Three major privacy regimes, three different thresholds and penalty structures — here's how founders should tell them apart.
Data Privacy Regulations Glossary: GDPR, India's DPDP Act & CCPA
A comparative glossary of GDPR, India's DPDP Act/Rules 2025, and CCPA/CPRA — covering scope, key roles, and penalty structures.
Founders operating across the US, EU, and India now juggle three distinct privacy regimes. This glossary lines up the core concepts so compliance requirements don't get conflated across jurisdictions.
GDPR (EU) — key terms
Data controller — The entity that determines the purposes and means of processing personal data.
Data processor — An entity processing personal data on behalf of a controller.
Maximum fine tier — €20 million or 4% of global annual turnover, whichever is greater, for the most severe violations (unlawful processing, breach of data-subject rights, unauthorized international transfers). A lower tier caps at €10 million or 2% of global revenue.
India's DPDP Act & Rules — key terms
Data Fiduciary — The entity determining the purpose and means of processing digital personal data of individuals in India (equivalent concept to GDPR's "controller").
Data Principal — The individual to whom the personal data relates (India's term for "data subject").
Significant Data Fiduciary (SDF) — A category of fiduciaries facing enhanced obligations — annual DPIAs, audits, algorithmic fairness assessments, and a mandatory Data Protection Officer.
DPDP Rules 2025 — Notified November 13, 2025, these operationalize the 2023 Act, mandating a standalone plain-language consent notice, minimum security safeguards (encryption, access controls, logging), a one-year minimum log-retention period, and breach notification to the Data Protection Board. Penalties can reach INR 250 crore.
CCPA / CPRA (California) — key terms
Business threshold — Applies to for-profit entities meeting any one of: $25M+ annual revenue, personal data on 100,000+ California consumers/year, or 50%+ revenue from selling/sharing data.
Right to opt out — Consumers can direct businesses to stop selling or sharing their personal information.
Penalties — $2,500 per unintentional violation, up to $7,988 per intentional violation under CPRA, with no aggregate cap.
How to use this
Map each regulation to the jurisdiction of your users, not your headquarters — GDPR and DPDP both apply extraterritorially based on where the individual is located.
Sources
EY: DPDP Act 2023 and DPDP Rules 2025 Compliance Guide, Sprinto: GDPR Fines in 2026, DeepStrike: Average Fines for GDPR, CCPA, CPRA.
Frequently asked questions
Yes, if the startup processes personal data of individuals located in the EU/EEA, regardless of where the company itself is based.
A for-profit business is covered if it meets at least one of: over $25 million in annual revenue, personal data on 100,000+ California consumers per year, or 50%+ of revenue from selling or sharing personal data.
Entities the government designates based on factors like data volume and sensitivity, which then face enhanced obligations including annual data protection impact assessments, audits, and appointing a dedicated Data Protection Officer.
