What Is GDPR Compliance and How DPDP Affects Your Payment Gateway
Highlights:
- Understand GDPR and DPDP Act requirements for protecting customer payment data stored by your payment gateway
- Learn RBI's data localisation mandate and card storage restrictions that apply to all Indian merchants
- Discover penalty structures, GDPR fines reach 4% of revenue, DPDP imposes fixed ₹250 crore caps
- Follow actionable compliance steps, including PCI DSS verification, tokenisation checks, and breach notification procedures
Introduction
Every online transaction leaves behind more than just a payment confirmation. It creates a trail of personal data: names, phone numbers, email addresses, billing addresses, IP details, and sometimes even behavioural data. For businesses using a payment gateway (PG), protecting this customer data is no longer just a security best practice. It is a legal obligation.
If your payment gateway stores or processes customer information, your business may need to comply with both the European Union’s General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection (DPDP) framework. Even if your company is based in India, GDPR may apply if you handle data from EU customers.
Understanding these regulations is essential. Compliance reduces legal risk, strengthens customer trust, and demonstrates responsible data governance.
What is GDPR?
The General Data Protection Regulation, or GDPR, is a European Union (EU) law that governs how organisations within and outside the EU handle the personal data of EU residents. GDPR was adopted by the European Parliament and Council of the EU in 2016 and took effect on 25 May 2018.
Specifically, GDPR
- defines legally approved ways to transfer and process personal data;
- details how organisations must protect personal data at rest and in transit; and
- establishes EU residents' rights over personal data collection, use and possession.
GDPR defines personal data as any information relating to an identifiable human being, including direct and indirect identifiers. Direct identifiers are a person's unique data points, like their name or credit card number. Indirect identifiers include non-unique traits that can still identify a person, like physical characteristics and dates of birth.
In GDPR parlance, a data subject is the person a piece of data is about. For example, if a company collects email addresses, the owners of those addresses would be the data subjects.
While GDPR is a European law, it has a global reach. It applies to any organisation anywhere that collects or uses the personal data of EU residents.
What is DPDP?
DPDP stands for Digital Personal Data Protection.
It refers to India’s Digital Personal Data Protection Act, 2023 (DPDP Act), which is India’s main law for regulating how organisations collect, use, store, and protect personal data in digital form.
The law was introduced to give individuals more control over their personal data and to make businesses more accountable for handling that data responsibly.
In simple terms, what is DPDP?
DPDP sets rules for how companies, websites, apps, and service providers can collect and process personal information, such as:
- Name
- Phone number
- Email address
- Address
- Payment details
- IP address
- Any other information that can identify a person
If a business collects this type of data digitally, it may need to comply with the DPDP Act.
Why Payment Gateways Need Special Attention
Payment gateways require special attention under GDPR and India's DPDP Act 2023 because they process massive volumes of highly sensitive financial and personal data, making them prime targets for cyberattacks. Both frameworks prioritise explicit consent and strict data handling, with India’s DPDP creating a "processing-centric" regime that holds fintechs strictly accountable, while GDPR imposes heavy global turnover penalties.
Key Reasons for Special Attention:
- High-Risk Data Handling: Payment gateways manage personal data, financial information, and transaction history, which must be protected through strict security measures, data minimisation, and privacy-by-design principles, as reflected in the security and compliance practices of PhonePe.
- Stringent Consent Mechanisms: Unlike GDPR, which allows for various legal bases, the DPDP Act makes informed, specific consent the primary requirement, demanding complex, per-transaction consent for swift digital payments.
- Data Localisation (DPDP): Indian regulations require end-to-end transaction data to be stored within India, demanding strict control over data flows.
- Severe Penalties: DPDP penalties can reach ₹250 crores (~₹30 million) for breaches, while GDPR allows fines up to 4% of annual global turnover.
- Interplay of Multiple Regulations: Payment gateways must navigate DPDP simultaneously with existing RBI regulations on cybersecurity and data storage.
Differences in Compliance Focus (GDPR vs DPDP):
- Consent: While both regulations focus on consent, the DPDP Act (2023) prioritises consent as the primary mechanism, making it more challenging to rely on "legitimate interest".
- Definitions: DPDP often has a broader definition of personal data, including pseudonymized data.
- Data Principal Rights: Both regulations empower users to access, erase, and correct their data, with DPDP requiring rapid response mechanisms from data fiduciaries.
Practical Steps to Ensure GDPR and DPDP Compliance
Ensuring compliance with GDPR and India's DPDPA involves auditing data, mapping flows, updating consent mechanisms, and implementing security measures like encryption. Key steps include appointing a Data Protection Officer (DPO), managing subject rights requests, and ensuring third-party contracts are updated to meet legal requirements.
Practical Steps for Compliance (2026 Focus)
- Data Discovery and Mapping: Conduct audits to classify personal data, identifying where it is collected, stored, and shared.
- Implement Data Subject Rights Procedures: Establish systems to handle requests for access, correction, or deletion (erasure) within mandatory deadlines.
- Revamp Consent Mechanisms: Ensure consent is freely given, specific, informed, and easy to withdraw (opt-in/opt-out).
- Appoint a Data Protection Officer (DPO): Designate a DPO to oversee compliance, especially for significant data fiduciaries under DPDPA.
- Strengthen Cybersecurity Measures: Utilise encryption and pseudonymization for data at rest and in transit.
- Update Third-Party Vendor Contracts: Ensure data processing agreements (DPAs) are in place, particularly for cross-border transfers.
- Data Retention and Deletion Policies: Define retention periods and set up automated deletion for data that is no longer necessary.
- Employee Training: Build a privacy-first culture by training staff on data protection obligations.
Key Compliance Differences: GDPR vs DPDP for Payment Data
| Compliance Area | GDPR (EU) | DPDP (India) |
|---|---|---|
| Scope of data covered | Personal data, including online identifiers and payment-related metadata | Digital personal data only, covering data collected or digitised electronically |
| Who it protects | Individuals in the European Union | Individuals in India |
| Business role is defined as | Data Controller / Data Processor | Data Fiduciary / Data Processor |
| Consent requirements | Must be freely given, specific, informed, and explicit in many cases | Must be clear, informed, and affirmative |
| Legal basis beyond consent | Multiple legal bases, such as contract, legal obligation, legitimate interest | Primarily consent-based, with certain legitimate uses allowed |
| Data subject rights | Access, correction, deletion, portability, restriction, objection | Access, correction, erasure, grievance redressal, consent withdrawal |
| Breach notification | Mandatory notification to the supervisory authority within 72 hours in many cases | Notification required to the Data Protection Board and affected individuals as prescribed |
| Cross-border data transfer | Allowed under strict adequacy and safeguard mechanisms | Allowed except for countries restricted by the Indian government |
| Children’s data | Special protections, parental consent under age thresholds | Strong protections, verifiable parental consent required for minors |
| Penalties | Up to €20 million or 4 per cent of global annual turnover | Financial penalties under the DPDP Act, depending on the violation |
Key Takeaways for Compliance-Focused Merchants
Payment gateway compliance isn't a one-time checklist; it's an ongoing obligation requiring vigilance as regulatory frameworks evolve. With DPDP core requirements effective May2027, Indian merchants have less than one year to implement consent mechanisms, breach notification protocols, and data security safeguards. Verify your payment gateway's RBI datalocalisationcompliance, PCI DSS certification, and tokenisation implementation now before regulatory deadlines arrive.
FAQs
What is GDPR, and does it apply to my Indian business?
GDPR is the EU's data protection law, effective May2018. If your business processes payment data from EU customers, even if the India-based GDPR applies. An Indian merchant shipping to Germany must comply when storing EU customer card details via a payment gateway.
What is India's DPDP Act, and when does it take effect?
India's Digital Personal Data Protection Act was enacted in August2023, with core compliance requirements effective May 13, 2027. It governs how Indian businesses collect, store, and process customer payment data digitally. All merchants using payment gateways must comply with this deadline.
What is the difference between GDPR and DPDP compliance for payment gateways?
GDPRcovers all personal data and requires multiple legal bases for processing, with penalties up to 4% of global revenue.DPDPcovers only digital personal data, relies primarily on consent, and imposes fixed penalties up to ₹250 crore. Indian merchants processing EU payments must comply with both frameworks simultaneously.
Can my payment gateway store customer card details in India?
No. RBI's June2022circular prohibits payment gateways and merchants from storing actual card numbers. Only card issuers and networks can store card details. Your gateway must use RBI-approved tokenisation, replacing card numbers with secure tokens for saved card features.
What is GDPR, and does it apply to my Indian business?
GDPR is the EU's data protection law, effective May2018. If your business processes payment data from EU customers, even if the India-based GDPR applies. An Indian merchant shipping to Germany must comply when storing EU customer card details via a payment gateway.
