DPDP to GDPR mapping:
the controls both laws test.
Every DPDP Act section and GDPR article in the TryTrustable control library that is evidenced by the same control, and every one that is not.
Last updated Published by TryTrustableNot legal advice
How does the DPDP Act map to the GDPR?
In the TryTrustable control library, 11 shared controls are tested against both DPDP Act and GDPR. Those controls reach 15 of the 15 DPDP Act requirements the library models and 17 of the 20 GDPR requirements. Each row below is one control and the requirements on each side it is evidence for.
The method is simple: both laws are broken into requirements, each requirement is mapped to the controls that evidence it, and two requirements are paired only when they share a control. The DPDP Act, 2023 is modelled from section 4 to section 17, and the GDPR by its key articles. For the law itself, side by side, see the DPDP vs GDPR table in the DPDP Act guide and the GDPR guide.
| Shared control | DPDP Act | GDPR |
|---|---|---|
| Periodic logical access reviewCTL-ACCESS-REVIEW | §8(5) Reasonable security safeguards to prevent personal data breach | Art.9 Processing of special categories of personal data restricted and safeguarded |
| Consent lifecycle managementCTL-CONSENT-MGMT | §4 Personal data processed only for lawful purpose with consent or legitimate use §6 Consent free, specific, informed, unconditional and unambiguous; easy withdrawal §9 Verifiable parental consent for children; no tracking or targeted ads to children | Art.7 Conditions for consent: demonstrable, freely given, as easy to withdraw as to give Art.21 Right to object to processing including direct marketing |
| Data retention and disposalCTL-DATA-RETENTION | §8(7) Erasure of personal data when purpose is served or consent withdrawn §12 Right to correction, completion, updating and erasure of personal data | Art.5 Principles: lawfulness, fairness, transparency, minimisation, accuracy, storage limitation Art.17 Right to erasure (right to be forgotten) honoured without undue delay |
| Data protection impact assessmentCTL-DPIA | §10 Significant Data Fiduciary obligations: DPO in India, audits, periodic DPIA | Art.35 Data protection impact assessments for high-risk processing |
| Data subject rights fulfilmentCTL-DSAR | §8(7) Erasure of personal data when purpose is served or consent withdrawn §11 Right to access summary of personal data and processing activities §12 Right to correction, completion, updating and erasure of personal data §13 Right to grievance redressal within prescribed time §14 Right to nominate another individual to exercise rights | Art.16 Right to rectification of inaccurate personal data Art.17 Right to erasure (right to be forgotten) honoured without undue delay Art.18 Right to restriction of processing Art.20 Right to data portability: structured, machine-readable export |
| Encryption of data at restCTL-ENCRYPT-REST | §8(5) Reasonable security safeguards to prevent personal data breach | Art.9 Processing of special categories of personal data restricted and safeguarded Art.25 Data protection by design and by default Art.32 Security of processing: encryption and pseudonymisation of PII |
| Encryption of data in transitCTL-ENCRYPT-TRANSIT | §8(5) Reasonable security safeguards to prevent personal data breach | Art.32 Security of processing: encryption and pseudonymisation of PII |
| Incident response plan and exerciseCTL-IR-PLAN | §8(6) Intimation of personal data breach to the Board and affected data principals | Art.33 Personal data breach notification to supervisory authority in 72h Art.34 Communication of personal data breach to affected data subjects |
| Policy review and attestationCTL-POLICY-REVIEW | §4 Personal data processed only for lawful purpose with consent or legitimate use §10 Significant Data Fiduciary obligations: DPO in India, audits, periodic DPIA §17 Exemptions applied narrowly and documented (research, enforcement, startups) | Art.5 Principles: lawfulness, fairness, transparency, minimisation, accuracy, storage limitation Art.37 Designation of a data protection officer |
| Privacy notice and transparencyCTL-PRIVACY-NOTICE | §5 Notice given to data principal before or at the time of requesting consent §8(9)-(10) Grievance redressal mechanism and contact of designated officer published §13 Right to grievance redressal within prescribed time | Art.12 Transparent information, communication and modalities for exercising rights Art.13 Information provided where personal data are collected from the data subject |
| Vendor due diligence and monitoringCTL-VENDOR-DD | §16 Cross-border transfer of personal data only to non-restricted countries | Art.28 Processor contracts and sub-processor due diligence (DPAs) |
Generated from the TryTrustable control library. Requirement descriptions are the library's own short wording of what the control is tested against, not the text of the standard or law. A mapping we could not stand behind on review is left out until it is corrected in the library.
43 rows: one per control and requirement, with the library description. Paste into a spreadsheet.
Which controls does only one side ask for?
A requirement can be reached through a general control and still need a specific one. These controls are mapped to requirements on one side only, so evidence for them does nothing for the other framework.
Only DPDP Act:
- Breach notification to Board and subjects CTL-BREACH-NOTIFY: §8(6)
- Verifiable parental consent for children CTL-CHILD-CONSENT: §9
- Lawful basis and consent capture CTL-CONSENT: §6
- Demonstrable consent and notice CTL-CONSENT-PROOF: §5, §6
- Centralised, tamper-evident logging CTL-LOGGING: §8(5)
- Multi-factor authentication enforced CTL-MFA: §8(5)
- Data Principal nomination CTL-NOMINATION: §14
- Processors engaged under valid contract CTL-PROCESSOR-CONTRACT: §16
- Lawful basis for every purpose CTL-PURPOSE-BASIS: §4, §17
- Rights requests answered within time CTL-RIGHTS-SLA: §8(9)-(10), §11, §13
- Significant Data Fiduciary assurance CTL-SDF-AUDIT: §10
- Withdrawal propagated to processors CTL-WITHDRAW-RELAY: §6, §8(7)
- Cross-border transfer control CTL-XBORDER: §16
Only GDPR:
- Asset inventory CTL-ASSET-INV: Art.30
- Secure software development lifecycle CTL-SDLC: Art.25
Where the GDPR controls carry over, and where they do not
The shared rows cluster in three places: security of processing (DPDP section 8(5) against Articles 25 and 32), rights fulfilment (sections 11 to 14 against Articles 16 to 20), and breach response (section 8(6) against Articles 33 and 34). An organisation with working GDPR controls in those areas can point the same evidence at both.
Consent is where reuse is thinnest. The DPDP-specific controls in the library, such as proof of the notice shown with each consent, withdrawal relayed to every processor, verifiable parental consent and the cross-border restricted list, have no GDPR requirement mapped to them, so they appear under controls only the DPDP side asks for. Every DPDP section is reached by some shared control, but that is not the same as being covered: section 14 is reached through the rights workflow, and nomination itself still has no GDPR counterpart. The DPDP consent notice guide and the consent platform cover that part, and the penalty schedule shows what each gap costs.
The things people ask us
Is DPDP compliance the same as GDPR compliance?
No. The security, rights-handling and breach-response controls you built for the GDPR are largely reusable, which is what the shared rows show. The legal bases are not: the DPDP Act has consent and a closed list of legitimate uses, with no general legitimate-interests basis, and it adds duties the GDPR does not have, such as nomination and a ban on tracking children.
Does the DPDP Act have a right to data portability?
No. The GDPR's Article 20 portability right has no counterpart in the DPDP Act, whose rights are access to a summary of processing, correction and erasure, grievance redressal and nomination. In the library, the rights-fulfilment control still covers both, because the same request workflow handles every right; the portability export is simply unused for DPDP.
Which DPDP duties have no GDPR equivalent?
Nomination under section 14, the outright prohibition in section 9 on tracking, behavioural monitoring and targeted advertising directed at children, notifying every personal data breach to the Board and to affected people, and the Significant Data Fiduciary regime under section 10. Each needs its own control rather than a GDPR one reused.
How do breach notification timings differ?
Under the GDPR the controller notifies the supervisory authority within 72 hours where feasible, unless the breach is unlikely to result in a risk, and tells individuals only when the risk is high. Under the DPDP Rules every breach goes to the Board and to affected Data Principals without delay, with a detailed report to the Board within 72 hours of becoming aware.
Can I download this mapping?
Use Copy as CSV above the gap lists. It copies every row of the table, one line per control and requirement with the library's description, ready to paste into a spreadsheet. The mapping is generated from the same control library the product uses, so it changes when the library does.
Is TryTrustable a Consent Manager under the DPDP Act?
No. TryTrustable is a consent management platform: software a Data Fiduciary runs on its own site and apps. A Consent Manager under the Act is a Board-registered intermediary company incorporated in India. The difference is explained on the DPDP Consent Managers guide.
Run DPDP and GDPR from one control set.
Thirty minutes. We show one control result landing against a DPDP section and a GDPR article at the same time, with the evidence behind it.