Post

DPIA Mandates: DPDPA Rules vs. GDPR Article 35

DPIA Mandates: DPDPA Rules vs. GDPR Article 35

As India’s Digital Personal Data Protection Act, 2023 (DPDPA) and its accompanying Rules have now taken full effect, Data Protection Impact Assessments (DPIAs) emerge as a critical compliance cornerstone for Data Fiduciaries. For Indian businesses navigating this new landscape, understanding the nuances of India’s DPIA requirements, particularly in comparison to global benchmarks like the EU’s General Data Protection Regulation (GDPR), is paramount. This analysis anchors on the Indian framework, comparing its approach to DPIAs against GDPR Article 35, highlighting areas of convergence and divergence.

DPDPA Rules: India’s Framework for Risk Assessment

The DPDPA Act, 2023, lays the groundwork for DPIAs, primarily through Section 10(1), which empowers the Central Government to prescribe “such other measures” as Data Fiduciaries must undertake to ensure compliance. The subsequently notified DPDPA Rules, 2024/2025 (as applicable by September 2026), concretise these obligations, specifying the circumstances under which a DPIA becomes mandatory.

While the Act itself does not detail the specifics of a DPIA, it is widely understood that the Rules mandate DPIAs for processing activities likely to pose a high risk to the rights of data principals. This includes, but is not limited to, large-scale processing of sensitive personal data, systematic profiling, or processing involving new technologies. Crucially, Section 10(2) of the DPDPA Act empowers the government to designate “Significant Data Fiduciaries” (SDFs) based on factors like the volume and sensitivity of data processed, risk of harm, and impact on public order. The DPDPA Rules impose more stringent obligations on SDFs, including a mandatory requirement to appoint an independent Data Protection Officer (DPO) under Section 10(2)(b), who would be integral to conducting DPIAs.

Beyond the DPDPA, India’s regulatory environment includes sector-specific mandates. For instance, the Reserve Bank of India (RBI) has long required its regulated entities to implement robust risk management frameworks and conduct comprehensive cybersecurity audits, which often encompass elements akin to a DPIA, albeit not explicitly termed as such. Similarly, the erstwhile Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, particularly Rule 4(1)(d) for significant social media intermediaries, already required “risk assessment” as part of their privacy policies. The DPDPA Rules build upon these existing layers, demanding a more formalised and comprehensive DPIA process.

GDPR Article 35: The Global Benchmark

In contrast, GDPR Article 35 explicitly details the requirement for a Data Protection Impact Assessment. Article 35(1) mandates a DPIA “where a type of processing… is likely to result in a high risk to the rights and freedoms of natural persons.” GDPR further provides specific examples of such high-risk processing in Article 35(3), including:

  • Systematic and extensive evaluation of personal aspects based on automated processing (profiling).
  • Large-scale processing of special categories of data (Article 9) or data relating to criminal convictions and offences (Article 10).
  • Systematic monitoring of a publicly accessible area on a large scale.

The content of a GDPR DPIA is also clearly prescribed under Article 35(7), requiring a description of processing operations, an assessment of necessity and proportionality, an assessment of risks to data subjects, and the measures envisaged to address those risks, including safeguards and security measures. Furthermore, Article 35(2) mandates consultation with the designated Data Protection Officer (DPO), and Article 36 requires prior consultation with the relevant Supervisory Authority if the DPIA indicates a high residual risk that cannot be mitigated.

Comparative Analysis: Stricter, Looser, or Silent?

When comparing the DPDPA Rules with GDPR Article 35, several distinctions emerge:

Triggers for Mandatory DPIAs

The DPDPA Rules, particularly for SDFs, are likely to be more prescriptive regarding mandatory DPIA triggers, potentially listing specific categories of data processing or types of data that necessitate an assessment. While GDPR provides a general “high risk” principle, the DPDPA Rules for SDFs might adopt a more explicit, checklist-driven approach in certain areas, potentially making it stricter for these entities. For non-SDFs, the DPDPA Rules might offer a degree of flexibility, depending on the final interpretation and guidance from the Data Protection Board of India (DPBI).

Scope and Content of Assessment

Both frameworks broadly align on the purpose and expected content of a DPIA: identifying, assessing, and mitigating risks to data subjects/principals. GDPR Article 35(7) provides clear guidance on content. The DPDPA Rules are expected to mirror these requirements, focusing on technical and organisational measures, but may include India-specific considerations, such as the unique challenges of processing data in a highly diverse linguistic and technological environment. In this regard, the DPDPA Rules are largely similar in intent, with potential for India-specific adaptations.

Consultation Requirements

Both regimes emphasise internal and external consultation. GDPR mandates DPO consultation (Article 35(2)) and prior consultation with the Supervisory Authority for unmitigated high risks (Article 36). The DPDPA Act, through Section 10(2)(b), makes DPO appointment mandatory for SDFs, implying their central role in DPIAs. While the DPDPA Rules are expected to detail when consultation with the DPBI (established under Section 18) is required, it is highly probable that similar to GDPR, unmitigated high risks will necessitate such engagement. For SDFs, the DPDPA is arguably stricter due to the explicit DPO mandate and the likely prescriptive nature of DPBI consultation.

Sector-Specific Overlays

A unique aspect of the Indian landscape is the overlay of existing sector-specific regulations. The DPDPA Rules integrate with and build upon frameworks from bodies like the RBI. This means that entities already complying with RBI’s risk assessment requirements will need to ensure their processes are harmonised with, and meet the enhanced requirements of, the DPDPA DPIA framework. This multi-layered compliance environment presents an added complexity that is silent in GDPR’s general application but critical for Indian businesses.

Practical Takeaway

For Indian businesses, especially those designated as Significant Data Fiduciaries, the DPDPA Rules introduce a robust and often more prescriptive DPIA regime. It is crucial to move beyond mere compliance checklists and embed DPIAs as an ongoing process within your data governance framework. Proactively identify high-risk processing activities, establish clear internal procedures for conducting DPIAs, and ensure your appointed DPO (for SDFs) is fully integrated into this process. For entities in regulated sectors like finance, harmonising DPDPA DPIA requirements with existing RBI guidelines is paramount. Monitor guidance from the Data Protection Board of India closely, as it will shape the practical implementation and enforcement of these critical risk assessment mandates.

This post is licensed under CC BY 4.0 by the author.