August 3, 2026 · 8 min read
GDPR vs DPDP Act: What Actually Changes for Indian Businesses
GDPR has six lawful bases; the DPDP Act has two. A working comparison of what actually changes — consent, rights, breach notification, children, transfers and penalties — for teams porting a GDPR programme to India.
GDPR vs DPDP Act: What Actually Changes
If your organisation already runs a GDPR programme, the Digital Personal Data Protection Act, 2023 will feel familiar for about ten minutes. Same premise: personal data belongs to the person, organisations hold it on trust, and mishandling it is expensive. Then you reach the lawful bases and the resemblance ends.
This is a working comparison for teams who have to operate under both, or who are porting a GDPR programme to India. It is written from the Act and the DPDP Rules as they stand, and it is candid about where the two regimes genuinely diverge rather than pretending India simply copied Europe.
The short version
The DPDP Act is narrower in scope and stricter in consent. It governs less — no sensitive-data category, fewer rights, no DPIA mandate for most organisations — but it removes the flexible lawful bases GDPR teams lean on hardest. If your European programme runs on legitimate interests, the single most important thing to understand is that legitimate interests does not exist in Indian law.
Lawful bases: six versus two
This is the difference that breaks GDPR playbooks. Article 6 GDPR gives you six lawful bases, and mature programmes route a large share of processing through legitimate interests with a balancing test on file.
The DPDP Act gives you two routes:
- Consent under §6 — free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and withdrawable as easily as it was given.
- Certain legitimate uses under §7 — a closed, enumerated list. Employment purposes, medical emergencies, state functions, compliance with law, and a handful of others.
§7 is a list, not a principle. There is no balancing test, no assessment you can perform to bring a new purpose inside it, and no residual category. If your processing is not consented and not on the §7 list, there is no third option.
Practical consequence: every legitimate-interest assessment in your GDPR file needs re-basing for India. Most of it will land on consent.
The vocabulary changes
Superficial, but it matters for policy documents and internal training:
- Data Controller becomes Data Fiduciary — a deliberate word, implying a duty of care rather than mere control.
- Data Subject becomes Data Principal.
- Supervisory Authority becomes the Data Protection Board of India.
- A new tier exists: the Significant Data Fiduciary, designated by the government based on volume and sensitivity of data, risk to electoral democracy, and public order.
The fiduciary framing is not decorative. It signals that Indian law treats the relationship as one of trust rather than contract, which is why the consent standard is stricter than GDPR's.
Rights: eight versus four
GDPR grants eight data subject rights. The DPDP Act grants four:
- Right to access information about processing (§11)
- Right to correction and erasure (§12)
- Right of grievance redressal (§13)
- Right to nominate someone to exercise rights on death or incapacity (§14)
Three GDPR rights have no Indian equivalent: data portability, the right to object, and rights concerning automated decision-making and profiling. If you built portability tooling for Europe, it is not required here — though it remains a reasonable thing to offer.
The nomination right in §14 runs the other way: it has no GDPR counterpart, and most GDPR-derived systems have nowhere to store it. See our guide to data principal rights under the Act for the operational detail.
Consent Managers — a role Europe never invented
The DPDP Act creates an intermediary that GDPR has no analogue for. A Consent Manager is a registered entity through which a Data Principal can give, manage, review and withdraw consent across multiple fiduciaries from a single interface. Consent Managers register with the Data Protection Board and must meet prescribed technical and financial conditions.
For a GDPR-trained team this is genuinely novel: consent becomes portable infrastructure rather than something each controller collects and keeps to itself. If you operate in India you will eventually have to interoperate with it. We cover the obligations in Consent Manager obligations under the DPDP Act.
Breach notification is stricter, not looser
GDPR gives you a risk threshold. You notify the supervisory authority within 72 hours unless the breach is unlikely to result in a risk, and you notify individuals only where there is a high risk to their rights and freedoms.
The DPDP Act has no such threshold. On becoming aware of a personal data breach, a Data Fiduciary must notify the Board and every affected Data Principal. There is no materiality carve-out and no risk assessment that lets you stay quiet about a minor incident.
In practice this means Indian breach response is more mechanical and higher volume than European. Teams used to triaging incidents against a risk threshold will notify considerably more often here.
Children: eighteen, not sixteen
GDPR sets the digital-consent age at 16, and member states may lower it to 13. Several have.
India sets it at 18, with no derogation. Processing a child's personal data requires verifiable consent from a parent or lawful guardian. Beyond that, the Act flatly prohibits tracking, behavioural monitoring and targeted advertising directed at children — not as a risk-managed activity, but outright.
For consumer products this is the single most disruptive difference. A design that is lawful for a 16-year-old in Germany is unlawful for the same user in India.
Cross-border transfers work backwards
GDPR is restrictive by default: transfers outside the EEA need an adequacy decision, standard contractual clauses, binding corporate rules or a derogation.
The DPDP Act inverts this. §16 permits transfer to any country except those the Central Government restricts by notification — a negative list rather than an allow list. The default is permissive.
Two caveats stop this being simpler than it sounds. Sectoral regulators, notably the RBI for payments data, impose their own localisation rules that survive independently of DPDP. And a negative list can change with a notification, which is a harder planning problem than a stable adequacy regime.
Penalties are capped, not proportional
GDPR fines scale with the organisation: up to €20 million or 4% of worldwide annual turnover, whichever is higher. A large multinational faces a genuinely existential number.
The DPDP Act sets fixed maxima per category of breach, the highest being up to ₹250 crore for failure to take reasonable security safeguards. There is no turnover linkage.
The asymmetry is worth understanding. For a large global company, Indian penalties are materially lower in absolute terms. For an Indian mid-market business, ₹250 crore is far beyond anything GDPR would have imposed on an organisation that size. Our breakdown of DPDP penalties sets out the full schedule.
What carries over from your GDPR programme
More than you would expect. If you have done GDPR properly, these assets transfer with modest rework:
- Your data inventory and processing records. DPDP has no formal RoPA article, but you cannot demonstrate compliance without one.
- Your retention schedules — the purpose-limitation logic is the same.
- Your processor contracts and vendor due-diligence process.
- Your security safeguards and incident-response runbooks.
- Your privacy notice structure, though the content needs rewriting for §5.
- Staff training on the underlying concepts.
The records of processing activities you already maintain remain the single most useful artefact in either regime.
What does not carry over
- Legitimate-interest assessments. There is no equivalent basis; re-base the processing on consent or a §7 legitimate use.
- Your consent language. §5 notice requirements are specific, and the notice must be available in English or any of the 22 languages in the Eighth Schedule.
- Your 16-year-old age gate.
- Risk-thresholded breach triage.
- Your DPIA trigger logic. DPDP requires impact assessments only for Significant Data Fiduciaries.
- Sensitive-personal-data special handling. DPDP has no such category, so controls keyed to it have no statutory hook here.
A migration checklist
If you are porting a GDPR programme to India, in rough order:
- Re-base every legitimate-interest processing activity onto consent or §7.
- Rewrite privacy notices to §5 and translate into the languages your users actually use.
- Rebuild consent capture to the §6 standard, with withdrawal as easy as granting.
- Raise the child age gate to 18 and remove behavioural advertising to minors entirely.
- Remove the risk threshold from breach response; assume every breach is notifiable.
- Add nomination capture under §14 to your identity model.
- Check whether you are likely to be designated a Significant Data Fiduciary, and if so plan for a DPO based in India, independent audits and DPIAs.
- Map your cross-border flows against §16 and any sectoral localisation rules that bind you.
For a structured route through this, see our step-by-step DPDP compliance guide or begin with a DPDP compliance assessment to establish where you currently stand.
Frequently Asked Questions
Does GDPR compliance mean we are DPDP compliant?
No. It gives you a substantial head start on governance, security and records, but the lawful bases, consent standard, child age threshold and breach notification rules all differ. The gaps are specific and must be closed deliberately.
Is there a legitimate interest basis under the DPDP Act?
No. The Act provides consent under §6 or a closed list of legitimate uses under §7. There is no balancing test and no residual category, so processing that relied on legitimate interests in Europe must be re-based in India.
Does the DPDP Act apply to companies outside India?
Yes. §3 extends the Act to processing carried out outside India where it relates to offering goods or services to Data Principals within India, mirroring GDPR's extraterritorial reach.
Does the DPDP Act have a data portability right?
No. The Act grants access, correction and erasure, grievance redressal and nomination. Portability, the right to object and rights concerning automated decision-making have no Indian equivalent.
Are DPDP penalties higher than GDPR fines?
In absolute terms, no — the maximum is up to ₹250 crore per category, against GDPR's €20 million or 4% of global turnover. But DPDP penalties are not linked to turnover, so for a mid-sized Indian business the exposure is proportionally far greater.
Related reading
For the Act itself, start with the DPDP Act 2023 explained. For the consent mechanics, see DPDP consent management. If you are evaluating tooling, our comparison of DPDP platforms in India is candid about where other products are stronger than ours.