DPDPA, GDPR & CCPA compliance — global privacy compliance backed by legal expertise.
Data privacy law is the most rapidly evolving area of regulation globally, and non-compliance carries financial penalties, regulatory investigation, and reputational harm. SIRI Law LLP's integrated privacy compliance practice combines qualified legal counsel with certified privacy engineers to build compliance programmes that satisfy India's DPDPA, Europe's GDPR, and California's CCPA simultaneously, without creating three separate, contradictory programmes.
Getting the DPDP Rules status right
The DPDP Rules aren't pending delegated legislation anymore. They're notified, dated, and already shaping enforcement.
Some privacy compliance content still describes DPDPA as reserving "significant provisions for delegated legislation that is not yet finalised." That's stale. The DPDP Rules 2025 were notified on 14 November 2025 — a firm, dated fact. The operative compliance deadline for most substantive obligations is 13 May 2027, which gives organisations a genuine transition window, but the rules themselves, including the Consent Manager framework, the breach notification procedure, and the criteria for Significant Data Fiduciary classification, are finalised and published, not awaiting future rule-making. The Data Protection Board of India is already staffed and has begun hearing early matters.
It's also worth being precise about what DPDPA actually grants Data Principals, rather than gesturing vaguely at "fewer explicit rights currently" than GDPR. DPDPA provides four core statutory rights under Sections 11 to 14: the right to access information about processing, the right to correction and erasure, the right to grievance redressal, and the right to nominate someone to exercise rights on the Data Principal's behalf in the event of death or incapacity — plus the ability to withdraw consent at any time. What DPDPA notably does not include, unlike GDPR, is a right to data portability, and it has no explicit general right against solely automated decision-making. These aren't oversights to work around quietly; they're structural differences that shape what a compliant product actually needs to build.
None of this changes the practical case for an integrated programme: the strictest applicable requirement in each area — consent architecture calibrated to DPDPA, data subject rights calibrated to GDPR's broader set, breach notification meeting both CERT-In's 6-hour window and GDPR's 72-hour one — still produces a single defensible programme rather than three overlapping, occasionally contradictory ones.
Evidence, not guesswork
What each framework actually grants — side by side
The specific rights, not a vague "differs significantly" gesture.
DPDPA (India)
- Right to Access
- Right to Correction & Erasure
- Right to Grievance Redressal
- Right to Nominate
- Right to Withdraw Consent
- No general right to data portability
- No explicit right against automated decisions
GDPR (EU)
- Right to Access
- Right to Rectification
- Right to Erasure ("right to be forgotten")
- Right to Data Portability
- Right to Object
- Right to Restrict Processing
- Rights re: automated decision-making
CCPA/CPRA (California)
- Right to Know
- Right to Delete
- Right to Correct
- Right to Opt-Out of Sale/Sharing
- Right to Limit Use of Sensitive Data
- Right to Non-Discrimination
- Private right of action for certain breaches
Sources: DPDPA 2023, Sections 11–14; DPDP Rules 2025; EU GDPR Chapter III (Articles 12–23); California Consumer Privacy Act as amended by CPRA. Confirm current interpretation with counsel before relying on this summary for a specific compliance submission.
Scope of services
What our engagement covers
- DPDPA 2023 gap assessment and compliance roadmap, mapped to the 13 May 2027 deadline
- GDPR gap assessment — Articles 5–49 applicable controls
- CCPA/CPRA compliance assessment
- Multi-jurisdiction privacy law gap analysis
- Personal data mapping and data flow documentation
- Records of Processing Activities (RoPA) development
- Legal basis analysis for all processing activities
- Consent architecture design and implementation advisory, including Consent Manager readiness
- Data Protection Impact Assessments (DPIAs) for high-risk processing
- Cross-border data transfer mechanisms — SCCs, BCRs, adequacy decisions
- Vendor Data Processing Agreement (DPA) templates and negotiation
- Data subject rights handling procedures — access, erasure, portability where applicable
- Breach notification workflows — CERT-In (6hr), Data Protection Board, GDPR (72hr)
- AI data governance — training data, inference, DPDPA/GDPR AI obligations
- Employee data privacy policies and monitoring framework
- Significant Data Fiduciary obligations advisory and data localisation requirements
What the numbers actually mean
Four figures that frame privacy compliance today
Per Schedule item — the ceiling for inadequate security safeguards leading to a breach, before Section 33(3) enhancement.
Whichever is higher — €20 million or 4% of global annual turnover, for the most serious infringements.
Access, correction/erasure, grievance redressal, nomination — plus consent withdrawal, but no portability.
Against DPDPA's near-total reliance on consent — the key architectural asymmetry between the two frameworks.
Our engagement process
How we work, step by step
Initial Scoping & Assessment
Gap assessment against the applicable framework(s), engagement scope definition, and a prioritised remediation roadmap with timeline and effort estimates.
Programme Design
Control framework, documentation structure, evidence requirements, and governance processes tailored to your organisation and its specific mix of frameworks.
Implementation Advisory
Advising on implementation of each required control, working alongside your technical and operational teams to build controls that are practical and auditable.
Internal Audit & Validation
Internal audit or readiness assessment identifying any remaining gaps before the formal certification or attestation process begins.
Certification / Attestation Support
Managing auditor queries, providing evidence, and resolving findings during the formal audit or assessment.
Post-Certification Advisory
Ongoing support — surveillance audit preparation, change management, and regulatory update advisory as DPDPA rule-making, GDPR guidance, and CCPA enforcement all continue to develop.
Typical engagement timeline varies by organisation size and existing control maturity.
Benefits & deliverables
What you get from this engagement
Multi-Jurisdiction Assessment
Holistic gap assessment across DPDPA, GDPR, and CCPA, identifying the highest compliance bar in each area and designing a single programme that satisfies all frameworks.
Data Mapping
Personal data inventory and data flow mapping, the foundation of every effective privacy compliance programme. You cannot protect what you cannot find.
Legal Basis & Consent Architecture
Legal basis analysis for every processing activity and consent architecture design for activities requiring consent, including layered consent for AI data use.
Documentation Programme
Complete documentation library — privacy notices, RoPA, DPIAs, data retention schedules, DPA templates — drafted by qualified privacy lawyers.
Data Subject Rights
Operational procedures for handling access, erasure, correction, portability (where applicable), and objection requests, including escalation and response templates.
Breach Response
Tested breach notification workflow — CERT-In (6 hours), Data Protection Board, GDPR supervisory authority (72 hours) — with legal strategy integrated from the first moment of detection.
Integration advantage
Privacy compliance backed by qualified legal counsel
Our compliance engagements ensure your programme satisfies both technical certification requirements and legal obligations under DPDPA, IT Act, and sector-specific regulation.
We know exactly what DPDPA grants and doesn't
Four core rights, consent-heavy legal basis, no portability, no automated-decision right — we build products and policies to the framework as it actually stands, not to a GDPR-shaped assumption.
We treat the DPDP Rules as notified, not pending
Your compliance roadmap is built against a finalised rule set and a real 13 May 2027 deadline, not a forecast of what delegated legislation might eventually say.
One programme, not three
We map processing activities once and build to the strictest applicable requirement in each area, producing a single privacy policy, a single RoPA, and one data subject rights process.
Certified engineers
Our team holds CCSP, CISM, CIPP/E, CEH, OSCP, CISSP, CPENT, and ISO 27001 Lead Auditor credentials — including CIPP/E, the certification specific to European privacy law practice.
Frequently asked
Privacy compliance, answered directly
Does GDPR apply to us if we are an Indian company?
GDPR applies to any organisation that has an establishment in the EU, or processes personal data of EU data subjects in connection with offering goods or services to them, or monitoring their behaviour within the EU. If your SaaS product has EU users, if you market to EU residents, or if you process EU employee data, GDPR likely applies to you regardless of where your servers or company are located. We advise on applicability and compliance obligations.
What are the key differences between DPDPA and GDPR?
DPDPA grants Data Principals four core statutory rights — access, correction and erasure, grievance redressal, and nomination — plus the ability to withdraw consent. It does not include a right to data portability and has no explicit, general right against solely automated decision-making, both of which GDPR provides. DPDPA also relies almost entirely on consent as its legal basis for processing, where GDPR recognises six separate lawful bases including legitimate interest and contractual necessity. Enforcement differs too: DPDPA uses the Data Protection Board of India, now active and hearing early matters, while GDPR uses supervisory authorities in each EU member state.
Are the DPDP Rules still pending, or have they been finalised?
The DPDP Rules 2025 were notified on 14 November 2025 — they are not pending delegated legislation. The operative compliance deadline for most substantive obligations is 13 May 2027, which gives organisations a genuine transition window, but the rules themselves, including the Consent Manager framework, breach notification procedure, and Significant Data Fiduciary criteria, are finalised and published, not awaiting future rule-making.
How do we handle a data subject's request to erase their data from our AI training dataset?
This is one of the most complex questions in current privacy law. The GDPR right to erasure, and the DPDPA's erasure obligation under Section 12, both apply to personal data used in AI training. For data used in model weights, erasure may require model retraining or machine unlearning techniques, since the data is not stored in a directly deletable record the way a database row is. We advise on a risk-based approach — documenting consent at training time, maintaining training data records, and advising on technical and legal responses to erasure requests targeting AI training data.
We process data under DPDPA, GDPR, and CCPA. Do we need three separate programmes?
No — an integrated programme is both possible and more effective. We start by mapping all processing activities and identifying the strictest applicable requirement in each area. The resulting programme typically satisfies all three frameworks with modest additional effort beyond the most demanding baseline. We build integrated documentation — a single privacy policy that satisfies all three frameworks, a single RoPA, and a unified data subject rights process.
Does DPDPA require a data portability feature in our product?
No. Unlike GDPR, DPDPA does not grant a general right to data portability. If your product also has EU users, however, GDPR's portability right will still apply to that user segment, meaning a portability feature may be commercially or legally necessary regardless of DPDPA's narrower scope.
Ready to start your privacy compliance journey?
All engagements begin with a complimentary scoping call.
Let us understand your environment and propose a single integrated programme across every framework you're subject to.
Related services
Other ways SIRI Law LLP supports your compliance posture
Visit or contact us
SIRI Law LLP — Hyderabad, India
| Registered office | HITEC City, Madhapur, Hyderabad, Telangana 500081, India |
| Telephone | +91 79819 12046 |
| info@sirilawllp.com | |
| Other offices | New Delhi, India · Austin, Texas, USA · Online worldwide |
| Hours | Mon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7 |

