Explainer 18 min read 9 September 2026

Data Privacy and Compliance Laws Compared: DPDP, GDPR, HIPAA, PCI DSS, ISO and the India Stack

Which frameworks actually apply to your business? DPDP, GDPR, HIPAA, PCI DSS, ISO 27001, SOC 2 and India’s CERT-In, RBI and SEBI rules, compared.

Most businesses meet this question in the same messy way: a customer’s procurement form asks for a SOC 2 report, a payment provider mentions PCI DSS, a European client sends a GDPR questionnaire, and somewhere underneath it all sits India’s DPDP Act with a 2027 deadline. It is genuinely hard to tell which of these you are legally required to follow, which are contractual, and which are simply things good vendors buy to win deals. This guide sorts them out: what each one is, who it actually binds, what it costs you in practice, and how they overlap.

All commencement dates, framework versions and compliance deadlines on this page are stated as of September 2026. Several of these frameworks are amended frequently; verify against the official texts linked at the bottom before relying on any date.

The Short Version

If you read nothing else, read this.

Think of it like the paperwork for a shop. Some of it is the law — the licence you must have, whether you like it or not. Some of it is a condition of doing business with someone — the mall won't give you a unit unless you follow their rules. And some of it is a certificate you put on the wall because customers trust it. All three are worth having. Only the first one gets you prosecuted.

For a business in India, in one line each
  • DPDP Act — the law on customer data. Applies to you. Obligations start 13 May 2027.
  • IT Act / SPDI Rules — the older law on sensitive data. Applies to you today, until May 2027.
  • CERT-In rules — if you are hacked, tell the government within six hours. Applies today.
  • PCI DSS — only if card numbers pass through your own systems.
  • GDPR — only if you have customers in Europe.
  • HIPAA — only if you handle American patients' records for an American client.
  • ISO 27001 / SOC 2 — nobody makes you. You buy them because customers ask.

Not sure which of those apply to you? The free DPDP checker asks a few questions about your business and tells you in about two minutes — no signup, no sales call.

Most small Indian businesses need the first three and nothing else. The rest arrive only when a particular customer, a card network, or a regulator brings them to your door. And here is the part that surprises people most: none of the certificates on that list make you DPDP compliant. You can hold every one of them and still be breaking Indian law, because not one of those audits ever looks at your signup form.

First, the Distinction That Explains Everything

Before comparing anything, separate the frameworks into three kinds. Almost every confusion in this area comes from treating them as interchangeable when they are not.

The practical consequence: a certification can never discharge a legal obligation. An ISO 27001 certificate is a real asset in a procurement conversation and worth nothing as a defence before the Data Protection Board, because the Board will ask whether your consent notice met Section 5, and no ISO auditor ever looked at it.

What this looks like in practice
  • A Pune software company spends eight months and a large budget getting ISO 27001 certified because three enterprise customers asked for it. The certificate wins the deals. It does not change the fact that their signup form still collects phone numbers with a pre-ticked marketing box — which is a consent problem under Section 6, and the ISO auditor was never asked to look at it.
  • A Coimbatore textile exporter is told by a European buyer to "be GDPR compliant." That instruction comes from a contract, not from Indian law. It is still binding — because losing the buyer is the penalty.

The Master Comparison

Every framework in this guide, side by side. Detail on each follows below.

FrameworkKindOriginWho it bindsCoversEnforcement / ceiling
DPDP Act 2023LawIndiaAnyone processing digital personal data of people in India, wherever locatedPersonal data — consent, notice, rights, breachData Protection Board; up to ₹250 crore per violation category
IT Act 2000 + SPDI Rules 2011LawIndiaBody corporates in India handling sensitive personal dataSensitive personal data — security practicesCompensation under Section 43A; omitted 13 May 2027
CERT-In Directions 2022LawIndiaAll service providers, intermediaries, data centres, body corporatesCyber incident reporting and loggingSection 70B(7) IT Act — up to 1 year imprisonment or fine
GDPRLawEU / EEAAnyone offering goods or services to, or monitoring, people in the EEAPersonal data — six lawful bases, rights, transfersNational DPAs; up to €20m or 4% of global turnover
HIPAALaw (+ contract)United StatesUS covered entities and their business associatesProtected health informationHHS Office for Civil Rights; tiered civil and criminal penalties
CCPA / CPRALawCalifornia, USABusinesses meeting revenue or data-volume thresholds serving CaliforniansConsumer personal information, sale and sharingCalifornia Privacy Protection Agency; per-violation penalties
PCI DSS 4.0.1ContractCard networksAnyone storing, processing or transmitting cardholder dataPayment card data onlyAcquiring bank; fines, higher fees, loss of card acceptance
ISO/IEC 27001CertificationInternationalVoluntaryInformation security management systemAccredited certification body; loss of certificate
ISO/IEC 27701CertificationInternationalVoluntaryPrivacy information management systemAccredited certification body; loss of certificate
SOC 2AttestationUnited StatesVoluntaryControls against five trust services criteriaCPA firm opinion; a qualified report
RBI directionsLawIndiaBanks, NBFCs, payment system operators, lending appsPayment data localisation, IT governance, outsourcingRBI; monetary penalties, business restrictions
SEBI CSCRFLawIndiaSEBI-regulated entities — brokers, AMCs, RTAs, exchangesCybersecurity and cyber resilienceSEBI; penalties and regulatory action

The India Stack: What Is Actually Law Here

Start here, because this is the part that binds an Indian business whether or not it ever sells abroad.

The DPDP Act 2023 and the DPDP Rules 2025

India’s general personal data law. It applies to processing of digital personal data within India, and, under Section 3(b), to processing outside India connected with offering goods or services to people in India. There is no revenue floor, no user-count threshold, and no requirement that anyone pay you: a free signup form counts.

The obligations that matter for most businesses are notice before collection, consent that is free, specific, informed and unconditional, the ability to honour access and erasure requests, reasonable security safeguards, and breach intimation. The DPDP Rules 2025 (G.S.R. 846(E), notified 13 November 2025) supply the procedure, and the core obligations commence on 13 May 2027. Penalties run to ₹250 crore for the most serious category; see the penalties guide for how the categories divide.

If you are unsure whether it reaches you at all, the short answer is that it almost certainly does; our guide on whether DPDP applies to your business works through the edge cases.

Who this catches
  • A sweet shop in Madurai that takes a name and phone number for Diwali order reminders. That is digital personal data. The Act applies.
  • A gym in Noida holding member names, photographs and payment history on a laptop.
  • A two-person Instagram clothing business collecting addresses over DMs. There is no size below which the Act stops applying — no revenue floor, no customer-count floor.

If that describes you, the 14-step DPDP compliance checklist is the practical version of this — what to do, in order, with a free one-page PDF you can work through.

The IT Act 2000 and the SPDI Rules 2011

This is the framework that governs Indian businesses today, and it is the one most often assumed to be already dead. It is not. Section 43A of the Information Technology Act 2000, together with the Reasonable Security Practices and Procedures and Sensitive Personal Data or Information Rules 2011, requires a body corporate handling sensitive personal data (passwords, financial information, health data, biometrics, sexual orientation) to maintain reasonable security practices, and makes it liable to pay compensation for negligence that causes wrongful loss.

Section 44(2) of the DPDP Act omits Section 43A and the SPDI Rules, and that omission takes effect on 13 May 2027, the same day the core DPDP obligations commence. Until then both frameworks coexist, and the SPDI Rules remain enforceable. One practical difference worth noting: the SPDI Rules do define a category of “sensitive” personal data with stricter handling. The DPDP Act does not. It treats all personal data under one standard, with the government empowered to notify stricter treatment later.

Why this matters right now
  • A diagnostic lab in Hyderabad storing test reports is holding health data — sensitive under the 2011 Rules. If those reports leak because nobody patched a server, the lab can be made to compensate the affected patients today. It does not have to wait for 2027.
  • The common mistake is reading "DPDP starts in 2027" as "nothing applies until 2027." The older law has been in force since 2011 and stays in force until the day DPDP takes over.

The CERT-In Directions, April 2022

Widely under-observed, and the shortest deadline in Indian compliance. Issued on 28 April 2022 under Section 70B(6) of the IT Act, these directions require every service provider, intermediary, data centre and body corporate to:

Note how this interacts with DPDP. The statutory duty to report a personal data breach sits in Section 8(6) of the Act; Rule 7 of the DPDP Rules 2025 supplies the procedure — tell affected individuals without delay, give the Board an initial intimation without delay, then detailed particulars within 72 hours. A breach at an Indian company can therefore trigger both a six-hour CERT-In report and, from May 2027, the Section 8(6) and Rule 7 obligations. They are separate filings to separate authorities on separate clocks. Our breach notification guide covers the DPDP side in detail.

Six hours is shorter than it sounds
  • A Chennai e-commerce firm discovers at 11pm on Saturday that its customer database was copied. The CERT-In clock starts at 11pm — not Monday morning when the founder reads the email. Six hours later it is 5am Sunday, and the report is already late.
  • This is why the useful preparation is not a policy document. It is knowing, before anything happens, who writes the report and what their login is. Most businesses fail this one on logistics, not on intent.

Sector regulators: RBI, SEBI, IRDAI

If you are regulated, your regulator’s rules sit on top of everything above and are usually stricter.

RBI. The April 2018 circular on Storage of Payment System Data requires payment system operators to store end-to-end transaction data only in India. This is unaffected by the DPDP Act’s comparatively permissive approach to cross-border transfers, because Section 16(2) expressly preserves stricter sectoral requirements. RBI also runs separate directions on IT governance, outsourcing of IT services, and digital lending.

SEBI. The Cybersecurity and Cyber Resilience Framework (CSCRF) consolidated SEBI’s earlier cyber circulars into one graded framework for regulated entities, with compliance dates through 2025 that were extended more than once by category of entity. It brings structured audit reporting and mandatory security operations arrangements.

IRDAI. Insurers and intermediaries follow IRDAI’s information and cyber security guidelines, including audit and reporting obligations.

The stricter rule wins
  • A payments startup reads that DPDP allows data to leave India and concludes it can move transaction records to a cheaper server abroad. It cannot. RBI's 2018 circular requires end-to-end payment data to stay in India, and Section 16(2) of the DPDP Act expressly leaves that requirement standing.
  • The general rule: where two rulebooks cover the same data, you follow the tighter one. A permissive national law never overrides a strict sectoral one.

The Global Privacy Laws

GDPR — the European baseline

The most influential privacy law in the world, and the one the DPDP Act is most often measured against. It applies if you are established in the EEA, or if you offer goods or services to people there, or if you monitor their behaviour.

Two differences matter most to an Indian business. First, lawful basis: the GDPR offers six, and legitimate interests carries a great deal of ordinary marketing and analytics. The DPDP Act offers consent plus a narrow list of legitimate uses in Section 7, with no general legitimate-interests basis, so a European programme does not port over unchanged. Second, penalty structure: GDPR fines scale to 4% of global turnover, while DPDP penalties are fixed rupee ceilings that fall much harder on a small company in relative terms. The full DPDP vs GDPR comparison works through all eight material differences.

The trap for Indian exporters
  • A Jaipur handicrafts exporter sells to customers in Germany through its own website. GDPR applies — not because the company is European, but because the customers are.
  • A Bengaluru SaaS company copies its European privacy policy into its Indian product and assumes it is covered. It is not. The European version leans on "legitimate interests" for marketing emails; that basis does not exist under the DPDP Act, so those emails need consent in India.

HIPAA — United States health data

HIPAA is narrow and frequently misunderstood in India. It is US federal law covering protected health information held by covered entities (US health plans, health care clearinghouses, and providers who transmit health information electronically for billing) and by the business associates who process that information for them.

An Indian hospital treating Indian patients is not a HIPAA covered entity. What brings HIPAA to India is service work for US healthcare: medical transcription, revenue-cycle management, coding, teleradiology, clinical SaaS. In those cases the obligation reaches you through a Business Associate Agreement, which is a contract. Since the HITECH Act, business associates also face direct statutory liability. Its Security Rule requires administrative, physical and technical safeguards; its Breach Notification Rule sets a 60-day outer limit for notifying affected individuals, which is a far longer clock than either CERT-In or DPDP.

Indian healthcare providers are instead governed by the DPDP Act, the IT Act and SPDI Rules, and clinical record-keeping requirements under National Medical Commission regulations. Our healthcare DPDP guide covers what an Indian clinic or hospital actually needs.

Two clinics, two different answers
  • A children's clinic in Kochi treating local families: HIPAA does not apply. Indian law does.
  • A Kochi company doing medical transcription for a hospital in Texas: HIPAA does apply, through the Business Associate Agreement it signed. The work is identical in character; the customer is what changes the answer.
  • Vendors selling "HIPAA compliance" to Indian hospitals with no American clients are selling something that hospital does not need.

CCPA and CPRA — California

California’s consumer privacy law, amended by the CPRA, applies to for-profit businesses that serve California residents and cross one of its thresholds: broadly, large annual revenue, large-scale handling of consumer personal information, or deriving substantial revenue from selling or sharing it. Its distinctive feature is the right to opt out of the sale or sharing of personal information, which is why “Do Not Sell or Share My Personal Information” links appear on US sites. It is an opt-out regime by default, where the DPDP Act and the GDPR are opt-in. Several other US states now run comparable laws.

Opt-in versus opt-out, in plain terms
  • Under Indian and European law, silence means no. You must ask first.
  • Under California's law, the default runs the other way for sale and sharing: you may proceed until the customer tells you to stop, which is why American websites carry a "Do Not Sell" link and Indian ones do not.
  • Practical effect for an Indian company: the thresholds are high enough that most SMBs never reach them. Do not build for CCPA until a Californian customer base actually exists.

COPPA — American children's data

Worth knowing if you build anything used by children. COPPA is US federal law regulating online services directed at children under 13, or general services that knowingly collect data from them. It requires verifiable parental consent before collection, enforced by the Federal Trade Commission.

Note the mismatch with India: the DPDP Act treats everyone under 18 as a child, and prohibits behavioural tracking and targeted advertising at them outright. So an Indian ed-tech company serving both markets is running two different age lines at once — 13 for its American users, 18 for its Indian ones — and the Indian rule is the stricter of the two.

Where this bites
  • A Hyderabad ed-tech app with students in both India and the United States cannot pick one age threshold. It needs parental consent for a 15-year-old in Chennai (Indian law) but not for the same-aged student in Chicago (American law) — while a 12-year-old triggers both.
  • A coaching centre in Kota with only Indian students ignores COPPA entirely and applies the under-18 rule.

The Security Frameworks

PCI DSS — payment cards

PCI DSS is not a law anywhere. It is the Payment Card Industry Data Security Standard, maintained by the PCI Security Standards Council on behalf of the card networks, and it reaches you through your acquiring bank or payment provider. If you store, process or transmit cardholder data, it applies in India exactly as it does in the United States.

The current version is 4.0.1, published June 2024; the future-dated requirements introduced in v4.0 became mandatory on 31 March 2025. Its twelve requirement areas are concrete and technical: network segmentation, no vendor-default passwords, encryption of cardholder data in transit and at rest, vulnerability management, access control, logging, testing, and a security policy.

Scope is the whole game here. If your checkout hands the customer to a gateway’s hosted page or iframe and card numbers never touch your systems, your obligations shrink to the lightest self-assessment questionnaire, mostly confirming that your provider is compliant and that card numbers never leak into your logs, emails or support tickets. If your own page collects the card number first, you are in scope properly. Note also that PCI DSS says nothing about consent, notice or erasure. It secures card data; it does not make you DPDP compliant.

The question that decides your scope
  • Does a card number ever touch something you own — a server, a spreadsheet, a WhatsApp message, a support ticket?
  • A Delhi boutique whose website sends customers to Razorpay's own payment page: card numbers never reach them, so their obligations are minimal.
  • A travel agency that takes card details over the phone and writes them on a booking form: fully in scope, and almost certainly unaware of it. A card number in a WhatsApp thread or a paper register is the most common breach of this standard among small Indian businesses.

ISO/IEC 27001 and ISO/IEC 27701

ISO/IEC 27001 is the international standard for an information security management system. You are certified by an accredited body after an audit, in a three-year cycle with annual surveillance. It is a management-system standard rather than a control checklist: it asks whether you have identified your risks, chosen controls deliberately, assigned ownership, and review the whole thing on a schedule.

ISO/IEC 27701 is the privacy counterpart. This one has changed materially and it is worth being current: the 2019 edition was an extension you could only apply on top of ISO 27001, and it has been withdrawn. The 2025 edition is a standalone standard. You can now certify a privacy information management system without holding ISO 27001 first, and it adds modern guidance on cloud, AI-related processing, biometrics and health data.

For an Indian business preparing for DPDP, ISO 27701 is the closest available certification to the Act’s subject matter, and its control set maps well onto DPDP’s security and governance obligations. It still does not certify DPDP compliance, and nothing does, because the Act creates no certification scheme.

Be careful what you are sold
  • No such thing as a "DPDP certificate" exists. The Act creates no certification scheme and appoints no certifying bodies. Anyone selling you one is selling their own opinion.
  • What ISO 27001 genuinely buys you is a shorter enterprise sales cycle and a documented answer when a regulator asks whether you took reasonable security measures. Those are real benefits. Neither is the same as compliance.

SOC 2

Not a certification and not a law: a SOC 2 report is an attestation written by a CPA firm under AICPA standards, describing your controls against the trust services criteria: security, and optionally availability, processing integrity, confidentiality and privacy. A Type I report tests design at a point in time; a Type II tests operating effectiveness across a period, typically three to twelve months, and is the one enterprise buyers actually want.

SOC 2 is prevalent in Indian SaaS because US buyers ask for it. It is the fastest way to satisfy enterprise procurement and, unlike ISO, produces a detailed report rather than a certificate, which is why it is shared under NDA rather than displayed on a website.

When to spend the money
  • A Bengaluru SaaS company loses two deals because procurement asked for a SOC 2 report and it had none. That is the signal to start — a real cost you can point at.
  • A company with no enterprise customers buying SOC 2 "to look serious" has bought an expensive document nobody has asked to read. It is a sales tool. Buy it when sales need it.

Where They Overlap, and Where They Do Not

The good news for anyone facing several of these at once: the operational core is shared. Build it once and it serves nearly everything.

ControlDPDPGDPRHIPAAPCI DSSISO 27001SOC 2
Data inventory / mappingNeeded in practiceRequired (Art. 30)RequiredRequired (scoping)RequiredRequired
Access controlRule 6Art. 32Security RuleReq. 7–8Annex ASecurity criteria
EncryptionRule 6Art. 32AddressableReq. 3–4Annex ASecurity criteria
Logging and monitoringRule 6Art. 32RequiredReq. 10Annex ASecurity criteria
Vendor / processor contractsSection 8(2)Art. 28BAAReq. 12Annex ARequired
Breach notificationRule 772 hours60 daysTo acquirerProcess onlyProcess only
Consent before collectionCoreOne of six basesNot the modelNoNoNo
Notice in local languagesSection 5(3)Plain languageNotice of practicesNoNoNo
Erasure on withdrawalSection 12(3)Art. 17LimitedNoNoNo

That middle row — notice in the individual's chosen language — is the one businesses most often discover late. Section 5(3) gives every customer the option of English or any of the 22 Eighth Schedule languages, and no ISO or SOC 2 audit will ever mention it. Our free consent notice generator writes one for your business in 23 languages; it runs entirely in your browser, so nothing you type is sent to us.

Read the bottom three rows carefully, because they are the reason a security certificate does not carry you. Consent before collection, notice in the individual’s chosen language, and erasure on withdrawal are the heart of the DPDP Act, and no security framework on this page asks for any of them. A company with ISO 27001, SOC 2 Type II and PCI DSS in hand can still be squarely non-compliant with the DPDP Act on 13 May 2027, because none of those audits ever looked at its signup form.

The breach row deserves the same attention, because the clocks do not agree with each other. One incident can start several at once, and they run at different speeds.

One breach, several clocks
  • An Indian company with American healthcare clients discovers a breach on Friday evening. CERT-In wants a report in six hours. From May 2027, the Board wants an initial intimation without delay and full particulars within 72 hours. HIPAA gives its 60-day outer limit for notifying affected individuals.
  • The dangerous instinct is to wait for the investigation to finish and then notify everyone at once. That comfortably meets the 60-day rule and badly misses the six-hour one.
  • The fix is to separate the two jobs: report early on what you know, keep investigating afterwards. You are not expected to have all the answers within six hours — you are expected to have told them.

So Which Ones Apply to You?

Work down this list. Each answer is independent of the others.

If this is true of youYou need
You collect any personal data from people in IndiaDPDP Act; IT Act and SPDI Rules until 13 May 2027
You run any ICT system in IndiaCERT-In directions — 6-hour reporting, 180-day logs
Your own systems touch card numbersPCI DSS
You have customers in the EU or EEAGDPR
You process US patient data for a US healthcare clientHIPAA, through a Business Associate Agreement
You serve California residents above the thresholdsCCPA / CPRA
You are an RBI, SEBI or IRDAI regulated entityYour regulator’s framework, on top of everything else
Enterprise buyers keep asking for proofSOC 2 Type II, or ISO 27001 — optional, commercially useful
You want a privacy-specific certificateISO/IEC 27701:2025 — optional

For most Indian SMBs the honest answer is short: the DPDP Act, the SPDI Rules until 2027, and the CERT-In directions. Everything else arrives only if a customer, a card network or a regulator brings it.

If you sell software across borders and the question is the other way round — which of the world's privacy regimes your product triggers — our companion guide comparing global data privacy laws: GDPR, DPDP, CCPA, LGPD, PIPL and the rest puts twelve of them side by side, with the consent defaults, breach clocks and transfer rules that differ between them.

A Sensible Order of Work

If several of these apply, do not run them as separate projects. They share too much.

  1. Know what you hold. One inventory of personal data: what you collect, why, where it lives, who you share it with, how long you keep it. Every framework here starts from this, and doing it once serves all of them.
  2. Satisfy Indian law first. It is the one you cannot decline. Notice and consent for DPDP — the consent notice generator gives you the notice itself — security practices for the SPDI Rules, and a CERT-In reporting process with someone named to run it.
  3. Add contractual obligations as they arrive. PCI DSS when card data enters your systems; a BAA when a US healthcare client signs; GDPR work when European customers do.
  4. Buy certification when it is being asked for. SOC 2 or ISO 27001 when procurement forms start blocking deals. Not before, and never as a substitute for step two.
What this looks like for a real business
  • A 20-person Shopify seller in Surat: write down what customer data you hold and why, fix the signup consent, publish a way for customers to ask for their data or its deletion, and name the person who reports a breach. That is the whole job. No certificate, no consultant, no ISO audit.
  • The same business three years later, selling to a European retailer and taking card payments on its own checkout: now add GDPR and PCI DSS, because the customer and the payment flow changed. Not before.

Three Free Tools to Start With

All three are free, need no signup, and are built for the step they name.

Start here
  • DPDP checker — answer a few questions, get the list of obligations that actually apply to your business. About two minutes.
  • 14-step compliance checklist — the work itself, in order, with a one-page PDF to keep.
  • Consent notice generator — a DPDP consent notice for your business in any of 23 languages, generated in your browser.

References & Sources

  1. India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text (Sections 3, 5, 7, 8, 12, 16, 44).
  2. Ministry of Electronics & IT — Data Protection Framework, including the Digital Personal Data Protection Rules 2025 (G.S.R. 846(E), notified 13 November 2025).
  3. Ministry of Electronics & IT — Information Technology Act, 2000 and the Reasonable Security Practices and Procedures and Sensitive Personal Data or Information Rules, 2011.
  4. CERT-In — Directions under Section 70B(6) of the IT Act, 2000, dated 28 April 2022 (six-hour incident reporting, 180-day log retention, NTP synchronisation).
  5. Reserve Bank of India — Storage of Payment System Data, circular DPSS.CO.OD No. 2785/06.08.005/2017-2018, 6 April 2018.
  6. Securities and Exchange Board of India — Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, and subsequent circulars extending compliance timelines.
  7. European Union — Regulation (EU) 2016/679 (General Data Protection Regulation), official text (Articles 3, 6, 17, 28, 30, 32, 83).
  8. U.S. Department of Health & Human Services — HIPAA for Professionals, covering the Privacy, Security and Breach Notification Rules and business associate obligations.
  9. California Privacy Protection Agency — California Consumer Privacy Act regulations, as amended by the CPRA.
  10. PCI Security Standards Council — PCI DSS v4.0.1 (June 2024) and guidance confirming the 31 March 2025 effective date for future-dated requirements.
  11. ISO — ISO/IEC 27001 Information security management systems.
  12. ISO — ISO/IEC 27701:2025 Privacy information management systems, the standalone second edition superseding ISO/IEC 27701:2019.
  13. AICPA — SOC 2 and the Trust Services Criteria.

This article is general information comparing Indian and international data protection, security and compliance frameworks. It is not legal advice, and it is not a substitute for advice on your own circumstances. Several frameworks named here are amended frequently and some obligations commence on future dates; verify against the current official texts, and consult a qualified professional before relying on any of it.

ComparisonGDPRHIPAAPCI DSSISO 27001CERT-InDPDP

Check Your DPDP Compliance

Free 2-minute checker — get your specific obligations and penalty exposure.

Related Articles

← All Blog Posts