From Europe's 1995 Directive to India's 2023 DPDPA — a global chronology of data protection legislation, with notes on what each law means for Indian businesses operating internationally. Written by Yuvaraj S., Founder, truConsent.
Global Chronology
Every major data protection law, in order of passage. Each entry notes what the law does — and what it means specifically for Indian businesses.
The world's first comprehensive data protection framework. Established the template for modern privacy law: consent, individual rights, and controller accountability across all EU member states.
For Indian businesses: The adequacy decision framework this directive created still affects Indian software companies serving EU clients today.
Applied to commercial activities across Canada. Consent-based and sector-neutral, PIPEDA introduced a privacy ombudsman model rather than a standalone regulator.
For Indian businesses: Indian IT/BPO firms with Canadian clients must align their consent practices with PIPEDA requirements.
One of the first comprehensive privacy laws in Latin America. Established a data protection authority and granted broad individual rights modelled on EU principles.
For Indian businesses: Niche relevance for Indian companies expanding into South America, but signals LATAM's alignment with the EU model.
A balanced approach that prioritises business enablement alongside individual rights. The 2020 amendment introduced mandatory breach notification, higher fines, and data portability.
For Indian businesses: Many Indian companies operate through Singapore entities. Dual PDPA and DPDPA compliance is increasingly common and warrants a unified consent platform.
The global gold standard: 99 articles, mandatory Data Protection Officers, Data Protection Impact Assessments, and penalties of up to €20M or 4% of global annual revenue — whichever is higher.
For Indian businesses: Any Indian company processing data of EU residents must comply — regardless of where the company is physically based.
The first US state privacy law with real teeth. Introduced opt-out rights for data sales, a private right of action for data breaches, and — via CPRA — a dedicated privacy regulator.
For Indian businesses: Indian SaaS companies with California users must support opt-out mechanisms, or face AG enforcement as Sephora discovered to the tune of $1.2M.
Brazil's GDPR equivalent. Defines 10 legal bases for processing, established the ANPD data protection authority, and carries fines of up to 2% of Brazilian revenue capped at R$50M per infraction.
For Indian businesses: The Brazilian market is growing for Indian tech exports. LGPD compliance is becoming a pre-condition in enterprise procurement contracts.
The strictest law globally on cross-border data transfers. Requires explicit, separate consent for data leaving China. The Didi Chuxing fine of ¥8.026 billion set the enforcement tone for the region.
For Indian businesses: Indian companies with Chinese operations or users face dual PIPL and DPDPA compliance — with potentially conflicting requirements on cross-border transfer mechanisms.
Modelled closely on the EU GDPR. Requires explicit consent for sensitive data, mandates a Data Protection Officer for large processors, and grants data subjects rights of access, erasure, and portability.
For Indian businesses: Indian companies expanding into Southeast Asia increasingly need PDPA awareness as Thailand has become a significant technology services market.
One of the first comprehensive privacy laws in the Gulf region. Applies to all personal data processing in the UAE and establishes a data protection office under the UAE government.
For Indian businesses: Large Indian diaspora and deep trade relationships make UAE compliance routine for Indian businesses — and the law's consent requirements are more prescriptive than many expect.
Broadly mirrors the EU GDPR but with UK-specific adequacy decisions, a domestic ICO, and a growing divergence as the UK pursues a lighter-touch reform agenda.
For Indian businesses: Indian companies with both EU and UK users need to track the divergence carefully — they may ultimately need separate consent workflows for each jurisdiction.
Australia is moving to opt-in consent, introducing a direct right of action for individuals, abolishing the small business exemption, and strengthening the OAIC's enforcement powers.
For Indian businesses: Australia is a major destination for Indian IT services. The reform will directly affect Indian outsourcing contracts and data handling obligations.
The world's first law to regulate AI systems with significant privacy implications. High-risk AI systems require conformity assessments, transparency obligations, and human oversight mechanisms.
For Indian businesses: India is expected to introduce AI regulation with partial influence from this Act. Indian AI product companies should begin gap assessments now.
Thirty clauses, a consent-first framework, the DPBI as adjudicatory body, a maximum penalty of ₹250 crore, and — uniquely globally — a licensed Consent Manager model that makes consent intermediaries accountable to a regulator.
For Indian businesses: This is your primary compliance obligation if you collect digital personal data in India. Everything else on this list is context; this is mandatory.
Editorial Perspective
Looking at this list, the convergence is striking. Every major privacy law — from Argentina in 2000 to India in 2023 — is built around four shared pillars: notice, consent, individual rights, and accountability. The vocabulary differs. The penalties differ. But the obligations are structurally consistent. This convergence is intentional — most newer laws were explicitly modelled on GDPR, which has become the de facto global template.
The divergence, however, is in enforcement appetite and specific mechanisms. GDPR uses a Data Protection Officer; DPDPA uses a Consent Manager — a licensed intermediary that GDPR has no equivalent for. CCPA creates opt-out rights; DPDPA requires opt-in consent. PIPL restricts cross-border transfers through government approval; India's DPDPA will use a negative list of prohibited countries. These differences are not cosmetic — they require different technical implementations.
This is the challenge for Indian businesses with global operations: they cannot apply GDPR logic to every jurisdiction and call it done. A consent platform that understands GDPR but not DPDPA will leave you exposed in your home market. One that handles DPDPA but not GDPR will cost you EU business. The right answer is a platform that maps obligations by jurisdiction — and truConsent is built specifically for the Indian compliance context while remaining structurally aware of the global landscape.
One specific issue to watch: DPDPA's pending Rules will define India's stance on cross-border data transfers via a "negative list" of prohibited countries. This is a deliberate departure from GDPR's positive adequacy model, where transfers are allowed only to countries on an approved list. India's approach inverts this — transfers are allowed everywhere except the countries on the prohibited list. Until the Rules are notified, Indian businesses operate in a transfer governance vacuum. That vacuum will close — and the compliance obligations will land simultaneously.
Comparative Analysis
How each major privacy law handles the transfer of personal data across national borders — and where India's approach sits in the global picture.
| Jurisdiction | Transfer Mechanism |
|---|---|
| EU GDPR | Adequacy decisions, Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs) |
| CCPA (California) | No cross-border transfer restriction model — domestic US focus |
| PIPL (China) | Explicit consent + Cyberspace Administration of China (CAC) approval for large-scale transfers |
| India DPDPA | Negative list model — prohibited countries only, Rules pending notification |
| Singapore PDPA | Whitelist of countries deemed to have adequate protection |
Status note: The Rules under DPDPA 2023 are the critical document for cross-border transfer governance in India. Until they are notified, Indian businesses cannot know exactly which cross-border transfers will require additional safeguards or contractual mechanisms. This is the single most operationally significant pending item in India's data protection landscape.
India is the only country where a Consent Manager is a licensed intermediary accountable to a regulator. truConsent is built specifically for DPDPA 2023 — consent lifecycle, data principal rights, breach management, and more.
Also in The History of Indian Privacy series: