India's DPDP Act 2023 vs GDPR: Key Differences
Consent and legitimate uses against six lawful bases, Consent Managers, the rights India's DPDP Act omits, the Data Protection Board, rupee penalties, and the phased commencement to May 2027.
Page 2 of 12
Consent and legitimate uses against six lawful bases, Consent Managers, the rights India's DPDP Act omits, the Data Protection Board, rupee penalties, and the phased commencement to May 2027.
Art. 35(3)(b) names large-scale Art. 9 processing, so a health DPIA is rarely optional. The Art. 35(7) content applied to a clinical system, WP248 criteria, Art. 36 prior consultation, and when to redo it.
When the GDPR reaches an Australian business under Art. 3(2), the two scope tests applied to Australian fact patterns, the Art. 27 EU representative duty, and what non-compliance costs.
Canada's adequacy decision does not exempt Canadian companies from the GDPR. When Art. 3(2) applies, the Art. 27 EU representative duty, and what health data changes.
Buying guide for Australian companies subject to the GDPR: EU hosting, Art. 30 records, DSAR workflow, Art. 27 representative arrangements, and dual Privacy Act + GDPR record-keeping.
Choosing GDPR compliance software in Canada: running Art. 30 records alongside PIPEDA and Quebec Law 25, bilingual output, three breach clocks, and what the market actually delivers.
GDPR software for Indian IT-services firms: Art. 30(2) processor records per client, sub-processor management, DPA and SCC registers, and audit evidence for European client due diligence.
Buying guide for Singapore companies subject to the GDPR: EEA hosting, Art. 30 records for controller and processor activities, DSAR workflow, Art. 27 representative records, dual PDPA + GDPR registers.
Health data needs an Art. 9(2) condition on top of an Art. 6 lawful basis. Controller mapping across providers, insurers and vendors, why consent fails in care, Art. 9(4) national law.
Most Indian companies meet the GDPR as processors for European clients, not through Art. 3(2) targeting. What Arts. 28, 30(2), 32 and 33(2) require, and why health data is audited hardest.
The MDR Art. 11 Authorised Representative does not satisfy GDPR Art. 27. Two separate appointments, plus controller/processor status for telemetry, post-market surveillance versus minimisation, and SaMD.
When the GDPR reaches a Singapore business under Art. 3(2), the processor nuance that catches regional service centres, the Art. 27 representative duty, and what follows for health data.
Which Art. 9(2) conditions health organisations actually rely on and how each one fails: explicit consent, 9(2)(h) with the Art. 9(3) secrecy trap, public health, and research under Art. 89(1).
India has no EU adequacy decision. Which SCC module applies to an Indian processor, how to run the transfer impact assessment, and how to answer the government-access questions.
The PDPA's consent-centric model against the GDPR's six lawful bases: access rights, the absence of a special-category tier, the DNC registry, breach notification timing, and PDPC enforcement.
PIPEDA's ten principles against the GDPR's structure: consent, erasure, breach reporting to the OPC, Quebec Law 25, enforcement powers and the state of federal reform.
The 13 Australian Privacy Principles against the GDPR's structure: lawful bases, consent, data subject rights, the NDB scheme vs Art. 33/34, OAIC vs EU supervisory authorities, and the reform direction.
Singapore has no EU adequacy decision, and the EU–Singapore Digital Trade Agreement is not one. Which SCC module applies, how to run the transfer impact assessment, and the contract path.