Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

DPDP vs GDPR explained

DPDP vs GDPR: 12 Clear Differences Explained (2026)

DPDP vs GDPR is the comparison every organisation that processes Indian and European personal data has to make, and the two laws are further apart than their shared vocabulary of consent, rights and breach notification suggests. India’s Digital Personal Data Protection Act, 2023 — Act No. 22 of 2023, with its Rules notified on 13 November 2025 and its substantive obligations commencing 13 May 2027 — covers digital personal data only, allows processing on consent or a short list of “legitimate uses”, knows no special categories, imposes penalties in rupee bands up to ₹250 crore, and gives individuals duties as well as rights.

The GDPR covers all personal data, offers six lawful bases including legitimate interests, treats special categories separately, fines up to €20 million or 4% of worldwide turnover, and imposes no duties on data subjects. This guide sets the two side by side on twelve points, walks the nine differences that change how a programme is built, and shows what a GDPR-compliant organisation has to add — and, in two places, remove — to be ready for India.

DPDP vs GDPR: nine differences that change the programme
Scope (digital only) · lawful bases (consent + legitimate uses) · no special categories · children under 18 with verifiable parental consent · Significant Data Fiduciaries · consent managers · data principal duties · penalties in rupee bands · transfers by government blacklist.

DPDP vs GDPR at a glance

DPDP Act 2023 (India) GDPR (EU)
Instrument Act No. 22 of 2023, enacted 11 August 2023; DPDP Rules 2025 notified 13 November 2025; obligations commence 13 November 2026 (consent managers) and 13 May 2027 (everything else) Regulation (EU) 2016/679, applicable since 25 May 2018
Regulator Data Protection Board of India — a digital office; appeals to the Telecom Disputes Settlement and Appellate Tribunal National supervisory authorities; European Data Protection Board; national courts
Scope of data Digital personal data — collected digitally, or collected offline and digitised All personal data, automated or in a filing system
Territorial reach Processing in India; processing outside India in connection with offering goods or services to data principals in India Establishment in the EU; offering goods or services to, or monitoring, data subjects in the EU
Roles Data Fiduciary, Data Processor, Data Principal, Significant Data Fiduciary, Consent Manager Controller, processor, data subject, joint controllers, representative
Lawful bases Consent, or the ‘certain legitimate uses’ listed in section 7 Six: consent, contract, legal obligation, vital interests, public task, legitimate interests
Special categories None Article 9 special categories and Article 10 criminal data
Children Under 18; verifiable parental consent; no tracking, behavioural monitoring or targeted advertising Under 16 (member states may set 13–16) for information society services; no blanket advertising ban
Individual rights Access, correction and erasure, grievance redressal, nomination Information, access, rectification, erasure, restriction, portability, objection, automated decision-making
Individual duties Yes — section 15, with a penalty up to ₹10,000 None
Breach notification Every breach: to the Board and each affected data principal, without delay; detailed report to the Board within 72 hours To the authority within 72 hours where risk is likely; to data subjects where high risk
Penalties Schedule bands: up to ₹250 crore (security safeguards), ₹200 crore (breach notification; children), ₹150 crore (Significant Data Fiduciary duties), ₹50 crore (other) Up to €20 million or 4% of worldwide annual turnover; €10 million or 2% for the lower tier

DPDP vs GDPR: the nine differences that change the programme

  1. Digital data only. The DPDP Act applies to personal data in digital form and to offline data that is subsequently digitised; a paper file that stays on paper is outside it. GDPR’s filing-system test brings structured paper records in.
  2. Consent or legitimate uses — no legitimate interests. Section 7 lists the legitimate uses: a purpose for which the data principal voluntarily provided the data and did not indicate objection; state functions and benefits; legal obligations; medical emergencies; epidemics and disasters; employment purposes; and a few others. There is no general balancing test. Marketing to existing customers, analytics and product improvement — legitimate-interest staples under GDPR — need consent in India unless they fit a listed use.
  3. No special categories. Health, biometric, caste, religion and financial data carry no separate regime; the Act treats all personal data alike, and the Rules’ security safeguards apply uniformly. Sector regulators (the RBI, SEBI, health) add their own rules on top.
  4. Children are under 18, with verifiable parental consent. Section 9 requires verifiable consent of a parent or lawful guardian before processing any child’s data and prohibits tracking, behavioural monitoring and targeted advertising directed at children; Rule 10 sets how the parent’s identity and age are verified. GDPR’s threshold is 16 or lower and applies to information society services offered directly to a child.
  5. Significant Data Fiduciaries. The Central Government may notify fiduciaries as significant on volume and sensitivity, risk to rights, sovereignty, electoral democracy, security and public order; they must appoint a Data Protection Officer based in India, an independent data auditor, and conduct a Data Protection Impact Assessment and audit every twelve months, with a report to the Board. GDPR’s DPO and DPIA duties attach by activity, not by designation.
  6. Consent managers. A registered intermediary through which an individual gives, manages, reviews and withdraws consent across fiduciaries — Rule 4, in force 13 November 2026. Nothing in GDPR corresponds.
  7. Duties on the individual. Section 15 obliges data principals not to impersonate, not to suppress material information, not to file false or frivolous grievances, and to give only verifiably authentic information when exercising correction or erasure — with a ₹10,000 penalty.
  8. Every breach is notified. Section 8(6) and Rule 7: each affected data principal is told without delay, and the Board receives an immediate description and a detailed report within 72 hours, with no risk threshold. GDPR notifies the authority only where a risk is likely and data subjects only where the risk is high.
  9. Transfers by blacklist, not adequacy. Section 16 lets the Central Government restrict transfers to notified countries; Rule 15 adds requirements for making data available to a foreign state. Until a restriction is notified, transfers are permitted — the reverse of GDPR’s Chapter V, which prohibits unless a mechanism applies. Significant Data Fiduciaries may face localisation of data the government specifies.

Our guides to the DPDP Act and the DPDP Rules 2025 cover the Indian side in full; GDPR principles covers Article 5.

DPDP vs GDPR in practice: what a GDPR programme has to add

Area GDPR position DPDP addition
Lawful basis register Six bases; legitimate interests assessments Re-map every activity to consent or a section 7 legitimate use; legitimate-interest processing moves to consent or stops
Notice Articles 13 and 14 Rule 3: a standalone notice with an itemised description of the data and purposes, the goods or services enabled, and the links to withdraw consent, exercise rights and complain to the Board
Consent mechanics Freely given, specific, informed, unambiguous Withdrawal as easy as giving; consent manager integration where relevant; consent records retained
Children Age 16 (or 13–16) for information society services Verifiable parental consent for under-18s per Rule 10; no tracking or targeted advertising; age-gating across the estate
Breach process Risk assessment gate; 72 hours to the authority No gate: notify every affected individual without delay; immediate Board notification; 72-hour detailed report
Security Appropriate measures Rule 6 minimum set: encryption or masking, access control, logging with one-year retention, backups, processor contract terms
Retention Storage limitation Rule 8 and the Third Schedule: fixed erasure periods for specified classes, with 48-hour advance notice to the individual
Significant Data Fiduciary DPO by activity; DPIA by risk If notified: India-based DPO, independent data auditor, annual DPIA and audit reported to the Board, algorithmic due diligence, possible localisation
Rights handling Eight rights, one month Access, correction and erasure, grievance redressal within the period the fiduciary publishes, nomination; the published means of exercise per Rule 14

DPDP vs GDPR: what a GDPR programme can drop for India, and what to keep

Two GDPR mechanisms have no DPDP counterpart: the legitimate-interests assessment, because there is no such basis, and the transfer mechanism (SCCs, adequacy) for data leaving India, because transfers are permitted unless restricted. Keeping the transfer register is still sensible — the government can notify restrictions and Significant Data Fiduciaries may be subject to localisation — and keeping special-category handling is sensible because sector regulators require it even though the Act does not.

What must not be carried over unchanged is the breach playbook: a GDPR-trained team that assesses risk before notifying will miss the DPDP Act’s duty to notify every affected individual and the Board regardless. Our guide to DPDP breach notification covers the 72-hour rule; Saudi PDPL vs GDPR is the comparable exercise for the Gulf.

Frequently asked questions

What is the difference in DPDP vs GDPR?
The DPDP Act covers digital personal data only, allows processing on consent or a fixed list of legitimate uses with no legitimate-interests test, has no special categories, treats under-18s as children with verifiable parental consent, designates Significant Data Fiduciaries, creates consent managers, imposes duties on individuals, requires every breach to be notified, permits transfers unless the government restricts them, and fines in rupee bands up to ₹250 crore. GDPR is broader in scope, more flexible on bases, risk-gated on breaches and fines up to 4% of turnover.

Is the DPDP Act in force?
Partly. The Data Protection Board provisions have been in force since 13 November 2025; consent manager registration commences 13 November 2026; the substantive obligations on data fiduciaries — notice, consent, security, breach, children, rights — commence 13 May 2027.

Does GDPR compliance make us DPDP compliant?
It gets you most of the governance and rights machinery, but not the lawful-basis mapping (no legitimate interests), the Rule 3 notice format, the under-18 verifiable consent, the no-threshold breach notification, the Rule 6 security minimums and the Significant Data Fiduciary duties if notified. Treat DPDP as an extension with three rewrites: bases, breach, children.

Which is stricter?
Neither uniformly. DPDP is stricter on consent (no legitimate interests), children (18, advertising ban) and breach notification (every breach, everyone); GDPR is stricter on special categories, transfers, portability and objection rights, and its fines scale with global turnover.

Do the penalties compare?
DPDP’s maximum is ₹250 crore per instance of failing security safeguards — roughly €25–28 million at recent rates — with fixed bands below it; GDPR’s maximum is the higher of €20 million or 4% of worldwide annual turnover, so for a large group GDPR’s ceiling is higher and DPDP’s is fixed.

Where this leaves you

Run DPDP vs GDPR as an extension with three rewrites: keep the GDPR governance, rights and security machinery; re-map every processing activity to consent or a section 7 legitimate use; rebuild the breach process without a risk gate; and age-gate for under-18s with verifiable parental consent. Then check whether you are likely to be notified as a Significant Data Fiduciary, because that is where the DPO, auditor and annual DPIA land — and the calendar says 13 May 2027.

References

More on the DPDP Act

The GDPR-to-DPDP gap assessment, the lawful basis and legitimate-use register, the Rule 3 notice template, the verifiable parental consent procedure and the breach notification workflow are in the DPDP Act Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.