📞 Call Now 💬 WhatsApp 📋 Report
⚖️
SIRI Law LLP
● Typically replies within 30 min
👋 Hi! How can SIRI Law LLP help you today?

We offer expert legal and cybersecurity advisory. Tap below for a confidential chat.
SIRI Law · Now
💬  Start Chat on WhatsApp
DPDPA, GDPR & CCPA Privacy Compliance in India | SIRI Law LLP
Privacy Compliance · DPDPA · GDPR · CCPA · Hyderabad, India

DPDPA, GDPR & CCPA compliance — global privacy compliance backed by legal expertise.

Data privacy law is the most rapidly evolving area of regulation globally, and non-compliance carries financial penalties, regulatory investigation, and reputational harm. SIRI Law LLP's integrated privacy compliance practice combines qualified legal counsel with certified privacy engineers to build compliance programmes that satisfy India's DPDPA, Europe's GDPR, and California's CCPA simultaneously, without creating three separate, contradictory programmes.

NotifiedDPDP Rules 2025 — finalised 14 Nov 2025, not pending delegated legislation
13 May 2027Operative deadline for most substantive DPDPA obligations
4Core statutory rights under DPDPA — access, correction/erasure, grievance, nomination
₹250 CrBase statutory maximum DPDPA penalty for serious violations
The privacy compliance clock
Live tracking · scroll to see every relevant date
Enacted
2023
DPDPA enacted, establishing India's first comprehensive personal data protection statute.
Notified
14 NOV 2025
DPDP Rules 2025 notified — a firm, dated fact, not pending or "expected" delegated legislation as some content still frames it.
Upcoming
13 NOV 2026
Consent Manager framework becomes operative — Rule 4 registration and integration obligations begin to bite.
Full enforcement
13 MAY 2027
Operative deadline for most substantive DPDPA obligations — the anchor most compliance timelines are built backward from.
Active
Board active
The Data Protection Board of India is staffed and has begun early inquiries — enforcement is a present, not future, concern.
Standing
GDPR / CCPA
Both remain in force unchanged for organisations with EU or California exposure — GDPR fines to €20M/4% turnover; CCPA/CPRA enforcement ongoing via the California Privacy Protection Agency.

Getting the DPDP Rules status right

The DPDP Rules aren't pending delegated legislation anymore. They're notified, dated, and already shaping enforcement.

Some privacy compliance content still describes DPDPA as reserving "significant provisions for delegated legislation that is not yet finalised." That's stale. The DPDP Rules 2025 were notified on 14 November 2025 — a firm, dated fact. The operative compliance deadline for most substantive obligations is 13 May 2027, which gives organisations a genuine transition window, but the rules themselves, including the Consent Manager framework, the breach notification procedure, and the criteria for Significant Data Fiduciary classification, are finalised and published, not awaiting future rule-making. The Data Protection Board of India is already staffed and has begun hearing early matters.

It's also worth being precise about what DPDPA actually grants Data Principals, rather than gesturing vaguely at "fewer explicit rights currently" than GDPR. DPDPA provides four core statutory rights under Sections 11 to 14: the right to access information about processing, the right to correction and erasure, the right to grievance redressal, and the right to nominate someone to exercise rights on the Data Principal's behalf in the event of death or incapacity — plus the ability to withdraw consent at any time. What DPDPA notably does not include, unlike GDPR, is a right to data portability, and it has no explicit general right against solely automated decision-making. These aren't oversights to work around quietly; they're structural differences that shape what a compliant product actually needs to build.

Consent is doing almost all the work under DPDPA
GDPR recognises six separate lawful bases for processing — consent, contract, legal obligation, vital interests, public task, and legitimate interest. DPDPA relies overwhelmingly on consent as its legal basis, with only narrow "legitimate uses" carved out for specific scenarios like employment and medical emergencies. For any organisation building a single compliance architecture across both frameworks, this asymmetry means the consent flow has to satisfy DPDPA's near-total reliance on it while still tracking GDPR's broader menu of lawful bases where those apply.

None of this changes the practical case for an integrated programme: the strictest applicable requirement in each area — consent architecture calibrated to DPDPA, data subject rights calibrated to GDPR's broader set, breach notification meeting both CERT-In's 6-hour window and GDPR's 72-hour one — still produces a single defensible programme rather than three overlapping, occasionally contradictory ones.

Evidence, not guesswork

What each framework actually grants — side by side

The specific rights, not a vague "differs significantly" gesture.

DPDPA (India)

  • Right to Access
  • Right to Correction & Erasure
  • Right to Grievance Redressal
  • Right to Nominate
  • Right to Withdraw Consent
  • No general right to data portability
  • No explicit right against automated decisions

GDPR (EU)

  • Right to Access
  • Right to Rectification
  • Right to Erasure ("right to be forgotten")
  • Right to Data Portability
  • Right to Object
  • Right to Restrict Processing
  • Rights re: automated decision-making

CCPA/CPRA (California)

  • Right to Know
  • Right to Delete
  • Right to Correct
  • Right to Opt-Out of Sale/Sharing
  • Right to Limit Use of Sensitive Data
  • Right to Non-Discrimination
  • Private right of action for certain breaches

Sources: DPDPA 2023, Sections 11–14; DPDP Rules 2025; EU GDPR Chapter III (Articles 12–23); California Consumer Privacy Act as amended by CPRA. Confirm current interpretation with counsel before relying on this summary for a specific compliance submission.

Scope of services

What our engagement covers

  • DPDPA 2023 gap assessment and compliance roadmap, mapped to the 13 May 2027 deadline
  • GDPR gap assessment — Articles 5–49 applicable controls
  • CCPA/CPRA compliance assessment
  • Multi-jurisdiction privacy law gap analysis
  • Personal data mapping and data flow documentation
  • Records of Processing Activities (RoPA) development
  • Legal basis analysis for all processing activities
  • Consent architecture design and implementation advisory, including Consent Manager readiness
  • Data Protection Impact Assessments (DPIAs) for high-risk processing
  • Cross-border data transfer mechanisms — SCCs, BCRs, adequacy decisions
  • Vendor Data Processing Agreement (DPA) templates and negotiation
  • Data subject rights handling procedures — access, erasure, portability where applicable
  • Breach notification workflows — CERT-In (6hr), Data Protection Board, GDPR (72hr)
  • AI data governance — training data, inference, DPDPA/GDPR AI obligations
  • Employee data privacy policies and monitoring framework
  • Significant Data Fiduciary obligations advisory and data localisation requirements

What the numbers actually mean

Four figures that frame privacy compliance today

₹250 Cr
DPDPA base max

Per Schedule item — the ceiling for inadequate security safeguards leading to a breach, before Section 33(3) enhancement.

€20M / 4%
GDPR maximum fine

Whichever is higher — €20 million or 4% of global annual turnover, for the most serious infringements.

4
DPDPA core statutory rights

Access, correction/erasure, grievance redressal, nomination — plus consent withdrawal, but no portability.

6
GDPR lawful bases

Against DPDPA's near-total reliance on consent — the key architectural asymmetry between the two frameworks.

Our engagement process

How we work, step by step

01

Initial Scoping & Assessment

Gap assessment against the applicable framework(s), engagement scope definition, and a prioritised remediation roadmap with timeline and effort estimates.

02

Programme Design

Control framework, documentation structure, evidence requirements, and governance processes tailored to your organisation and its specific mix of frameworks.

03

Implementation Advisory

Advising on implementation of each required control, working alongside your technical and operational teams to build controls that are practical and auditable.

04

Internal Audit & Validation

Internal audit or readiness assessment identifying any remaining gaps before the formal certification or attestation process begins.

05

Certification / Attestation Support

Managing auditor queries, providing evidence, and resolving findings during the formal audit or assessment.

06

Post-Certification Advisory

Ongoing support — surveillance audit preparation, change management, and regulatory update advisory as DPDPA rule-making, GDPR guidance, and CCPA enforcement all continue to develop.

Typical engagement timeline varies by organisation size and existing control maturity.

Benefits & deliverables

What you get from this engagement

Multi-Jurisdiction Assessment

Holistic gap assessment across DPDPA, GDPR, and CCPA, identifying the highest compliance bar in each area and designing a single programme that satisfies all frameworks.

Data Mapping

Personal data inventory and data flow mapping, the foundation of every effective privacy compliance programme. You cannot protect what you cannot find.

Legal Basis & Consent Architecture

Legal basis analysis for every processing activity and consent architecture design for activities requiring consent, including layered consent for AI data use.

Documentation Programme

Complete documentation library — privacy notices, RoPA, DPIAs, data retention schedules, DPA templates — drafted by qualified privacy lawyers.

Data Subject Rights

Operational procedures for handling access, erasure, correction, portability (where applicable), and objection requests, including escalation and response templates.

Breach Response

Tested breach notification workflow — CERT-In (6 hours), Data Protection Board, GDPR supervisory authority (72 hours) — with legal strategy integrated from the first moment of detection.

Integration advantage

Privacy compliance backed by qualified legal counsel

Our compliance engagements ensure your programme satisfies both technical certification requirements and legal obligations under DPDPA, IT Act, and sector-specific regulation.

01 — Precision

We know exactly what DPDPA grants and doesn't

Four core rights, consent-heavy legal basis, no portability, no automated-decision right — we build products and policies to the framework as it actually stands, not to a GDPR-shaped assumption.

02 — Currency

We treat the DPDP Rules as notified, not pending

Your compliance roadmap is built against a finalised rule set and a real 13 May 2027 deadline, not a forecast of what delegated legislation might eventually say.

03 — Integration

One programme, not three

We map processing activities once and build to the strictest applicable requirement in each area, producing a single privacy policy, a single RoPA, and one data subject rights process.

04 — Credentials

Certified engineers

Our team holds CCSP, CISM, CIPP/E, CEH, OSCP, CISSP, CPENT, and ISO 27001 Lead Auditor credentials — including CIPP/E, the certification specific to European privacy law practice.

Frequently asked

Privacy compliance, answered directly

Does GDPR apply to us if we are an Indian company?

GDPR applies to any organisation that has an establishment in the EU, or processes personal data of EU data subjects in connection with offering goods or services to them, or monitoring their behaviour within the EU. If your SaaS product has EU users, if you market to EU residents, or if you process EU employee data, GDPR likely applies to you regardless of where your servers or company are located. We advise on applicability and compliance obligations.

What are the key differences between DPDPA and GDPR?

DPDPA grants Data Principals four core statutory rights — access, correction and erasure, grievance redressal, and nomination — plus the ability to withdraw consent. It does not include a right to data portability and has no explicit, general right against solely automated decision-making, both of which GDPR provides. DPDPA also relies almost entirely on consent as its legal basis for processing, where GDPR recognises six separate lawful bases including legitimate interest and contractual necessity. Enforcement differs too: DPDPA uses the Data Protection Board of India, now active and hearing early matters, while GDPR uses supervisory authorities in each EU member state.

Are the DPDP Rules still pending, or have they been finalised?

The DPDP Rules 2025 were notified on 14 November 2025 — they are not pending delegated legislation. The operative compliance deadline for most substantive obligations is 13 May 2027, which gives organisations a genuine transition window, but the rules themselves, including the Consent Manager framework, breach notification procedure, and Significant Data Fiduciary criteria, are finalised and published, not awaiting future rule-making.

How do we handle a data subject's request to erase their data from our AI training dataset?

This is one of the most complex questions in current privacy law. The GDPR right to erasure, and the DPDPA's erasure obligation under Section 12, both apply to personal data used in AI training. For data used in model weights, erasure may require model retraining or machine unlearning techniques, since the data is not stored in a directly deletable record the way a database row is. We advise on a risk-based approach — documenting consent at training time, maintaining training data records, and advising on technical and legal responses to erasure requests targeting AI training data.

We process data under DPDPA, GDPR, and CCPA. Do we need three separate programmes?

No — an integrated programme is both possible and more effective. We start by mapping all processing activities and identifying the strictest applicable requirement in each area. The resulting programme typically satisfies all three frameworks with modest additional effort beyond the most demanding baseline. We build integrated documentation — a single privacy policy that satisfies all three frameworks, a single RoPA, and a unified data subject rights process.

Does DPDPA require a data portability feature in our product?

No. Unlike GDPR, DPDPA does not grant a general right to data portability. If your product also has EU users, however, GDPR's portability right will still apply to that user segment, meaning a portability feature may be commercially or legally necessary regardless of DPDPA's narrower scope.

Ready to start your privacy compliance journey?

All engagements begin with a complimentary scoping call.

Let us understand your environment and propose a single integrated programme across every framework you're subject to.

or call +91 79819 12046 — Mon–Sat, 9 AM – 7 PM IST

Visit or contact us

SIRI Law LLP — Hyderabad, India

Registered officeHITEC City, Madhapur, Hyderabad, Telangana 500081, India
Telephone+91 79819 12046
Emailinfo@sirilawllp.com
Other officesNew Delhi, India · Austin, Texas, USA · Online worldwide
HoursMon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7
© SIRI Law LLP · Hyderabad, Telangana

This page is provided for general informational purposes only. Compliance requirements vary by organisation, sector, and jurisdiction. References to DPDPA, DPDP Rules 2025, GDPR, and CCPA/CPRA reflect publicly available information as of publication and remain subject to further regulatory change, delegated notifications, and case law development; confirm current requirements before relying on any specific provision here. Engagement with SIRI Law LLP requires a formal retainer. This page does not constitute legal advice. SIRI Law LLP is a registered law firm under the Limited Liability Partnership Act 2008, practising under the Advocates Act 1961; complaints regarding professional conduct may be directed to the Bar Council of Telangana.

Scroll to Top