Learning from the World: Global Privacy Developments That Shaped India’s Approach

India wasn’t writing its privacy law in isolation. By 2023, most of the world already had one. Here’s what India was watching — and what it deliberately chose not to copy.

THE GLOBAL PICTURE

25 MAY 2018

GDPR takes effect

The EU’s General Data Protection Regulation becomes the reference point almost every later privacy law gets measured against, including India’s.

144

Countries with a privacy law today

Roughly seven in ten countries now have some form of national data protection legislation — covering about four-fifths of the world’s population.

2018–2023

The wave reaches Asia

Brazil, Japan, South Korea, Thailand, Indonesia and others pass or update comprehensive privacy laws in the years leading up to India’s own Act.
GDPR didn’t hand India a template to fill in — it showed the shape a privacy law could take, and India adapted that shape to its own priorities. The clearest example: GDPR lets businesses process data under a broad, judgement-based ‘legitimate interest’ test. India’s Act deliberately skips that option. Instead, Section 7 lists a fixed, narrow set of situations where consent isn’t required — nothing broader, nothing left to a business’s own judgement call.
Common misconception — That every new privacy law is basically a copy of GDPR. GDPR set the direction, but each country adapts it heavily — India, for instance, replaced GDPR’s open-ended ‘legitimate interest’ test with a short, fixed list instead.
The world showed India what to build toward. It didn’t tell India what to copy.

Ready to get compliant?

Talk to our team or register your organisation to get started with ConveyGrid.