International Journal For Multidisciplinary Research
E-ISSN: 2582-2160
•
Impact Factor: 9.24
A Widely Indexed Open Access Peer Reviewed Multidisciplinary Bi-monthly Scholarly International Journal
Home
Research Paper
Submit Research Paper
Publication Guidelines
Publication Charges
Upload Documents
Track Status / Pay Fees / Download Publication Certi.
Editors & Reviewers
View All
Join as a Reviewer
Get Membership Certificate
Current Issue
Publication Archive
Conference
Publishing Conf. with IJFMR
Upcoming Conference(s) ↓
Conferences Published ↓
DePaul-2026
IC-AIRCM-T3-2026
NSSFIGTMA-2025
SPHERE-2025
AIMAR-2025
SVGASCA-2025
ICRTET-4
ICCE-2025
Chinai-2023
PIPRDA-2023
ICMRS'23
Contact Us
Plagiarism is checked by the leading plagiarism checker
Call for Paper
Volume 8 Issue 5
September-October 2026
Indexing Partners
The Gdpr and India's Data Protection Regime: Comparative Lessons, Constitutional Challenges
| Author(s) | Mr. Gunnam Bhaskar Rao, Dr. Malay Kumar Behera, Prof. Dr. Sudhansu Ranjan Mohapatra |
|---|---|
| Country | India |
| Abstract | The emergence of data-driven governance has transformed personal information into a source of economic, administrative and political power. Contemporary privacy harms no longer arise solely from unauthorised disclosure or physical intrusion; they increasingly result from the continuous collection, aggregation, profiling, inference and automated use of personal data by both public and private actors. The European Union's General Data Protection Regulation (GDPR) represents the most influential contemporary model of comprehensive data protection. It combines principles governing data processing, multiple lawful bases, enforceable data-subject rights, organisational accountability, independent supervision and safeguards relating to automated decision-making. India has developed along a different constitutional trajectory. The recognition of privacy as a fundamental right in Justice K S Puttaswamy (Retd) v Union of India supplied a constitutional foundation for informational privacy grounded in dignity, autonomy, liberty and proportionality. The Digital Personal Data Protection Act 2023 (DPDP Act) and the Digital Personal Data Protection Rules 2025 constitute India's principal attempt to establish a dedicated statutory framework for digital personal data. This article argues that the central comparative question is not whether India should replicate the GDPR. Such an inquiry assumes that regulatory similarity is the appropriate measure of legal adequacy. This article advances instead a constitutional equivalence model of comparative data protection. Under this model, a domestic data protection regime need not reproduce the institutional or textual architecture of the GDPR, but it must provide functionally equivalent safeguards against arbitrary and disproportionate concentrations of informational power. The constitutional adequacy of India's regime should therefore be measured by its capacity to protect dignity, autonomy, equality and democratic participation while subjecting both State and corporate data processing to meaningful legality, necessity, proportionality, accountability and oversight. The article undertakes a detailed section-by-section comparison of the GDPR and the DPDP Act in relation to scope, processing principles, consent, lawful grounds, individual rights, sensitive data, children's data, accountability, automated decision-making, regulatory institutions, State exemptions, penalties and cross-border transfers. It argues that India has deliberately adopted a simplified and distinctive framework rather than a GDPR clone. However, certain differences are not merely matters of legislative style. The limited treatment of profiling and consequential automated decision-making, the breadth of certain State exemptions, questions concerning institutional independence and the limited statutory articulation of data minimisation and purpose limitation raise constitutional concerns. The article concludes that India should pursue neither wholesale transplantation nor regulatory exceptionalism. Instead, it should develop an indigenous model of constitutional data governance based on constitutional equivalence, differentiated accountability, independent oversight, algorithmic safeguards and proportionate regulation of informational power. |
| Keywords | Digital Personal Data Protection Act 2023; DPDP Rules 2025; privacy; Puttaswamy; constitutionalism; comparative law; data protection; algorithmic accountability; digital governance. |
| Published In | Volume 8, Issue 5, September-October 2026 |
| Published On | 2026-09-04 |
Share this

E-ISSN 2582-2160
CrossRef DOI prefix of IJFMR is 10.36948/ijfmr
All research papers published on this website are licensed under Creative Commons Attribution-ShareAlike 4.0 International License, and all rights belong to their respective authors/researchers.
Powered by Sky Research Publication and Journals