Symmetrical comparison · IN ↔ BR

DPDP vs LGPD: similar ambitions, different legal machinery

Both are national privacy frameworks for large digital economies. That context is a research prompt, not a legal category or proof of equivalence.

Reading boundary

Difference map, not a league table.

This essay compares legal architecture, status and implementation questions. It does not assess adequacy, equivalence, compliance or jurisdiction quality.

Carry this pair into the explorer

17-factor research trace

Turn a shareable lens into an evidence reading path.

Every methodology factor points to one of the five mirrored questions below. A shared URL can change the order of attention, but never the law, source record or conclusion.

URL lens · browser only

All 17 questions

No reader priorities are stored in this URL, so the published methodology order is shown.

Revise this research brief

Attention values apply to questions only. They are not findings, scores or a jurisdiction ranking.

All 17 research questions shown in the published order.
  1. Q01Readable rulesDrafting clarity

    How much interpretation is needed before a team can identify the rule that governs its activity?

    Evidence to seek
    Controlling text, amendment history, commencement records and an issue-specific reading path.
    Do not infer
    Shorter text is not automatically clearer, safer or cheaper to implement.
    Trace to mirrored question: What is operative now?
  2. Q02Readable rulesScope and reach

    Which entities, people, data and overseas activities fall inside the framework?

    Evidence to seek
    Definitions, territorial provisions, exclusions, coverage thresholds and relevant official guidance.
    Do not infer
    A national market presence does not by itself prove that a specific activity is covered.
    Trace to mirrored question: How is processing organised?
  3. Q03Readable rulesProcessing grounds

    Which processing grounds exist, and how does an organisation document the one it relies on?

    Evidence to seek
    Operative ground or exception, purpose record, applicable conditions and supporting documentation.
    Do not infer
    Matching labels across laws do not make processing grounds interchangeable.
    Trace to mirrored question: How is processing organised?
  4. Q04Readable rulesNotice usability

    What must a person be told, when, and in what form before data is used?

    Evidence to seek
    Operative notice duties, delivery context, language or accessibility rules and tested user comprehension.
    Do not infer
    Publishing a notice does not prove that people saw or understood it.
    Trace to mirrored question: How is processing organised?
  5. Q05Individual agencyPreference control

    Can a person reverse a choice through a practical, understandable route?

    Evidence to seek
    Operative withdrawal rule, interface steps, downstream propagation and documented exceptions.
    Do not infer
    A stated right to withdraw does not prove that the practical route is equivalent to giving consent.
    Trace to mirrored question: What can an individual ask for?
  6. Q06Individual agencyRights and remedy

    Which rights exist, and what must happen before a person can obtain a remedy?

    Evidence to seek
    Operative right, identity and timing rules, refusal grounds, escalation path and outcome evidence.
    Do not infer
    A longer catalogue of rights does not by itself show that remedies are more accessible.
    Trace to mirrored question: What can an individual ask for?
  7. Q07Individual agencyChildren and guardians

    How does the framework recognise age, guardianship and risks to younger people?

    Evidence to seek
    Age definition, guardian mechanism, applicable safeguards, exceptions and child-facing design evidence.
    Do not infer
    A single age threshold does not capture the whole child-safety or guardian model.
    Trace to mirrored question: What can an individual ask for?
  8. Q08Organisational architectureAccountability roles

    Who remains accountable when processing is delegated or shared?

    Evidence to seek
    Role definitions, contracts, instruction boundaries, onward delegation and responsibility for failures.
    Do not infer
    Vendor terminology in one framework cannot be copied directly into another role system.
    Trace to mirrored question: How is accountability organised?
  9. Q09Organisational architectureSecurity and breach

    Which safeguards and breach steps are specified, and when are they triggered?

    Evidence to seek
    Operative safeguard standard, trigger tests, notification recipients, timing and incident records.
    Do not infer
    A detailed checklist does not prove effective security or consistent breach response.
    Trace to mirrored question: How is accountability organised?
  10. Q10Organisational architectureRisk assessment

    When must an organisation investigate and document risk before processing?

    Evidence to seek
    Trigger criteria, required assessment content, reviewer or consultation route and retained decision record.
    Do not infer
    Using an impact-assessment template does not prove that the relevant risks were identified.
    Trace to mirrored question: How is accountability organised?
  11. Q11Individual agencyAutomated decisions

    What transparency or recourse applies when automated processing affects a person?

    Evidence to seek
    Scope of covered decisions, explanation or notice duties, contest route and evidence of human review.
    Do not infer
    Generic transparency language does not establish a right against every automated outcome.
    Trace to mirrored question: What can an individual ask for?
  12. Q12Organisational architectureCross-border transfer

    Which transfer routes exist, and what continuing safeguards travel with the data?

    Evidence to seek
    Destination, transfer route, restrictions, contract or assessment record and onward-transfer controls.
    Do not infer
    A permitted destination does not remove continuing security or accountability duties.
    Trace to mirrored question: How is accountability organised?
  13. Q13Institutions and remedyRegulator design

    How can people and organisations reach the institution, and what can it do?

    Evidence to seek
    Operative mandate, procedure, access route, published powers and evidence of actual use.
    Do not infer
    A digital portal or broad statutory power does not prove timely or accessible resolution.
    Trace to mirrored question: What institutional record exists?
  14. Q14Institutions and remedyPenalty design

    How are sanctions linked to conduct, context and due process?

    Evidence to seek
    Operative penalty provisions, decision factors, appeal route and dated enforcement records.
    Do not infer
    A higher maximum penalty does not automatically mean stronger protection or enforcement.
    Trace to mirrored question: What institutional record exists?
  15. Q15Organisational architectureMSME burden

    Which obligations create fixed costs, and what tailoring exists for smaller organisations?

    Evidence to seek
    Role-specific task inventory, exemptions or tailoring, recurring workload and organisation-level cost evidence.
    Do not infer
    Concise legislation does not prove low implementation cost for a smaller organisation.
    Trace to mirrored question: How is accountability organised?
  16. Q16Organisational architectureInteroperability

    Could teams implement the rule through portable patterns without weakening legal context?

    Evidence to seek
    Compatible definitions, documented interfaces, governance ownership and tests across real operating contexts.
    Do not infer
    Technical reuse does not make the underlying legal requirements equivalent.
    Trace to mirrored question: How is accountability organised?
  17. Q17Institutions and remedyEnforcement maturity

    What has the framework's operation, guidance and enforcement record actually demonstrated?

    Evidence to seek
    Dated guidance, decisions, enforcement records, appeal outcomes and evidence about access in practice.
    Do not infer
    Age or publication volume alone is not a measure of institutional quality.
    Trace to mirrored question: What institutional record exists?
01

Strongest similarity

Shared ground

Both texts have extra-territorial elements and address individual rights, organisational duties, security and overseas data movement.

02

Strongest difference

Material distinction

DPDP is limited to digital personal data and relies on a smaller enacted set of processing routes. LGPD governs personal-data processing more broadly and enumerates multiple legal bases within an operative framework.

03

Implementation consequence

What changes operationally

A shared emerging-market narrative cannot replace role, scope, legal-basis and transfer analysis. Each processing activity needs its own jurisdiction-specific map.

Five mirrored questions

Read both columns in the same order.

Every row exposes its source coordinates. Press a coordinate to inspect the drawer without leaving the essay.

A symmetrical reading table. It maps legal architecture and status; it does not award points.
Research questionIndia DPDPComparison Brazil LGPDProvenance Source coordinates
01What is operative now?Selected provisions are in force; most core processing duties and rights are appointed for May 2027.The main LGPD provisions have operated since September 2020, with administrative sanctions operative since August 2021.Sources for this row:IN-02 · Gazette of India / MeitYBR-01 · Presidency of the Republic of Brazil
02How is processing organised?The Act covers digital personal data and enacts consent plus specified certain legitimate uses, subject to phased commencement.The LGPD covers personal-data processing within its scope and enumerates multiple legal bases for ordinary and sensitive data.Sources for this row:IN-01 · Gazette of India / MeitYIN-02 · Gazette of India / MeitYBR-01 · Presidency of the Republic of Brazil
03What can an individual ask for?The enacted future rights architecture includes information access, correction, erasure, grievance redress and nomination.Article 18 sets out data-subject rights within an operative framework, supplemented by regulator material and procedural context.Sources for this row:IN-01 · Gazette of India / MeitYIN-02 · Gazette of India / MeitYBR-01 · Presidency of the Republic of Brazil
04How is accountability organised?Data Fiduciary and Data Processor roles, security duties and added Significant Data Fiduciary duties are enacted with future dates for core provisions.Controller and operator roles, security duties and international-transfer mechanisms operate under the LGPD and ANPD regulation.Sources for this row:IN-01 · Gazette of India / MeitYIN-03 · Gazette of India / MeitYBR-01 · Presidency of the Republic of Brazil
05What institutional record exists?The Board framework is partly commenced; substantive enforcement experience is not yet comparable.The ANPD operates within an established statutory and regulatory record, which still requires a defined method before it can support any cross-jurisdiction conclusion.Sources for this row:IN-02 · Gazette of India / MeitYBR-01 · Presidency of the Republic of BrazilBR-02 · Brazilian National Data Protection Authority (ANPD)

The strongest objection to a simple conclusion

Institutional maturity can illuminate real implementation work, but counting years or regulator publications without a defined method can create a superficial winner.

Caveats to carry forward

  • The official Portuguese LGPD text controls; the ANPD English version is a research aid.
  • Large-economy context does not itself establish deployability, protection quality or institutional effectiveness.
View dated update log
  1. Added official consolidated Brazilian text and separated economic context from legal comparison.

Article revision record

What changed on this page.

This register begins with the private-preview editorial rebuild. It records material content, method, interface and trust-policy changes without inventing a history that predates the available repository evidence.

ROUTE/compare/dpdp-v-lgpd
ENTRIES01
Inspect the full revision register
Legal or editorial substance changedExpanded the symmetrical essay and connected all 17 reader priorities to a shareable, source-led research trace.
Why this changed
Emerging-economy privacy frameworks under different institutions require mirrored evidence and visible translation limits.
Claim impact
The comparison preserves source hierarchy and produces no jurisdiction ranking or recommendation.
Review state
Human legal or editorial review still required
Change ID
PAIR-LGPD-20260826-01
Source impactIN-01 · Gazette of India / MeitYIN-02 · Gazette of India / MeitYIN-03 · Gazette of India / MeitYBR-01 · Presidency of the Republic of BrazilBR-02 · Brazilian National Data Protection Authority (ANPD)

Source record

Source record

Authority
Pinpoint
Legal status
Checked
Basis

Official guidance can explain a rule, but it does not replace the controlling legal text.