundled consent.
Certain legitimate uses: Voluntarily provided,
Not indicated objection, Judicial/legal
obligation, Medical/health emergencies,
Breakdown of public order and employment
Rights Right of withdrawal of consent, Right to Right to access, Right to rectification, Right to know, Right to delete, Right to
access information about personal data, Right Right to erasure, Right to restrict opt-out of sale, Right to non-
to correction and erasure of personal data, processing, Right to data portability, discrimination, Right to correct
Right of retention of personal data after Right to object, Rights in relation to inaccurate personal information, Right to
withdrawal of consent, Right of grievance automated decision making and profiling limit use of sensitive personal
redressal, Right to nominate, Right to information
withdraw consent
Exclusions Processing for: Domestic use by individual, Processing for: Journalistic purposes, Processing for: Journalistic purposes,
Research and Statistical purposes, Publicly Research and Statistical purposes, Research and Statistical purposes,
available personal data, Startups [S.17(3)], Publicly available personal data, Publicly available personal data,
Government entities (prior notice), Domestic use by individual, Legal Domestic use by individual, Legal claims,
Sovereignty and integrity of India, Security claims, Public interest, Health and social Public interest, Health and social care,
of the state, Friendly relations with foreign care, Archiving purposes in the public Archiving purposes in the public interest,
states, Maintenance of public order, The interest, scientific or historical research scientific or historical research purposes
prevention of incitement to commit crimes. purposes or statistical purposes or statistical purposes
Employer-employee are also exempted. Non-
Indian data principals too. Enforcement of
legal claim, Prevention, detection,
investigation or prosecution of any offense,
Mergers, amalgamations or restructuring
approved by relevant courts, Ascertaining
financial information of individuals who are
loan defaulters
Data Protection Data Protection Board of India (DPBI) is European Data Protection Board California Privacy Protection Agency
Authority merely an adjudication body without (EDPB) (CPPA)
regulatory powers. Independent supervisory
authority, chairperson and government-
appointed members serving two-year
renewable terms. Judicial powers of civil
court under CPC, 1908 but no legislative
powers.
Appellate Body The act clearly forecloses individual’s access Right to appeal to national courts and Right to appeal to the California Attorney
to civil court for relief under the law, while the Court of Justice of the European General or the CPPA
giving right to appeal before the Telecom Union (CJEU)
Disputes Settlement and Appellate Tribunal
(TDSAT)
Penalties 10k on Data Principal for preventing undue Fines up to €20 million or 4% of the Fines up to $7,500 per intentional
advantage in case of non-compliance under annual global turnover, whichever is violation and $2,500 per unintentional
the law. 50 cr for breach of provision or for higher. Data subjects have the right to violation. Data subjects have the right to
implementing rules for which no penalty is compensation for damages. sue for data breaches.
stipulated. 250 cr for failure to fulfil the
obligation to take reasonable security
safeguards. There is no Data Principal’s right
to compensation.
Cross-Border Data Blacklist approach but no proper basis for Transfers allowed to countries with Transfers allowed if the recipient offers a
Transfers listing like GDPR. adequate protection (Art. 45), level of protection equivalent to that of
appropriate safeguards (Art. 46), or the CCPA.
binding corporate rules (Art. 47).