78% of DPOs Are Carrying GDPR Residue

Most Indian organisations arrived at data protection compliance through the GDPR door — either because they handle EU personal data, because their international parent mandated GDPR-aligned processes, or because GDPR was simply the only mature template available when they started building governance programmes.

The result is that the vast majority of ROPA templates in circulation within Indian enterprises today are GDPR-derived. They ask the right general questions — what data, whose data, why, how long — but they were built on a legal architecture that is fundamentally different from DPDP Rules 2025.

GDPR assumes a legitimate interest framework. Processing can be justified without consent, through a balancing test that weighs the controller's interests against the data subject's rights. DPDP takes a different approach: consent is the primary basis, it must be specific and informable, and — critically — it must be traceable. You cannot point to a balancing test in a DPDP inquiry. You must point to an artifact.

"GDPR asks 'what's your legal basis?' DPDP asks 'show me the consent artifact linked to this specific processing activity.' These are very different questions."

This architectural difference cascades into your ROPA. Fields that GDPR never required are now mandatory. Fields that GDPR defined one way now carry different obligations. And one entire category — the Consent Artifact ID — has no GDPR equivalent at all.

What DPDP Rules 2025 Actually Require

DPDP Rules 2025, read alongside the DPDP Act 2023, require data fiduciaries to maintain records of processing activities that contain the following fields. The table below maps each field against its typical status in GDPR-derived templates used by Indian organisations.

# Field Status Note
01 Processing Activity Name & Description Usually captured
02 Purpose of Processing Usually captured
03 Category of Personal Data Usually captured
04 Categories of Data Principals Usually captured
05 Legal Basis (Consent / Legitimate Use) MISSINGCHECK Often absent in GDPR templates
06 Consent Artifact ID & Linkage MISSINGCHECK Unique to DPDP — frequently missing
07 Data Retention Period Usually captured
08 Cross-Border Transfer Destinations MISSINGCHECK Under-documented in BFSI
09 Data Processor / Sub-Processor Details MISSINGCHECK Vendor contracts often not linked
10 Security Safeguards Applied MISSINGCHECK Generic — needs control mapping
11 Grievance Officer Contact Reference MISSINGCHECK DPDP-specific — not in GDPR

6 of 11 fields are frequently incomplete in GDPR-derived ROPA templates used by Indian organisations

The Consent Artifact ID Gap Is the Critical One

Under DPDP Rules 2025, every ROPA entry involving personal data must be traceable to the consent artifact issued to the data principal at the time of collection. If you cannot produce that artifact ID for a data protection board inquiry, the processing activity is presumed non-compliant. This field has no GDPR equivalent — GDPR-derived templates do not include it.

How Consent Artifacts Connect to Your ROPA

The requirement is not just to collect consent — it is to maintain a machine-queryable chain from every ROPA entry back to the consent artifact issued at the point of collection. The diagram below shows the architecture that DPDP Rules 2025 require Significant Data Fiduciaries to implement.

Data Principal Provides consent via Notice consent CONSENT MANAGER Issues Artifact ID DPDP §6 Timestamped & Signed ROPA Record Field 06: Artifact ID linked here CSITe Portal DPDP Board Filing Significant Fiduciaries Audit Trail DPBOARD queryable

Under DPDP Rules 2025, every ROPA entry must be traceable to the consent artifact issued at collection — a requirement with no GDPR equivalent.

This traceability requirement has architectural implications. It is not sufficient to note "consent obtained" in your ROPA. The specific artifact ID — issued by the Consent Manager at the moment of collection, scoped to the specific purpose — must be recorded in Field 06 and queryable on demand. For Significant Data Fiduciaries, this chain must extend to the CSITe portal.

Where the Two Regimes Diverge

The table below sets out the specific points of divergence between GDPR Article 30 ROPA requirements and DPDP Rules 2025. These are not theoretical differences — each row represents a field or obligation your template likely handles incorrectly today.

Requirement GDPR (Art. 30) DPDP Rules 2025
Legal basis documentation Legitimate interest allowed Consent OR notified legitimate use only
Consent artifact Not required in ROPA Mandatory — must link Artifact ID
Data processor contracts Documented separately Must be referenced in ROPA entry
Grievance officer DPO details Grievance Officer + contact in each entry
CSITe / regulatory filing Not applicable Significant fiduciaries must file
Cross-border transfer basis Standard Contractual Clauses Adequacy list or DPBOARD approval
Retention basis Purpose / legal requirement Purpose + consent duration alignment
The Legitimate Interest Trap

GDPR's legitimate interest basis (Article 6(1)(f)) is widely used in European ROPA templates. DPDP does not have an equivalent provision — processing requires either consent or falls within the enumerated 'legitimate uses' in Section 7. If your ROPA currently documents 'legitimate interest' as the legal basis for any processing activity, that entry is non-compliant under DPDP.

What Non-Compliance Costs

DPDP Act 2023 Chapter VI sets out penalties by category of data fiduciary and type of violation. Penalties are cumulative — multiple violations across different ROPA entries can attract separate penalty proceedings.

Significant Data Fiduciaries
₹250 Cr
BFSI Data Fiduciaries (General)
₹200 Cr
Healthcare Data Fiduciaries
₹200 Cr
Other Commercial Entities
₹50 Cr
Failure to Notify Breach
₹200 Cr
Non-Implementation of Security
₹250 Cr

Source: DPDP Act 2023 — Chapter VI (Offences and Penalties). Cumulative penalties across violations apply.

₹250Cr
Max penalty — Significant Fiduciaries, Per violation
72hr
Breach notification window, DPDP Rules 2025
May 2027
Expected compliance deadline, Estimated enforcement start
6
ROPA fields missing in most templates, Indian BFSI average

A Structured Path to DPDP-Compliant ROPA

Below is a phased approach that BFSI and enterprise organisations can adapt to move from GDPR-residue ROPA to full DPDP Rules 2025 compliance. The sequence matters: consent audit cannot precede template upgrade, and processor mapping should follow consent remediation.

1
Days 1–14
Inventory & Classify
  • Map all processing activities across departments
  • Identify data categories and data principals
  • Flag cross-border transfers and third-party processors
2
Days 15–35
Template Upgrade
  • Replace GDPR ROPA template with DPDP-compliant version
  • Add Consent Artifact ID column and linkage fields
  • Add Grievance Officer and CSITe reference fields
3
Days 36–60
Consent Audit
  • Audit existing consent artifacts against each ROPA entry
  • Identify gaps where consent records cannot be linked
  • Remediate — re-collect or document legitimate use basis
4
Days 61–80
Processor Mapping
  • Link vendor contracts to each ROPA processing activity
  • Confirm sub-processor chains for cloud and SaaS vendors
  • Document data flow and transfer destinations
5
Days 81–90
Validation & Filing
  • Internal ROPA review (Maker/Checker sign-off)
  • Legal counsel review of consent basis documentation
  • CSITe portal registration if Significant Data Fiduciary
The Maker/Checker Principle Applies to ROPA Too

ROPA entries should not be authored and approved by the same person. Establish a Maker/Checker workflow: the department privacy champion creates and maintains entries; the DPO (or a designated deputy) reviews and approves. This dual-control structure is defensible to regulators and creates an audit trail that demonstrates governance maturity.

"A ROPA that cannot demonstrate consent linkage is not a record of processing — it's a list of processing activities. The Data Protection Board is not interested in lists."

DPDP Assurance Platform — ROPA Register

Built for DPDP Rules 2025

12 assurance modules purpose-built for Indian data protection law. ROPA, DPIA, PIA Wizard, consent management, breach triage, and CSITe filing — all linked.

Explore DPDP Assurance →