| Parameter |
EU |
India |
| Consent |
Users must have informed consent about the way their data is processed so that they can opt in or out. |
Processing of data should be done in a fair and transparent manner, while also ensuring privacy |
| Breach |
Supervisory authority must be notified of a breach within 72 hours of the leak so that users can take steps to protect information |
Data Protection Authority must be informed within 72 hours; DPA will decide whether users need to be informed and steps to be taken |
| Transition period |
Two-year transition period for provisions of GDPR to be put in place |
24 months overall; 9 months for registration of data fiduciaries, 6 months for DPA to start |
| Data fiduciary |
Data fiduciary is any natural or legal person, public authority, agency or body that determines purpose and means of data processing |
Similar suggestions; additionally, NGOs which also process data to be included as fiduciaries |