Xplore Publications
* Volume 3 of Transformations in Management is open for submissions until 30 August 2026. *

Chapter 107

Abstract Sukriti Ghosh

ISBN
978-81-992602-2-0
Published
21 July 2026
Accesses
2 views · 0 downloads
Reading time
~2 min

Full text

A COMPARATIVE ANALYSIS OF GDPR AND DPDP ACT: DATA PROTECTION AND THE BLACK-BOX CHAOS

ABSTARCT

The emergence of Artificial Intelligence has shaken many data-driven industries, along with the traditional concepts around data protection. This paper takes up two data protection laws from two distinct demographics to understand the impact and analyse their foundational nature and preparedness to integrate new-age technology. The General Data Protection Regulation and the Digital Personal Data Protection Act are two laws that retain two diverse sets of principles showing contrasting values towards data protection.

The EU’s General Data Protection Regulation is the oldest and a comprehensive legal regime that includes provisions to protect essential individual rights like the right to be forgotten, right to object, and principles to ensure a fair data processing ecosystem like data portability, data minimisation, and purpose limitation. On the other hand, India’s Digital Personal Data Protection Act, 2023, specifically focuses on exempting the central government to allow acquiring data for security concerns, and provides for a mechanism for "voluntary undertaking" for the data fiduciaries.

This paper compares these two laws based on their foundational philosophies and background, their focus on fundamental rights, how they deal with cross-border data flow and tests them for preparedness of tackling challenges posed by AI models like data minimization, the “black box” nature of AI models, anonymization, accountability and transparency. Ultimately, the paper argues that the foundational differences map out the landscape for the integration of AI. The paper suggests mechanisms like using synthetic data, federated learning and developing explainable AI to ensure an ethical AI ecosystem. In the conclusion, the paper discusses the adaptability of these two acts for AI models and their resilience to harness a digital environment that preserves the right to individual freedoms.

Keywords : Artificial Intelligence, privacy, data protection, data processing, personal data

Get an email when we publish new research and open calls for chapters.

Create a free account