Strongest similarity
Shared ground
Both texts address consent, individual-facing rights, organisational duties and extra-territorial situations. Those shared headings do not make the mechanics equivalent.
Symmetrical comparison · IN ↔ EU
One text is younger and substantially phased; the other has applied since 2018. Compare legal architecture without turning age, detail or concision into a verdict.
Reading boundary
This essay compares legal architecture, status and implementation questions. It does not assess adequacy, equivalence, compliance or jurisdiction quality.
Carry this pair into the explorer17-factor research trace
Every methodology factor points to one of the five mirrored questions below. A shared URL can change the order of attention, but never the law, source record or conclusion.
URL lens · browser only
All 17 questionsNo reader priorities are stored in this URL, so the published methodology order is shown.
Attention values apply to questions only. They are not findings, scores or a jurisdiction ranking.
How much interpretation is needed before a team can identify the rule that governs its activity?
Which entities, people, data and overseas activities fall inside the framework?
Which processing grounds exist, and how does an organisation document the one it relies on?
What must a person be told, when, and in what form before data is used?
Can a person reverse a choice through a practical, understandable route?
Which rights exist, and what must happen before a person can obtain a remedy?
How does the framework recognise age, guardianship and risks to younger people?
Who remains accountable when processing is delegated or shared?
Which safeguards and breach steps are specified, and when are they triggered?
When must an organisation investigate and document risk before processing?
What transparency or recourse applies when automated processing affects a person?
Which transfer routes exist, and what continuing safeguards travel with the data?
How can people and organisations reach the institution, and what can it do?
How are sanctions linked to conduct, context and due process?
Which obligations create fixed costs, and what tailoring exists for smaller organisations?
Could teams implement the rule through portable patterns without weakening legal context?
What has the framework's operation, guidance and enforcement record actually demonstrated?
Strongest similarity
Both texts address consent, individual-facing rights, organisational duties and extra-territorial situations. Those shared headings do not make the mechanics equivalent.
Strongest difference
The operative position is asymmetric. GDPR applies now; many core DPDP processing duties and rights have a notified date of 13 May 2027.
Implementation consequence
A team cannot safely port a single policy pack between the two. It must first map operative dates, legal roles, processing grounds and the rights actually available in each context.
Five mirrored questions
Every row exposes its source coordinates. Press a coordinate to inspect the drawer without leaving the essay.
| Research question | India DPDP | Comparison EU GDPR | Provenance Source coordinates |
|---|---|---|---|
| 01What is operative now? | Selected institutional, definition and rulemaking provisions are in force. Most substantive processing duties and Data Principal rights have notified future commencement. | The regulation has applied since 25 May 2018; issue-specific Member State law and regulator guidance may supplement it. | Sources for this row:IN-02 · Gazette of India / MeitYIN-03 · Gazette of India / MeitYEU-01 · EUR-Lex / Official Journal of the European Union |
| 02How is processing authorised? | The enacted text uses consent and specified certain legitimate uses. The relevant core provisions are in the future commencement cohort. | Article 6 sets out multiple lawful bases, alongside principles and special-category rules elsewhere in the regulation. | Sources for this row:IN-01 · Gazette of India / MeitYIN-02 · Gazette of India / MeitYEU-01 · EUR-Lex / Official Journal of the European Union |
| 03What can an individual ask for? | The enacted Act describes access to information, correction, erasure, grievance redress and nomination. The rights provisions are not yet operative on the as-of date. | Articles 12–22 include access, rectification, erasure, restriction, portability, objection and safeguards connected with certain automated decisions. | Sources for this row:IN-01 · Gazette of India / MeitYIN-02 · Gazette of India / MeitYEU-01 · EUR-Lex / Official Journal of the European Union |
| 04How is accountability organised? | Data Fiduciary duties, processor use and additional Significant Data Fiduciary obligations are enacted with phased commencement. | Controller and processor responsibilities, records, security, impact assessments and data-protection officers are detailed across Articles 24–39. | Sources for this row:IN-01 · Gazette of India / MeitYIN-03 · Gazette of India / MeitYEU-01 · EUR-Lex / Official Journal of the European Union |
| 05What institutional record exists? | The Board framework is in the first commencement cohort. That legal design does not yet establish a comparable substantive enforcement record. | The regulation establishes independent supervisory authorities and EU cooperation mechanisms, with a multi-year operating record that still varies by context. | Sources for this row:IN-02 · Gazette of India / MeitYEU-01 · EUR-Lex / Official Journal of the European Union |
The strongest objection to a simple conclusion
Caveats to carry forward
Article revision record
This register begins with the private-preview editorial rebuild. It records material content, method, interface and trust-policy changes without inventing a history that predates the available repository evidence.
PAIR-GDPR-20260826-01