Live Founding Cohort open, limited seats remaining Back to main site →

The dual-regime reality: one incident, three regulators, three clocks

An Indian company that processes EU personal data does not choose between GDPR and DPDP. Both apply. This lesson lays out the dual-regime reality and the reason we teach these two frameworks as one operating programme.

Free preview 8 min read Verified
Legal basis
GDPR primary-source stack current to 10 August 2026. Core: Regulation (EU) 2016/679 (GDPR), in force 25 May 2018. EDPB Guidelines: 3/2018 (territorial scope, endorsed 12 November 2019), 05/2020 (consent, adopted 4 May 2020 v1.1), 07/2020 (controller/processor, adopted 7 July 2021 v2.1), 9/2022 (breach notification, v2.0 adopted 28 March 2023), 1/2024 (legitimate interests, adopted 8 October 2024), draft 02/2026 (Anonymisation, published for consultation 7 July 2026), 02/2025 v2.0 (Blockchain, adopted 7 July 2026). Cross-border: Commission Implementing Decision (EU) 2021/914 SCCs (4 June 2021); EU-US Data Privacy Framework Adequacy Decision C(2023) 4745 final (10 July 2023, Latombe C-703/25 P appeal pending at CJEU); adequacy list including Brazil mutual (Implementing Decision 2026/179, 26 January 2026), UK renewal (19 December 2025 with sunset 27 December 2031). Adjacent EU: Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), Data Governance Act (Regulation 2022/868), Data Act (Regulation 2023/2854), AI Act (Regulation 2024/1689) as amended by Regulation (EU) 2026/1744 Digital Omnibus on AI (OJ 24 July 2026, in force 27 July 2026, postponing high-risk AI to 2 December 2027 and 2 August 2028), NIS2 Directive (Directive 2022/2555). Landmark CJEU: Schrems II (C-311/18, 16 Jul 2020), Meta v Bundeskartellamt (C-252/21, 4 Jul 2023), IAB Europe (C-604/22, 7 Mar 2024), Lindenapotheke (C-21/23, 4 Oct 2024). India crosswalk: DPDP Act 2023 (No. 22 of 2023, assented 11 Aug 2023), DPDP Rules 2025 (notified 13 Nov 2025, operative Rules commencement expected 13 May 2027), RBI Payment Data Storage Direction (DPSS.CO.OD.No.2785 dated 6 Apr 2018), CERT-In Directions (No. 20(3)/2022-CERT-In dated 28 Apr 2022).

You work at an Indian SaaS company. A customer in Berlin uses your product. Their account contains their name, email, IP address, and usage telemetry. On a Tuesday morning your SOC finds a threat actor exfiltrating a slice of your customer database. Berlin is in that slice.

From that Tuesday morning, three regulatory clocks start running on three different desks, all measuring the same event.

  • CERT-In clock: six hours. Direction (ii) of the CERT-In Directions of 28 April 2022 requires you to report the incident to CERT-In within six hours of noticing it [L1-C1]. You are a body corporate in India; the Direction applies regardless of who the affected data subjects are.
  • DPDP Board clock: 72 hours. DPDP Rules 2025 Rule 7 requires you to intimate the Data Protection Board of India of a personal data breach without delay, with the full report within 72 hours [L1-C2]. It applies whenever you process the personal data of Data Principals within the territory of India; if your Berlin user also has an India-facing dimension in your product it is safer to file. The Rules operative commencement is expected around 13 May 2027 but the readiness posture starts now.
  • GDPR clock: 72 hours. GDPR Article 33 requires the controller to notify the competent supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons [L1-C3]. If you are a processor of an EU controller, Article 33(2) requires you to notify the controller without undue delay so it can meet its 72-hour clock. If you are the controller (you determined the purposes and means of processing the Berlin user's data), you notify the DPA yourself.

Three regulators. Three clocks. One incident. This is what "dual regime" means in the ordinary week of an Indian privacy professional.

Why we teach GDPR alongside DPDP rather than separately

Almost every Indian privacy professional we know either has DPDP knowledge and is picking up GDPR, or has GDPR knowledge (often from IAPP CIPP/E) and is picking up DPDP. Both learning paths lead to the same operating desk. If you learn GDPR without DPDP context you will keep making mistakes at the DPDP interface: the Consent Manager, the algorithmic-fairness audit under Rule 12, the nomination right under DPDP Section 13 that has no GDPR equivalent. If you learn DPDP without GDPR context you will keep making mistakes at the GDPR interface: the six-basis Article 6 architecture (broader than DPDP\'s consent-plus-legitimate-uses), the Article 27 EU Representative appointment, the Schrems II Transfer Impact Assessment.

Teaching them together gives you one operating programme. One incident register. One consent design. One DPO office. One ROPA. One breach runbook. Where the two regimes align, teach the alignment. Where they diverge, teach the divergence and the stricter default.

What this course assumes about you

You have three or more years in a privacy or compliance role. You have working DPDP familiarity, either from dcomply Academy\'s DPDP Act 2023 free course, from the DPDP Rules 2025 Practitioner course, or from independent reading. You are comfortable reading a Regulation article and an EDPB Guideline in original English text. You are not looking for an IAPP CIPP/E prep book; you are looking for the operational discipline to run the two regimes together on a working desk.

What this course does not do

It does not certify you as a globally recognised GDPR professional. IAPP CIPP/E does that, and it costs a lakh or more. If you need the CV signal, take IAPP CIPP/E. This course teaches you the operational job that CIPP/E does not teach at the depth of the primary sources, at a price accessible to an individual Indian buyer.

The rest of the course builds this dual-regime operating programme, module by module, cited to primary sources throughout.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 8 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 8 paid modules (30 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹14,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
CERT-In Directions 2022, CERT-In 6-hour Rule (CERT-In Directions 2022 six-hour incident reporting) L1-C1
CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, effective 27 June 2022. Direction (ii): every service provider, intermediary, data centre, body corporate and Government organisation must mandatorily report cyber incidents of the type specified in Annexure I to CERT-In within six hours of noticing or being brought to notice about such incidents. For an Indian entity handling EU personal data, the 6-hour CERT-In clock runs from detection in parallel with the 72-hour DPDP Rule 7 clock and the 72-hour GDPR Art 33 clock. All three are separate obligations; the incident-response runbook fires all three from a single incident record.
DPDP Rules 2025, DPDP Rule 7 Breach (DPDP Rules 2025 Rule 7 breach notification) L1-C2
DPDP Rule 7 requires a Data Fiduciary to intimate the Data Protection Board of India of a personal data breach without delay and in any event within 72 hours of becoming aware of the breach, and to notify each affected Data Principal in plain-language terms without delay. Timing aligns with GDPR Art 33 72-hour clock, so a single incident record can serve both filings. Where GDPR permits a risk-based waiver of data-subject notice (Art 34(1) "unless likely to result in a high risk"), DPDP does not, so default to notify Data Principals in the dual-regime workflow.
GDPR (EU) 2016/679, Articles 33-34 Breach (Articles 33 and 34 breach notification) L1-C3
Article 33 requires the controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Late notifications must be accompanied by reasons for the delay. The notification must describe the nature of the breach, the categories and approximate number of data subjects, the categories and approximate number of personal data records concerned, the name and contact details of the DPO, likely consequences, and measures taken or proposed. Article 34 requires the controller to communicate the breach to the data subject without undue delay when it is likely to result in a high risk to the rights and freedoms of natural persons; exceptions include appropriate technical and organisational measures that render the data unintelligible (e.g. encryption) and disproportionate effort. EDPB Guidelines 9/2022 v2.0 is the operational workflow.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: why GDPR reaches you as an Indian practitioner
Module 2: Lawful basis and consent
  • The six Article 6 lawful bases and why consent is overused
  • Legitimate interests: the three-part test (Guidelines 1/2024)
  • Article 7 consent standards and Guidelines 05/2020
  • Article 9 special categories and the ten Art 9(2) gateways
Module 3: Data subject rights end-to-end
  • The rights inventory and the one-month response clock
  • Article 15 access requests: the practitioner playbook
  • Article 17 erasure: six triggers, ten exceptions
  • Articles 20, 21, 22: portability, objection, automated decisions
Module 4: Controller vs processor, contracts, subprocessing
  • Determining the role: factually, not contractually
  • Article 28 processor contract: the eight mandatory clauses
  • Joint controllership under Article 26 and the transparency obligation
  • Article 30 records of processing: what an Indian processor's ROPA must show
Module 5: DPO office, DPIA, records of processing
  • Article 37 DPO trigger: when a DPO must be appointed
  • Articles 38-39: DPO independence, resources, tasks
  • Article 35 DPIA: when and how
  • One DPO office serving GDPR and DPDP in parallel
Module 6: Breach notification and the triple clock
  • Article 33: when the 72-hour clock actually starts
  • Article 34 data-subject notification: the high-risk test
  • The triple clock: CERT-In 6h, DPDP 72h, GDPR 72h
  • Worked scenario: ransomware at an Indian SaaS with EU customers
Module 7: Cross-border transfers: SCCs, adequacy, DPF, Transfer Impact Assessment
  • Chapter V architecture: adequacy, Article 46, Article 49 derogations
  • Commission SCCs 2021/914: four modules walkthrough
  • Schrems II TIA obligation: the practitioner working reference
  • EU-US Data Privacy Framework: read as fragile additional layer
  • DPDP Section 16 + Rule 15: the negative-list mirror
Module 8: Adjacent EU instruments + enforcement pattern + capstone
  • DSA, DMA, Data Act, AI Act, NIS2: what reaches an Indian entity
  • Top-15 GDPR fines 2018-2026: practitioner lessons
  • Reading the 2024-2026 enforcement pattern
  • AI Act plus GDPR for Indian AI providers: DPIA plus FRIA overlap
  • Capstone: dual-regime compliance programme for an Indian IT services firm
Module 9: Final Exam and Certificate