IAPP Privacy. Security. Risk. + AI Governance Global 2026
Seattle
6-9 October
Conference
8-9 Oct.
Training
6-7 Oct.
Workshops
7 Oct.
India's Digital Personal Data Protection Act: Leveraging US and EU Approaches
Friday, 9 Oct.
15:45 - 16:45 PDT
Intermediate level
Global businesses must address India's new privacy law, the Digital Personal Data Protection Act, in their data privacy programs, and some must consider “data embassy” arrangements for data centers. Most provisions, and their extra-territorial reach, will come into force in 2027. India's landmark regime empowers users and places significant responsibilities to handle digital information ethically, securely and with a high degree of transparency. The Indian law draws inspiration from the principles of the GDPR but is tailored and scaled for India. How does the law compare with U.S., U.K. and EU law? What are the powers of the new Data Protection Board of India? What must a global company consider in terms of cross border data flows, legal bases for collection and protection of children's and employees' data? How would your preparedness need to re-evaluated should you be declared a significant data fiduciary? Gain practical guidance on how to address new Indian requirements and enforcement trends, and have your questions answered in this one-hour session with experts in Indian, U.S. and EU law, regulation and enforcement trends.
What you will learn:
- Determine how India's Digital Data Protection Act applies to your company or institution and whether your business will be declared a significant data fiduciary.
- Introduction and updates on compliance strategies, new AI rules and risk mitigation.
- How you can leverage GDPR and California compliance measures for Indian requirements.
Featured in this session

Lothar Determann
Partner
Baker McKenzie

Elizabeth Denham
Chair
Jersey Data Protection Authority