
Introduction
The Digital Personal Data Protection Act, 2023 (“DPDP Act”) borrows some of the European Union (“EU”)’s General Data Protection Regulation (“GDPR”)’s vocabulary a Data Fiduciary echoes a “controller,” a Data Principal echoes a “data subject” and the legal architecture behind those words is roughly the same.
In several places the DPDP Act gives a familiar-sounding concept a narrower role than its European counterpart. In others, it leaves out a safeguard a GDPR-trained reader instinctively expects to find. Reading a GDPR safeguard into a DPDP Act silence does not make the advice more careful. It just moves the error from understating a client’s obligations to overstating them or, now that the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”) have started to follow, the other way round.
What follows sets out nine places where GDPR instinct and the DPDP Act’s actual text part ways, what the drafting history says about why, what has changed operationally since the DPDP Rules were notified in November 2025, and a short test for keeping European habit from quietly rewriting Indian law.
Interpretation of the term ‘Privacy’
The term “Privacy” does not appear anywhere in the operative provisions of the DPDP Act. The constitutional backdrop is a separate document: Justice K.S. Puttaswamy (Retd.) v. Union of India, decided by a nine-judge Bench of the Supreme Court on 24 August 2017 and reported at (2017) 10 SCC 1, which held unanimously that the right to privacy is a fundamental right protected under Article 21, read with Articles 14 and 19, of the Constitution. The DPDP Act sits underneath that constitutional right it was never drafted to restate or codify it. It is a narrower statute, concerned specifically with the processing of digital personal data for lawful purposes.
The Act covers digital personal data only. It has no distinct tier for sensitive data. It says nothing about profiling as a standalone concept. It lets the State claim broad exemptions without an express proportionality clause in the text. And when the Data Protection Board of India levies a penalty, that money is credited to the Consolidated Fund of India not paid to the person who was actually harmed. None of this is buried in a footnote. It sits in the text. GDPR-trained readers tend to read past it anyway, because their training taught them to expect a different kind of statute.
The drafting history does not support that reading. “Deemed consent” in Section 8 of the 2022 Bill became “certain legitimate uses” in Section 7 of the final Act, and neither version carried an open-ended, GDPR-style legitimate-interests ground or the balancing test Article 6(1)(f) requires. The publicly-available-data exclusion in Section 3(c)(ii) moved the other way it was added between the 2022 Bill and the final Act, a deliberate widening rather than an accidental gap. Profiling and its territorial trigger went the way of deletion instead. The separate category for sensitive personal data disappeared earlier still, somewhere between the 2019 Bill and the 2022 draft. When a protection appears in an earlier version of the law and is gone by the time the Act is enacted, that is Parliament making a choice. It is not a gap for an adviser to quietly fill in on the client’s behalf.
Evolution Since November 2025
The DPDP Act existed on paper without functioning machinery assented to on 11 August 2023, but waiting on rules to operationalise it. The Ministry of Electronics and Information Technology released draft DPDP Rules for public consultation on 3 January 2025, drawing several thousand stakeholder submissions over the following months. The final DPDP Rules, 2025 were notified on 13 November 2025, alongside separate notifications enforcing the Act’s provisions and establishing the Data Protection Board of India, a four-member body operating out of the National Capital Region.
Implementation is staggered across three dates. From 13 November 2025, the definitional provisions and the sections establishing and operating the Data Protection Board came into force immediately, so the Board now exists and can begin functioning. A second phase, effective 13 November 2026, brings in the framework for registering Consent Managers. The remaining substantive obligations the notice-and-consent architecture, breach notification timelines, data principal rights, children’s data safeguards, cross-border transfer rules, and the Significant Data Fiduciary obligations discussed above become enforceable on 13 May 2027, eighteen months after notification.
Two practical points follow. First, the Data Protection Board can already receive complaints and issue directions for corrective steps even though most monetary penalties will not be available until later phases so reputational and operational exposure can arrive well before financial exposure does. Second, Board orders are appealable to the Telecom Disputes Settlement and Appellate Tribunal within sixty days, with a further appeal on questions of law to the Supreme Court, giving the enforcement structure a defined judicial check that did not exist while the Act sat dormant.
A Three-Question Test Before Importing a GDPR Reading
Before carrying an EDPB position, or a GDPR recital, into DPDP Act advice, three questions are worth running through first:
- Does the Act actually contain an equivalent provision, or does it merely use a similar-sounding term?
- Did this protection exist in an earlier draft of India’s data protection law and get dropped along the way meaning it was a choice, not an oversight?
- Does reading it the GDPR way widen the client’s compliance burden beyond what the Act actually requires, or does it overstate a protection Parliament chose not to include?
There is no single right answer here what matters is being explicit with the client about which direction the advice moves them in: toward a voluntary best practice worth adopting anyway, or toward a legal obligation that, on the text of the DPDP Act, does not actually exist.
AMLEGALS Remarks
The DPDP Act should be read on its own terms, not as a shorthand translation of the GDPR. In several places it asks less of businesses than its European counterpart does, and Indian companies are entitled to that difference. That said, the Act not demanding a particular safeguard does not make the safeguard a bad idea a compensation clause in a vendor contract, or a human-review step before a high-stakes automated decision, can remain good governance even where the statute stays silent, particularly while the Data Protection Board is already active and the compliance clock is running toward May 2027. The job of the adviser is to keep those two things distinct, and here is what the law requires, and here is what we are recommending on top of it. Blur that line, even with good intentions, and the advice ends up describing a law that exists only in the adviser’s head, not in the Gazette.
For any queries or feedback, feel free to connect with mridusha.guha@amlegals.com or Khilansha.mukhija@amlegals.com
