Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

Tool

Where a GDPR program needs separate DPDP review

A GDPR program is a head start, not a certificate. Each area below states the DPDP position from the primary sources and points at the official EUR Lex provisions to review on the GDPR side. This comparison is educational; it never concludes that compliance with one framework satisfies the other.

GDPR pointers cite the official EUR Lex text of Regulation (EU) 2016/679. This site does not restate GDPR requirements; read them at the source.

The provisions behind this comparison

The provisions below are the sources for the legal statements on this page. Each links to the official document it was verified against, and to the provision on this site wherever this site publishes that provision. The label says whether the site is reporting a requirement, explaining it, reading it, recommending something, or pointing at a text it does not restate.

  • DPDP Rules 2025, r. 7

    Official requirement · Verified 16 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) On becoming aware of any personal data breach, the Data Fiduciary shall, to the best of its knowledge, intimate to each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered by her with the Data Fiduciary, — (a) a description of the breach, including its nature, extent and the timing of its occurrence; (b) the consequences relevant to her, that are likely to arise from the breach; (c) the measures implemented and being implemented by the Data Fiduciary, if any, to mitigate risk; (d) the safety measures that she may take to protect her interests; and (e) business contact information of a person who is able to respond on behalf of the Data Fiduciary, to queries, if any, of the Data Principal. (2) On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf, — (i) updated and detailed information in respect of such description; (ii) the broad facts related to the events, circumstances and reasons leading to the breach; (iii) measures implemented or proposed, if any, to mitigate risk; (iv) any findings regarding the person who caused the breach; (v) remedial measures taken to prevent recurrence of such breach; and (vi) a report regarding the intimations given to affected Data Principals.

    Rule 7 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • GDPR, Articles 33 and 34

    Pointer to the official text, not restated on this site · Verified 16 August 2026

    Document status: in force

    Official source ↗

    Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.

  • DPDP Rules 2025, r. 3

    Official requirement · Verified 16 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    The notice given by the Data Fiduciary to the Data Principal shall — (a) be presented and be understandable independently of any other information that has been, is or may be made available by such Data Fiduciary; (b) give, in clear and plain language, a fair account of the details necessary to enable the Data Principal to give specific and informed consent for the processing of her personal data, which shall include, at the minimum, — (i) an itemised description of such personal data; and (ii) the specified purpose or purposes of, and specific description of the goods or services to be provided or uses to be enabled by, such processing; and (c) give, the particular communication link for accessing the website or app, or both, of such Data Fiduciary, and a description of other means, if any, using which such Data Principal may — (i) withdraw her consent, with the ease of doing so being comparable to that with which such consent was given; (ii) exercise her rights under the Act; and (iii) make a complaint to the Board.

    Rule 3 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • GDPR, Articles 12 to 14

    Pointer to the official text, not restated on this site · Verified 16 August 2026

    Document status: in force

    Official source ↗

    Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.

  • DPDP Act 2023, s. 9

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) The Data Fiduciary shall, before processing any personal data of a child or a person with disability who has a lawful guardian obtain verifiable consent of the parent of such child or the lawful guardian, as the case may be, in such manner as may be prescribed. Explanation. — For the purpose of this sub-section, the expression “consent of the parent” includes the consent of lawful guardian, wherever applicable. (2) A Data Fiduciary shall not undertake such processing of personal data that is likely to cause any detrimental effect on the well-being of a child. (3) A Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.

    Section 9 on this site Official source ↗

    Quoted here are sub-sections (1) to (3). The conditional exemptions are in sub-sections (4) and (5), on the same Gazette page, and in Rule 12 with the Fourth Schedule.

  • DPDP Act 2023, s. 2(f)

    Official requirement · Verified 17 August 2026

    In force since 13 November 2025

    “child” means an individual who has not completed the age of eighteen years

    Section 2 on this site Official source ↗

  • GDPR, Article 8

    Pointer to the official text, not restated on this site · Verified 16 August 2026

    Document status: in force

    Official source ↗

    Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.

  • DPDP Act 2023, s. 8, (7)

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (7) A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force,— (a) erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier; and (b) cause its Data Processor to erase any personal data that was made available by the Data Fiduciary for processing to such Data Processor.

    Section 8 on this site Official source ↗

    Sub-section (7) begins on Gazette page 7 and concludes on page 8.

  • DPDP Rules 2025, r. 8

    Official requirement · Verified 16 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) A Data Fiduciary, who is of such class and is processing personal data for such corresponding purposes as are specified in Third Schedule, shall erase such personal data, unless its retention is necessary for compliance with any law for the time being in force, or, for the corresponding time period specified in the Third Schedule, if the Data Principal neither approaches such Data Fiduciary for the performance of the specified purpose nor exercises her rights in relation to such processing. (2) At least forty-eight hours before completion of the time period for erasure of personal data under this rule, the Data Fiduciary shall inform the Data Principal that such personal data shall be erased upon completion of such period, unless she logs into her user account or otherwise initiates contact with the Data Fiduciary for the performance of the specified purpose or exercises her rights in relation to the processing of such personal data. (3) Without prejudice to sub-rules (1) and (2), a Data Fiduciary shall retain, in respect of any processing of personal data undertaken by it or on its behalf by a Data Processor, such personal data, associated traffic data and other logs of the processing for a minimum period of one year from the date of such processing, for the purposes as specified in the Seventh Schedule, after which the Data Fiduciary shall cause such personal data and logs to be erased, unless further retention is required for compliance with any other law for the time being in force or notified by the Government.

    Rule 8 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • GDPR, Article 5(1)(e) and Article 17

    Pointer to the official text, not restated on this site · Verified 16 August 2026

    Document status: in force

    Official source ↗

    Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.

  • DPDP Act 2023, s. 11

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) The Data Principal shall have the right to obtain from the Data Fiduciary to whom she has previously given consent, including consent as referred to in clause (a) of section 7 (hereinafter referred to as the said Data Fiduciary), for processing of personal data, upon making to it a request in such manner as may be prescribed,— (a) a summary of personal data which is being processed by such Data Fiduciary and the processing activities undertaken by that Data Fiduciary with respect to such personal data; (b) the identities of all other Data Fiduciaries and Data Processors with whom the personal data has been shared by such Data Fiduciary, along with a description of the personal data so shared; and (c) any other information related to the personal data of such Data Principal and its processing, as may be prescribed. (2) Nothing contained in clause (b) or clause (c) of sub-section (1) shall apply in respect of the sharing of any personal data by the said Data Fiduciary with any other Data Fiduciary authorised by law to obtain such personal data, where such sharing is pursuant to a request made in writing by such other Data Fiduciary for the purpose of prevention or detection or investigation of offences or cyber incidents, or for prosecution or punishment of offences.

    Section 11 on this site Official source ↗

  • DPDP Act 2023, s. 12

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) A Data Principal shall have the right to correction, completion, updating and erasure of her personal data for the processing of which she has previously given consent, including consent as referred to in clause (a) of section 7, in accordance with any requirement or procedure under any law for the time being in force. (2) A Data Fiduciary shall, upon receiving a request for correction, completion or updating from a Data Principal,— (a) correct the inaccurate or misleading personal data; (b) complete the incomplete personal data; and (c) update the personal data. (3) A Data Principal shall make a request in such manner as may be prescribed to the Data Fiduciary for erasure of her personal data, and upon receipt of such a request, the Data Fiduciary shall erase her personal data unless retention of the same is necessary for the specified purpose or for compliance with any law for the time being in force.

    Section 12 on this site Official source ↗

  • DPDP Act 2023, s. 13

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) A Data Principal shall have the right to have readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager in respect of any act or omission of such Data Fiduciary or Consent Manager regarding the performance of its obligations in relation to the personal data of such Data Principal or the exercise of her rights under the provisions of this Act and the rules made thereunder. (2) The Data Fiduciary or Consent Manager shall respond to any grievances referred to in sub-section (1) within such period as may be prescribed from the date of its receipt for all or any class of Data Fiduciaries. (3) The Data Principal shall exhaust the opportunity of redressing her grievance under this section before approaching the Board.

    Section 13 on this site Official source ↗

  • DPDP Act 2023, s. 14

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) A Data Principal shall have the right to nominate, in such manner as may be prescribed, any other individual, who shall, in the event of death or incapacity of the Data Principal, exercise the rights of the Data Principal in accordance with the provisions of this Act and the rules made thereunder. (2) For the purposes of this section, the expression “incapacity” means inability to exercise the rights of the Data Principal under the provisions of this Act or the rules made thereunder due to unsoundness of mind or infirmity of body.

    Section 14 on this site Official source ↗

  • DPDP Rules 2025, r. 14, (3)

    Official requirement · Verified 26 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (3) Every Data Fiduciary and Consent Manager shall prominently publish on its website or app, or both, as the case may be, within a reasonable period not exceeding ninety days under its grievance redressal system for responding to the grievances of Data Principals and shall, for ensuring the effectiveness of the system in responding within such period, implement appropriate technical and organisational measures.

    Rule 14 on this site Official source ↗ Also on MeitY (byte identical) ↗

    Rule 14 begins on Gazette page 29 and concludes on page 30. Sub rule (3), on page 30, is printed with no object for "publish". Corrigenda G.S.R. 892(E) do not correct page 30.

  • DPDP Act 2023, s. 40, (2)(o)

    Interpretation, requires judgment · Verified 26 August 2026

    In force since 13 November 2025

    Section 40 on this site Official source ↗

    Rule 14(3) as printed carries no object for "publish", so what the words "not exceeding ninety days" cap is not stated on the face of the text. This site reads them as capping the response period the Data Fiduciary must publish, because section 40(2)(o) describes the thing to be prescribed as "the period within which the Data Fiduciary shall respond to any grievances under sub-section (2) of section 13", and the same sub rule requires measures for responding "within such period". That reading is this site's and not a statement the printed rule makes.

  • GDPR, Articles 12 and 15 to 22

    Pointer to the official text, not restated on this site · Verified 16 August 2026

    Document status: in force

    Official source ↗

    Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.

  • DPDP Rules 2025, r. 15

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    Any personal data processed by a Data Fiduciary under the Act may be transferred outside the territory of India subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State.

    Rule 15 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • DPDP Act 2023, s. 16

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified. (2) Nothing contained in this section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data by a Data Fiduciary outside India in relation to any personal data or Data Fiduciary or class thereof.

    Section 16 on this site Official source ↗

  • DPDP Rules 2025, r. 13, (4)

    Official requirement · Verified 26 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (4) A Significant Data Fiduciary shall undertake measures to ensure that personal data specified by the Central Government, on the basis of the recommendations of a committee constituted by it, is processed subject to the restriction that the personal data and the traffic data pertaining to its flow is not transferred outside the territory of India.

    Rule 13 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • GDPR, Chapter V, Articles 44 to 49

    Pointer to the official text, not restated on this site · Verified 16 August 2026

    Document status: in force

    Official source ↗

    Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.

  • DPDP Rules 2025, r. 9

    Official requirement · Verified 16 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    Every Data Fiduciary shall prominently publish on its website or app, and mention in every response to a communication for the exercise of the rights of a Data Principal under the Act, the business contact information of the Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary the questions of the Data Principal about the processing of her personal data.

    Rule 9 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • GDPR, Articles 37 to 39

    Pointer to the official text, not restated on this site · Verified 16 August 2026

    Document status: in force

    Official source ↗

    Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.

  • DPDP Rules 2025, r. 6

    Official requirement · Verified 16 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach, which shall include, at the minimum, — (a) appropriate data security measures, such as securing of personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data; (b) appropriate measures to control access to the computer resources used by such Data Fiduciary or such a Data Processor, wherever applicable; (c) visibility on the accessing of such personal data, through appropriate logs, monitoring and review, for enabling detection of unauthorised access, its investigation and remediation to prevent recurrence; (d) reasonable measures for continued processing in the event of confidentiality, integrity or availability of such personal data being compromised as a result of destruction or loss of access to personal data or otherwise, such as by way of data-backups; (e) for enabling the detection of unauthorised access, its investigation, remediation to prevent recurrence and continued processing in the event of such a compromise, retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise; (f) appropriate provision in the contract entered into between such Data Fiduciary and such a Data Processor, wherever applicable, for taking reasonable security safeguards; and (g) appropriate technical and organisational measures to ensure effective observance of security safeguards.

    Rule 6 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • GDPR, Article 32

    Pointer to the official text, not restated on this site · Verified 16 August 2026

    Document status: in force

    Official source ↗

    Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.

  • DPDP Rules 2025, r. 13

    Official requirement · Verified 17 August 2026

    Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed

    (1) A Significant Data Fiduciary shall, once in every period of twelve months from the date on which it is notified as such or is included in the class of Data Fiduciaries notified as such, undertake a Data Protection Impact Assessment and an audit to ensure effective observance of the provisions of this Act and the rules made thereunder. (2) A Significant Data Fiduciary shall cause the person carrying out the Data Protection Impact Assessment and audit to furnish to the Board a report containing significant observations in the Data Protection Impact Assessment and audit. (3) A Significant Data Fiduciary shall observe due diligence to verify that technical measures including algorithmic software adopted by it for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data processed by it are not likely to pose a risk to the rights of Data Principals. (4) A Significant Data Fiduciary shall undertake measures to ensure that personal data specified by the Central Government, on the basis of the recommendations of a committee constituted by it, is processed subject to the restriction that the personal data and the traffic data pertaining to its flow is not transferred outside the territory of India.

    Rule 13 on this site Official source ↗ Also on MeitY (byte identical) ↗

  • GDPR, Article 35

    Pointer to the official text, not restated on this site · Verified 16 August 2026

    Document status: in force

    Official source ↗

    Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.

Sources cited on this page

  1. [1]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, p. 26. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
  2. [2]
    Regulation (EU) 2016/679 (General Data Protection Regulation) (CELEX 32016R0679), Articles 33 and 34. Official source ↗ · Pointer to the official text, not restated on this site · Verified 16 August 2026Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.
  3. [3]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 3, p. 24. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
  4. [4]
    Regulation (EU) 2016/679 (General Data Protection Regulation) (CELEX 32016R0679), Articles 12 to 14. Official source ↗ · Pointer to the official text, not restated on this site · Verified 16 August 2026Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.
  5. [5]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 9, p. 8. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026Quoted here are sub-sections (1) to (3). The conditional exemptions are in sub-sections (4) and (5), on the same Gazette page, and in Rule 12 with the Fourth Schedule.
  6. [6]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 2(f), p. 2. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
  7. [7]
    Regulation (EU) 2016/679 (General Data Protection Regulation) (CELEX 32016R0679), Article 8. Official source ↗ · Pointer to the official text, not restated on this site · Verified 16 August 2026Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.
  8. [8]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, (7), p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026Sub-section (7) begins on Gazette page 7 and concludes on page 8.
  9. [9]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 8, p. 27. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
  10. [10]
    Regulation (EU) 2016/679 (General Data Protection Regulation) (CELEX 32016R0679), Article 5(1)(e) and Article 17. Official source ↗ · Pointer to the official text, not restated on this site · Verified 16 August 2026Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.
  11. [11]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 11, p. 9. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
  12. [12]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 12, p. 10. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
  13. [13]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 13, p. 10. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
  14. [14]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 14, p. 10. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
  15. [15]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 14, (3), p. 30. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 26 August 2026Rule 14 begins on Gazette page 29 and concludes on page 30. Sub rule (3), on page 30, is printed with no object for "publish". Corrigenda G.S.R. 892(E) do not correct page 30.
  16. [16]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 40, (2)(o), p. 18. Published 11 August 2023. Official source ↗ · Interpretation, requires judgment · Verified 26 August 2026Rule 14(3) as printed carries no object for "publish", so what the words "not exceeding ninety days" cap is not stated on the face of the text. This site reads them as capping the response period the Data Fiduciary must publish, because section 40(2)(o) describes the thing to be prescribed as "the period within which the Data Fiduciary shall respond to any grievances under sub-section (2) of section 13", and the same sub rule requires measures for responding "within such period". That reading is this site's and not a statement the printed rule makes.
  17. [17]
    Regulation (EU) 2016/679 (General Data Protection Regulation) (CELEX 32016R0679), Articles 12 and 15 to 22. Official source ↗ · Pointer to the official text, not restated on this site · Verified 16 August 2026Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.
  18. [18]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 15, p. 30. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026
  19. [19]
    The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 16, p. 11. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
  20. [20]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 13, (4), p. 29. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 26 August 2026
  21. [21]
    Regulation (EU) 2016/679 (General Data Protection Regulation) (CELEX 32016R0679), Chapter V, Articles 44 to 49. Official source ↗ · Pointer to the official text, not restated on this site · Verified 16 August 2026Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.
  22. [22]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 9, p. 27. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
  23. [23]
    Regulation (EU) 2016/679 (General Data Protection Regulation) (CELEX 32016R0679), Articles 37 to 39. Official source ↗ · Pointer to the official text, not restated on this site · Verified 16 August 2026Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.
  24. [24]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 6, p. 26. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
  25. [25]
    Regulation (EU) 2016/679 (General Data Protection Regulation) (CELEX 32016R0679), Article 32. Official source ↗ · Pointer to the official text, not restated on this site · Verified 16 August 2026Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.
  26. [26]
    Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 13, p. 29. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026
  27. [27]
    Regulation (EU) 2016/679 (General Data Protection Regulation) (CELEX 32016R0679), Article 35. Official source ↗ · Pointer to the official text, not restated on this site · Verified 16 August 2026Pointer to the official EUR-Lex text for separate review; this site does not restate GDPR requirements.

Read the guide

DPDP vs GDPR: the key differences Why the 2 regimes diverge structurally, including the Consent Manager institution the article sets against the GDPR side by side.