How does India's DPDP Act 2023 differ from GDPR? India's Digital Personal Data Protection Act 2023 (DPDP) and the EU's GDPR share the same foundational principles — consent, purpose limitation, and data principal rights — but differ significantly in scope and obligations. DPDP applies only to digital personal data and does not require a Data Protection Officer (DPO) for most organisations, whereas GDPR mandates a DPO for large-scale processors. DPDP penalties max out at ₹250 crore (~€27M) per violation, compared to GDPR's €20M or 4% of global turnover.
India's data protection law borrows from GDPR — but with critical differences. Here's what they mean for your business.
Applies to processing of digital personal data in India, or processing outside India if it relates to offering goods or services to persons in India.
Applies to processing of data of EU residents anywhere in the world. Broad extraterritorial reach regardless of where the processor is established.
If you have EU customers, GDPR still applies to you — DPDP compliance alone is not enough. Dual compliance is necessary for any company with cross-border operations.
Only two bases — (1) Consent and (2) Legitimate use (government, employment, medical, emergency purposes). No "legitimate interests" basis available.
Six lawful bases including legitimate interests, contract necessity, legal obligation, vital interests, public task, and consent.
Under DPDP, most commercial data processing requires explicit consent — the legitimate interests shortcut that GDPR allows does not exist. Re-audit your processing activities.
Consent must be free, specific, informed, unconditional, and unambiguous. Must be given through a clear affirmative act. Must be separate from other terms and conditions.
Consent must be freely given, specific, informed, and unambiguous. "Explicit" consent required for special categories of data. No explicit "unconditional" standard.
DPDP's "unconditional" standard means you cannot condition service access on consent to non-essential processing — a higher bar than GDPR in practice.
Under 18 years (or lower age if government notifies). Verifiable parental consent is mandatory. Processing that tracks children or serves targeted advertising is prohibited. Penalty: up to ₹200 crore.
Under 16 years (member states may lower to 13). Parental or guardian consent required. No blanket ban on targeted advertising to minors under GDPR itself.
Indian companies face a 2-year higher threshold — more users require parental consent under DPDP than under GDPR. Ed-tech and consumer apps are especially exposed.
No right to data portability in the current version of the Act. The Act may be updated by Rules, but portability is not included in the base legislation.
Explicit right to receive personal data in a structured, commonly used, machine-readable format and to transmit it to another controller (Article 20).
For now, DPDP is less burdensome on portability — no infrastructure required to export user data on request. This may change once detailed Rules are finalised.
5 rights: Access (information about processing), Correction, Erasure, Nomination (appoint someone to act after death or incapacity), and Grievance Redressal. No portability or right to object.
8 rights: Access, Rectification, Erasure, Restriction of processing, Portability, Objection, rights relating to Automated decision-making, and Data subject requests.
GDPR's right to object and restriction of processing are absent in DPDP. However, Erasure and Correction carry similar operational weight. Build a single rights-request workflow that covers both.
Notify the Data Protection Board (DPB) and all affected Data Principals "as soon as possible" — draft rules indicate a 72-hour window. ALL breaches must be reported regardless of risk level. Penalty for failure: up to ₹200 crore.
Notify supervisory authority within 72 hours if there is a risk to rights and freedoms. Notify affected individuals only if the breach poses a "high risk" — lower-risk breaches do not require individual notification.
DPDP requires notification for ALL breaches — no risk threshold. This is stricter than GDPR and demands a mature, always-ready incident response capability.
Up to ₹250 crore (~€27 million) per violation category. Penalties are stackable across categories. Significant Data Fiduciaries face enhanced scrutiny. The Act fixes absolute ceilings rather than turnover percentages.
Up to €20 million or 4% of global annual turnover (whichever is higher) — for large multinationals this can amount to billions of euros. GDPR penalties scale with company size.
For large multinationals, GDPR penalties are far higher. For Indian SMEs and mid-market companies, ₹250 crore is a very significant deterrent — especially given personal liability for board members.
No Data Protection Officer requirement for most organisations. Consent Manager roles and additional obligations apply only to notified Significant Data Fiduciaries (SDFs). All Fiduciaries must publish a grievance officer contact.
Mandatory DPO for public authorities, organisations engaged in large-scale systematic monitoring, or those processing special categories of data at scale. No India-residency equivalent.
Most Indian organisations avoid the formal DPO burden under DPDP — but SDFs face equivalent oversight obligations. A Grievance Officer must still be appointed and publicly named.
Transfers are allowed to all countries except those on a government-notified blacklist (negative-list / restriction approach). Sectoral regulators (RBI, SEBI, IRDAI) may impose additional localisation requirements.
Transfers require an adequacy decision, Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or other Article 46 approved safeguards. Whitelist / positive-list approach.
DPDP's transfer regime is pending notification. Once the blacklist is published, Indian companies may face sudden restrictions on sending data to specific countries — watch regulatory updates closely.
No explicit requirement to maintain Records of Processing Activities in the current Act. Data Fiduciaries must be able to demonstrate compliance, but a formal ROPA is not mandated.
Article 30 mandates detailed ROPA for both controllers and processors: purpose, categories, recipients, transfers, retention periods, and security measures must be documented.
DPDP is less administratively burdensome here — but a data inventory remains best practice for managing consent records and demonstrating accountability if the Board investigates.
Not explicitly mandated in the Act for general Fiduciaries. Implied through general security obligations and additional SDF requirements. The Act expects "appropriate technical and organisational measures."
Article 25 mandates data protection by design and by default — privacy must be built into systems from the outset, with the most privacy-protective settings as the default.
Less prescriptive under DPDP, but the Act's general security obligations require the same thinking in practice. Embedding privacy into product development is the safest approach regardless.
Processors (called "Data Processors" under DPDP) are liable primarily through their contract with the Data Fiduciary. Direct enforcement by the Data Protection Board is aimed at the Fiduciary, not the Processor.
Processors are directly liable to supervisory authorities and data subjects in many situations — e.g., acting outside controller instructions, failing to maintain security, or violating processor-specific obligations.
Under DPDP, the Data Fiduciary carries most regulatory risk — making strong Data Processing Agreements (DPAs) with vendors and cloud providers even more critical to manage liability flow-down.
Data Protection Board of India (DPBI) — a single, centralised enforcement body. Digital-first proceedings (complaints can be filed online). Currently being constituted; enforcement expected from May 2027.
27 national Data Protection Authorities (DPAs), coordinated by the European Data Protection Board (EDPB). Over 7 years of case law, significant penalties already enforced across member states.
India's single enforcement body may mean faster and more consistent enforcement — but also less predictability in early decisions. GDPR enforcement patterns offer some guidance on likely priorities.
Data Principals can request erasure when the purpose of processing is served or consent is withdrawn. The Fiduciary must comply unless retention is required by law. Right applies to data shared with third parties.
Explicit "right to be forgotten" under Article 17 — broader in scope with 6 distinct grounds for erasure including where data is no longer necessary, where consent is withdrawn, or where data was unlawfully processed.
DPDP's erasure right is narrower in stated grounds but the operational impact is very similar for most organisations. Build a single deletion workflow that handles both consent-withdrawal erasure (DPDP) and the full GDPR grounds.
If you serve EU customers or have EU-origin employees, both laws apply simultaneously. Key areas where they conflict or require dual action:
Our dual-compliance assessment maps your current gaps against both frameworks and produces a single prioritised action plan.
Get your organisation's scored compliance profile across all DPDP obligations.
Check whether your existing privacy policy meets DPDP Act requirements.
Determine exactly which DPDP obligations apply to your organisation — free.
India is no longer a peripheral jurisdiction in the global data privacy conversation. The Digital Personal Data Protection Act 2023, with enforcement expected from May 2027, creates binding obligations for virtually every organisation that handles the personal data of Indian citizens — whether that organisation is based in Mumbai, Singapore, or Dublin.
For the tens of thousands of Indian IT services, SaaS, BPO, and HRMS companies that already hold GDPR compliance programmes, the instinct is to treat DPDP as a minor extension. This instinct is frequently wrong, and expensively so. The structural differences between the two laws are not cosmetic — they reflect fundamentally different legislative philosophies. GDPR operates on a permissive but heavily documented model: you may process data if you can justify it under one of six lawful bases, maintain detailed records, and meet subject rights within tight timelines. DPDP operates on a consent-or-nothing model for private-sector processing: if you cannot point to consent or one of a narrow set of statutory legitimate uses, the processing is unlawful. The "legitimate interests" balancing test that GDPR compliance teams rely on for marketing, fraud prevention, network security, and dozens of other commercial flows does not exist in Indian law.
The growth of cross-border data flows intensifies the need for this analysis. Indian companies increasingly process data generated in the EU — through EU-headquartered clients, remote European employees, and SaaS platforms serving European end-users. At the same time, Indian-headquartered companies are accumulating the personal data of Indian users at scale through HR systems, CRM platforms, fintech apps, and logistics software. Both directions of data flow now carry regulatory exposure. The 2026 landscape demands a compliance architecture that is explicitly dual-framework rather than one-law-first.
AI-driven data processing adds a further layer of complexity. Large-scale profiling, automated decision-making, and training data derived from personal information all raise distinct questions under each framework. GDPR's Article 22 on automated decision-making has no direct DPDP equivalent, but DPDP's requirement to process only for notified purposes and with consent still constrains AI use cases. Companies deploying AI on Indian user data need legal analysis under DPDP even if their GDPR AI governance is mature.
The fifteen comparisons above are designed to give compliance teams, in-house counsel, and board-level risk owners the structured framework they need to scope a dual-compliance programme — or to identify, precisely, where their GDPR controls transfer to India and where they do not.
One of the genuinely new structures introduced by the DPDP Act is the Consent Manager — an entity interposed between Data Principals and Data Fiduciaries to help individuals manage their consents at scale. This has no direct equivalent in GDPR, which relies on controllers to manage consent directly.
What is a Consent Manager? A Consent Manager is a registered intermediary — registered with the Data Protection Board — that allows a Data Principal to give, review, and withdraw consent for multiple Fiduciaries through a single interface. The concept is modelled loosely on the DEPA (Data Empowerment and Protection Architecture) framework developed by iSPIRT, and is analogous in some ways to the Account Aggregator framework in financial services.
Consent Managers are expected to become relevant primarily for Significant Data Fiduciaries — organisations notified by the government as processing personal data at scale or of high sensitivity. SDFs will be required to work with registered Consent Managers to ensure that data principals can exercise their rights through a common interface. For most organisations, the practical impact will arrive via API integrations with registered Consent Manager platforms rather than building the infrastructure in-house.
GDPR's consent management landscape is handled through Consent Management Platforms (CMPs) which are market products rather than regulated intermediaries. The DPDP approach of formally registering and regulating Consent Managers represents a higher degree of state involvement in the consent infrastructure — and creates a new category of regulated entity in India's data economy. Companies building DPDP compliance programmes should treat Consent Manager integration as a medium-term architectural requirement, especially if they anticipate SDF designation or operate in sectors where the government is likely to prioritise enforcement.
For most Indian organisations that process the data of both Indian and EU users, the practical question is not "which law do I comply with?" but "how do I build one programme that satisfies both simultaneously?" The good news is that the two frameworks share enough structural DNA — rights, breach notification, data minimisation, purpose limitation — that a well-designed compliance programme can address both without doubling the effort.
The recommended approach is to start with the stricter requirement in each category. For children's data, that is DPDP's under-18 threshold. For consent, that means meeting DPDP's "unconditional" standard, which also satisfies GDPR's "freely given" requirement if designed correctly. For breach notification, build a process that can file simultaneously with both the DPBI and the relevant EU DPA within 72 hours — the timelines are aligned, though the content requirements differ.
Areas where the frameworks genuinely diverge — such as the GDPR's legitimate interests basis for data processing and the DPDP's absence of that basis — require separate documented positions for each jurisdiction. A processing activity that you justify under GDPR's Article 6(1)(f) legitimate interests must be separately re-evaluated for DPDP purposes, and likely converted to a consent basis or discontinued for Indian users.
The most operationally intensive area of divergence is data subject / Data Principal rights. Your rights management workflow must handle GDPR's 8 rights (including portability and restriction) for EU data subjects, and DPDP's 5 rights (including the unique Nomination right) for Indian Data Principals. Building a unified rights request intake form with jurisdiction-routing logic is the most practical solution.
The DPDP Act received Presidential assent in August 2023. Rules were notified in April 2025. The Data Protection Board of India is currently being constituted, with enforcement expected to begin from May 2027. This 18-month runway between Rule notification and enforcement is not an invitation to delay — it is the time available to complete implementation before penalties apply.
Based on GDPR's enforcement history, the first wave of DPBI enforcement actions is likely to focus on: (a) high-profile breaches where notification obligations were not met, (b) consumer-facing companies with clearly non-compliant consent collection practices, and (c) Significant Data Fiduciaries that have not met their enhanced obligations. Companies that can demonstrate good-faith compliance efforts — documented gap assessments, a remediation roadmap, updated privacy notices — are significantly better positioned even if implementation is incomplete by May 2027.
Unlike GDPR, which launched with years of existing jurisprudence from member state DPAs, DPDP will begin enforcement with a blank slate. The DPBI will develop its own enforcement priorities and interpretive positions. Companies that engage early — through compliance programmes, industry consultations, and documented accountability frameworks — will help shape that enforcement culture.
NitiBharat's DPDP readiness assessments are structured specifically to help organisations demonstrate good-faith compliance preparation — producing a scored gap analysis, a documented remediation plan, and an accountability trail that stands up to regulatory scrutiny from day one of enforcement.
Does DPDP apply to personal data of Indian citizens living abroad? The Act applies to processing of personal data "in connection with" activity in India — not specifically tied to citizenship. The detailed extraterritorial scope will be clarified by the DPBI over time.
Can a company be fined under both DPDP and GDPR for the same breach? Yes — if the breach involves both Indian and EU personal data, both the DPBI and the relevant EU DPA can independently investigate and fine the company. The penalties are separate and cumulative.
Is DPDP compliance mandatory for small businesses? The Act applies to all Data Fiduciaries regardless of size, though the government may notify different obligations for different classes of Fiduciary. Enhanced obligations (DPO equivalent, annual DPIAs, Consent Manager) apply only to Significant Data Fiduciaries.
How does DPDP treat employee data? Processing of employee data is included in the "legitimate uses" under Section 7 — meaning employers do not need individual consent for most routine HR processing (payroll, benefits, performance management). However, consent remains required for processing beyond those stated purposes.
What happens to existing consents and privacy policies after DPDP takes effect? Existing privacy policies and consent mechanisms must be updated to meet DPDP standards before the enforcement deadline. Data collected under pre-DPDP practices with consent that does not meet the new standard will technically require re-consent.
The DPDP Act sets fixed penalty ceilings per category of violation. Unlike GDPR, which scales penalties as a percentage of global turnover, DPDP uses absolute rupee caps. Below is a summary of the key penalty categories:
| Violation Category | Maximum Penalty (DPDP) | GDPR Equivalent |
|---|---|---|
| Failure to implement adequate security safeguards | ₹250 crore | Up to €10M or 2% turnover |
| Failure to notify breach to Board / Data Principals | ₹200 crore | Up to €10M or 2% turnover |
| Non-compliance with children's data obligations | ₹200 crore | Up to €20M or 4% turnover |
| Non-compliance with Significant Data Fiduciary obligations | ₹150 crore | Up to €20M or 4% turnover |
| Failure to honour Data Principal rights requests | ₹50 crore | Up to €20M or 4% turnover |
| Other non-compliance with Act provisions | ₹50 crore | Up to €10M or 2% turnover |
Penalties are per violation category and may be imposed cumulatively. The DPBI may consider the nature, gravity, duration, and previous non-compliance when determining the final penalty amount.
| Area | DPDP (India) | GDPR (EU) | Stricter for Indian Businesses |
|---|---|---|---|
| Territorial scope | India + services to India | EU residents globally | Similar |
| Legal bases | 2 (Consent + Legitimate uses) | 6 including Legitimate interests | DPDP stricter |
| Children's threshold | Under 18 | Under 16 (can be 13) | DPDP stricter |
| Breach notification threshold | All breaches | Risk-based threshold | DPDP stricter |
| DPO requirement | SDFs only | Broader categories | GDPR stricter |
| Data portability | Not required | Mandatory right | GDPR stricter |
| ROPA requirement | Not mandated | Mandatory (Article 30) | GDPR stricter |
| Maximum penalty | ₹250 crore (~€27M fixed) | €20M or 4% global turnover | Depends on company size |
GET STARTED
Use our free tools to benchmark your current position, or speak directly with a NitiBharat expert for a tailored assessment.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.