Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

DPDP Act vs GDPR: the 9 differences compared side by side

DPDP Act vs GDPR: The Complete 2026 Guide to 9 Differences

DPDP Act vs GDPR is the comparison every company selling into India is now being asked to make, and the honest answer is that a working GDPR program gets you about two-thirds of the way. The remaining third is not detail.

India’s Digital Personal Data Protection Act, 2023 runs on a different consent model, a different age of consent, a different breach trigger and a penalty scale written in fixed rupee amounts rather than percentages of turnover. This guide sets out the nine differences that actually change what you build, read from the Act and the DPDP Rules, 2025 rather than from summaries of them, and finishes with the gaps a GDPR program should expect to close before the main obligations commence on 13 May 2027.

DPDP Act vs GDPR at a glance

Every DPDP Act vs GDPR comparison starts from the same place: both laws regulate an organization that decides why and how personal data is processed, and the individual the data is about. The vocabulary differs (a controller is a Data Fiduciary, a data subject is a Data Principal) and so, in nine places, does the substance.

Point of comparisonDPDP Act, 2023 (India)GDPR (EU)
Data in scopeDigital personal data only; publicly available data excluded (s. 3)All personal data, including structured paper filing systems (Art. 2)
Grounds for processingConsent, or one of the “certain legitimate uses” in s. 7Six lawful bases in Art. 6, including legitimate interests
Special category dataNo separate categoryArt. 9 special categories with their own conditions
Age of a childUnder 18; verifiable parental consent; no tracking or targeted ads (s. 9)Under 16 for online services, lowered to 13 by some member states (Art. 8)
Individual rightsAccess, correction and erasure, grievance redressal, nomination (ss. 11–14)Access, rectification, erasure, restriction, portability, objection, automated decisions (Arts. 15–22)
Duties on the individualYes (s. 15), penalty up to ₹10,000None
DPO and impact assessmentOnly for a Significant Data Fiduciary; DPO must be based in India (s. 10)DPO where Art. 37 applies; DPIA for high-risk processing (Art. 35)
Breach notificationEvery breach, to the Board and each affected individual; detailed report within 72 hours (s. 8(6), rule 7)To the authority within 72 hours unless unlikely to result in a risk; to individuals only if high risk (Arts. 33–34)
International transfersPermitted unless the country is on a government blacklist (s. 16)Adequacy decisions, SCCs, BCRs or a derogation (Arts. 44–49)
Maximum penaltyUp to ₹250 crore per breach category (Schedule)Up to €20 million or 4% of worldwide turnover (Art. 83)

The 9 differences that change your program

1. Scope: digital data only, and public data is out

The first DPDP Act vs GDPR difference is what counts as data at all. The DPDP Act applies to personal data collected in digital form, or collected on paper and digitized afterwards. It does not apply at all to personal data the individual has made publicly available themselves, or that another person is legally required to publish. The Act’s own illustration is a blogger who posts her personal details on social media. GDPR has no such carve-out; scraping public profiles is still processing under Art. 6.

Both laws reach outside their home territory, but differently. Section 3(b) captures processing outside India connected to offering goods or services to people in India. GDPR Art. 3(2) adds a second limb, monitoring behavior, that the DPDP Act does not have.

2. Grounds for processing: no legitimate interests

This is the largest structural difference in the DPDP Act vs GDPR comparison. GDPR gives you six lawful bases, and most corporate processing (fraud prevention, security logging, analytics, B2B marketing) runs on legitimate interests with a balancing test. The DPDP Act has consent plus a closed list of “certain legitimate uses” in section 7: data the individual volunteered for a specified purpose, state functions and benefits, legal obligations and court orders, medical emergencies, epidemics, disasters, and employment-related processing including protection of trade secrets. There is no balancing test and no contract basis as such.

If your purpose is not on the list, you need consent that is “free, specific, informed, unconditional and unambiguous with a clear affirmative action” under section 6.

There is also no special-category concept. Health, biometric and financial data get no separate legal test under the DPDP Act, although the Rules’ security standard and the Significant Data Fiduciary designation both key off sensitivity.

3. Notice, withdrawal and the Consent Manager

A GDPR privacy notice can cross-refer to a longer policy. Rule 3 of the DPDP Rules requires a notice that is understandable independently of any other information, with an itemized description of the personal data and the specified purposes. Withdrawal must be as easy as giving consent. And the Act creates an institution GDPR does not have: the Consent Manager, a registered intermediary through which an individual can give, review and withdraw consent across organizations. Registration opens on 13 November 2026, and your consent records will need to recognize a consent that arrives that way. Our guide to the DPDP consent manager covers what a fiduciary has to build.

4. Children: 18, not 16, and no targeted advertising

Age is the DPDP Act vs GDPR difference most consumer products get wrong. Section 2(f) defines a child as anyone under 18. Before processing a child’s data a fiduciary must obtain verifiable consent from a parent or guardian, and section 9(3) flatly prohibits tracking, behavioral monitoring and targeted advertising directed at children. GDPR Art. 8 sets the age at 16 for information society services offered to a child, lets member states go as low as 13, and has no outright advertising ban. A consumer product that is age-gated at 13 or 16 for Europe is age-gated wrong for India.

5. Rights and duties of the individual

The DPDP Act gives four rights: access to a summary of the data and processing, correction and erasure, grievance redressal, and the right to nominate someone to exercise those rights on death or incapacity. There is no right to data portability, no right to object, no restriction right and no right against solely automated decisions. The Rules require the fiduciary to publish a response period for rights requests of no more than 90 days; GDPR Art. 12(3) gives one month, extendable by two.

Uniquely, section 15 imposes duties on the individual: not to impersonate anyone, not to suppress material information, and not to file false or frivolous complaints. The Schedule attaches a penalty of up to ₹10,000. A data subject under GDPR has no duties at all.

6. Accountability roles: the Significant Data Fiduciary

Under GDPR, a DPO is mandatory for public bodies and for large-scale monitoring or special-category processing, a DPIA is mandatory for any high-risk processing, and processors carry direct obligations of their own under Art. 28. The DPDP Act puts all of that on a class the Central Government designates.

A Significant Data Fiduciary must appoint a Data Protection Officer who is based in India and answers to the board, appoint an independent data auditor, and run a periodic Data Protection Impact Assessment and audit, which rule 13 sets at once every twelve months with a report of significant observations to the Board. Everyone else is subject to section 8’s general duties, and section 8(1) makes the fiduciary responsible for compliance regardless of what its processor does. A DPDP data processor has no direct statutory obligations; the processor contract carries the load.

7. Breach notification: no risk threshold

Breach handling is where a DPDP Act vs GDPR gap analysis usually finds the most rework. GDPR Art. 33 requires notification to the supervisory authority within 72 hours unless the breach is unlikely to result in a risk, and Art. 34 requires telling individuals only where the risk is high. Section 8(6) of the DPDP Act has no threshold: every personal data breach is reported to the Data Protection Board and to each affected Data Principal. Rule 7 sets the mechanics.

Individuals are told without delay. The Board gets an initial description without delay and then, within 72 hours, the detailed facts, the measures taken and any findings on who caused it. That sits on top of the separate CERT-In direction requiring cyber incidents to be reported within six hours, so an Indian breach playbook has three clocks where a European one has two.

8. International transfers: a blacklist, not a whitelist

On transfers the DPDP Act vs GDPR positions are mirror images. GDPR Chapter V starts from prohibition and lets data out through adequacy decisions, standard contractual clauses, binding corporate rules or a derogation. Section 16 inverts that. Transfers are permitted to any country except one the Central Government has notified as restricted, and rule 15 adds that the government may set conditions on particular categories of data. No SCC equivalent exists. The catch is section 16(2): any sectoral law with a stricter rule, such as the RBI’s payment data localization direction, continues to apply on top.

9. Penalties: fixed caps, and no compensation route

GDPR fines scale with the company, up to €20 million or 4% of worldwide annual turnover, and Art. 82 gives individuals a right to compensation. The DPDP Act’s Schedule uses fixed rupee ceilings per category of breach, and section 34 credits everything the Board collects to the Consolidated Fund of India. There is no compensation claim through the Board.

Breach under the DPDP ActSectionMaximum penalty
Failure to take reasonable security safeguards8(5)₹250 crore (about $26 million at September 2026 rates)
Failure to notify the Board or affected individuals of a breach8(6)₹200 crore
Breach of the children’s data obligations9₹200 crore
Breach of Significant Data Fiduciary obligations10₹150 crore
Any other provision of the Act or Rules₹50 crore
Breach of duties by a Data Principal15₹10,000

For a large group the GDPR ceiling is higher. For a company with less than about $650 million in turnover, ₹250 crore is the bigger number, and it applies whether you are a 50-person SaaS firm or a conglomerate.

What a GDPR program still lacks under the DPDP Act vs GDPR test

Run the DPDP Act vs GDPR test against an existing program and the result is consistent. If you already run a GDPR program, the records of processing, retention schedule, processor contracts, breach procedure and security controls transfer with light edits. Five things do not.

  • A consent-first lawful basis map. Every processing activity currently justified by legitimate interests or contract needs to be re-based on consent or on a section 7 legitimate use, and the ones that cannot be need to stop or be redesigned.
  • A standalone, itemized notice that meets rule 3 without cross-referring to your privacy policy.
  • An age gate at 18 with verifiable parental consent under rule 10, and the removal of any behavioral advertising aimed at minors.
  • A no-threshold breach procedure with three clocks: without delay to individuals, without delay then 72 hours to the Board, six hours to CERT-In.
  • A Significant Data Fiduciary decision, written down, with the India-based DPO, independent auditor and annual DPIA ready if the answer is yes.

Companies that have already mapped GDPR against another consent-led regime will recognize the pattern; our Saudi PDPL vs GDPR comparison shows the same lawful-basis problem arising in a different jurisdiction.

When the DPDP Act actually applies

Timing is the last DPDP Act vs GDPR difference that matters, because GDPR has applied since 25 May 2018 and the DPDP Act is still commencing. The Act received assent on 11 August 2023 but its obligations were switched on by notification in three tranches from 13 November 2025. The Data Protection Board provisions took effect immediately.

Consent Manager registration under rule 4 commences on 13 November 2026. Everything that governs processing, including notice, consent, security safeguards, breach intimation, children’s data, Significant Data Fiduciary duties, rights and transfers, commences on 13 May 2027. The full commencement table is in our guide to the DPDP Act timeline, and the rule-by-rule obligations are in the DPDP Rules 2025 guide.

Frequently asked questions

Does GDPR compliance mean I comply with the DPDP Act?

No. The DPDP Act vs GDPR overlap covers governance, records, security and breach handling, but the DPDP Act has no legitimate-interests basis, a higher age of consent, a no-threshold breach duty and a standalone notice standard that a GDPR notice usually fails. Treat a GDPR program as a head start of roughly two-thirds.

Which law has the bigger fine, the DPDP Act or GDPR?

It depends on turnover. In the DPDP Act vs GDPR penalty comparison, GDPR’s ceiling is €20 million or 4% of worldwide annual turnover, whichever is higher. The DPDP Act’s is a fixed ₹250 crore, about $26 million, for a security safeguards failure. Below roughly $650 million in turnover the DPDP ceiling is larger.

Does the DPDP Act require a Data Protection Officer?

Only for a Significant Data Fiduciary designated by the Central Government. That DPO must be based in India, be responsible to the board and be the contact point for grievances. Every other fiduciary must publish the contact details of a person able to answer questions about its processing.

Does the DPDP Act restrict data transfers outside India?

Only to countries the Central Government notifies as restricted. There is no adequacy or SCC mechanism to satisfy. Stricter sectoral localization rules, such as those for payment data, continue to apply.

When do the DPDP Act obligations start?

Consent Manager registration from 13 November 2026; the substantive obligations on data fiduciaries, including notice, consent, breach reporting and children’s data, from 13 May 2027.

The short version

DPDP Act vs GDPR comes down to consent. GDPR lets you process on legitimate interests and asks you to justify it; the DPDP Act asks for consent or one of nine listed uses and does not negotiate. Layer on a child defined as under 18, a breach duty with no risk threshold, a blacklist transfer model, penalties capped in rupees rather than percentages, and a Data Protection Officer only when the government says so, and the shape of the work is clear: keep the GDPR governance, rebuild the lawful basis map, the notice and the age gate, and have it running before 13 May 2027.

References. MeitY, Data Protection Framework (the Act, the Rules and the commencement notifications); Regulation (EU) 2016/679 (GDPR). Section and rule references are to the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as notified on 13 November 2025.

More on privacy compliance. The seven GDPR principles; handling data subject requests. The DPDP notice, consent record, breach intimation and Significant Data Fiduciary templates are in the DPDP Act Toolkit (91 privacy templates, $99), and the European side is covered by the GDPR Toolkit.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.