DPDP Act vs GDPR — Quick Summary

The table below captures the headline comparison across every major dimension. Each row is explained in depth in the sections that follow.

DimensionDPDP Act (India)GDPR (EU)
JurisdictionIndiaEU + EEA
EnactedAugust 2023May 2018
Territorial scopeIndian citizens' data globallyData of EU residents globally
Data subject rights4 rights8 rights
Consent basisConsent + legitimate state functionsConsent + 5 other legal bases
Legitimate interest basisNoYes (Article 6(f))
DPO requirementSignificant Data Fiduciaries onlyPublic bodies + high-risk processors
Max penalty₹250 crore (~€27M)€20M or 4% global turnover
Breach notification72 hours (draft Rules)72 hours to authority
Data portability rightNoYes (Article 20)
Right to objectNoYes (Article 21)
Children's age threshold1816 (varies by member state, min 13)
Data localisationApproved-country list (pending)Adequacy decisions + SCCs

1. The Number of Rights — 4 vs 8

This is the most visible structural difference between the two frameworks. GDPR gives individuals 8 rights; the DPDP Act gives 4.

GDPR's 8 rights

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure — the "right to be forgotten" (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object to processing (Article 21)
  • Rights related to automated decision-making and profiling (Article 22)
  • Right to withdraw consent at any time

DPDP Act's 4 rights (Data Principal rights)

  • Right to access information about personal data (Section 11)
  • Right to correction and erasure (Section 12)
  • Right to grievance redressal (Section 13)
  • Right to nominate a person to exercise rights in case of death or incapacity (Section 14)

Key missing DPDP rights that GDPR provides: the right to data portability (users cannot extract their data and take it to another service), the right to object to processing (users can only withdraw consent, not object to processing on other grounds), the right to restrict processing, and rights related to automated profiling decisions.

Unique to DPDP

The right to nominate — which allows a Data Principal to designate another person to exercise their data rights after death or incapacity — has no GDPR equivalent. This reflects India's cultural context around digital succession and is a genuine DPDP innovation.

GDPR gives controllers 6 lawful bases for processing personal data (Article 6): consent, contract, legal obligation, vital interests, public task, and legitimate interests. In practice, most commercial organisations rely on consent, contract, and legitimate interests.

The DPDP Act is significantly narrower. It recognises essentially 2 categories of lawful basis: (1) consent, and (2) "certain legitimate uses" — which are narrowly defined state or legally mandated functions such as compliance with court orders, medical emergencies, employment-related processing, and government services. There is no broad legitimate interest basis equivalent to GDPR Article 6(1)(f).

This is a critical compliance gap for organisations operating under both frameworks. Activities that European teams process under legitimate interest — marketing analytics, fraud prevention, network security monitoring, internal data sharing within corporate groups — all need a consent basis under the DPDP Act. This means consent notices, consent records, and consent withdrawal mechanisms for processing that GDPR never required consent for.

If your compliance programme relies heavily on GDPR's legitimate interest basis, your single biggest DPDP gap is consent management for Indian users. Every LI-based activity needs review.

3. Penalties — ₹250 Crore Cap vs 4% Global Turnover

The penalty structures differ in absolute amount, structure, and scaling. GDPR's penalties are intentionally designed to hurt large multinationals; the DPDP Act's penalty cap is significant for Indian businesses but modest by GDPR standards for global companies.

DPDP Act penalty tiers

₹250 Cr
Most serious violations
Failure to implement adequate security safeguards; breach of children's data obligations
₹200 Cr
Breach notification failure
Failure to notify the Data Protection Board of a personal data breach as required
₹50 Cr
Operational failures
Failure to honour Data Principal rights; failure to maintain data accuracy; non-cooperation with Board

GDPR's maximum is €20 million or 4% of global annual turnover, whichever is higher. For a company with €1 billion in global revenue, a GDPR fine can reach €40 million — more than 1.5× the DPDP Act's highest penalty ceiling. For a company with €5 billion in global revenue, the GDPR maximum is €200 million versus DPDP's ₹250 crore (~€27M).

For purely Indian mid-market companies, however, ₹250 crore is a material and existential risk. The DPDP penalty structure is calibrated to the Indian market — not to the global enterprise.

4. DPO Requirement — All High-Risk vs Designated Subset

Under GDPR, a Data Protection Officer is mandatory for: public authorities and bodies, organisations whose core activities require large-scale systematic monitoring of individuals, and organisations whose core activities involve large-scale processing of special category data. Thousands of organisations across Europe maintain DPOs as a result — and the DPO must be registered with the national supervisory authority.

Under the DPDP Act, a DPO is only mandatory for Significant Data Fiduciaries — a smaller, government-designated subset of organisations that process data at scale or with elevated risk. The Central Government has not yet published the SDF designation list, but the most likely candidates are large social media platforms, fintech companies, telecom operators, and health data processors.

The practical implication: most Indian organisations have no DPO obligation under the DPDP Act, even if they process substantial volumes of personal data, as long as they are not designated as SDFs. This is a significant difference in compliance burden for the broad mid-market.

5. Children's Age Threshold — 18 vs 16

The DPDP Act sets 18 as the default age below which parental or guardian consent is required before processing a child's personal data. GDPR sets the threshold at 16, with member states permitted to lower it to a minimum of 13.

This creates a meaningful operational difference for platforms targeting young adults. A 17-year-old in Germany can consent to data processing independently under GDPR; the same person, as an Indian resident, cannot consent without parental verification under the DPDP Act. Platforms serving both markets must implement different consent flows by jurisdiction.

The DPDP Act also prohibits targeted advertising directed at children and requires that Data Fiduciaries not track, monitor, or engage in behavioural advertising toward children — provisions that broadly mirror but extend GDPR's approach to children's data.

6. Cross-Border Transfers — Approved List vs Adequacy Decisions

GDPR has a mature cross-border transfer framework built over 25+ years: adequacy decisions (covering 30+ countries including the UK, Japan, South Korea, and most recently the US via the Data Privacy Framework), Standard Contractual Clauses, Binding Corporate Rules, and derogations for specific situations.

The DPDP Act takes a different approach: the Central Government will publish a list of approved countries to which personal data of Indian residents can be transferred. Until that list is published — which has not yet occurred — the cross-border transfer position remains uncertain. There is no DPDP equivalent of SCCs or BCRs for transfers to non-approved countries.

Transfer uncertainty

Until India's approved country list is published, organisations should document their cross-border transfer flows and be prepared to restrict or restructure them if their destination countries are not approved. Cloud providers, payroll processors, and marketing platforms sending Indian personal data offshore are most exposed to this risk.

7. Data Localisation — Sector-Specific vs GDPR Framework

GDPR does not require data localisation — it facilitates the free flow of personal data within the EEA and provides transfer mechanisms for data moving outside. Data can be stored anywhere that meets the transfer requirements.

The DPDP Act does not impose blanket localisation either, but sector-specific regulators in India have their own requirements that continue to apply alongside the DPDP Act. The Reserve Bank of India requires payment data to be stored only in India. SEBI, IRDAI, and other sectoral regulators have their own localisation rules. Children's data under the DPDP Act may face additional storage restrictions once Rules are published.

For multinational organisations with Indian operations, the effective localisation requirement comes from sector regulators — not the DPDP Act directly. But DPDP compliance programmes must account for these sector requirements as part of their data mapping exercise.

8. Data Processor Obligations — Direct vs Via Fiduciary

GDPR gives Data Processors direct obligations under Chapter IV of the regulation. Processors must: maintain records of processing activities, implement appropriate security measures, notify controllers of breaches without undue delay, appoint a DPO in some cases, and not engage sub-processors without controller authorisation. Processors can be fined directly by supervisory authorities.

The DPDP Act takes a fundamentally different approach. Data Processors have no direct obligations under the DPDP Act — their obligations flow entirely through their contract with the Data Fiduciary. The Data Fiduciary is responsible for ensuring that processors comply; the Board can hold the Fiduciary liable for processor failures.

This means that cloud providers, payroll processors, marketing platforms, and CRM vendors serving Indian businesses are not directly regulated by the DPDP Act. The burden falls on their clients — the Data Fiduciaries — to impose appropriate contractual obligations on processors and verify compliance.

9. Right to Data Portability — GDPR Has It, DPDP Doesn't

GDPR Article 20 gives individuals the right to receive their personal data "in a structured, commonly used and machine-readable format" and to transmit that data to another controller. This is the legal backbone of account switching in banking, healthcare records transfer, and social media data exports.

The DPDP Act has no data portability right. Data Principals can request access to their data and can request correction or erasure — but they cannot demand it in a machine-readable format or compel the Data Fiduciary to transfer it to a competitor.

This is viewed by digital rights advocates as a significant gap, particularly for fintech, healthtech, and BNPL sectors where portability would accelerate competition and consumer choice. It is possible that future DPDP Rules or sector-specific regulations (such as RBI's Account Aggregator framework for financial data) will create portability mechanisms — but the base DPDP Act does not.

10. Enforcement Body — Data Protection Board vs Supervisory Authorities

GDPR is enforced by national supervisory authorities — the ICO in the UK (post-Brexit), the CNIL in France, the BfDI in Germany, and so on. These are established, well-resourced regulatory bodies with significant enforcement track records. Since GDPR came into force in May 2018, over 5,000 fines totalling more than €4 billion have been issued.

The DPDP Act creates a new body — the Data Protection Board of India — as the enforcement authority. The Board is not yet operational; appointments and procedural rules are expected in 2026–27. This means that, unlike GDPR where regulatory risk is real and documented, DPDP enforcement risk is still building.

Organisations that treat this as a reason to delay compliance are making a governance error. The Board will be operational, it will have penalty powers up to ₹250 crore, and organisations that have not built compliance infrastructure before enforcement begins will face a catch-up problem under regulatory scrutiny. The GDPR experience — where many companies scrambled to comply only after enforcement began — is a clear cautionary tale.

If You're GDPR-Compliant, How Much More Work Is DPDP?

Good news: GDPR compliance gives you roughly 80% of DPDP compliance. The foundational security safeguards, breach notification processes, data mapping, consent infrastructure, and Data Principal rights workflows all transfer with minimal modification. The legal concepts — lawful basis, purpose limitation, data minimisation, storage limitation — are structurally similar.

Gap areas to address for DPDP

  • Consent notice format: The DPDP Act requires consent notices to be presented in plain language, per-purpose, and in Indian languages if the Data Principal requests. GDPR-standard privacy notices typically do not meet these requirements.
  • Legitimate interest processing: Not a valid DPDP basis. Review every activity your team processes under GDPR legitimate interest and determine whether Indian users can be moved to consent — or whether the processing should stop for Indian data.
  • Right to nominate: A new right with no GDPR equivalent. You must build the infrastructure to accept, record, and act on nominations from Data Principals.
  • Grievance mechanism: The DPDP Act requires a dedicated grievance contact for Indian users — a named officer, a contact process, and a defined response timeline. This must be disclosed in your consent notice.
  • Children's data — 18 threshold: If you currently treat 16–17 year olds as adults for consent purposes (as GDPR allows), you need to reconfigure your age verification and consent flows for Indian users to treat 16–17 year olds as children requiring parental consent.
  • Processor contracts: Review all your Data Processing Agreements for GDPR. Indian versions need different structuring — the obligations flow to the Fiduciary, not the Processor, so your contracts with Indian processors need to reflect DPDP-specific requirements rather than GDPR DPA templates.
DPDP compliance guide

For the complete DPDP Act compliance framework — obligations, rights, penalties, timeline, and readiness checklist — see our DPDP Act compliance guide. For a structured task list, use the free DPDP compliance checklist.

What GDPR compliance does not give you

Beyond the specific gaps above, GDPR compliance gives you no ready-made answer to the Significant Data Fiduciary question. If your India operations are large enough to qualify for SDF designation, you will need to build DPO infrastructure, DPIA processes, and independent audit capability — none of which GDPR's DPO requirements map neatly onto, given the different scope and governance structure the DPDP Act uses for SDFs.

The DPDP Rules 2025 — still pending final notification — will add further specificity around notice formats, breach timelines, children's data verification, and SDF obligations. Organisations with active GDPR compliance programmes should track these Rules closely and build their India compliance programme to be updated incrementally as Rules are published.