If your organisation already complies with the GDPR, the tempting assumption is that India's DPDP Act 2023 is covered by the same programme. It is not, and the gaps sit in expensive places: a missing legal basis your European processing relies on, an 18-year consent threshold, and a breach notification duty with no risk filter.
Here are the 12 differences that matter most, and what each one means for your compliance programme.
The Side-by-Side Comparison
| Dimension | DPDP Act 2023 (India) | GDPR (EU) |
|---|---|---|
| Scope | Digital personal data only | All personal data (digital and non-digital) |
| Legal bases | Consent + a closed list of legitimate uses | 6 legal bases (Art. 6) + special categories (Art. 9) |
| "Legitimate interests" basis | Does not exist | Art. 6(1)(f), widely used |
| Consent standard | Free, specific, informed, unconditional, unambiguous | Freely given, specific, informed, unambiguous |
| Children's age threshold | Under 18, no variation | Under 16 (Member States may lower to 13) |
| Cross-border transfers | Negative list: allowed unless restricted | Adequacy model: blocked unless approved |
| Data Principal duties | Yes, with a ₹10,000 penalty | No duties on data subjects |
| Maximum penalty | ₹250 crore, fixed cap per breach type | €20M or 4% of global turnover, whichever is higher |
| Breach notification to individuals | Always, without delay, no risk filter | Only when "high risk" to the individual |
| Right to portability | Not included | Yes (Art. 20) |
| DPO requirement | Significant Data Fiduciaries only | Public authorities + large-scale processors |
| Regulator | One national body (the DPB) | One per Member State + EDPB coordination |
Key Takeaway
GDPR compliance does not equal DPDP compliance. The DPDP Act is narrower in scope but stricter on children's data and breach notification, has no legitimate-interests basis, and uses a penalty structure that does not scale with revenue. India needs its own compliance workstream.
Where the DPDP Act Is Narrower
1. Digital Data Only
The GDPR covers personal data in any form: paper files, audio, CCTV. The DPDP Act covers digital personal data only, plus data collected on paper and later digitised. In practice the exclusion shrinks every year, because almost every business process generates digital records anyway.
2. Fewer Legal Bases, and No "Legitimate Interests"
The GDPR offers six legal bases. The DPDP Act recognises exactly two routes: consent, or a closed list of legitimate uses in Section 7.
This is the single biggest operational difference. Processing that European businesses justify under legitimate interests (fraud prevention, direct marketing, network security) has no equivalent justification under the DPDP Act. There is no balancing test to run. You find consent or a Section 7 ground, or you stop processing.
3. No Right to Data Portability
GDPR Article 20 lets individuals demand their data in a machine-readable format. The DPDP Act has no portability right: Data Principals can access and request deletion, but not a portable export.
4. No Standalone Right to Object
GDPR data subjects can object to specific processing, including profiling, while a service continues. Under the DPDP Act the remedy is blunter: withdraw consent, which stops the processing that depended on it.
Where the DPDP Act Is Stricter
5. Children's Data: 18 vs 16
The GDPR default is 16, lowerable to 13 by Member States. The DPDP Act sets it at 18, with no variation, and requires verifiable parental consent below it. A 15-year-old who can lawfully consent in most EU countries cannot consent in India. For EdTech, gaming, and social platforms, this single number reshapes the consent architecture.
6. Consent Must Also Be "Unconditional"
Both laws require free, specific, informed, unambiguous consent. The DPDP Act adds unconditional as an explicit statutory requirement: access to a service cannot be conditioned on consent to unrelated processing. The GDPR reaches a similar place through "freely given" and bundling guidance; the DPDP Act writes it into the statute.
7. Individuals Have Duties Too
Unique to the DPDP Act: Section 15 imposes duties on Data Principals, including not filing false or frivolous complaints, not impersonating others, and not suppressing material information, backed by a penalty of up to ₹10,000.
Why This Matters for Businesses
The duties provision gives organisations a counterweight the GDPR lacks. The Board can warn or impose costs on complainants whose cases are found false or frivolous, which discourages weaponised complaints.
Where the Two Laws Diverge Structurally
8. Cross-Border Transfers: Negative List vs Adequacy
The most structurally different provision. The GDPR blocks transfers by default unless an adequacy decision, SCCs, BCRs, or another approved mechanism applies. The DPDP Act allows transfers by default, to any country except those the Central Government specifically restricts by notification. As of June 2026, no country is on the restricted list.
What this means: India-to-abroad transfers are straightforward today, but the list can change by notification, overnight. Build your data architecture so a specific destination can be cut quickly. Our cross-border transfer chapter covers the mechanics.
9. Penalties: Fixed Caps vs Revenue-Linked
GDPR penalties scale with turnover: 4% of global revenue or €20 million, whichever is higher. The DPDP Act uses fixed rupee caps, topping out at ₹250 crore (roughly €27 million) for security-safeguard failures.
The fixed structure cuts both ways. For a mid-size Indian business, ₹250 crore is existential, proportionally far harsher than 4% of turnover. For a global giant, the DPDP cap is lighter than its GDPR exposure. Note also that the Central Government can double any cap by notification, and one incident can stack multiple categories: the penalty framework breakdown runs the numbers.
10. Breach Notification: No Risk Filter
The GDPR requires notifying the authority within 72 hours, and individuals only when the breach poses a high risk to them. The DPDP Act requires notifying the Board without delay with a detailed report within 72 hours, and notifying affected Data Principals without delay, in every case. There is no internal risk assessment that lets you skip telling individuals.
This is the difference most likely to break a GDPR-trained incident response process. The full two-stage timeline, including the parallel 6-hour CERT-In clock, is in our breach notification guide for CISOs.
11. One Regulator vs Many
The GDPR runs through a supervisory authority per Member State with EDPB coordination, lead-authority rules, and cross-border procedures. The DPDP Act has one regulator: the Data Protection Board of India, with one appeals path (TDSAT, then the Supreme Court). Simpler to deal with, and no forum shopping.
12. DPO: By Designation, Not by Activity
The GDPR requires a DPO based on what you do (public authority, large-scale monitoring, special categories at scale). The DPDP Act requires one only for Significant Data Fiduciaries: organisations the Central Government specifically designates. If you are not designated, no DPO is legally required, though large data-heavy businesses should plan for designation rather than assume it away.
The Dual-Compliance Punch List
Running in both India and the EU? These are the concrete deltas to work through:
- Consent flows: add the unconditional requirement, unbundle purposes, and give the option to access the notice in English or any of the 22 Eighth Schedule languages. Your GDPR consent screens do not transfer as-is.
- Legitimate-interests inventory: list every processing activity currently justified under Art. 6(1)(f) and find each one a DPDP home: consent or a Section 7 ground. This audit finds the gaps that hurt.
- Age gates: thresholds of 13 or 16 must become 18 for Indian users, with verifiable parental consent beneath it.
- Transfers: no SCCs needed for India, but build the kill-switch for restricted destinations.
- Breach runbook: add an India branch with no risk-assessment gate on individual notification, and the two-stage Board timeline.
Not sure where your organisation stands?
Take the free 3-minute DPDP Readiness Assessment and get a personalised compliance score.
Check Your ReadinessThe Bottom Line
The two laws share a goal and diverge on the mechanics that cost money. The DPDP Act is shorter and in places stricter (children's data, unconditional consent, mandatory individual notification); the GDPR is broader and revenue-scaled. Treating GDPR compliance as sufficient for India creates real gaps; treating the two as unrelated duplicates work. The practical path: build India-specific controls where the 12 differences bite, and reuse your GDPR infrastructure everywhere else.
Frequently Asked Questions
Is GDPR compliance enough for the DPDP Act?+
No. The DPDP Act has no legitimate-interests basis, sets the children's consent threshold at 18, requires notifying affected individuals of every breach without a risk filter, and adds an "unconditional" consent requirement. Each of these needs India-specific controls on top of a GDPR programme.
Does the DPDP Act have a legitimate interests basis like GDPR?+
No. The DPDP Act recognises only consent and a closed list of legitimate uses in Section 7, such as voluntary provision, certain State functions, medical emergencies, and employment purposes. Processing justified under GDPR Article 6(1)(f), including most marketing and analytics, needs consent in India.
How do DPDP and GDPR penalties compare?+
The GDPR scales with revenue: up to €20 million or 4% of global turnover, whichever is higher. The DPDP Act uses fixed caps, with a maximum of ₹250 crore (roughly €27 million) for security-safeguard failures, and the Central Government can double any cap by notification.
What is the age of consent for data processing in India vs the EU?+
India: 18, with no variation, and verifiable parental consent required below it. The EU: 16 by default, and Member States may lower it to 13.
How does breach notification differ between DPDP and GDPR?+
Under the GDPR, you notify the authority within 72 hours and individuals only if the breach poses a high risk to them. Under the DPDP Act, you notify the Data Protection Board without delay plus a detailed report within 72 hours, and you notify every affected individual without delay, regardless of risk level.
Does the DPDP Act restrict transferring data outside India?+
By default, no. The DPDP Act uses a negative-list model: transfers are allowed to any country except those the Central Government restricts by notification, and as of June 2026 no country has been restricted. Sectoral rules such as RBI data-localisation mandates still apply on top.
For the full text of every DPDP Act section and rule explained in plain English, see our complete DPDP Act guide.
Legal Disclaimer: This article is for informational purposes only and does not constitute legal advice. Laws and regulations may change; for advice specific to your organisation's situation, consult a qualified legal professional. While every effort has been made to ensure accuracy, Vratex makes no representations as to the completeness or currency of the information contained herein.
Not sure where your organisation stands?
Take the free 3-minute DPDP Readiness Assessment and get a personalised compliance score with actionable next steps.
Check Your DPDP Readiness