GDPR, DPDP and the AI Act: One Compliance Map for Three Jurisdictions
An organisation operating across the EU, India and building with AI is subject to three regulatory regimes simultaneously, each with different definitions and different triggers. Treating them as three separate checklists wastes effort that a single map would save.

An organisation operating across the EU, the UK, India and building AI features is subject to several regulatory regimes simultaneously. Treating each as a separate checklist, worked through independently by different teams, duplicates effort and misses the places where the regimes actually overlap or conflict. This is a companion piece to our guide on data security for enterprise software projects.
The three frameworks, in brief
GDPR (Regulation (EU) 2016/679), in force since 2018, is the most mature of the three and the one the others are frequently compared against. It centres on lawful basis for processing, data subject rights, and accountability obligations for controllers and processors.
India's DPDP Rules, 2025, notified 14 November 2025 with an eighteen-month phased compliance window, are newer and structurally different — consent-centric, with a specific Significant Data Fiduciary category carrying heavier audit and assessment obligations. We cover the timeline in detail in a dedicated piece.
The EU AI Act (Regulation (EU) 2024/1689), reaching general application 2 August 2026, with Annex III high-risk obligations deferred by the AI Omnibus to 2 December 2027, is different in kind from the other two — it regulates AI systems by risk category rather than personal data processing generally, though the two overlap heavily wherever an AI system processes personal data.
Where they overlap
Consent and lawful basis. GDPR's lawful-basis framework and DPDP's consent-centric model both require a defensible basis for processing personal data — but they define "consent" and its alternatives differently enough that a consent flow built purely for GDPR compliance may not satisfy DPDP's specific requirements, and vice versa.
Data subject rights. Both GDPR and DPDP grant individuals rights over their data — access, correction, deletion — though the specific mechanics, response timelines and exceptions differ. A single rights-management system can serve both, but it needs to be built to the stricter of the two requirements wherever they diverge, not to whichever was implemented first.
Transparency and explainability. The AI Act's transparency obligations for certain AI systems overlap with GDPR's existing requirements around automated decision-making (Article 22) and with the general expectation, reflected in the UK's Algorithmic Transparency Recording Standard, that algorithmic decisions affecting people should be explicable. An organisation building one transparency and audit-trail capability, covered in our companion piece, can largely satisfy all three simultaneously if it is designed to the most demanding standard among them.
Cross-border data transfer. GDPR's transfer restrictions, DPDP's (currently less developed) transfer provisions, and the AI Act's requirements around high-risk AI system documentation all touch on where data physically resides and who can access it — a single, well-documented data residency and access-control architecture serves all three.
Where they genuinely diverge
Penalty structure. DPDP's ₹250 crore maximum penalty comes from the Act (not the Rules) and applies specifically to failure to maintain reasonable security safeguards. GDPR's penalty structure is percentage-of-revenue based, up to 4% of global annual turnover for the most serious violations. These are not directly comparable, and a compliance programme sized for one will not automatically be sized correctly for the other.
Regulatory maturity and enforcement precedent. GDPR has years of enforcement decisions, guidance and case law informing how it is actually applied. DPDP's Rules were notified in November 2025 — enforcement precedent does not yet exist at meaningful scale, which means compliance decisions currently rest more on the text of the Rules and less on established interpretation.
What triggers heightened obligations. GDPR's heightened obligations (like DPO requirements) trigger on factors like processing scale and special category data. DPDP's Significant Data Fiduciary designation is a distinct trigger with its own criteria. The AI Act's high-risk classification is based on the AI system's application domain (employment, law enforcement, essential services, and similar), not on data volume or type at all. An organisation needs to check all three triggers independently — meeting one framework's threshold for extra scrutiny says nothing about whether you meet another's.
A practical approach
Build one data map, not three. Where does personal data live, how does it flow, who can access it — this single exercise informs compliance work under all three frameworks and should not be repeated separately for each.
Design to the most demanding requirement wherever the frameworks overlap. A consent mechanism, a rights-request process, or an audit trail built to satisfy the strictest of the three applicable frameworks will generally satisfy the other two as well, though always verify rather than assume.
Track each framework's distinct triggers and timelines separately. The overlap in mechanism does not mean the obligations activate at the same time or under the same conditions — DPDP's phased window, the AI Act's staggered application dates, and GDPR's already-active requirements are each on their own clock.
Assign clear ownership across legal, engineering and compliance, because a map spanning three regulatory regimes and an AI-specific risk framework is not a task any single team can own end to end.
What we do
We build the underlying data architecture — mapping, consent, audit trails — once, to the most demanding applicable standard, and layer jurisdiction-specific requirements on top rather than building parallel, duplicative systems for each regime. If you are trying to make sense of overlapping compliance obligations across jurisdictions, that is a conversation we are glad to have.
Kaizen Spark Tech designs and delivers software, AI, automation and digital infrastructure for businesses and institutions. Regulatory information in this article is accurate as of September 2026 and reviewed quarterly, because DPDP implementation guidance and AI Act application dates are both still moving.
