Privacy and Data Protection: GDPR and DPDP for Developers

Advanced
11 min

Privacy and Data Protection: GDPR and DPDP for Developers

Security asks "can an attacker get this data?" Privacy asks "should we have this data at all, and what did we promise the person it belongs to?" The EU's General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP) turn those questions into legal duties with significant penalties, and most of the duties land on engineering teams as features and constraints.

In this lesson you will learn the principles the two laws share, their vocabulary, the user rights you must implement in code, how to design for minimisation and retention, and what a breach obliges you to do.

Shared Principles and Vocabulary

| Principle | Engineering meaning | |---|---| | Lawful basis and consent | Know why you process each field; consent is specific, informed and withdrawable | | Purpose limitation | Data collected for delivery is not reused for advertising without a new basis | | Data minimisation | Collect and store only what the feature needs | | Storage limitation | Delete or anonymise when the purpose ends | | Accuracy and accountability | Let people correct their data; keep records that show what you do |

The vocabulary differs: GDPR speaks of a data controller, processor and data subject, supervised by national authorities; DPDP speaks of a Data Fiduciary, Data Processor and Data Principal, supervised by the Data Protection Board of India, and adds the Consent Manager, a registered intermediary for giving and withdrawing consent. The engineering work is nearly identical under both.

Rights You Must Implement

People can ask for their data, correct it, delete it, and withdraw consent. Each request needs an authenticated path, a tracked deadline and an auditable outcome. The sample code handles erasure, the hardest one: it deletes what it can, anonymises what accounting rules require you to keep, and leaves a tombstone so the identifier is never reused. Access requests need a job that exports every record linked to the person:

javascript
app.get("/me/export", requireAuth, requireRecentLogin, async (req, res) => { const bundle = await collectPersonalData(req.user.id); // profile, orders, addresses, preferences res.set("Content-Disposition", 'attachment; filename="my-data.json"'); res.json({ exportedAt: new Date().toISOString(), data: bundle }); });

Minimisation and Retention by Design

Privacy by design is mostly deletion by design. Decide at schema time which fields are needed and how long they live, and write it down where a job can enforce it:

yaml
# retention.yml: consumed by a nightly job sessions: { keep: 30d, then: delete } search_history: { keep: 90d, then: delete } support_tickets: { keep: 2y, then: anonymise } invoices: { keep: 8y, then: delete } # statutory accounting period

Apply the same rules to logs, analytics, backups and staging copies; production personal data does not belong in developer databases. Record consent as data too, to prove it and honour withdrawal:

json
{ "userId": "u_42", "purpose": "marketing_email", "policyVersion": "2026-02", "granted": true, "at": "2026-03-01T10:15:00Z", "channel": "web" }

Breach Response Obligations

Both laws require prompt notification when personal data is compromised. GDPR requires reporting to the supervisory authority within 72 hours of becoming aware, and to affected people when the risk is high. DPDP requires notifying the Data Protection Board and each affected Data Principal within the timelines set by the rules. Engineering makes that possible: logs decide whether you can say which records were accessed, and a documented incident process decides whether legal teams hear in time. Keep a register of every incident, including ones that did not require notification.

Quick Quiz
Question 1 of 2

Which principle is violated when a delivery address collected for shipping is later used to build advertising profiles without a new basis?

Key Takeaways

  • GDPR and DPDP share the same principles: lawful basis, purpose limitation, minimisation, retention limits, security, accountability.
  • Controller and Data Fiduciary, data subject and Data Principal are the same roles under different names.
  • Implement authenticated, audited flows for access, correction, erasure and consent withdrawal; anonymise what must be kept.
  • Define retention per data type in configuration and enforce it with jobs, including logs, backups and staging copies.
  • Be ready to notify authorities and affected people quickly; logs and an incident process make that possible.

Next lesson: Building a Security Mindset: Audits, Updates and Incident Response — turning everything so far into an ongoing practice.

Privacy and Data Protection: GDPR and DPDP for Developers - Cyber Security | CodeYourCraft | CodeYourCraft