Mapping · DPDP Act ↔ GDPR

DPDP to GDPR mapping:
the controls both laws test.

Every DPDP Act section and GDPR article in the TryTrustable control library that is evidenced by the same control, and every one that is not.

11 shared controlsDPDP Act: 15/15 reachedGDPR: 17/20 reachedCopy as CSV

Last updated Published by TryTrustableNot legal advice

01

How does the DPDP Act map to the GDPR?

In the TryTrustable control library, 11 shared controls are tested against both DPDP Act and GDPR. Those controls reach 15 of the 15 DPDP Act requirements the library models and 17 of the 20 GDPR requirements. Each row below is one control and the requirements on each side it is evidence for.

The method is simple: both laws are broken into requirements, each requirement is mapped to the controls that evidence it, and two requirements are paired only when they share a control. The DPDP Act, 2023 is modelled from section 4 to section 17, and the GDPR by its key articles. For the law itself, side by side, see the DPDP vs GDPR table in the DPDP Act guide and the GDPR guide.

Shared controlDPDP ActGDPR
Periodic logical access reviewCTL-ACCESS-REVIEW
§8(5) Reasonable security safeguards to prevent personal data breach
Art.9 Processing of special categories of personal data restricted and safeguarded
Consent lifecycle managementCTL-CONSENT-MGMT
§4 Personal data processed only for lawful purpose with consent or legitimate use
§6 Consent free, specific, informed, unconditional and unambiguous; easy withdrawal
§9 Verifiable parental consent for children; no tracking or targeted ads to children
Art.7 Conditions for consent: demonstrable, freely given, as easy to withdraw as to give
Art.21 Right to object to processing including direct marketing
Data retention and disposalCTL-DATA-RETENTION
§8(7) Erasure of personal data when purpose is served or consent withdrawn
§12 Right to correction, completion, updating and erasure of personal data
Art.5 Principles: lawfulness, fairness, transparency, minimisation, accuracy, storage limitation
Art.17 Right to erasure (right to be forgotten) honoured without undue delay
Data protection impact assessmentCTL-DPIA
§10 Significant Data Fiduciary obligations: DPO in India, audits, periodic DPIA
Art.35 Data protection impact assessments for high-risk processing
Data subject rights fulfilmentCTL-DSAR
§8(7) Erasure of personal data when purpose is served or consent withdrawn
§11 Right to access summary of personal data and processing activities
§12 Right to correction, completion, updating and erasure of personal data
§13 Right to grievance redressal within prescribed time
§14 Right to nominate another individual to exercise rights
Art.16 Right to rectification of inaccurate personal data
Art.17 Right to erasure (right to be forgotten) honoured without undue delay
Art.18 Right to restriction of processing
Art.20 Right to data portability: structured, machine-readable export
Encryption of data at restCTL-ENCRYPT-REST
§8(5) Reasonable security safeguards to prevent personal data breach
Art.9 Processing of special categories of personal data restricted and safeguarded
Art.25 Data protection by design and by default
Art.32 Security of processing: encryption and pseudonymisation of PII
Encryption of data in transitCTL-ENCRYPT-TRANSIT
§8(5) Reasonable security safeguards to prevent personal data breach
Art.32 Security of processing: encryption and pseudonymisation of PII
Incident response plan and exerciseCTL-IR-PLAN
§8(6) Intimation of personal data breach to the Board and affected data principals
Art.33 Personal data breach notification to supervisory authority in 72h
Art.34 Communication of personal data breach to affected data subjects
Policy review and attestationCTL-POLICY-REVIEW
§4 Personal data processed only for lawful purpose with consent or legitimate use
§10 Significant Data Fiduciary obligations: DPO in India, audits, periodic DPIA
§17 Exemptions applied narrowly and documented (research, enforcement, startups)
Art.5 Principles: lawfulness, fairness, transparency, minimisation, accuracy, storage limitation
Art.37 Designation of a data protection officer
Privacy notice and transparencyCTL-PRIVACY-NOTICE
§5 Notice given to data principal before or at the time of requesting consent
§8(9)-(10) Grievance redressal mechanism and contact of designated officer published
§13 Right to grievance redressal within prescribed time
Art.12 Transparent information, communication and modalities for exercising rights
Art.13 Information provided where personal data are collected from the data subject
Vendor due diligence and monitoringCTL-VENDOR-DD
§16 Cross-border transfer of personal data only to non-restricted countries
Art.28 Processor contracts and sub-processor due diligence (DPAs)

Generated from the TryTrustable control library. Requirement descriptions are the library's own short wording of what the control is tested against, not the text of the standard or law. A mapping we could not stand behind on review is left out until it is corrected in the library.

43 rows: one per control and requirement, with the library description. Paste into a spreadsheet.

02

Which DPDP Act requirements have no shared control with GDPR?

These DPDP Act requirements are modelled in the library but share no control with any GDPR requirement. They are the work that GDPR does not cover for you, or places where the library has not linked them yet.

None.

And the GDPR requirements with no shared control on the DPDP Act side:

  • Art.6 Lawful basis documented for each processing activity
  • Art.15 Right of access: subject access requests fulfilled within one month
  • Art.30 Records of processing activities (RoPA) maintained and current
03

Which controls does only one side ask for?

A requirement can be reached through a general control and still need a specific one. These controls are mapped to requirements on one side only, so evidence for them does nothing for the other framework.

Only DPDP Act:

  • Breach notification to Board and subjects CTL-BREACH-NOTIFY: §8(6)
  • Verifiable parental consent for children CTL-CHILD-CONSENT: §9
  • Lawful basis and consent capture CTL-CONSENT: §6
  • Demonstrable consent and notice CTL-CONSENT-PROOF: §5, §6
  • Centralised, tamper-evident logging CTL-LOGGING: §8(5)
  • Multi-factor authentication enforced CTL-MFA: §8(5)
  • Data Principal nomination CTL-NOMINATION: §14
  • Processors engaged under valid contract CTL-PROCESSOR-CONTRACT: §16
  • Lawful basis for every purpose CTL-PURPOSE-BASIS: §4, §17
  • Rights requests answered within time CTL-RIGHTS-SLA: §8(9)-(10), §11, §13
  • Significant Data Fiduciary assurance CTL-SDF-AUDIT: §10
  • Withdrawal propagated to processors CTL-WITHDRAW-RELAY: §6, §8(7)
  • Cross-border transfer control CTL-XBORDER: §16

Only GDPR:

  • Asset inventory CTL-ASSET-INV: Art.30
  • Secure software development lifecycle CTL-SDLC: Art.25
04

Where the GDPR controls carry over, and where they do not

The shared rows cluster in three places: security of processing (DPDP section 8(5) against Articles 25 and 32), rights fulfilment (sections 11 to 14 against Articles 16 to 20), and breach response (section 8(6) against Articles 33 and 34). An organisation with working GDPR controls in those areas can point the same evidence at both.

Consent is where reuse is thinnest. The DPDP-specific controls in the library, such as proof of the notice shown with each consent, withdrawal relayed to every processor, verifiable parental consent and the cross-border restricted list, have no GDPR requirement mapped to them, so they appear under controls only the DPDP side asks for. Every DPDP section is reached by some shared control, but that is not the same as being covered: section 14 is reached through the rights workflow, and nomination itself still has no GDPR counterpart. The DPDP consent notice guide and the consent platform cover that part, and the penalty schedule shows what each gap costs.

Questions

The things people ask us

Is DPDP compliance the same as GDPR compliance?

No. The security, rights-handling and breach-response controls you built for the GDPR are largely reusable, which is what the shared rows show. The legal bases are not: the DPDP Act has consent and a closed list of legitimate uses, with no general legitimate-interests basis, and it adds duties the GDPR does not have, such as nomination and a ban on tracking children.

Does the DPDP Act have a right to data portability?

No. The GDPR's Article 20 portability right has no counterpart in the DPDP Act, whose rights are access to a summary of processing, correction and erasure, grievance redressal and nomination. In the library, the rights-fulfilment control still covers both, because the same request workflow handles every right; the portability export is simply unused for DPDP.

Which DPDP duties have no GDPR equivalent?

Nomination under section 14, the outright prohibition in section 9 on tracking, behavioural monitoring and targeted advertising directed at children, notifying every personal data breach to the Board and to affected people, and the Significant Data Fiduciary regime under section 10. Each needs its own control rather than a GDPR one reused.

How do breach notification timings differ?

Under the GDPR the controller notifies the supervisory authority within 72 hours where feasible, unless the breach is unlikely to result in a risk, and tells individuals only when the risk is high. Under the DPDP Rules every breach goes to the Board and to affected Data Principals without delay, with a detailed report to the Board within 72 hours of becoming aware.

Can I download this mapping?

Use Copy as CSV above the gap lists. It copies every row of the table, one line per control and requirement with the library's description, ready to paste into a spreadsheet. The mapping is generated from the same control library the product uses, so it changes when the library does.

Is TryTrustable a Consent Manager under the DPDP Act?

No. TryTrustable is a consent management platform: software a Data Fiduciary runs on its own site and apps. A Consent Manager under the Act is a Board-registered intermediary company incorporated in India. The difference is explained on the DPDP Consent Managers guide.

Book a walkthrough

Run DPDP and GDPR from one control set.

Thirty minutes. We show one control result landing against a DPDP section and a GDPR article at the same time, with the evidence behind it.