GDPR for Indian Companies (with DPDP Crosswalk) Practitioner
One programme, two regimes: run GDPR and DPDP from one operating desk
A citation-anchored, exam-backed practitioner course on the EU General Data Protection Regulation as it applies to Indian companies that offer goods or services to EU data subjects, monitor their behaviour, or process EU personal data as processors of EU controllers. Not a green-field GDPR primer. This course assumes you know DPDP (or are learning it in parallel through the dcomply Academy DPDP Act 2023 or DPDP Rules 2025 Practitioner courses) and teaches GDPR alongside DPDP so you can operate under both regimes as one programme. Every claim is anchored to a primary source: Regulation (EU) 2016/679 article, Recital, EDPB Guideline number, Commission decision, CJEU judgment, DPA enforcement order, DPDP Section or Rule, or CERT-In Direction.
Written against the primary sources current to 10 August 2026, including the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026) which postponed high-risk AI applicability, the EU-US Data Privacy Framework Latombe appeal (Case C-703/25 P pending at CJEU with Microsoft admitted as intervener), the UK adequacy renewal (19 December 2025 with sunset 27 December 2031), Brazil mutual adequacy (26 January 2026 via Implementing Decision 2026/179), the latest EDPB Guidelines including draft 02/2026 on Anonymisation and 02/2025 v2.0 on Blockchain, and the top-15 GDPR fines including Meta €1.2B (2023), TikTok €530M (May 2025), LinkedIn €310M (Oct 2024), and Uber €290M (Aug 2024).
What you will learn
- Determine whether GDPR reaches your Indian entity via Article 3(1) establishment or Article 3(2) targeting or monitoring
- Read one incident against three parallel clocks: CERT-In 6 hours, DPDP Board 72 hours, GDPR lead DPA 72 hours
- Run the six-basis Article 6 analysis for every processing activity, and know when to reach for the three-part legitimate-interests test
- Manage the full Chapter III data-subject-rights workflow within the one-month response window
- Draft an Article 28 processor contract that satisfies both the eight mandatory clauses and the DPDP Rule 6 security-safeguards flow-down
- Stand up an Article 37 DPO office that satisfies GDPR independence rules and doubles as the DPDP Rule 12 SDF DPO
- Design a DPIA that satisfies Article 35 GDPR and the Rule 12 DPDP-plus items including the algorithmic-fairness audit
- Execute a Chapter V transfer using SCCs plus a Schrems II Transfer Impact Assessment, and read the current adequacy list correctly
- Read the EU-US Data Privacy Framework as a fragile additional layer, not a durable base, given the Latombe appeal pendency
- Anticipate DPA enforcement risk based on the 2018-2026 pattern: transfer breaches, adtech legal-basis failures, coverage-gap violations, plaintext-password Art 32 failures
- Prepare a Board-approved dual-regime compliance programme for an Indian IT services firm processing EU customer personal data
Prerequisites
- Working experience as a privacy professional, DPO, in-house counsel, or IT / security lead at an Indian company that processes EU personal data — 3+ years in a privacy or compliance role recommended
- DPDP familiarity: completion of the dcomply Academy DPDP Act 2023 course (free) or DPDP Rules 2025 / DPO Practitioner course (paid), or equivalent working knowledge
- Comfort reading a Regulation article and an EDPB Guideline in original English text
Who this is for
- Privacy officers, DPOs, and Data Protection Coordinators at Indian IT services companies (TCS, Infosys, Wipro, HCL, LTIMindtree, Cognizant, Tech Mahindra, Persistent, Mphasis, Coforge)
- Privacy leads at Indian SaaS companies selling into EU enterprise customers
- Compliance and legal heads at Indian BPOs and KPOs processing EU customer data
- In-house counsel at Indian companies that are data processors of EU controllers
- Consultants and lawyers advising Indian data-transfer arrangements to and from the EU
- Chief Information Security Officers at Indian companies with EU subsidiaries or EU customer bases
- DPDP compliance officers at Significant Data Fiduciaries whose EU exposure adds a GDPR overlay
- Big 4 associates working on GDPR compliance mandates for Indian clients
- What we collect: name, email, IP address (for security logging), and course progress.
- Why: to email you the one-click access link, deliver lessons, issue your certificate, and (with your consent) send course updates plus a Day-7 follow-up about dcomply.
- How long: kept until you unsubscribe or request erasure.
- Your rights under the DPDP Act 2023: access, correction, erasure, and grievance redressal. Write to [email protected] to exercise any of them.
- Unsubscribe any time using the link in every email we send you.
Syllabus
9 modules, 35 lessons. Click any module to expand.
Article 3 GDPR walks two limbs, establishment and targeting, and the Indian professional needs both. The seven Article 5 principles map to DPDP Section 8 duties. Key definitions worth memorising.
The primary-source pack you must bookmark before any GDPR advice leaves your desk. Free preview so serious buyers can validate depth before purchasing.
- 1. The dual-regime reality: one incident, three regulators, three clocks 8 min
- 2. Article 3 territorial scope: does GDPR actually reach your entity? 12 min
- 3. The seven Article 5 principles and their DPDP counterparts 10 min
- 4. Definitions worth memorising: personal data, processing, controller, processor, pseudonymisation, third country, transfer 8 min
- 5. The primary-source pack every GDPR practitioner must bookmark 6 min
The six lawful bases under Article 6 and why Indian practitioners default too easily to consent. The three-part legitimate-interests test post EDPB Guidelines 1/2024. Article 7 conditions for valid consent.
Article 9 special-category processing gateways. DPDP Section 4-7 crosswalk (consent-plus-legitimate-uses vs GDPR six-basis architecture). Adtech legal basis after IAB Europe (C-604/22) and Meta v Bundeskartellamt (C-252/21).
- 1. The six Article 6 lawful bases and why consent is overused 10 min
- 2. Legitimate interests: the three-part test (Guidelines 1/2024) 11 min
- 3. Article 7 consent standards and Guidelines 05/2020 10 min
- 4. Article 9 special categories and the ten Art 9(2) gateways 9 min
Chapter III rights inventory. Access (Art 15) playbook. Erasure (Art 17) six triggers and ten exceptions.
Portability (Art 20) machine-readable format. Objection (Art 21) and automated-decision rights (Art 22). DPDP Sec 11-14 union of rights plus the Sec 13 nomination extension unique to DPDP.
Building one DSR workflow that satisfies both regimes.
- 1. The rights inventory and the one-month response clock 8 min
- 2. Article 15 access requests: the practitioner playbook 9 min
- 3. Article 17 erasure: six triggers, ten exceptions 10 min
- 4. Articles 20, 21, 22: portability, objection, automated decisions 9 min
Determining the role is factual, not what the contract calls it (EDPB Guidelines 07/2020). Article 28 processor contract eight mandatory clauses. Joint controllership Article 26 and the transparency arrangement.
Subprocessor onboarding and flow-down. Article 30 records of processing and what an Indian processor's ROPA must show. Practical: an Indian IT services firm on Module 2 SCCs plus a signed DPA.
- 1. Determining the role: factually, not contractually 9 min
- 2. Article 28 processor contract: the eight mandatory clauses 10 min
- 3. Joint controllership under Article 26 and the transparency obligation 8 min
- 4. Article 30 records of processing: what an Indian processor's ROPA must show 8 min
When Article 37 requires a DPO. How Articles 38-39 protect DPO independence and set the tasks. Article 35 DPIA when and how, using WP248 nine criteria.
Prior consultation Article 36. Records under Article 30. DPDP Section 10 SDF trigger and Rule 12 DPIA-plus obligations including the algorithmic-fairness audit.
One DPO office that satisfies both regimes.
- 1. Article 37 DPO trigger: when a DPO must be appointed 8 min
- 2. Articles 38-39: DPO independence, resources, tasks 9 min
- 3. Article 35 DPIA: when and how 10 min
- 4. One DPO office serving GDPR and DPDP in parallel 7 min
Article 33 notification to DPA within 72 hours: when the clock actually starts (EDPB Guidelines 9/2022 v2.0). Article 34 notification to data subjects, the high-risk test. DPDP Rule 7 breach notification (Data Principal notice without delay, DPB report in 72 hours).
CERT-In 6-hour reporting under the 28 April 2022 Directions. Triple-clock worked scenario: a ransomware incident at an Indian SaaS with EU customers.
- 1. Article 33: when the 72-hour clock actually starts 10 min
- 2. Article 34 data-subject notification: the high-risk test 8 min
- 3. The triple clock: CERT-In 6h, DPDP 72h, GDPR 72h 9 min
- 4. Worked scenario: ransomware at an Indian SaaS with EU customers 10 min
Chapter V architecture: adequacy first (Art 45), then Article 46 mechanisms, then Article 49 derogations. Current adequacy list as of Aug 2026 (Brazil mutual adopted 26 Jan 2026, UK renewed 19 Dec 2025). Why India is not on the list and what that means.
Commission SCCs 2021/914 four modules walkthrough. Schrems II Transfer Impact Assessment obligation. EU-US Data Privacy Framework current status and the Latombe appeal (C-703/25 P) pending at CJEU.
DPDP Section 16 plus Rule 15 negative-list architecture as the mirror of GDPR positive-list adequacy.
- 1. Chapter V architecture: adequacy, Article 46, Article 49 derogations 8 min
- 2. Commission SCCs 2021/914: four modules walkthrough 10 min
- 3. Schrems II TIA obligation: the practitioner working reference 10 min
- 4. EU-US Data Privacy Framework: read as fragile additional layer 8 min
- 5. DPDP Section 16 + Rule 15: the negative-list mirror 7 min
The adjacent EU instruments that reach Indian entities: DSA (Reg 2022/2065), DMA (Reg 2022/1925), Data Act (Reg 2023/2854), AI Act (Reg 2024/1689) as amended by Digital Omnibus on AI (Reg 2026/1744, in force 27 July 2026 with high-risk AI postponed to 2 Dec 2027 and 2 Aug 2028), NIS2 (Directive 2022/2555). Top-15 GDPR fines 2018-2026 with practitioner lesson each. 2024-2026 enforcement pattern: coverage-gap transfers, adtech legal-basis failures, plaintext-password Art 32 breaches, third-country transfer enforcement.
Capstone: design an end-to-end dual-regime compliance programme for an Indian IT services firm processing EU customer personal data.
- 1. DSA, DMA, Data Act, AI Act, NIS2: what reaches an Indian entity 11 min
- 2. Top-15 GDPR fines 2018-2026: practitioner lessons 11 min
- 3. Reading the 2024-2026 enforcement pattern 8 min
- 4. AI Act plus GDPR for Indian AI providers: DPIA plus FRIA overlap 8 min
- 5. Capstone: dual-regime compliance programme for an Indian IT services firm 13 min
Final certification exam covering all eight content modules. Every question is anchored to a specific GDPR Article, Recital, EDPB Guideline, CJEU judgment, DPA enforcement order, DPDP Section or Rule, or CERT-In Direction cited in the course. Randomised order, shuffled options, explanations shown after each question cite the source.
Lessons coming soon.
Everything a buyer usually asks
Who is this course for?
Is there a free preview?
What do I get when I enrol?
Is there a certificate on completion?
How much does the course cost?
How long do I have to complete the course?
Can I retake the final exam?
How do you keep the course current when the law changes?
Is this course legal advice?
This course is a paid practitioner training programme aimed at Indian privacy professionals, DPOs, in-house counsel, and compliance leads at Indian companies that process EU personal data. Every substantive claim is anchored to a primary source. Verification pass 2 (10 August 2026) confirmed the Digital Omnibus on AI (Regulation (EU) 2026/1744) postponement of high-risk AI applicability, the EU-US Data Privacy Framework Latombe appeal (Case C-703/25 P) as pending at the Court of Justice with Microsoft admitted as intervener, the current adequacy list including Brazil (Implementing Decision 2026/179 of 26 January 2026) and UK renewal (19 December 2025 with sunset 27 December 2031), the EDPB draft Guidelines 02/2026 on Anonymisation (open for consultation to 30 October 2026), and the EDPB Guidelines 02/2025 v2.0 on Blockchain (adopted 7 July 2026). Items marked STILL OPEN as of 10 August 2026: Commission SCCs for Article 3(2) importers remain draft; DPDP Board of India Chairperson appointment is not confirmed by tier-1 legal reporting; NEVER use the "Ghosal Pankaraj IMS" name that appeared in a preliminary fabricated Wikipedia excerpt.
The course maintains a 15-item DPO/CISO manual-verification checklist. This is not legal advice and does not create a lawyer-client relationship. For specific compliance decisions, consult qualified data-protection counsel or a registered European DPO.
GDPR primary-source stack current to 10 August 2026. Core: Regulation (EU) 2016/679 (GDPR), in force 25 May 2018. EDPB Guidelines: 3/2018 (territorial scope, endorsed 12 November 2019), 05/2020 (consent, adopted 4 May 2020 v1.1), 07/2020 (controller/processor, adopted 7 July 2021 v2.1), 9/2022 (breach notification, v2.0 adopted 28 March 2023), 1/2024 (legitimate interests, adopted 8 October 2024), draft 02/2026 (Anonymisation, published for consultation 7 July 2026), 02/2025 v2.0 (Blockchain, adopted 7 July 2026). Cross-border: Commission Implementing Decision (EU) 2021/914 SCCs (4 June 2021); EU-US Data Privacy Framework Adequacy Decision C(2023) 4745 final (10 July 2023, Latombe C-703/25 P appeal pending at CJEU); adequacy list including Brazil mutual (Implementing Decision 2026/179, 26 January 2026), UK renewal (19 December 2025 with sunset 27 December 2031). Adjacent EU: Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), Data Governance Act (Regulation 2022/868), Data Act (Regulation 2023/2854), AI Act (Regulation 2024/1689) as amended by Regulation (EU) 2026/1744 Digital Omnibus on AI (OJ 24 July 2026, in force 27 July 2026, postponing high-risk AI to 2 December 2027 and 2 August 2028), NIS2 Directive (Directive 2022/2555). Landmark CJEU: Schrems II (C-311/18, 16 Jul 2020), Meta v Bundeskartellamt (C-252/21, 4 Jul 2023), IAB Europe (C-604/22, 7 Mar 2024), Lindenapotheke (C-21/23, 4 Oct 2024).
India crosswalk: DPDP Act 2023 (No. 22 of 2023, assented 11 Aug 2023), DPDP Rules 2025 (notified 13 Nov 2025, operative Rules commencement expected 13 May 2027), RBI Payment Data Storage Direction (DPSS.CO.OD.No.2785 dated 6 Apr 2018), CERT-In Directions (No. 20(3)/2022-CERT-In dated 28 Apr 2022).