AI law comparison · Data verified 2026-08-22
GDPR Article 22 vs India DPDP Act
GDPR Article 22 and India DPDP Act are two of the 169 AI and data regulations Aegis Firma tracks. They have different scopes, effective dates, and penalties — and many businesses fall under both. Here is the side-by-side, drawn directly from the regulatory registry.
Find which laws apply to my businessSide by side
Summary of publicly available regulatory text. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
The key difference
GDPR Article 22 takes effect first, so it is usually the more urgent of the two. GDPR Article 22 tracks 5 compliance requirements and India DPDP Act tracks 5. They are not interchangeable — meeting one does not discharge the other. The practical question is not which law is “stricter,” but which of them — or both — actually applies to your business.
EU GDPR Article 22 — Automated Decision-Making & AI Profiling
GDPR Article 22 (in force since May 25, 2018) gives EU and EEA residents the right not to be subject to decisions based solely on automated processing — including AI profiling — that produces legal or similarly significant effects (credit scores, hiring, insurance pricing, content moderation). Organizations must inform individuals of automated processing, provide meaningful explanations of logic, implement human revi…
Full GDPR Article 22 requirementsIndia Digital Personal Data Protection Act 2023 (DPDPA)
India's Digital Personal Data Protection Act 2023 (DPDPA) is the most significant Indian data law since IT Act 2000. The implementing DPDP Rules were FINALIZED 2025-11-13 (CYCLE 4: previously described as still in draft) on a phased timeline — Data Protection Board of India (DPBI) establishment rules took force immediately, consent-manager rules apply from 2026-11-13, and the remaining Rules take full effect 2027-05-…
Full India DPDP Act requirementsCommon questions
Could both GDPR Article 22 and India DPDP Act apply to my business?
Yes. GDPR Article 22 and India DPDP Act are separate regulations with separate scopes — a business can fall under both at once. GDPR Article 22 covers GDPR Art. India DPDP Act covers The DPDPA applies to the processing of digital personal data of Data Principals (individuals) who are in India, regardless of whether processing occurs within o… If your operations meet both scopes, you must comply with both. Aegis Firma's free scan checks all 169 tracked regulations against your business profile so you do not have to read each law to find out.
Which has the higher maximum penalty — GDPR Article 22 or India DPDP Act?
GDPR Article 22: €20,000,000 or 4% of global annual turnover — whichever is higher (GDPR Art. 83(5)) India DPDP Act: ₹250 Crore (~$30M USD) maximum — but the Schedule sets DIFFERENT caps per violation type, which can stack: ₹250 Cr for failure to implement reasonable security safeguards (Sec. 8(5)); ₹200 Cr for failure to notify a breach to DPBI/Data Principals (Sec. 8(6)); ₹200 Cr for children's-data non-compliance (Sec. 9); ₹150 Cr for SDF-obligation failures (Sec. 10). The Data Protection Board must weigh mitigating/aggravating factors — penalties are not automatically set at the maximum. The previously stated "up to ₹500 Crore for repeat violations" figure could not be corroborated this cycle and has been removed. Penalty structures differ by regulator and violation type — read each law's full page for the cure periods and per-violation detail.
When does each law take effect?
GDPR Article 22 — effective 2018-05-25. India DPDP Act — effective 2023-08-11, enforcement from 2025-01-01. Dates last verified against official sources on 2026-08-22 and 2026-08-22 respectively.
Related comparisons
Stop guessing which laws apply
Answer a short questionnaire about your business and Aegis Firma tells you exactly which of 169 regulations apply — and what each one requires you to do.
Start free compliance scan