DPDP Act vs GDPR: Side-by-Side for Compliance Professionals

DPDP Act Vs GDPR: For Compliance Professionals

DPDP Act vs GDPR is a comparison of two statutes that share a vocabulary and diverge on almost every count a compliance programme is actually built from. The General Data Protection Regulation (Regulation (EU) 2016/679) runs on six lawful bases, eight data subject rights, a risk threshold that decides whether a breach is reported at all, and fines pegged to 4% of worldwide turnover. The Digital Personal Data Protection Act, 2023 runs on consent plus nine listed legitimate uses, four Data Principal rights, no breach threshold of any kind, and fixed rupee ceilings that stop at 250 crore. Neither text maps cleanly onto the other, and the Indian substantive duties bind nobody until 13 May 2027.

This article sets out DPDP Act vs GDPR as the two texts actually state the position.

Quick context first: the distance between the two regimes shows up in enforcement volume. The CMS GDPR Enforcement Tracker Report 2025/2026 logged 2,685 publicly documented fines totalling roughly 6.11 billion euro to a cut-off of 1 March 2026. India’s count is zero, and it stays zero for a reason unrelated to compliance rates: the Data Protection Board of India was established in November 2025 and still had no appointed Chairperson and no appointed Members as of 1 August 2026 (a moving fact, and the line on this page most likely to have changed by the time it is read).



Scope and roles under DPDP Act vs GDPR

Scope under DPDP Act vs GDPR separates on three measures: what counts as covered data, what triggers reach over a foreign company, and how many categories of personal data the law recognises. On the third measure the answer is nine against one.

Start with material scope, because it decides which filing cabinets are in the audit. Article 2(1) of the GDPR reaches processing wholly or partly by automated means, and it also reaches non-automated processing of personal data that forms part of a filing system. Section 3(a) of the DPDP Act reaches digital personal data collected in digital form, or collected in non-digital form and digitised subsequently. A paper personnel file sitting in a Frankfurt office is regulated; the same file in a Pune office is outside the Indian Act entirely until somebody scans it.

Territorial reach splits the same way, on one limb rather than two. Article 3(2) catches a non-EU controller that offers goods or services to people in the Union, and separately catches one that monitors their behaviour. Section 3(b) carries only the first of those, applying to processing outside India that is in connection with any activity related to offering goods or services to Data Principals in India.

So what happens to a foreign adtech or analytics operation that tracks Indian users without selling them anything? On the text of section 3(b), it sits outside the Act. That asymmetry is the single widest gap in coverage between the two laws, and it has no counterpart running the other way.

The Indian Act also carries an exclusion the GDPR has no general analogue for. Section 3(c)(ii) removes personal data that the Data Principal has made publicly available, or that another person is legally obliged to publish. But Article 9(2)(e) does something much narrower, lifting only the prohibition on special-category processing for data manifestly made public, while every other GDPR obligation continues to apply.

Here’s the count that matters most for anyone porting a data map. Article 9 lists nine special categories, from racial or ethnic origin through to health and sexual orientation, and Article 10 adds criminal conviction data on top (ten protected classes before a single national derogation). The DPDP Act recognises exactly one undifferentiated class of personal data. A patient’s diagnosis and a marketing email address carry identical statutory treatment in India, with identical consent requirements and identical penalty exposure.

Worth flagging: India does currently tier sensitivity, just not under this Act. The SPDI Rules of 2011 do it, and they hang off section 43A of the Information Technology Act, 2000, which the DPDP Act deletes in the same eighteen-month tranche. India loses its only sensitivity tier on the day the new regime arrives.

The role names transfer almost intact. A Data Fiduciary is a controller, a Data Processor is a processor, and a Data Principal is a data subject. But liability does not transfer with the names.

Articles 28(3), 30(2), 32, 33(2) and 37 impose direct statutory duties on an EU processor, and Article 82 exposes it to direct claims. Section 8(1) instead makes the Data Fiduciary responsible for compliance whatever the contract says. The practical reality is that Indian processor exposure is contractual first and statutory barely at all.

The officer positions diverge furthest. Article 37(1) makes a Data Protection Officer mandatory on three self-assessed triggers, so a mid-size EU company can work out for itself that it needs one. Section 10(2)(a) attaches the DPO only to a Significant Data Fiduciary, which arrives by Central Government designation rather than self-assessment, and no entity or class has been designated (the position on designation is set out in the DPDP Act compliance checklist). Every other Indian business owes section 8(9) instead: publish contact details for someone able to answer questions about the processing.

And one Indian role has no European counterpart at all. The Consent Manager under rule 4 of the Digital Personal Data Protection Rules, 2025 is a registered intermediary, requiring incorporation in India and a net worth of not less than two crore rupees, with registration opening on 13 November 2026.

DPDP Act vs GDPR, side by side

Eight measures a compliance programme is actually built from Position as of 8 September 2026
Measure
GDPRRegulation (EU) 2016/679, in force since 2018
DPDP Act, 2023Substantive duties commence 13 May 2027
Material scopeWhat data is covered
Automated processing, and non-automated data in a filing system. Paper files included.Article 2(1)
Digital personal data only, or non-digital data digitised later. Paper files excluded.Section 3(a)
Extraterritorial reachWhich foreign firms are caught
Two limbs. Offering goods or services, and monitoring behaviour in the Union.Article 3(2)
One limb. Offering goods or services to Data Principals in India. Monitoring alone is not caught.Section 3(b)
Sensitivity tiersCategories of personal data
Ten. Nine special categories, plus criminal conviction data.Articles 9 and 10
One. A single undifferentiated class. A diagnosis and an email address rank alike.Section 2(t)
Lawful basesGrounds to process
Six, including legitimate interests and contract necessity.Article 6(1)
Consent, or one of nine listed legitimate uses. No legitimate interests, no balancing test.Sections 4 and 7
Individual rightsWhat a person can demand
Eight. Access, rectification, erasure, restriction, portability, objection, automated decisions.Articles 15 to 22
Four. Summary of data, correction and erasure, grievance redressal, nomination.Sections 11 to 14
Child thresholdAge and advertising
16, and a Member State may lower it to 13. Applies to consent-based online services.Article 8
18 for every purpose. Tracking, behavioural monitoring and targeted ads barred outright.Sections 2(f) and 9
Breach reportingThreshold and clocks
72 hours to the authority, unless the breach is unlikely to be risky. The individual is told only on high risk.Articles 33 and 34
No threshold. Every affected person told without delay, the Board without delay then in detail within 72 hours.Rule 7
Cross-border transferThe default position
Default deny. Barred unless adequacy, safeguards such as standard clauses, or a derogation applies.Chapter V, Articles 44 to 49
Default allow. Permitted except to countries the Central Government notifies. None notified so far.Section 16(1), rule 15
On one side only: four items with no counterpart in the other law
GDPR only: portability and the right to be forgotten
GDPR only: direct statutory duties on processors
DPDP only: nomination of a person to exercise rights
DPDP only: the registered Consent Manager
Response clocks are not comparable. The GDPR requires action on a rights request within one month, extendable by two further months (Article 12(3)). The DPDP Act sets no clock on a rights request at all, and the ninety days quoted everywhere is rule 14(3)’s ceiling on grievance response, which measures something different.
Source: the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, Ministry of Electronics and Information Technology; Regulation (EU) 2016/679, EUR-Lex. Indian substantive obligations commence 13 May 2027 and bind nobody today.
SkillArbitrage

Lawful basis and individual rights

Lawful basis is where the two regimes are furthest apart in structure, not just in detail. Article 6(1) of the GDPR offers six bases and lets the controller pick. Section 4 of the DPDP Act offers two footings only, consent or one of the legitimate uses listed in section 7, and section 7 closes at nine specific entries.

Advertisement

So which European basis has no Indian equivalent at all? Article 6(1)(f), legitimate interests: there’s no balancing test in the Act, no equivalent provision in the Rules, and no residual category in section 7. Article 6(1)(b), necessity for a contract, has no direct analogue either, and the nearest thing is section 7(a), which covers a specified purpose for which the Data Principal has voluntarily provided personal data without indicating an objection. That one collapses the moment an objection is registered.

This is where most GDPR programmes lose their footing on the way to India. Fraud detection, network security monitoring, product analytics and much of direct marketing run on legitimate interests in Europe, precisely because consent for them is impractical. Re-based on Indian consent, all of it becomes withdrawable under section 6(4), and withdrawal then triggers erasure under section 8(7) unless a law requires retention.

Here’s what that actually looks like.

Take a payments company running device-fingerprint fraud scoring across its EU and Indian user bases. In the EU the basis is Article 6(1)(f), documented in a legitimate interests assessment, and no user can switch it off. In India the same processing needs section 6 consent, so it appears in the notice as a purpose the user can decline, and a withdrawal obliges the company to stop scoring that account and to cause its processors to stop within a reasonable time.

The mistake we see most often is treating that as a paperwork exercise. It isn’t. A risk control that was an internal decision in one jurisdiction becomes a user-facing toggle in the other, and the consent and notice rules make the withdrawal route as easy as the consent route by statute.

The traffic runs the other way on employment. Section 7(i) gives an Indian employer a standing ground covering employment purposes and safeguarding the employer from loss or liability, including protection of trade secrets and provision of services or benefits to employees. But nothing in Article 6 is drafted that broadly for employers, so an EU employer falls back on a legitimate interests assessment for the same processing.

Children are the sharpest single divergence. Article 8 sets the consent age at 16, lets a Member State lower it to 13, applies only to information society services offered directly to a child, and bites only where consent is the basis. Section 2(f) of the DPDP Act sets 18 for every purpose, section 9(1) requires verifiable parental consent, and section 9(3) prohibits tracking, behavioural monitoring and advertising directed at children outright, with no consent override available. A 17-year-old is an adult for a German social app and a child for the same app in India.

Bottom line: rights drop from eight to four. Articles 15 to 22 give access, rectification, erasure, restriction, portability, objection and a right not to be subject to solely automated decisions. Sections 11 to 14 give a summary of personal data, correction and erasure, grievance redressal, and nomination. Portability and the right to be forgotten did not survive into the 2023 Act (both sat in the 2019 Bill, which was withdrawn in 2022), and restriction, objection and the automated-decision right were never in an Indian draft at all.

Nomination runs the other way. Section 14 lets an individual nominate one or more people to exercise their rights in the event of death or incapacity, which the GDPR leaves entirely to national law under Recital 27.

So what does the difference mean for a rights request? Response clocks favour the European reader by a wide margin. Article 12(3) requires action within one month of receipt, extendable by two further months where the request is complex. The DPDP Act sets no statutory clock on a rights request at all, and the ninety days quoted everywhere comes from rule 14(3), which caps the response under a grievance redressal system rather than a section 11 access request.

Thirty days against ninety, then, and the ninety measures something different. For anyone building this into a practice, whether in-house or as a data privacy consultant, the re-basing work is the billable part rather than the gap analysis.

Breach reporting and transfers under DPDP Act vs GDPR

Breach reporting and transfers under DPDP Act vs GDPR invert each other. India is materially stricter on notification and materially looser on export, and a programme built for Europe gets both wrong in the same direction.

Breach reporting

The GDPR reports breaches conditionally. Article 33(1) requires notification to the supervisory authority without undue delay and where feasible within 72 hours, unless the breach is unlikely to result in a risk to rights and freedoms, and Article 33(5) lets the controller document a non-reportable breach internally instead. Article 34(1) reaches the individual only where the breach is likely to result in a high risk, and Article 34(3) then supplies three ways out, including encryption and a public communication where individual contact would be disproportionate.

But rule 7 of the DPDP Rules, 2025 carries no threshold anywhere in it. Rule 7(1) requires the Data Fiduciary, on becoming aware of any personal data breach, to intimate each affected Data Principal without delay, in a concise, clear and plain manner, through the user account or a registered mode of communication. Rule 7(2) then requires the Board to be told without delay in outline, and within 72 hours in detail, covering the events and circumstances, the mitigation measures, any findings on who caused it, the remedial steps and a report on what the affected individuals were told.

In practice, though, the delta is wider than the shared 72-hour figure suggests. A low-risk EU incident, say an internal email sent to the wrong colleague and recalled within minutes, is logged under Article 33(5) and goes no further. The same incident in India is a two-channel unconditional notification, and failing to make it carries the second-highest ceiling in the Schedule at 200 crore rupees (the full ladder sits in the DPDP Act penalties post).

So how many clocks does an Indian company actually run? Three, not one. The CERT-In Directions of April 2022, issued under section 70B(6) of the IT Act, require a listed cyber incident to be reported within six hours of noticing it (six hours rather than seventy-two, and the two clocks start from different trigger events), and nothing in the DPDP Act or the Rules replaces, extends or absorbs that deadline.

Cross-border transfers

Chapter V of the GDPR is default-deny. Articles 44 to 49 prohibit a transfer to a third country unless it rests on an adequacy decision under Article 45, appropriate safeguards under Article 46 such as standard contractual clauses or binding corporate rules, or one of the narrow derogations in Article 49.

Section 16(1) of the DPDP Act is default-allow. It restricts transfer only to countries the Central Government notifies, and not one country has been notified. Rule 15 adds a single further condition, requiring the Data Fiduciary to meet whatever requirements the Central Government specifies about making personal data available to a foreign State or an entity under its control. Rule 13(4) layers localisation on top, but only for Significant Data Fiduciaries and only for categories the Government specifies later, so it currently binds nobody.

This is where most India entry plans go wrong. Section 16(2) leaves sectoral rules untouched, and the Reserve Bank of India’s payment system data direction and the IRDAI’s record-keeping rules are where the real Indian export restriction lives. The DPDP Act relaxes neither.

Frankly, this gets overlooked. A professional who reads only the Act concludes Indian transfers are unregulated, which is the wrong answer reached by correct reading of the wrong instrument.

Penalties differ in structure rather than in severity, which the headline figures hide. Article 83(5) sets the top GDPR tier at 20 million euro or 4% of total worldwide annual turnover, whichever is higher, so exposure scales with the company. But the DPDP Schedule sets fixed rupee ceilings topping out at 250 crore, with no percentage and no floor, so it bites hardest on mid-market Indian firms and softest on the largest multinationals.

Frequently asked questions

Does GDPR compliance make an organisation DPDP compliant?

Four Indian requirements have no GDPR source to inherit: verifiable parental consent under section 9(1) for everyone under 18, the section 9(3) ban on tracking children, unconditional breach notification under rule 7, and rule 3(a)’s standalone notice test.

Is the DPDP Act stricter than the GDPR?

On three measures India is stricter: every breach is reportable with no risk threshold, the child age is 18 rather than 16, and section 9(3) bars child-directed advertising outright. On lawful basis and rights it’s narrower, with four rights against eight. DPDP Act vs GDPR is a design difference.

Which law applies when an Indian company processes personal data of EU residents?

Both apply cumulatively. Article 3(2)(a) reaches the Indian company because it offers goods or services to people in the Union, and section 3(a) reaches the same processing because it happens within India. Compliance with one is never a defence to the other.

Does the DPDP Act require a record of processing activities like GDPR Article 30?

Rule 6(1)(e) requires logs to be retained for one year, and section 8(1) makes the Data Fiduciary responsible for demonstrating compliance whatever its contracts say. Neither creates the standing register that GDPR Article 30 records of processing mandates.

References

Official guidance and regulations

  1. CERT-In Directions under section 70B(6) of the Information Technology Act, 2000. Indian Computer Emergency Response Team, April 2022
  2. Digital Personal Data Protection Act, 2023 (No. 22 of 2023). Ministry of Electronics and Information Technology
  3. Digital Personal Data Protection Rules, 2025, G.S.R. 846(E). MeitY, 13 November 2025
  4. Notification G.S.R. 843(E), commencement of the DPDP Act, 2023. MeitY, 13 November 2025
  5. Regulation (EU) 2016/679, General Data Protection Regulation. EUR-Lex, European Union
  6. The Digital Personal Data Protection Bill, 2023, legislative history. PRS Legislative Research

Data and research

  1. GDPR Enforcement Tracker Report 2025/2026, numbers and figures. CMS, cut-off 1 March 2026

This article is for informational and educational purposes only and does not constitute legal, professional or compliance advice. Data protection obligations under the Digital Personal Data Protection Act, 2023 and the General Data Protection Regulation depend on the specific facts of a processing operation. Consult a qualified professional before acting on any compliance decision.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *