Webinar
10 Years of GDPR: Signals for India's DPDP Era

About This Webinar

Nearly a decade after the General Data Protection Regulation (GDPR) reshaped privacy regulation in Europe, organisations have evolved from basic compliance to building mature, operational privacy programmes shaped by enforcement and real-world challenges.

As India moves into the implementation phase of the Digital Personal Data Protection Act (DPDP Act), this webinar explores the key lessons from GDPR’s first decade and what Indian organisations should prioritise now to build scalable, future-ready privacy programmes.

What This Webinar Covers

  • Key lessons from ten years of GDPR implementation and enforcement
  • How privacy programmes evolved from legal compliance to operational governance
  • Similarities and important differences between GDPR and DPDP
  • Operational challenges organisations often underestimate when implementing privacy laws
  • The role of consent management, data discovery, and governance infrastructure
  • Practical steps organisations can take today to accelerate DPDP readiness

Why Watch This Now

  1. Learn how privacy regulations play out over timeGDPR offers a rare long-term view into how privacy laws reshape internal processes, accountability structures, and technology investments inside organisations.
  2. Avoid early compliance pitfallsMany companies underestimate the operational complexity of privacy programmes. Learn the common pitfalls organisations encountered under GDPR and how to avoid them in the DPDP era.
  3. Make privacy an organisational capabilityPrivacy is quickly becoming an organisational capability, not just a legal requirement. This session explores how leaders can start building the systems, governance, and culture needed for the long run.
Speakers
Malcolm Gomes

Malcolm Gomes

COO

IDfy

Ben Rapp

Ben Rapp

Group CEO

Securys

Akanksha Garg

Akanksha Garg

Data Protection Officer & Head-Digital Products PMO

HDFC Securities

Christopher Parkinson

Christopher Parkinson

Head of Data Protection

UK-based Leading Fintech

FAQs

No. While both regulations focus on data privacy and protection, DPDP has stricter consent requirements and different operational rules. So just being GDPR-compliant alone won’t cover you.

DPDP requires explicit, purpose-specific consent tied to actual data use, unlike GDPR, where legitimate interest can sometimes suffice.

No. GDPR allows processing under legitimate interest; DPDP distinguishes between legitimate use and consented purpose, making consent often mandatory.

Not entirely. DPDP has separate cross-border data transfer norms that must be followed independently.

Relying on GDPR assumptions, using vague consent forms, ignoring purpose-specific processing, and failing to maintain evidence of consent are major risks under DPDP.