78% of DPOs Are Carrying GDPR Residue
Most Indian organisations arrived at data protection compliance through the GDPR door — either because they handle EU personal data, because their international parent mandated GDPR-aligned processes, or because GDPR was simply the only mature template available when they started building governance programmes.
The result is that the vast majority of ROPA templates in circulation within Indian enterprises today are GDPR-derived. They ask the right general questions — what data, whose data, why, how long — but they were built on a legal architecture that is fundamentally different from DPDP Rules 2025.
GDPR assumes a legitimate interest framework. Processing can be justified without consent, through a balancing test that weighs the controller's interests against the data subject's rights. DPDP takes a different approach: consent is the primary basis, it must be specific and informable, and — critically — it must be traceable. You cannot point to a balancing test in a DPDP inquiry. You must point to an artifact.
"GDPR asks 'what's your legal basis?' DPDP asks 'show me the consent artifact linked to this specific processing activity.' These are very different questions."
This architectural difference cascades into your ROPA. Fields that GDPR never required are now mandatory. Fields that GDPR defined one way now carry different obligations. And one entire category — the Consent Artifact ID — has no GDPR equivalent at all.
What DPDP Rules 2025 Actually Require
DPDP Rules 2025, read alongside the DPDP Act 2023, require data fiduciaries to maintain records of processing activities that contain the following fields. The table below maps each field against its typical status in GDPR-derived templates used by Indian organisations.
| # | Field | Status | Note |
|---|---|---|---|
| 01 | Processing Activity Name & Description | Usually captured | — |
| 02 | Purpose of Processing | Usually captured | — |
| 03 | Category of Personal Data | Usually captured | — |
| 04 | Categories of Data Principals | Usually captured | — |
| 05 | Legal Basis (Consent / Legitimate Use) | MISSINGCHECK | Often absent in GDPR templates |
| 06 | Consent Artifact ID & Linkage | MISSINGCHECK | Unique to DPDP — frequently missing |
| 07 | Data Retention Period | Usually captured | — |
| 08 | Cross-Border Transfer Destinations | MISSINGCHECK | Under-documented in BFSI |
| 09 | Data Processor / Sub-Processor Details | MISSINGCHECK | Vendor contracts often not linked |
| 10 | Security Safeguards Applied | MISSINGCHECK | Generic — needs control mapping |
| 11 | Grievance Officer Contact Reference | MISSINGCHECK | DPDP-specific — not in GDPR |
6 of 11 fields are frequently incomplete in GDPR-derived ROPA templates used by Indian organisations
Under DPDP Rules 2025, every ROPA entry involving personal data must be traceable to the consent artifact issued to the data principal at the time of collection. If you cannot produce that artifact ID for a data protection board inquiry, the processing activity is presumed non-compliant. This field has no GDPR equivalent — GDPR-derived templates do not include it.
How Consent Artifacts Connect to Your ROPA
The requirement is not just to collect consent — it is to maintain a machine-queryable chain from every ROPA entry back to the consent artifact issued at the point of collection. The diagram below shows the architecture that DPDP Rules 2025 require Significant Data Fiduciaries to implement.
Under DPDP Rules 2025, every ROPA entry must be traceable to the consent artifact issued at collection — a requirement with no GDPR equivalent.
This traceability requirement has architectural implications. It is not sufficient to note "consent obtained" in your ROPA. The specific artifact ID — issued by the Consent Manager at the moment of collection, scoped to the specific purpose — must be recorded in Field 06 and queryable on demand. For Significant Data Fiduciaries, this chain must extend to the CSITe portal.
Where the Two Regimes Diverge
The table below sets out the specific points of divergence between GDPR Article 30 ROPA requirements and DPDP Rules 2025. These are not theoretical differences — each row represents a field or obligation your template likely handles incorrectly today.
| Requirement | GDPR (Art. 30) | DPDP Rules 2025 |
|---|---|---|
| Legal basis documentation | Legitimate interest allowed | Consent OR notified legitimate use only |
| Consent artifact | Not required in ROPA | Mandatory — must link Artifact ID |
| Data processor contracts | Documented separately | Must be referenced in ROPA entry |
| Grievance officer | DPO details | Grievance Officer + contact in each entry |
| CSITe / regulatory filing | Not applicable | Significant fiduciaries must file |
| Cross-border transfer basis | Standard Contractual Clauses | Adequacy list or DPBOARD approval |
| Retention basis | Purpose / legal requirement | Purpose + consent duration alignment |
GDPR's legitimate interest basis (Article 6(1)(f)) is widely used in European ROPA templates. DPDP does not have an equivalent provision — processing requires either consent or falls within the enumerated 'legitimate uses' in Section 7. If your ROPA currently documents 'legitimate interest' as the legal basis for any processing activity, that entry is non-compliant under DPDP.
What Non-Compliance Costs
DPDP Act 2023 Chapter VI sets out penalties by category of data fiduciary and type of violation. Penalties are cumulative — multiple violations across different ROPA entries can attract separate penalty proceedings.
Source: DPDP Act 2023 — Chapter VI (Offences and Penalties). Cumulative penalties across violations apply.
A Structured Path to DPDP-Compliant ROPA
Below is a phased approach that BFSI and enterprise organisations can adapt to move from GDPR-residue ROPA to full DPDP Rules 2025 compliance. The sequence matters: consent audit cannot precede template upgrade, and processor mapping should follow consent remediation.
- Map all processing activities across departments
- Identify data categories and data principals
- Flag cross-border transfers and third-party processors
- Replace GDPR ROPA template with DPDP-compliant version
- Add Consent Artifact ID column and linkage fields
- Add Grievance Officer and CSITe reference fields
- Audit existing consent artifacts against each ROPA entry
- Identify gaps where consent records cannot be linked
- Remediate — re-collect or document legitimate use basis
- Link vendor contracts to each ROPA processing activity
- Confirm sub-processor chains for cloud and SaaS vendors
- Document data flow and transfer destinations
- Internal ROPA review (Maker/Checker sign-off)
- Legal counsel review of consent basis documentation
- CSITe portal registration if Significant Data Fiduciary
ROPA entries should not be authored and approved by the same person. Establish a Maker/Checker workflow: the department privacy champion creates and maintains entries; the DPO (or a designated deputy) reviews and approves. This dual-control structure is defensible to regulators and creates an audit trail that demonstrates governance maturity.
"A ROPA that cannot demonstrate consent linkage is not a record of processing — it's a list of processing activities. The Data Protection Board is not interested in lists."
Built for DPDP Rules 2025
12 assurance modules purpose-built for Indian data protection law. ROPA, DPIA, PIA Wizard, consent management, breach triage, and CSITe filing — all linked.
Explore DPDP Assurance →