You work at an Indian SaaS company. A customer in Berlin uses your product. Their account contains their name, email, IP address, and usage telemetry. On a Tuesday morning your SOC finds a threat actor exfiltrating a slice of your customer database. Berlin is in that slice.
From that Tuesday morning, three regulatory clocks start running on three different desks, all measuring the same event.
- CERT-In clock: six hours. Direction (ii) of the CERT-In Directions of 28 April 2022 requires you to report the incident to CERT-In within six hours of noticing it
[L1-C1]. You are a body corporate in India; the Direction applies regardless of who the affected data subjects are. - DPDP Board clock: 72 hours. DPDP Rules 2025 Rule 7 requires you to intimate the Data Protection Board of India of a personal data breach without delay, with the full report within 72 hours
[L1-C2]. It applies whenever you process the personal data of Data Principals within the territory of India; if your Berlin user also has an India-facing dimension in your product it is safer to file. The Rules operative commencement is expected around 13 May 2027 but the readiness posture starts now. - GDPR clock: 72 hours. GDPR Article 33 requires the controller to notify the competent supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons
[L1-C3]. If you are a processor of an EU controller, Article 33(2) requires you to notify the controller without undue delay so it can meet its 72-hour clock. If you are the controller (you determined the purposes and means of processing the Berlin user's data), you notify the DPA yourself.
Three regulators. Three clocks. One incident. This is what "dual regime" means in the ordinary week of an Indian privacy professional.
Why we teach GDPR alongside DPDP rather than separately
Almost every Indian privacy professional we know either has DPDP knowledge and is picking up GDPR, or has GDPR knowledge (often from IAPP CIPP/E) and is picking up DPDP. Both learning paths lead to the same operating desk. If you learn GDPR without DPDP context you will keep making mistakes at the DPDP interface: the Consent Manager, the algorithmic-fairness audit under Rule 12, the nomination right under DPDP Section 13 that has no GDPR equivalent. If you learn DPDP without GDPR context you will keep making mistakes at the GDPR interface: the six-basis Article 6 architecture (broader than DPDP\'s consent-plus-legitimate-uses), the Article 27 EU Representative appointment, the Schrems II Transfer Impact Assessment.
Teaching them together gives you one operating programme. One incident register. One consent design. One DPO office. One ROPA. One breach runbook. Where the two regimes align, teach the alignment. Where they diverge, teach the divergence and the stricter default.
What this course assumes about you
You have three or more years in a privacy or compliance role. You have working DPDP familiarity, either from dcomply Academy\'s DPDP Act 2023 free course, from the DPDP Rules 2025 Practitioner course, or from independent reading. You are comfortable reading a Regulation article and an EDPB Guideline in original English text. You are not looking for an IAPP CIPP/E prep book; you are looking for the operational discipline to run the two regimes together on a working desk.
What this course does not do
It does not certify you as a globally recognised GDPR professional. IAPP CIPP/E does that, and it costs a lakh or more. If you need the CV signal, take IAPP CIPP/E. This course teaches you the operational job that CIPP/E does not teach at the depth of the primary sources, at a price accessible to an individual Indian buyer.
The rest of the course builds this dual-regime operating programme, module by module, cited to primary sources throughout.