DPIAs: DPDPA Rules vs. GDPR Article 35 – An Indian Perspective
As India’s Digital Personal Data Protection Act, 2023 (DPDPA) and its accompanying Rules have fully come into effect, Indian businesses are grappling with their new compliance obligations. Among the most critical is the requirement for Data Protection Impact Assessments (DPIAs), a mechanism for identifying and mitigating risks associated with data processing. For organisations operating globally or dealing with international data flows, understanding the nuances between the DPDPA Rules and established frameworks like the EU’s General Data Protection Regulation (GDPR) is paramount. This analysis anchors on the Indian regime, comparing it against GDPR Article 35, highlighting areas of convergence, divergence, and unique Indian provisions.
Mandatory Assessment Triggers
Under the DPDPA, the obligation to conduct a DPIA primarily falls upon “Significant Data Fiduciaries” (SDFs). Section 10(2) of the DPDPA mandates that an SDF must undertake a DPIA for specific processing activities as may be prescribed by the DPDPA Rules. These Rules, now operational, detail the criteria for what constitutes “significant” processing, often involving large-scale processing of sensitive personal data, profiling, or activities that pose a high risk to Data Principals. The Data Protection Board of India (DPBI) is empowered to specify further activities requiring DPIAs.
In contrast, GDPR Article 35(1) establishes a broader trigger: a DPIA is required whenever processing is “likely to result in a high risk to the rights and freedoms of natural persons.” While the GDPR does not explicitly define “high risk,” Article 35(3) provides illustrative examples, such as systematic and extensive evaluation of personal aspects, large-scale processing of special categories of data, or systematic monitoring of publicly accessible areas. Unlike the DPDPA’s explicit focus on SDFs and prescribed activities, GDPR’s trigger is more principles-based, requiring organisations to assess risk proactively. This makes the DPDPA potentially narrower in its initial scope of mandatory DPIAs, focusing on designated entities and activities, but also offers more clarity once the Rules specify these.
Scope and Content of the Assessment
Both regimes expect a comprehensive assessment. The DPDPA Rules, building on Section 10(2)(a), require a DPIA to include a description of the processing operation, its purposes, an assessment of the necessity and proportionality of the processing, an assessment of the risks to Data Principals, and the measures envisaged to address those risks, including safeguards, security measures, and mechanisms to ensure the protection of personal data. Notably, Section 10(2)(b) also mandates SDFs to undertake “periodic audits” and other measures, implying an ongoing assessment and review process beyond a one-off DPIA.
GDPR Article 35(7) similarly outlines the minimum content for a DPIA: a systematic description of the processing operations and purposes; an assessment of the necessity and proportionality of the processing; an assessment of the risks to the rights and freedoms of data subjects; and the measures envisaged to address the risks, including safeguards, security measures, and mechanisms to ensure the protection of personal data and to demonstrate compliance. The core elements are largely aligned, focusing on understanding the processing, identifying risks, and proposing mitigation. However, the DPDPA’s requirement for “periodic audits” for SDFs suggests a potentially stricter, continuous compliance burden compared to GDPR’s typically project-specific DPIA.
Engagement with Regulatory Authorities
A key distinction lies in the interaction with supervisory authorities. Under the DPDPA, Section 10(3) stipulates that an SDF must submit its DPIA report to the DPBI when prescribed by the DPDPA Rules. This implies a direct oversight mechanism where the regulator may review the assessment itself for certain high-risk processing activities or for specific categories of SDFs.
GDPR Article 36, on the other hand, mandates consultation with the supervisory authority prior to processing only if the DPIA indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk. This is a pre-processing consultation triggered by unmitigated high risk, rather than a general requirement to submit DPIAs. The DPDPA’s potential for mandatory submission for certain activities or entities could be seen as a more direct and potentially stricter regulatory engagement model for SDFs in India.
Comparative Rigour and Gaps
Comparing the two, the DPDPA, through its Rules, appears to be stricter in certain aspects, particularly for SDFs. The explicit designation of SDFs, coupled with the potential for mandatory submission of DPIAs to the DPBI (Section 10(3)) and the requirement for “periodic audits” (Section 10(2)(b)), introduces a higher bar for continuous compliance and regulatory scrutiny than GDPR’s general “high risk” trigger and conditional consultation.
However, the DPDPA relies heavily on the specifics outlined in the Rules. While GDPR Article 35(3) provides concrete examples of processing requiring a DPIA, the DPDPA’s triggers are more dependent on the prescriptions in the Rules and the DPBI’s future guidance. This means that while the DPDPA has the potential for greater rigour, its actual impact depends on the granularity of these specifications. Currently, the DPDPA is also silent on the explicit involvement of a Data Protection Officer (DPO) in the DPIA process, unlike GDPR Article 35(2) which mandates consultation with the DPO. Nevertheless, given the DPDPA’s emphasis on accountability, it is expected that SDFs will involve internal experts, including any designated DPO-equivalent roles, in their DPIA processes.
Practical takeaway
Indian businesses, particularly those designated as Significant Data Fiduciaries, must proactively understand their obligations under the DPDPA Rules. While drawing lessons from GDPR best practices for conducting DPIAs is valuable, strict adherence to the DPDPA’s specific triggers, content requirements, and submission mandates is crucial. This includes closely monitoring DPBI guidance on what constitutes “prescribed” activities for DPIAs and understanding the scope of “periodic audits.” Integrating DPIAs into the organisational risk management framework, rather than treating them as one-off compliance exercises, will be key to navigating India’s evolving data protection landscape.