SlideShare uma empresa Scribd logo
1 de 17
Baixar para ler offline
DPDP India
vs
GDPR Europe
Key differences between two of
the most important Data Privacy
Laws
The Indian Parliament passed the Digital
Personal Data Protection (DPDP) Bill, 2023 in
August 2023.
It has now become the Digital Personal Data
Protection Act, 2023.
Which make it legally enforceable.
The GDPR was introduced a few years earlier:
May 2018.
At core, both regulations are similar in that
both laws aim to shield the privacy of their
users by protecting their data.
Yet there are significant differences between
the two.
This presentation takes you through 5 key
areas where Europe’s GDPR and India’s
DPDP are different.
1. The enshrined principles
1. The enshrined principles
GDPR:
Seven principles lie behind the GDPR: lawfulness, fairness, and transparency;
purpose limitation; data minimization; accuracy; storage limitation; integrity
and confidentiality; and accountability.
DPDP:
No principles are listed out explicitly. However, the Justice B N Srikrishna
Committee mentions two guiding factors: Directive Principles of State and
idea of a self-disciplinary state that says to;; “prone to excess”.
2. How the data is processed
2. How the data is processed
GDPR:
Any piece data that’s a part of a database / filing system, if personal in nature,
needs to be protected and processed appropriately. That’s because the GDPR
applies to all types of data, not just processed by machines.
DPDP:
The DPDP applies only to data that is processed using automation: “wholly or
partly automated operation…” This is likely because India has already tons of
data, so the government is moving in stages.
3. Data Protection Boards and enforcement
3. Data Protection Boards and enforcement
GDPR:
Member-states have their own supervisory authorities. If the data crosses
borders within the EU, the European Data Protection Board (EDPB) will step in
for consistent compliance to the regulations.
DPDP:
The Data Protection Board of India (DPBI) may pass orders, not laws. If you’re
not happy with the DPBI, you may appeal to the Telecom Disputes Settlement
Authority of India (TDSAI), and then to the Supreme Court.
4. Consent and responsibility
4. Consent and responsibility
GDPR:
The GDPR requires that you display notice at the time of collecting the
personal data. Data controllers as well as the data processors may share the
responsibility of compliance.
DPDP:
Unlike the GDPR, the DPDP expects only the data fiduciary responsible for
everything, including their data processors. That’s because the data fiduciary,
in almost all cases, is the only one who gains from data.
5. Children’s data
5. Children’s data
GDPR:
Upto the age of 16, people are defined as children by the GDPR. Parental
consent is a must to process children’s data, except when providing
“preventive or counseling services directly to a child”.
DPDP:
People below 18 are defined as children. People with disabilities have been
put with the category of children, when it comes to guardian / parental
consent. Data fiduciary may not serve targeted ads to this category.
Summing up
Both the GDPR and the DPDP aim to protect people’s data.
Owing to several differences in geographies, precedents, and law structures,
the two laws are similar but not identical.
Compliance with one will make compliance easier with the other. But you
can’t take it for granted.
Thank you!

Mais conteúdo relacionado

Semelhante a EU's GDPR vs India's DPDP: A Comparison

Semelhante a EU's GDPR vs India's DPDP: A Comparison (20)

Checklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR complianceChecklist for SMEs for GDPR compliance
Checklist for SMEs for GDPR compliance
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
GDPR A Practical Guide with Varonis
GDPR A Practical Guide with VaronisGDPR A Practical Guide with Varonis
GDPR A Practical Guide with Varonis
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
Data theft rules and regulations things you should know (pt.1)
Data theft rules and regulations  things you should know (pt.1)Data theft rules and regulations  things you should know (pt.1)
Data theft rules and regulations things you should know (pt.1)
 
Magento checklist AVG / GDPR - Algemene Verordering Gegevensbescherming
Magento checklist  AVG / GDPR - Algemene Verordering GegevensbeschermingMagento checklist  AVG / GDPR - Algemene Verordering Gegevensbescherming
Magento checklist AVG / GDPR - Algemene Verordering Gegevensbescherming
 
Practical Guide to GDPR 2017
Practical Guide to GDPR 2017Practical Guide to GDPR 2017
Practical Guide to GDPR 2017
 
GDPR: Are you Ready?
GDPR: Are you Ready?GDPR: Are you Ready?
GDPR: Are you Ready?
 
GDPR Is Coming – Are Emailers Ready?
GDPR Is Coming – Are Emailers Ready?GDPR Is Coming – Are Emailers Ready?
GDPR Is Coming – Are Emailers Ready?
 
2014 dpa training february nn
2014 dpa training february nn2014 dpa training february nn
2014 dpa training february nn
 
General data protection
General data protectionGeneral data protection
General data protection
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
All you need to know about GDPR
All you need to know about GDPRAll you need to know about GDPR
All you need to know about GDPR
 
The Definitive GDPR Guide for Event Professionals
The Definitive GDPR Guide for Event ProfessionalsThe Definitive GDPR Guide for Event Professionals
The Definitive GDPR Guide for Event Professionals
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing Mindset
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpr
 
GDPR Explained - A Quick Guide for US Businesses
GDPR Explained - A Quick Guide for US BusinessesGDPR Explained - A Quick Guide for US Businesses
GDPR Explained - A Quick Guide for US Businesses
 
Webinar: What the Hell is Legitimate Interest?
Webinar: What the Hell is Legitimate Interest?Webinar: What the Hell is Legitimate Interest?
Webinar: What the Hell is Legitimate Interest?
 
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxPERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
 

Mais de QuickEmailVerification

Mais de QuickEmailVerification (15)

Successful Email marketing for Sold-out Events
Successful Email marketing for Sold-out EventsSuccessful Email marketing for Sold-out Events
Successful Email marketing for Sold-out Events
 
How to Get Off Spamhaus Blocklist - 5 Step Process
How to Get Off Spamhaus Blocklist - 5 Step ProcessHow to Get Off Spamhaus Blocklist - 5 Step Process
How to Get Off Spamhaus Blocklist - 5 Step Process
 
Email list building strategies
Email list building strategiesEmail list building strategies
Email list building strategies
 
Using Voice of Customer to increase sales
Using Voice of Customer to increase salesUsing Voice of Customer to increase sales
Using Voice of Customer to increase sales
 
Inactive email subscribers
Inactive email subscribersInactive email subscribers
Inactive email subscribers
 
Marketing Strategies for Startups.pdf
Marketing Strategies for Startups.pdfMarketing Strategies for Startups.pdf
Marketing Strategies for Startups.pdf
 
Top email marketing mistakes marketers should avoid
Top email marketing mistakes marketers should avoidTop email marketing mistakes marketers should avoid
Top email marketing mistakes marketers should avoid
 
Powerful Marketing Tips for Small Businesses
Powerful Marketing Tips for Small BusinessesPowerful Marketing Tips for Small Businesses
Powerful Marketing Tips for Small Businesses
 
Simple email hacks
Simple email hacksSimple email hacks
Simple email hacks
 
12 tips to prevent emails from going to spam folder
12 tips to prevent emails from going to spam folder12 tips to prevent emails from going to spam folder
12 tips to prevent emails from going to spam folder
 
How Artificial Intelligence (AI) works with email marketing
How Artificial Intelligence (AI) works with email marketingHow Artificial Intelligence (AI) works with email marketing
How Artificial Intelligence (AI) works with email marketing
 
Post purchase emails you must send
Post purchase emails you must sendPost purchase emails you must send
Post purchase emails you must send
 
Black Friday Cyber Monday Marketing Ideas for the Last Minute
Black Friday Cyber Monday Marketing Ideas for the Last MinuteBlack Friday Cyber Monday Marketing Ideas for the Last Minute
Black Friday Cyber Monday Marketing Ideas for the Last Minute
 
Email marketing guide
Email marketing guideEmail marketing guide
Email marketing guide
 
How to write better emails in 2019
How to write better emails in 2019How to write better emails in 2019
How to write better emails in 2019
 

Último

Termination of Employees under the Labor Code.pptx
Termination of Employees under the Labor Code.pptxTermination of Employees under the Labor Code.pptx
Termination of Employees under the Labor Code.pptx
BrV
 

Último (20)

CHP 5 OF OFFENCES AGAINST WOMEN AND CHILDREN.pptx
CHP 5 OF OFFENCES AGAINST WOMEN AND CHILDREN.pptxCHP 5 OF OFFENCES AGAINST WOMEN AND CHILDREN.pptx
CHP 5 OF OFFENCES AGAINST WOMEN AND CHILDREN.pptx
 
How Can an Attorney Help With My Car Accident Claim?
How Can an Attorney Help With My Car Accident Claim?How Can an Attorney Help With My Car Accident Claim?
How Can an Attorney Help With My Car Accident Claim?
 
IRDA role in Insurance sector in India .pptx
IRDA role in Insurance sector in India .pptxIRDA role in Insurance sector in India .pptx
IRDA role in Insurance sector in India .pptx
 
Dabholkar-matter-Judgement-1.pdfrefp;sdPp;
Dabholkar-matter-Judgement-1.pdfrefp;sdPp;Dabholkar-matter-Judgement-1.pdfrefp;sdPp;
Dabholkar-matter-Judgement-1.pdfrefp;sdPp;
 
Dandan Liu is the worst real estate agent on earth..pdf
Dandan Liu is the worst real estate agent on earth..pdfDandan Liu is the worst real estate agent on earth..pdf
Dandan Liu is the worst real estate agent on earth..pdf
 
TTD - PPT on social stock exchange.pptx Presentation
TTD - PPT on social stock exchange.pptx PresentationTTD - PPT on social stock exchange.pptx Presentation
TTD - PPT on social stock exchange.pptx Presentation
 
Embed-6 (1).pdfc p;p;kdk[odk[drskpokpopo
Embed-6 (1).pdfc p;p;kdk[odk[drskpokpopoEmbed-6 (1).pdfc p;p;kdk[odk[drskpokpopo
Embed-6 (1).pdfc p;p;kdk[odk[drskpokpopo
 
Streamline Legal Operations: A Guide to Paralegal Services
Streamline Legal Operations: A Guide to Paralegal ServicesStreamline Legal Operations: A Guide to Paralegal Services
Streamline Legal Operations: A Guide to Paralegal Services
 
dandan liu need to rot when she dies..pdf
dandan liu need to rot when she dies..pdfdandan liu need to rot when she dies..pdf
dandan liu need to rot when she dies..pdf
 
Embed-1-1.pdfohediooieoiehohoiefoloeohefoi
Embed-1-1.pdfohediooieoiehohoiefoloeohefoiEmbed-1-1.pdfohediooieoiehohoiefoloeohefoi
Embed-1-1.pdfohediooieoiehohoiefoloeohefoi
 
Indian Partnership Act 1932, Rights and Duties of Partners
Indian Partnership Act 1932, Rights and Duties of PartnersIndian Partnership Act 1932, Rights and Duties of Partners
Indian Partnership Act 1932, Rights and Duties of Partners
 
HOW LAW FIRMS CAN SUPPORT MILITARY DIVORCE CASES
HOW LAW FIRMS CAN SUPPORT MILITARY DIVORCE CASESHOW LAW FIRMS CAN SUPPORT MILITARY DIVORCE CASES
HOW LAW FIRMS CAN SUPPORT MILITARY DIVORCE CASES
 
File Taxes Online Simple Steps for Efficient Filing.pdf
File Taxes Online Simple Steps for Efficient Filing.pdfFile Taxes Online Simple Steps for Efficient Filing.pdf
File Taxes Online Simple Steps for Efficient Filing.pdf
 
Does Apple Neurotechnology Patents Go To Far?
Does Apple  Neurotechnology Patents Go To Far?Does Apple  Neurotechnology Patents Go To Far?
Does Apple Neurotechnology Patents Go To Far?
 
(Hamad khadam ) ENGLISH LEGAL 2.0.docx
(Hamad khadam )   ENGLISH LEGAL 2.0.docx(Hamad khadam )   ENGLISH LEGAL 2.0.docx
(Hamad khadam ) ENGLISH LEGAL 2.0.docx
 
Mergers and Acquisitions in Kenya - An explanation
Mergers and Acquisitions in Kenya - An explanationMergers and Acquisitions in Kenya - An explanation
Mergers and Acquisitions in Kenya - An explanation
 
Termination of Employees under the Labor Code.pptx
Termination of Employees under the Labor Code.pptxTermination of Employees under the Labor Code.pptx
Termination of Employees under the Labor Code.pptx
 
Starbucks Corp. v. Sardarbuksh Coffee Co.
Starbucks Corp. v. Sardarbuksh Coffee Co.Starbucks Corp. v. Sardarbuksh Coffee Co.
Starbucks Corp. v. Sardarbuksh Coffee Co.
 
Embed-1-4.pdf Decision of the High Court
Embed-1-4.pdf Decision of the High CourtEmbed-1-4.pdf Decision of the High Court
Embed-1-4.pdf Decision of the High Court
 
INAUGURAL SIPAC FORUM - POST EVENT REPORT.pdf
INAUGURAL SIPAC FORUM - POST EVENT REPORT.pdfINAUGURAL SIPAC FORUM - POST EVENT REPORT.pdf
INAUGURAL SIPAC FORUM - POST EVENT REPORT.pdf
 

EU's GDPR vs India's DPDP: A Comparison

  • 1. DPDP India vs GDPR Europe Key differences between two of the most important Data Privacy Laws
  • 2. The Indian Parliament passed the Digital Personal Data Protection (DPDP) Bill, 2023 in August 2023. It has now become the Digital Personal Data Protection Act, 2023. Which make it legally enforceable.
  • 3. The GDPR was introduced a few years earlier: May 2018.
  • 4. At core, both regulations are similar in that both laws aim to shield the privacy of their users by protecting their data. Yet there are significant differences between the two.
  • 5. This presentation takes you through 5 key areas where Europe’s GDPR and India’s DPDP are different.
  • 6. 1. The enshrined principles
  • 7. 1. The enshrined principles GDPR: Seven principles lie behind the GDPR: lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability. DPDP: No principles are listed out explicitly. However, the Justice B N Srikrishna Committee mentions two guiding factors: Directive Principles of State and idea of a self-disciplinary state that says to;; “prone to excess”.
  • 8. 2. How the data is processed
  • 9. 2. How the data is processed GDPR: Any piece data that’s a part of a database / filing system, if personal in nature, needs to be protected and processed appropriately. That’s because the GDPR applies to all types of data, not just processed by machines. DPDP: The DPDP applies only to data that is processed using automation: “wholly or partly automated operation…” This is likely because India has already tons of data, so the government is moving in stages.
  • 10. 3. Data Protection Boards and enforcement
  • 11. 3. Data Protection Boards and enforcement GDPR: Member-states have their own supervisory authorities. If the data crosses borders within the EU, the European Data Protection Board (EDPB) will step in for consistent compliance to the regulations. DPDP: The Data Protection Board of India (DPBI) may pass orders, not laws. If you’re not happy with the DPBI, you may appeal to the Telecom Disputes Settlement Authority of India (TDSAI), and then to the Supreme Court.
  • 12. 4. Consent and responsibility
  • 13. 4. Consent and responsibility GDPR: The GDPR requires that you display notice at the time of collecting the personal data. Data controllers as well as the data processors may share the responsibility of compliance. DPDP: Unlike the GDPR, the DPDP expects only the data fiduciary responsible for everything, including their data processors. That’s because the data fiduciary, in almost all cases, is the only one who gains from data.
  • 15. 5. Children’s data GDPR: Upto the age of 16, people are defined as children by the GDPR. Parental consent is a must to process children’s data, except when providing “preventive or counseling services directly to a child”. DPDP: People below 18 are defined as children. People with disabilities have been put with the category of children, when it comes to guardian / parental consent. Data fiduciary may not serve targeted ads to this category.
  • 16. Summing up Both the GDPR and the DPDP aim to protect people’s data. Owing to several differences in geographies, precedents, and law structures, the two laws are similar but not identical. Compliance with one will make compliance easier with the other. But you can’t take it for granted.