"Our privacy policy is GDPR-compliant" doesn't answer the DPDP question
Need help with dpdp? We can handle it for you.
"We already did GDPR, so India should be a formality." We hear a version of this from almost every founder who has a European customer base or an EU-trained legal advisor. It's a fair instinct. GDPR is the most thorough data protection law most people have encountered, and reusing that work feels efficient. The trouble is that one clause carrying a large share of a typical GDPR programme doesn't exist in Indian law at all.
The clause that's missing
GDPR Article 6(1)(f), legitimate interests, is the lawful basis European privacy teams reach for constantly. Marketing to an existing customer, running product analytics, screening for fraud: a European DPO runs a balancing test, documents it, and moves on. It's flexible by design, which is exactly why it carries so much of the weight in a GDPR programme.
DPDP has no equivalent ground. Processing personal data in India runs on one of two rails: consent under section 6, or the closed list of legitimate uses in section 7. There's no third option, no balancing test, no catch-all for "we have a good reason."
The closed list, in full
Section 7 sets out nine grounds, each specific, none of them a blank cheque:
| Clause | Ground |
|---|---|
| 7(a) | Data voluntarily provided by the person for a specified purpose, where she has not objected |
| 7(b) | State provision of a subsidy, benefit, service, certificate, licence or permit |
| 7(c) | A State function under law, or sovereignty, integrity and security of the State |
| 7(d) | Compliance with a legal obligation to disclose information |
| 7(e) | Compliance with a judgment, decree or order of a court or tribunal |
From the blog
Prefer to skip the paperwork?
BuildWright can take this off your plate — done properly, the first time.
Get new templates and compliance updates by email.