Live Founding Cohort open, limited seats remaining Back to main site →

Why you can trust this course

We don't ask you to take our word for it. Every claim in every lesson is anchored to a Section, Rule, or judgment. This page is the master register of every authority we cite.

Legal basis snapshot: GDPR primary-source stack current to 10 August 2026. Core: Regulation (EU) 2016/679 (GDPR), in force 25 May 2018. EDPB Guidelines: 3/2018 (territorial scope, endorsed 12 November 2019), 05/2020 (consent, adopted 4 May 2020 v1.1), 07/2020 (controller/processor, adopted 7 July 2021 v2.1), 9/2022 (breach notification, v2.0 adopted 28 March 2023), 1/2024 (legitimate interests, adopted 8 October 2024), draft 02/2026 (Anonymisation, published for consultation 7 July 2026), 02/2025 v2.0 (Blockchain, adopted 7 July 2026). Cross-border: Commission Implementing Decision (EU) 2021/914 SCCs (4 June 2021); EU-US Data Privacy Framework Adequacy Decision C(2023) 4745 final (10 July 2023, Latombe C-703/25 P appeal pending at CJEU); adequacy list including Brazil mutual (Implementing Decision 2026/179, 26 January 2026), UK renewal (19 December 2025 with sunset 27 December 2031). Adjacent EU: Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), Data Governance Act (Regulation 2022/868), Data Act (Regulation 2023/2854), AI Act (Regulation 2024/1689) as amended by Regulation (EU) 2026/1744 Digital Omnibus on AI (OJ 24 July 2026, in force 27 July 2026, postponing high-risk AI to 2 December 2027 and 2 August 2028), NIS2 Directive (Directive 2022/2555). Landmark CJEU: Schrems II (C-311/18, 16 Jul 2020), Meta v Bundeskartellamt (C-252/21, 4 Jul 2023), IAB Europe (C-604/22, 7 Mar 2024), Lindenapotheke (C-21/23, 4 Oct 2024). India crosswalk: DPDP Act 2023 (No. 22 of 2023, assented 11 Aug 2023), DPDP Rules 2025 (notified 13 Nov 2025, operative Rules commencement expected 13 May 2027), RBI Payment Data Storage Direction (DPSS.CO.OD.No.2785 dated 6 Apr 2018), CERT-In Directions (No. 20(3)/2022-CERT-In dated 28 Apr 2022).

How this GDPR for Indian Companies (with DPDP Crosswalk) Practitioner register is built

This trust page is the citation register for the GDPR for Indian Companies (with DPDP Crosswalk) Practitioner course. It cites 38 authorities across 15 statutory instruments, drawn from the legal basis snapshot above (GDPR primary-source stack current to 10 August 2026. Core: Regulation (EU) 2016/679 (GDPR), in force 25 May 2018. EDPB Guidelines: 3/2018 (territorial scope, endorsed 12 November 2019), 05/2020 (consent, adopted 4 May 2020 v1.1), 07/2020 (controller/processor, adopted 7 July 2021 v2.1), 9/2022 (breach notification, v2.0 adopted 28 March 2023), 1/2024 (legitimate interests, adopted 8 October 2024), draft 02/2026 (Anonymisation, published for consultation 7 July 2026), 02/2025 v2.0 (Blockchain, adopted 7 July 2026). Cross-border: Commission Implementing Decision (EU) 2021/914 SCCs (4 June 2021); EU-US Data Privacy Framework Adequacy Decision C(2023) 4745 final (10 July 2023, Latombe C-703/25 P appeal pending at CJEU); adequacy list including Brazil mutual (Implementing Decision 2026/179, 26 January 2026), UK renewal (19 December 2025 with sunset 27 December 2031). Adjacent EU: Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), Data Governance Act (Regulation 2022/868), Data Act (Regulation 2023/2854), AI Act (Regulation 2024/1689) as amended by Regulation (EU) 2026/1744 Digital Omnibus on AI (OJ 24 July 2026, in force 27 July 2026, postponing high-risk AI to 2 December 2027 and 2 August 2028), NIS2 Directive (Directive 2022/2555). Landmark CJEU: Schrems II (C-311/18, 16 Jul 2020), Meta v Bundeskartellamt (C-252/21, 4 Jul 2023), IAB Europe (C-604/22, 7 Mar 2024), Lindenapotheke (C-21/23, 4 Oct 2024). India crosswalk: DPDP Act 2023 (No. 22 of 2023, assented 11 Aug 2023), DPDP Rules 2025 (notified 13 Nov 2025, operative Rules commencement expected 13 May 2027), RBI Payment Data Storage Direction (DPSS.CO.OD.No.2785 dated 6 Apr 2018), CERT-In Directions (No. 20(3)/2022-CERT-In dated 28 Apr 2022).).

Primary sources: GDPR (EU) 2016/679 (11 entries), EDPB Guidelines (6 entries), GDPR Enforcement (4 entries).

Every claim in every GDPR for Indian Companies (with DPDP Crosswalk) Practitioner lesson traces back to a Section, Rule, or judgment listed below. If a lesson references a specific obligation, click the [Lx-Cy] marker in that lesson to jump to the verbatim text in the register.

Our verification promise

  1. Every factual claim has a source. If we say "Section 9 allows a three-month limitation period", you can click the [Lx-Cy] marker next to it and read the verbatim text of Section 9 of the Sexual Harassment of Women at Workplace Act, 2013.
  2. Every source is on this page. Below you will find every Section, Rule and judgment we have relied on, grouped by category, with the verbatim text we hold in our register.
  3. Every source has a public link. Wherever an authoritative public link exists (India Code, the official court website, a reputable law-reports portal), we link to it.
  4. Bug bounty for errors. If you find a factual error in any lesson, write to [email protected] with the lesson, the claim and the corrected source. We will credit your account ₹1,000 for the first report of any verifiable error, ₹5,000 for a substantial error.
9
modules
35
lessons
38
cited authorities
recent
last reviewed

The full citation register

Every authority used in any lesson appears below. Click a row to expand the verbatim text.

CERT-In 6-hour Rule , CERT-In Directions 2022 six-hour incident reporting 28 Apr 2022
Plain summary: CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, effective 27 June 2022. Direction (ii): every service provider, intermediary, data centre, body corporate and Government organisation must mandatorily report cyber incidents of the type specified in Annexure I to CERT-In within six hours of noticing or being brought to notice about such incidents. For an Indian entity handling EU personal data, the 6-hour CERT-In clock runs from detection in parallel with the 72-hour DPDP Rule 7 clock and the 72-hour GDPR Art 33 clock. All three are separate obligations; the incident-response runbook fires all three from a single incident record.
CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022. Direction (ii): Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within six hours of noticing such incidents or being brought to notice about such incidents. Direction (iii): Enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days within the Indian jurisdiction.

Schrems II C-311/18 , Schrems II (Case C-311/18, 16 July 2020) 16 Jul 2020
Plain summary: Court of Justice of the European Union judgment of 16 July 2020 in Case C-311/18 (Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems). Invalidated the EU-US Privacy Shield adequacy decision on the basis that US surveillance laws (including FISA section 702 and Executive Order 12333) do not provide essentially equivalent protection to that guaranteed under Union law. Confirmed the validity of Commission SCCs as a transfer mechanism BUT imposed an ongoing Transfer Impact Assessment obligation: exporter must assess third-country law and practice; where essentially equivalent protection cannot be assured, supplementary measures (typically technical, such as end-to-end encryption where the importer cannot access the plaintext) are needed; if such measures are insufficient, the transfer must be suspended.
Court of Justice judgment of 16 July 2020, Case C-311/18, Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems (Schrems II). The Court declared Commission Implementing Decision (EU) 2016/1250 of 12 July 2016 on the adequacy of the protection provided by the EU-US Privacy Shield invalid. Commission Decision 2010/87/EU of 5 February 2010 on standard contractual clauses for the transfer of personal data to processors established in third countries is valid, but the controller or processor established in the European Union is required to verify, on a case-by-case basis and, where appropriate, in collaboration with the recipient of the data, whether the law of the third country of destination ensures adequate protection under EU law of personal data transferred pursuant to standard data protection clauses.
Meta Bundeskartellamt C-252/21 , Meta v Bundeskartellamt (C-252/21, 4 July 2023) 04 Jul 2023
Plain summary: CJEU judgment of 4 July 2023 in Case C-252/21 (Meta Platforms Inc and others v Bundeskartellamt). Held that national competition authorities may find GDPR infringements in the course of assessing abuse of a dominant position; must consult DPAs. Consent given to a dominant operator is not automatically free (contextual analysis required). Personalised-advertising legal basis cannot rest on the "contract" gateway (Art 6(1)(b)) or on legitimate interests alone in a consumer setting; consent must be separately captured for behavioural advertising. Special-category data disclosed by the data subject "manifestly" under Art 9(2)(e) is narrowly construed: requires explicit intent that the data be public.
Court of Justice judgment of 4 July 2023 in Case C-252/21, Meta Platforms Inc, Meta Platforms Ireland Ltd, Facebook Deutschland GmbH v Bundeskartellamt. In the context of the examination of an abuse of a dominant position by an undertaking, it may be necessary for the competition authority of the Member State concerned also to examine whether that undertaking's conduct complies with rules other than those relating to competition law, such as the rules laid down by the GDPR. Processing of personal data by the operator of an online social network cannot be regarded as necessary for the performance of a contract to which the data subject is party, within the meaning of Article 6(1)(b) of the GDPR, on the ground that that operator, through certain third-party interfaces or websites, personalises advertising for that user.
IAB Europe C-604/22 , IAB Europe (C-604/22, 7 March 2024) 07 Mar 2024
Plain summary: CJEU judgment of 7 March 2024 in Case C-604/22 (IAB Europe v Belgian Data Protection Authority). Held that the Transparency and Consent Framework (TCF) Consent String, even in pseudonymous form, constitutes personal data where identifiability is reasonably likely. IAB Europe is a joint controller with adtech participants for the processing associated with the TCF signal, insofar as it influences purposes and means. Reshapes adtech: operators can no longer treat TCF strings as anonymous. Practical impact for Indian adtech vendors serving EU users: TCF integration alone does not launder legal-basis analysis.
Court of Justice judgment of 7 March 2024 in Case C-604/22, IAB Europe v Gegevensbeschermingsautoriteit. A string composed of a combination of letters and characters, such as the TC String, containing the preferences of a user of the internet or of an application relating to that user's consent to the processing of personal data concerning him or her by website or application providers, constitutes personal data within the meaning of that provision insofar as, when it can, by reasonable means, be associated with an identifier, such as the IP address of that user's device, it may allow the data subject to be identified. IAB Europe must be considered a joint controller within the meaning of that provision insofar as it influences, for its own purposes, the processing of personal data at issue in the main proceedings.

Commission SCCs 2021 , Commission Implementing Decision (EU) 2021/914 SCCs 04 Jun 2021
Plain summary: Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679. Four modular sets: Module 1 (Controller-to-Controller), Module 2 (Controller-to-Processor), Module 3 (Processor-to-Processor), Module 4 (Processor-to-Controller). Repealed the 2001/497/EC and 2010/87/EU old-SCC decisions after an 18-month transition to 27 December 2022. Mandatory Docking Clause allows additional parties to accede. Mandatory Annex on technical and organisational measures. Clause 14 (TIA obligation), Clause 15 (obligations in case of access requests from public authorities). For an Indian processor onboarding a sub-processor in a further third country, use Module 3 plus a TIA.
Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council. Clause 14: The Parties warrant that they have no reason to believe that the laws and practices in the third country of destination applicable to the processing of the personal data by the data importer, including any requirements to disclose personal data or measures authorising access by public authorities, prevent the data importer from fulfilling its obligations under these Clauses. Where the data importer cannot comply, it shall promptly notify the data exporter, which shall suspend the transfer.

DPDP Act Section 3 , DPDP Act 2023 Section 3 extraterritorial reach 11 Aug 2023
Plain summary: Section 3 of the Digital Personal Data Protection Act 2023 (Act No. 22 of 2023, assented 11 August 2023) governs applicability. Section 3(b) captures processing outside India in connection with any activity related to the offering of goods or services to Data Principals within the territory of India. This is the DPDP mirror of GDPR Art 3(2). Consequence: EU companies serving Indian consumers are caught by DPDP; Indian companies serving EU consumers are caught by GDPR. A dual-regime entity manages both obligations from one operating programme.
Section 3, Digital Personal Data Protection Act 2023. Application of Act. Subject to the provisions of this Act, it shall (a) apply to the processing of digital personal data within the territory of India where the personal data is collected: (i) in digital form; or (ii) in non-digital form and digitised subsequently; (b) also apply to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India.

DPDP Rule 12 SDF , DPDP Rules 2025 Rule 12 Significant Data Fiduciary duties 13 Nov 2025
Plain summary: DPDP Section 10 read with Rule 12 sets additional obligations for Significant Data Fiduciaries (SDFs) designated by the Central Government on factors including volume and sensitivity of personal data processed, risk to Data Principal rights, potential impact on sovereignty and integrity of India, and public order. SDF-additional obligations include appointing a Data Protection Officer based in India who reports to the Board, undertaking a periodic Data Protection Impact Assessment, an algorithmic-fairness audit for algorithmic decisions with significant impact on Data Principal rights, and independent audit by a person appointed by the SDF. Practitioner reading: SDF designation triggers a heavier compliance regime that maps closely to GDPR Art 35 DPIA plus Art 37 DPO plus general accountability.
DPDP Rules 2025 Rule 12. Additional obligations of Significant Data Fiduciary. A Significant Data Fiduciary shall: (a) undertake, once in every period of twelve months, a Data Protection Impact Assessment; (b) undertake an audit of the compliance with the provisions of the Act and rules, once in every period of twelve months, by a person appointed by the Significant Data Fiduciary; (c) observe due diligence to verify that algorithmic software deployed by it for hosting, display, uploading, modification, publishing, transmission, storage, updation or sharing of personal data processed by it, is not likely to pose a risk to the rights of Data Principals.
DPDP Rule 15 Transfer , DPDP Rules 2025 Rule 15 cross-border transfer (negative-list) 13 Nov 2025
Plain summary: DPDP Section 16 read with Rule 15 establishes India's cross-border transfer regime on a negative-list architecture: transfers are permitted unless the Central Government notifies a country to which transfer is restricted. This is the architectural mirror of GDPR's positive-list adequacy model under Art 45. As of Aug 2026 no restricted-country list has been notified. For an Indian company operating both regimes, this means: EU-to-India inbound requires an Art 46 mechanism plus TIA; India-to-EU outbound (and India-to-most-other-destinations) is permitted subject to notice, consent, and general safeguards, until MeitY publishes a Rule 15 list.
DPDP Act 2023, Section 16. Processing of personal data outside India. The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified. Nothing contained in sub-section (1) shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data by a Data Fiduciary outside India in relation to any personal data or Data Fiduciary or class thereof.
DPDP Rule 7 Breach , DPDP Rules 2025 Rule 7 breach notification 13 Nov 2025
Plain summary: DPDP Rule 7 requires a Data Fiduciary to intimate the Data Protection Board of India of a personal data breach without delay and in any event within 72 hours of becoming aware of the breach, and to notify each affected Data Principal in plain-language terms without delay. Timing aligns with GDPR Art 33 72-hour clock, so a single incident record can serve both filings. Where GDPR permits a risk-based waiver of data-subject notice (Art 34(1) "unless likely to result in a high risk"), DPDP does not, so default to notify Data Principals in the dual-regime workflow.
DPDP Rules 2025 Rule 7. Intimation of personal data breach. (1) On becoming aware of any personal data breach, a Data Fiduciary shall, without delay, intimate to the Board a description of the breach in the form specified. (2) The Data Fiduciary shall, within 72 hours of becoming aware of the personal data breach, or such longer period as the Board may allow, further intimate to the Board the specified additional information. (3) The Data Fiduciary shall, without delay, intimate every affected Data Principal in a concise, clear and plain manner about the nature of the breach, its likely consequences, mitigation measures, and safety measures the Data Principal may take.

DPO Guidelines WP243 , WP243 Guidelines on Data Protection Officers (as endorsed) 13 Dec 2016
Plain summary: WP243 rev.01 on Data Protection Officers, adopted 13 December 2016 by the Article 29 Working Party and endorsed by the EDPB. Interprets Articles 37-39. Key operational readings: "core activities" as inherent to reaching the controller's primary objective, not ancillary; "large scale" evaluated with respect to number of data subjects, volume of data, duration of processing, geographical extent; "regular and systematic monitoring" includes all forms of tracking and profiling on the internet, including for behavioural advertising. DPO must be positioned to advise independently and cannot be dismissed for performing DPO tasks. Group DPO permitted if easily accessible from each establishment.
WP243 rev.01 Guidelines on Data Protection Officers, adopted 13 December 2016. The GDPR does not define what constitutes 'core activities', but Recital 97 provides that these are 'the primary business activities of the controller, but relating to the processing of personal data, that is essential for reaching those goals'. 'Regular and systematic monitoring of data subjects' includes all forms of tracking and profiling on the internet, including for the purposes of behavioural advertising. 'Large scale' should be evaluated with reference to the number of data subjects concerned, volume of data, duration of the processing, and geographical extent of the processing activity.
Guidelines 3/2018 Territorial , EDPB Guidelines 3/2018 on territorial scope (Article 3) 12 Nov 2019
Plain summary: Endorsed by the EDPB in November 2019. Explains the "establishment" limb (Art 3(1)) and the "targeting" limb (Art 3(2)) with worked examples. Establishment is interpreted broadly: even a minor presence with a stable arrangement in a Member State can qualify, per Weltimmo (C-230/14). Targeting: Recital 23 factors include use of a Member-State language or currency, provision of shipping to a Member-State address, marketing at Member-State users, and use of a top-level domain of a Member State. Monitoring: Recital 24 factors include tracking on the internet with subsequent profiling. Foundational for the Indian audience: this Guideline decides whether GDPR reaches your Indian entity at all.
EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), version 2.1 as endorsed on 12 November 2019. The territorial scope of the Regulation is determined by application of the establishment criterion (Article 3(1)) and the targeting criterion (Article 3(2)). The Guidelines note that the mere accessibility of the controller's, processor's or an intermediary's website in the Union, an email address or contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to determine such an intention. Elements such as, on the other hand, the mention of the offer being addressed to users in one or more Member States by name are indicative of an intention to target data subjects in the Union.
Guidelines 05/2020 Consent , EDPB Guidelines 05/2020 on consent under GDPR 04 May 2020
Plain summary: Adopted 4 May 2020, version 1.1. Consolidates and replaces WP29 Guidelines 05/2011 (WP259). Elaborates the four elements of valid consent: freely given, specific, informed, unambiguous with clear affirmative action. Freely-given analysis includes cookie-wall discussion: making access to a website conditional on consent to non-essential cookies is generally not freely given. Bundled consent for multiple purposes is not specific. Silence, pre-ticked boxes and inactivity are not affirmative action. Withdrawal must be as easy as giving consent; controllers must design withdrawal mechanisms symmetrically.
EDPB Guidelines 05/2020 on consent under Regulation 2016/679, version 1.1 adopted on 4 May 2020. Consent under the GDPR should be a freely given, specific, informed and unambiguous indication of the individual's wishes. If a controller uses a cookie wall which forces users to consent to the processing of personal data (through cookies), such consent cannot be considered freely given. Silence, pre-ticked boxes or inactivity should not constitute consent.
Guidelines 07/2020 Roles , EDPB Guidelines 07/2020 on controller and processor concepts 07 Jul 2021
Plain summary: Adopted 7 July 2021, version 2.1. Successor to WP169. Determination of the role is factual not contractual: an entity that determines the purposes and essential means of processing is a controller, regardless of what the contract calls it. Joint controllership (Art 26) applies where two or more controllers jointly determine purposes and means; the arrangement must be transparent to data subjects. Processor (Art 4(8)) processes on behalf of the controller under documented instructions. Subprocessor engagement (Art 28(2), (4)) requires prior specific or general written authorisation and flow-down of Art 28 obligations.
EDPB Guidelines 07/2020 on the concepts of controller and processor in the GDPR, version 2.1 adopted on 7 July 2021. The concept of controller is a functional concept, aiming to allocate responsibilities according to the actual roles of the parties. It is therefore based on a factual rather than a formal analysis. Being 'controller' is primarily the consequence of the factual circumstance that an entity has chosen to process personal data for its own purposes. A processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Guidelines 9/2022 Breach , EDPB Guidelines 9/2022 on personal data breach notification 28 Mar 2023
Plain summary: Guidelines 9/2022 version 2.0 adopted 28 March 2023. Operational guidance for Articles 33 and 34. The 72-hour clock starts when the controller has reasonable degree of certainty that a security incident has occurred, has led to personal data being compromised. Investigation may continue in parallel; a controller can file a preliminary notification and complete it later. Data subject notification (Art 34) required when likely to result in high risk; risk-assessment factors include type of breach, nature/sensitivity of data, ease of identification, severity of consequences, special characteristics of individual and of controller, and number of affected individuals. Practical examples show ransomware, data exfiltration, mis-delivery, loss of device.
EDPB Guidelines 9/2022 on personal data breach notification under GDPR, version 2.0 adopted 28 March 2023. The controller should be regarded as having become aware of a personal data breach when it has a reasonable degree of certainty that a security incident has occurred that has led to personal data being compromised. Where a controller first learns of a potential breach, it may need to carry out a short period of investigation in order to establish whether or not a breach has in fact occurred. During this period of investigation the controller may not be regarded as being aware; however, this initial investigation should begin as soon as possible.
Guidelines 1/2024 LI , EDPB Guidelines 1/2024 on legitimate interests (Article 6(1)(f)) 08 Oct 2024
Plain summary: Adopted 8 October 2024. Successor operational guidance to WP217. Restates the three-part test: (1) legitimacy of the interest pursued (must be lawful, clearly articulated and real, not speculative); (2) necessity of the processing (least intrusive means; can the interest be achieved without the processing?); (3) balancing against the fundamental rights and freedoms of data subjects, taking into account reasonable expectations. Introduces sector-specific worked examples including fraud prevention, direct marketing, IT security, physical security, employee monitoring. Post Meta v Bundeskartellamt (C-252/21), personalised advertising cannot be defended on legitimate interest alone in most consumer contexts.
EDPB Guidelines 1/2024 on processing personal data based on Article 6(1)(f) GDPR, adopted 8 October 2024. Reliance on Article 6(1)(f) requires a three-step test: first, the pursuit of a legitimate interest by the controller or by a third party; second, the need to process personal data for the purposes of the legitimate interest(s) pursued; and third, that the interests or fundamental freedoms and rights of the data subjects do not override the legitimate interest(s) pursued by the controller or by a third party.

Adequacy List Aug 2026 , EU Commission Adequacy Decisions in force (as of Aug 2026) 26 Jan 2026
Plain summary: Third countries and international organisations recognised by the European Commission as ensuring an adequate level of protection: Andorra, Argentina, Brazil (mutual adequacy adopted 26 January 2026), Canada (commercial organisations only), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, United Kingdom (adequacy renewed 19 December 2025), Uruguay, European Patent Organisation. United States: adequacy applies only to organisations self-certified to the EU-US Data Privacy Framework. India is NOT on the adequacy list; all EU-to-India personal-data transfers require an Art 46 mechanism (SCCs, BCRs, certification, code of conduct) plus a Schrems II Transfer Impact Assessment.
European Commission Adequacy Decisions register. As of Aug 2026 the following third countries and international organisations are recognised as ensuring an adequate level of protection under Article 45 GDPR: Andorra, Argentina, Brazil (mutual adequacy 26 January 2026), Canada (commercial organisations under PIPEDA), Faroe Islands, Guernsey, Israel, Isle of Man, Japan (with additional safeguards), Jersey, New Zealand, Republic of Korea, Switzerland, United Kingdom (renewed 19 December 2025), United States (EU-US Data Privacy Framework only), Uruguay, European Patent Organisation. India: not adequate. Transfers require Article 46 mechanism plus Transfer Impact Assessment.

AI Act Applicability , Regulation (EU) 2024/1689 EU AI Act, as amended by Regulation (EU) 2026/1744 13 Jun 2024
Plain summary: Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence, entered into force 1 August 2024. Phased application: Article 4 (AI literacy) and Article 5 (prohibited AI practices) from 2 February 2025; General Purpose AI model provisions (Chapter V) from 2 August 2025. The original 2 August 2026 date for high-risk AI system conformity obligations was postponed by Regulation (EU) 2026/1744 (Digital Omnibus on AI), published OJ 24 July 2026, in force 27 July 2026: standalone Annex III high-risk AI is now applied from 2 December 2027, and embedded Annex I high-risk AI from 2 August 2028. Two additional Article 5 prohibitions (non-consensual intimate imagery generation and CSAM generation) added with a grace period to 2 December 2026. Extra-territorial reach: applies to providers placing AI systems on the EU market irrespective of where they are established (Art 2), and to deployers established in the EU. For Indian AI providers serving EU customers, AI Act obligations layer on top of GDPR: DPIA under Art 35 GDPR plus Fundamental Rights Impact Assessment under Art 27 AI Act.
Regulation (EU) 2024/1689 (Artificial Intelligence Act), as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI, OJ 24 July 2026, in force 27 July 2026). Article 113 (as amended) entry into force and application. Chapters I and II apply from 2 February 2025. Chapter V (general-purpose AI models) and Chapter XII apply from 2 August 2025. Standalone high-risk AI systems under Annex III apply from 2 December 2027. High-risk AI systems that are safety components of products covered by harmonised Union legislation listed in Annex I apply from 2 August 2028. Article 5 was amended to add prohibitions on non-consensual intimate imagery generation and child sexual abuse material generation, applicable from 2 December 2026.
Digital Omnibus AI 2026/1744 , Regulation (EU) 2026/1744 Digital Omnibus on AI 24 Jul 2026
Plain summary: Regulation (EU) 2026/1744 amending the AI Act, published OJ 24 July 2026, entered into force 27 July 2026. Postpones the high-risk AI system conformity deadline: standalone Annex III high-risk AI moves from 2 August 2026 to 2 December 2027; embedded Annex I high-risk AI moves to 2 August 2028. Adds two Art 5 prohibitions (non-consensual intimate imagery generation and child sexual abuse material generation) with grace period to 2 December 2026. Practitioner implication for Indian AI providers: high-risk AI conformity work continues but the compliance deadline moves out by 16-24 months; use the extra time to build up documentation and technical standards adherence.
Regulation (EU) 2026/1744 of the European Parliament and of the Council amending Regulation (EU) 2024/1689 (Digital Omnibus on Artificial Intelligence). Published in the Official Journal of the European Union on 24 July 2026. Entry into force on 27 July 2026. Extends the application dates for high-risk AI systems in accordance with Article 6(1) and Annex I of Regulation (EU) 2024/1689 (embedded high-risk AI) to 2 August 2028, and for high-risk AI systems in accordance with Article 6(2) and Annex III (standalone high-risk AI) to 2 December 2027. Amends Article 5 to add prohibitions on non-consensual intimate imagery generation and on child sexual abuse material generation, applicable from 2 December 2026.

Data Act Applicability , Regulation (EU) 2023/2854 Data Act 13 Dec 2023
Plain summary: Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data. Entered into force 11 January 2024. Main provisions applied from 12 September 2025. Interoperability requirements for cloud services from 12 September 2026. Key obligations: data-sharing between IoT product users and third parties; switching between cloud providers within stipulated windows; standard contractual clauses for data-sharing contracts; safeguards against unlawful third-country government access. GDPR takes precedence for personal data; Data Act complements and specifies for IoT product data portability.
Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act). This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union. It shall apply from 12 September 2025.

DSA Applicability , Regulation (EU) 2022/2065 Digital Services Act 19 Oct 2022
Plain summary: Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market for Digital Services. Applied from 17 February 2024 for all intermediaries; Very Large Online Platform (VLOP) and Very Large Online Search Engine (VLOSE) obligations applied earlier from four months after designation. Practitioner overlap with GDPR: DSA transparency and content-moderation duties for Indian platforms serving EU users, with GDPR governing the personal-data dimension. EDPB Guidelines 3/2025 on the DSA-GDPR interplay is the operational reading.
Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act). This Regulation shall apply from 17 February 2024. However, Article 24(2), (3) and (6), Article 33(3) to (6), Article 37(7), Article 40(13), Article 43 and Sections 4, 5 and 6 of Chapter IV shall apply from 16 November 2022.

NIS2 Directive Scope , Directive (EU) 2022/2555 NIS2 Directive 14 Dec 2022
Plain summary: Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union. Transposition deadline: 17 October 2024. Establishes essential-entity and important-entity categories across sectors including energy, transport, banking, financial market infrastructures, health, drinking water, digital infrastructure, ICT service management, public administration, space; and important entities including postal services, waste management, chemicals, food, manufacturing of critical products, digital providers, research. Only applies directly to entities established in the Union. An Indian entity without EU establishment is not directly in scope but will meet NIS2 obligations through EU customer/partner contractual flow-through as a supply-chain risk-management obligation on the essential/important entity.
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive). Member States shall adopt and publish, by 17 October 2024, the measures necessary to comply with this Directive. They shall apply those measures from 18 October 2024.

EU-US DPF Adequacy , EU-US Data Privacy Framework Adequacy Decision 10 Jul 2023
Plain summary: Commission Implementing Decision C(2023) 4745 final of 10 July 2023 on the adequate level of protection of personal data under the EU-US Data Privacy Framework. Adequacy applies only to US organisations self-certified to the DPF under the Framework Principles. Underpinned by US Executive Order 14086 (7 Oct 2022) on Enhancing Safeguards for United States Signals Intelligence Activities, and Attorney-General regulations establishing the Data Protection Review Court. Latombe challenge (Case T-553/23) was dismissed by the General Court on 3 September 2025. Latombe appeal to CJEU (Case C-703/25 P) is pending. Practitioner posture: use SCCs plus TIA as the durable base for US transfers; treat DPF as an additional layer that reduces contractual burden but is legally fragile.
Commission Implementing Decision C(2023) 4745 final of 10 July 2023 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate level of protection of personal data under the EU-US Data Privacy Framework. The United States ensures an adequate level of protection for personal data transferred from the Union to organisations in the United States that are included in the DPF List. The DPF List is maintained and made publicly available by the US Department of Commerce.

Article 27 EU Representative , Article 27 obligation to designate an EU Representative 27 Apr 2016
Plain summary: Article 27 requires controllers and processors that are not established in the Union but are subject to GDPR by virtue of Art 3(2) to designate in writing a representative in the Union. Exceptions: (a) processing which is occasional; (b) processing which does not include, on a large scale, processing of special categories or personal data relating to criminal convictions; and (c) processing which is unlikely to result in a risk to the rights and freedoms of natural persons. Public authorities are also exempt. The representative is the addressee for supervisory authorities and data subjects on all issues related to processing. Named commercial providers of Art 27 Representative services include Prighter, VeraSafe, EU-Rep.com, GDPR-Rep.eu, Datenschutzagentur, and DPO-Consulting; typical annual fees for a mid-size Indian SaaS range from EUR 500 to EUR 3000 depending on volume tier.
Article 27 GDPR. Representatives of controllers or processors not established in the Union. (1) Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union. (2) The obligation laid down in paragraph 1 of this Article shall not apply to: (a) processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or (b) a public authority or body. (3) The representative shall be established in one of those Member States where the data subjects, whose personal data are processed in relation to the offering of goods or services to them, or whose behaviour is monitored, are.
Article 28 Processor , Article 28 processor engagement and mandatory contract clauses 27 Apr 2016
Plain summary: Article 28 requires processing by a processor to be governed by a contract or other legal act that is binding on the processor with regard to the controller, setting out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller. Article 28(3) sets eight mandatory contract clauses covering documented-instructions-only processing, confidentiality of personnel, security under Art 32, subprocessor authorisation, data subject rights assistance, breach and DPIA assistance, deletion or return at end of engagement, and demonstration and audit right. Art 28(4) sets the flow-down obligation on subprocessors.
Article 28(3) GDPR. Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall stipulate, in particular, that the processor: (a) processes the personal data only on documented instructions from the controller; (b) ensures persons authorised to process the personal data have committed themselves to confidentiality; (c) takes all measures required pursuant to Article 32; (d) respects the conditions referred to in paragraphs 2 and 4 for engaging another processor; (e) assists the controller for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights; (f) assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36; (g) at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services; (h) makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits.
Article 3 Territorial Scope , Article 3 territorial scope: establishment and targeting 27 Apr 2016
Plain summary: Article 3 has two limbs. Art 3(1) applies GDPR to processing in the context of the activities of an establishment of a controller or processor in the Union, regardless of whether the processing takes place in the Union. Art 3(2) applies GDPR to non-EU controllers or processors that (a) offer goods or services to data subjects in the Union, whether or not payment is required, or (b) monitor the behaviour of data subjects taking place within the Union. Art 3(3) covers Member-State law application in a place where Member-State law applies by virtue of public international law. EDPB Guidelines 3/2018 is the operational reading.
Article 3, Regulation (EU) 2016/679. Territorial scope. (1) This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not. (2) This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union.
Article 35 DPIA , Article 35 Data Protection Impact Assessment 27 Apr 2016
Plain summary: Article 35 requires the controller to carry out a Data Protection Impact Assessment (DPIA) prior to processing where a type of processing, in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons. Art 35(3) sets three specific mandatory triggers: systematic and extensive evaluation of personal aspects based on automated processing (profiling), including decisions producing legal or similarly significant effects; large-scale processing of special-category or criminal-conviction data; systematic monitoring of publicly accessible areas on a large scale. WP248 (endorsed by EDPB) sets nine additional criteria. DPAs publish DPIA lists (Art 35(4)-(5)).
Article 35(1) GDPR. Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. (3) A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of: (a) a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person; (b) processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or (c) a systematic monitoring of a publicly accessible area on a large scale.
Article 5 Principles , Article 5 seven data protection principles 27 Apr 2016
Plain summary: Article 5(1) sets seven principles: (a) lawfulness, fairness and transparency; (b) purpose limitation; (c) data minimisation; (d) accuracy; (e) storage limitation; (f) integrity and confidentiality. Article 5(2) adds accountability: the controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1. Principles are enforceable in their own right and often cited in enforcement action alongside the specific-provision breach (Amazon €746m, H&M €35m, LinkedIn €310m).
Article 5 GDPR. Principles relating to processing of personal data. 1. Personal data shall be: (a) processed lawfully, fairly and in a transparent manner in relation to the data subject; (b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; (c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed; (d) accurate and, where necessary, kept up to date; (e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; (f) processed in a manner that ensures appropriate security of the personal data. 2. The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (accountability).
Article 6 Lawful Basis , Article 6 six lawful bases for processing 27 Apr 2016
Plain summary: Article 6(1) sets six lawful bases: (a) consent; (b) performance of a contract; (c) compliance with a legal obligation; (d) protection of vital interests; (e) task carried out in the public interest; (f) legitimate interests. Legitimate interests requires a three-part test: legitimacy, necessity, balance against data subject rights (EDPB Guidelines 1/2024 dated 8 Oct 2024). Art 6(4) governs compatibility of further processing with the original purpose. Special-category data (Art 9) has its own gateway list; where both apply, the entity needs both an Art 6 basis and an Art 9 gateway.
Article 6 GDPR. Lawfulness of processing. 1. Processing shall be lawful only if and to the extent that at least one of the following applies: (a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes; (b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; (c) processing is necessary for compliance with a legal obligation to which the controller is subject; (d) processing is necessary in order to protect the vital interests of the data subject or of another natural person; (e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; (f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
Article 7 Consent , Article 7 conditions for consent 27 Apr 2016
Plain summary: Article 7 sets four operational conditions for valid consent under Art 6(1)(a) and Art 9(2)(a). (1) Demonstrability: controller shall be able to demonstrate that the data subject has consented. (2) Distinguishability: if consent is given in a written declaration that also concerns other matters, the request for consent shall be presented in a manner clearly distinguishable, in an intelligible and easily accessible form, using clear and plain language. (3) Withdrawability: the data subject shall have the right to withdraw consent at any time; withdrawal shall not affect the lawfulness of processing based on consent before its withdrawal; it shall be as easy to withdraw as to give consent. (4) Freely-given: assessment shall take utmost account of whether the performance of a contract is conditional on consent to processing that is not necessary for the performance.
Article 7 GDPR. Conditions for consent. (1) Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data. (2) If the data subject's consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. (3) The data subject shall have the right to withdraw his or her consent at any time. It shall be as easy to withdraw as to give consent. (4) When assessing whether consent is freely given, utmost account shall be taken of whether the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
Articles 33-34 Breach , Articles 33 and 34 breach notification 27 Apr 2016
Plain summary: Article 33 requires the controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Late notifications must be accompanied by reasons for the delay. The notification must describe the nature of the breach, the categories and approximate number of data subjects, the categories and approximate number of personal data records concerned, the name and contact details of the DPO, likely consequences, and measures taken or proposed. Article 34 requires the controller to communicate the breach to the data subject without undue delay when it is likely to result in a high risk to the rights and freedoms of natural persons; exceptions include appropriate technical and organisational measures that render the data unintelligible (e.g. encryption) and disproportionate effort. EDPB Guidelines 9/2022 v2.0 is the operational workflow.
Article 33(1) GDPR. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay. Article 34(1). When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.
Articles 37-39 DPO , Articles 37-39 Data Protection Officer 27 Apr 2016
Plain summary: Article 37(1) requires designation of a Data Protection Officer where: (a) processing is carried out by a public authority; (b) the core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale; or (c) the core activities consist of processing on a large scale of special categories or criminal-conviction data. Art 37(2)-(3) allow group DPO structures. Art 37(4) permits designation on other grounds. Art 37(5) sets qualifications: expert knowledge of data protection law and practices. Art 38 governs position: involvement in all issues, sufficient resources, no conflicting tasks, direct reporting to highest management, protection from dismissal for performing DPO tasks. Art 39 lists tasks: inform and advise, monitor compliance, cooperate with the DPA, act as contact point.
Article 37(1) GDPR. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or (c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10.
Chapter V Transfers , Articles 44-50 transfers to third countries 27 Apr 2016
Plain summary: Chapter V governs transfers to third countries and international organisations. Art 44 general principle: any transfer, including onward transfers, requires compliance with Chapter V. Art 45 adequacy: transfer permissible if the Commission has decided the third country ensures an adequate level of protection. Art 46 appropriate safeguards: transfers may take place if the controller or processor has provided appropriate safeguards, including SCCs adopted by the Commission (Art 46(2)(c)), BCRs (Art 46(2)(b) and Art 47), approved code of conduct or certification with binding and enforceable commitments (Art 46(2)(e)-(f)), or ad-hoc contractual clauses (Art 46(3)(a), needing DPA authorisation). Art 47 BCRs. Art 48 non-EU orders to disclose. Art 49 derogations for specific situations: explicit consent, contract necessity, public interest, legal claims, vital interests. Schrems II (C-311/18) imposed the Transfer Impact Assessment obligation on SCC-based transfers.
Article 44 GDPR. General principle for transfers. Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation. All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined.
Data Subject Rights 12-22 , Articles 12-22 data subject rights 27 Apr 2016
Plain summary: Chapter III GDPR sets out data subject rights. Art 12 governs modality (transparency, timing, format). Art 13-14 transparency-at-collection duties. Art 15 right of access. Art 16 rectification. Art 17 erasure (six triggers, ten exceptions). Art 18 restriction. Art 19 notification of rectification, erasure or restriction to recipients. Art 20 data portability (machine-readable format). Art 21 right to object. Art 22 automated individual decision-making, including profiling. Timeline: response without undue delay and in any event within one month of receipt, extendable by two further months for complex requests, with reasons.
Article 12 GDPR. Transparent information, communication and modalities for the exercise of the rights of the data subject. The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication under Articles 15 to 22 and 34 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child. The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests.

Meta €1.2B Ireland 2023 , Meta Platforms Ireland €1.2 billion DPC Ireland May 2023 22 May 2023
Plain summary: Ireland Data Protection Commission (DPC) fine of €1.2 billion imposed on Meta Platforms Ireland Limited on 22 May 2023. Contravention: Article 46(1) GDPR. Systematic transfer of EU user personal data (Facebook service) to Meta infrastructure in the United States using Commission SCCs where the Transfer Impact Assessment could not conclude essentially equivalent protection was in place. Order also required suspension of the transfers and restoration to lawfulness within stipulated windows. Largest GDPR fine to date as of Aug 2026. Practitioner lesson: Schrems II TIA has teeth; the exporter's own conclusion of "adequate" does not override the DPA assessment.
Data Protection Commission (Ireland) Final Decision of 12 May 2023 in the matter of Meta Platforms Ireland Limited (Facebook Service). The DPC found that Meta had infringed Article 46(1) GDPR when it continued to transfer personal data to the United States following the delivery of the Schrems II judgment. An administrative fine of EUR 1,200,000,000 was imposed. Meta was also directed to suspend any future transfer of personal data to the United States within a period of five months from the date of the DPC's decision and to bring its processing operations into compliance with Chapter V of the GDPR within a period of six months.
Uber €290M Netherlands 2024 , Uber B.V. €290 million AP Netherlands August 2024 22 Aug 2024
Plain summary: Autoriteit Persoonsgegevens (Netherlands DPA) fine of €290 million imposed on Uber Technologies Inc. and Uber B.V. on 22 August 2024. Contravention: Article 44 GDPR general principle for transfers, read with Chapter V. Between August 2021 (when the SCCs used by Uber under the old decisions expired) and November 2023 (when Uber implemented the 2021 Commission SCCs), Uber transferred EU driver personal data to the United States without a valid Art 46 mechanism. Practitioner lesson: coverage gaps between transfer mechanisms are themselves violations, even when transfers eventually resumed under a compliant mechanism. Every mechanism-change milestone needs a pre-planned transition period.
Autoriteit Persoonsgegevens (Netherlands DPA) decision of 22 August 2024 in the Uber inquiry. Uber Technologies Inc. and Uber B.V. transferred personal data of European drivers to servers in the United States without appropriate safeguards for a period from 6 August 2021 to 27 November 2023, thereby infringing Article 44 of the GDPR. Administrative fine of EUR 290 million imposed.
LinkedIn €310M Ireland 2024 , LinkedIn Ireland €310 million DPC Ireland October 2024 24 Oct 2024
Plain summary: DPC Ireland fine of €310 million imposed on LinkedIn Ireland Unlimited Company on 24 October 2024. Contravention: Articles 6(1), 5(1)(a) GDPR. LinkedIn's behavioural analysis and targeted advertising processing relied on legal bases (contract necessity, legitimate interests, consent) that the DPC found insufficient. Reprimand plus order to bring processing into compliance. Practitioner lesson: legitimate-interest basis for targeted advertising is defensively hard to hold; contract-necessity basis is not available; explicit granular consent is the operating standard.
Data Protection Commission (Ireland) Final Decision of 24 October 2024 in the LinkedIn inquiry. The DPC found LinkedIn had infringed the GDPR through its processing of personal data of users of the LinkedIn platform for behavioural analysis and targeted advertising. Administrative fine of EUR 310 million. LinkedIn was ordered to bring its processing operations into conformity with the GDPR.
TikTok €530M Ireland 2025 , TikTok Technology Ltd €530 million DPC Ireland May 2025 02 May 2025
Plain summary: DPC Ireland fine of €530 million imposed on TikTok Technology Limited on 2 May 2025. Contravention: GDPR Chapter V transfer rules. EEA user personal data transferred to and stored on servers in the People's Republic of China, where Chinese national-security laws (including the National Intelligence Law 2017 and the Data Security Law 2021) provide access powers to state authorities that are not essentially equivalent to EU standards. Fine composed of €485 million for transfer infringement and €45 million for transparency deficiencies in the privacy notice. Practitioner lesson: third-country transfer enforcement is durable. Every non-adequate destination requires its own TIA and, where surveillance-law exposure is material, supplementary technical measures or transfer suspension.
Data Protection Commission (Ireland) Final Decision of 2 May 2025 in the inquiry into TikTok Technology Limited (Chapter V of the GDPR). The DPC found that TikTok infringed the GDPR in respect of its transfers of EEA user data to the People's Republic of China. The DPC imposed administrative fines totalling EUR 530 million (EUR 485 million for the Chapter V infringement; EUR 45 million for infringements of transparency obligations under Articles 13 and 14). TikTok was ordered to bring its data processing into compliance within six months.

Payment Data Localisation , RBI Payment Data Storage Direction 2018 06 Apr 2018
Plain summary: RBI Circular DPSS.CO.OD No.2785/06.08.005/2017-2018 dated 6 April 2018 requires all system providers and their service providers, intermediaries, third-party vendors and other entities in the payment ecosystem to store the entire data relating to payment systems operated by them in a system only in India. Data may be processed abroad but must be brought back to India within one business day or 24 hours of processing, whichever is earlier. For an Indian payment-service provider processing EU cardholder data, GDPR Chapter V transfer rules and RBI Payment Data Storage rules both apply; comply with both by design (typically Indian primary storage plus EU-region processing for the EU leg, both with SCCs where cross-border transfer under GDPR applies).
RBI Circular DPSS.CO.OD No.2785/06.08.005/2017-18 dated 6 April 2018. Subject: Storage of Payment System Data. All system providers shall ensure that the entire data relating to payment systems operated by them are stored in a system only in India. For the foreign leg of the transaction, if any, the data can also be stored in the foreign country, if required. In case the processing is done abroad, the data should be deleted from the systems abroad and brought back to India not later than the one business day or 24 hours from payment processing, whichever is earlier.

Found an error? We pay for it.

If you find a factual error in any lesson, write to [email protected] with the lesson title, the specific claim, and the corrected source.

  • ₹1,000 credit for the first report of any verifiable factual error.
  • ₹5,000 credit for a substantial error (e.g. a wrong section number, an obsolete ruling, a misrepresented holding).
  • Credit on your dcomply Academy account usable against any future course.

We pay because we'd rather know than not know. If the law changes (and it will), we want to be the first to fix our lessons.

On this page
  • 🟢 Our verification promise
  • 📊 Course statistics
  • 📚 Full citation register
  • 🐛 Bug bounty for errors

Maintained by the dcomply Academy editorial team. Last reviewed recently.