Data Protection

DPDP Act vs GDPR: 12 Differences That Change Your Compliance Strategy

4 June 20266 min read

If your organisation already complies with the GDPR, the tempting assumption is that India's DPDP Act 2023 is covered by the same programme. It is not, and the gaps sit in expensive places: a missing legal basis your European processing relies on, an 18-year consent threshold, and a breach notification duty with no risk filter.

Here are the 12 differences that matter most, and what each one means for your compliance programme.

The Side-by-Side Comparison

DimensionDPDP Act 2023 (India)GDPR (EU)
ScopeDigital personal data onlyAll personal data (digital and non-digital)
Legal basesConsent + a closed list of legitimate uses6 legal bases (Art. 6) + special categories (Art. 9)
"Legitimate interests" basisDoes not existArt. 6(1)(f), widely used
Consent standardFree, specific, informed, unconditional, unambiguousFreely given, specific, informed, unambiguous
Children's age thresholdUnder 18, no variationUnder 16 (Member States may lower to 13)
Cross-border transfersNegative list: allowed unless restrictedAdequacy model: blocked unless approved
Data Principal dutiesYes, with a ₹10,000 penaltyNo duties on data subjects
Maximum penalty₹250 crore, fixed cap per breach type€20M or 4% of global turnover, whichever is higher
Breach notification to individualsAlways, without delay, no risk filterOnly when "high risk" to the individual
Right to portabilityNot includedYes (Art. 20)
DPO requirementSignificant Data Fiduciaries onlyPublic authorities + large-scale processors
RegulatorOne national body (the DPB)One per Member State + EDPB coordination

Key Takeaway

GDPR compliance does not equal DPDP compliance. The DPDP Act is narrower in scope but stricter on children's data and breach notification, has no legitimate-interests basis, and uses a penalty structure that does not scale with revenue. India needs its own compliance workstream.

Where the DPDP Act Is Narrower

1. Digital Data Only

The GDPR covers personal data in any form: paper files, audio, CCTV. The DPDP Act covers digital personal data only, plus data collected on paper and later digitised. In practice the exclusion shrinks every year, because almost every business process generates digital records anyway.

The GDPR offers six legal bases. The DPDP Act recognises exactly two routes: consent, or a closed list of legitimate uses in Section 7.

This is the single biggest operational difference. Processing that European businesses justify under legitimate interests (fraud prevention, direct marketing, network security) has no equivalent justification under the DPDP Act. There is no balancing test to run. You find consent or a Section 7 ground, or you stop processing.

3. No Right to Data Portability

GDPR Article 20 lets individuals demand their data in a machine-readable format. The DPDP Act has no portability right: Data Principals can access and request deletion, but not a portable export.

4. No Standalone Right to Object

GDPR data subjects can object to specific processing, including profiling, while a service continues. Under the DPDP Act the remedy is blunter: withdraw consent, which stops the processing that depended on it.

Where the DPDP Act Is Stricter

5. Children's Data: 18 vs 16

The GDPR default is 16, lowerable to 13 by Member States. The DPDP Act sets it at 18, with no variation, and requires verifiable parental consent below it. A 15-year-old who can lawfully consent in most EU countries cannot consent in India. For EdTech, gaming, and social platforms, this single number reshapes the consent architecture.

Both laws require free, specific, informed, unambiguous consent. The DPDP Act adds unconditional as an explicit statutory requirement: access to a service cannot be conditioned on consent to unrelated processing. The GDPR reaches a similar place through "freely given" and bundling guidance; the DPDP Act writes it into the statute.

7. Individuals Have Duties Too

Unique to the DPDP Act: Section 15 imposes duties on Data Principals, including not filing false or frivolous complaints, not impersonating others, and not suppressing material information, backed by a penalty of up to ₹10,000.

Why This Matters for Businesses

The duties provision gives organisations a counterweight the GDPR lacks. The Board can warn or impose costs on complainants whose cases are found false or frivolous, which discourages weaponised complaints.

Where the Two Laws Diverge Structurally

8. Cross-Border Transfers: Negative List vs Adequacy

The most structurally different provision. The GDPR blocks transfers by default unless an adequacy decision, SCCs, BCRs, or another approved mechanism applies. The DPDP Act allows transfers by default, to any country except those the Central Government specifically restricts by notification. As of June 2026, no country is on the restricted list.

What this means: India-to-abroad transfers are straightforward today, but the list can change by notification, overnight. Build your data architecture so a specific destination can be cut quickly. Our cross-border transfer chapter covers the mechanics.

9. Penalties: Fixed Caps vs Revenue-Linked

GDPR penalties scale with turnover: 4% of global revenue or €20 million, whichever is higher. The DPDP Act uses fixed rupee caps, topping out at ₹250 crore (roughly €27 million) for security-safeguard failures.

The fixed structure cuts both ways. For a mid-size Indian business, ₹250 crore is existential, proportionally far harsher than 4% of turnover. For a global giant, the DPDP cap is lighter than its GDPR exposure. Note also that the Central Government can double any cap by notification, and one incident can stack multiple categories: the penalty framework breakdown runs the numbers.

10. Breach Notification: No Risk Filter

The GDPR requires notifying the authority within 72 hours, and individuals only when the breach poses a high risk to them. The DPDP Act requires notifying the Board without delay with a detailed report within 72 hours, and notifying affected Data Principals without delay, in every case. There is no internal risk assessment that lets you skip telling individuals.

This is the difference most likely to break a GDPR-trained incident response process. The full two-stage timeline, including the parallel 6-hour CERT-In clock, is in our breach notification guide for CISOs.

11. One Regulator vs Many

The GDPR runs through a supervisory authority per Member State with EDPB coordination, lead-authority rules, and cross-border procedures. The DPDP Act has one regulator: the Data Protection Board of India, with one appeals path (TDSAT, then the Supreme Court). Simpler to deal with, and no forum shopping.

12. DPO: By Designation, Not by Activity

The GDPR requires a DPO based on what you do (public authority, large-scale monitoring, special categories at scale). The DPDP Act requires one only for Significant Data Fiduciaries: organisations the Central Government specifically designates. If you are not designated, no DPO is legally required, though large data-heavy businesses should plan for designation rather than assume it away.

The Dual-Compliance Punch List

Running in both India and the EU? These are the concrete deltas to work through:

  • Consent flows: add the unconditional requirement, unbundle purposes, and give the option to access the notice in English or any of the 22 Eighth Schedule languages. Your GDPR consent screens do not transfer as-is.
  • Legitimate-interests inventory: list every processing activity currently justified under Art. 6(1)(f) and find each one a DPDP home: consent or a Section 7 ground. This audit finds the gaps that hurt.
  • Age gates: thresholds of 13 or 16 must become 18 for Indian users, with verifiable parental consent beneath it.
  • Transfers: no SCCs needed for India, but build the kill-switch for restricted destinations.
  • Breach runbook: add an India branch with no risk-assessment gate on individual notification, and the two-stage Board timeline.

Not sure where your organisation stands?

Take the free 3-minute DPDP Readiness Assessment and get a personalised compliance score.

Check Your Readiness

The Bottom Line

The two laws share a goal and diverge on the mechanics that cost money. The DPDP Act is shorter and in places stricter (children's data, unconditional consent, mandatory individual notification); the GDPR is broader and revenue-scaled. Treating GDPR compliance as sufficient for India creates real gaps; treating the two as unrelated duplicates work. The practical path: build India-specific controls where the 12 differences bite, and reuse your GDPR infrastructure everywhere else.

Frequently Asked Questions

Is GDPR compliance enough for the DPDP Act?+

No. The DPDP Act has no legitimate-interests basis, sets the children's consent threshold at 18, requires notifying affected individuals of every breach without a risk filter, and adds an "unconditional" consent requirement. Each of these needs India-specific controls on top of a GDPR programme.

Does the DPDP Act have a legitimate interests basis like GDPR?+

No. The DPDP Act recognises only consent and a closed list of legitimate uses in Section 7, such as voluntary provision, certain State functions, medical emergencies, and employment purposes. Processing justified under GDPR Article 6(1)(f), including most marketing and analytics, needs consent in India.

How do DPDP and GDPR penalties compare?+

The GDPR scales with revenue: up to €20 million or 4% of global turnover, whichever is higher. The DPDP Act uses fixed caps, with a maximum of ₹250 crore (roughly €27 million) for security-safeguard failures, and the Central Government can double any cap by notification.

What is the age of consent for data processing in India vs the EU?+

India: 18, with no variation, and verifiable parental consent required below it. The EU: 16 by default, and Member States may lower it to 13.

How does breach notification differ between DPDP and GDPR?+

Under the GDPR, you notify the authority within 72 hours and individuals only if the breach poses a high risk to them. Under the DPDP Act, you notify the Data Protection Board without delay plus a detailed report within 72 hours, and you notify every affected individual without delay, regardless of risk level.

Does the DPDP Act restrict transferring data outside India?+

By default, no. The DPDP Act uses a negative-list model: transfers are allowed to any country except those the Central Government restricts by notification, and as of June 2026 no country has been restricted. Sectoral rules such as RBI data-localisation mandates still apply on top.

For the full text of every DPDP Act section and rule explained in plain English, see our complete DPDP Act guide.

Legal Disclaimer: This article is for informational purposes only and does not constitute legal advice. Laws and regulations may change; for advice specific to your organisation's situation, consult a qualified legal professional. While every effort has been made to ensure accuracy, Vratex makes no representations as to the completeness or currency of the information contained herein.

Not sure where your organisation stands?

Take the free 3-minute DPDP Readiness Assessment and get a personalised compliance score with actionable next steps.

Check Your DPDP Readiness