DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr

Quick Answer

How does India's DPDP Act 2023 differ from GDPR? India's Digital Personal Data Protection Act 2023 (DPDP) and the EU's GDPR share the same foundational principles — consent, purpose limitation, and data principal rights — but differ significantly in scope and obligations. DPDP applies only to digital personal data and does not require a Data Protection Officer (DPO) for most organisations, whereas GDPR mandates a DPO for large-scale processors. DPDP penalties max out at ₹250 crore (~€27M) per violation, compared to GDPR's €20M or 4% of global turnover.

🇮🇳 DPDP Act 2023 🇪🇺 EU GDPR 2018 Updated Jun 2026

DPDP Act vs GDPR — Key Differences Explained for Indian Businesses

India's data protection law borrows from GDPR — but with critical differences. Here's what they mean for your business.

1. Territorial Scope

Scope
🇮🇳 DPDP Act 2023

Applies to processing of digital personal data in India, or processing outside India if it relates to offering goods or services to persons in India.

🇪🇺 EU GDPR

Applies to processing of data of EU residents anywhere in the world. Broad extraterritorial reach regardless of where the processor is established.

IMPLICATION FOR INDIAN BUSINESSES

If you have EU customers, GDPR still applies to you — DPDP compliance alone is not enough. Dual compliance is necessary for any company with cross-border operations.

2. Legal Bases for Processing

Consent
🇮🇳 DPDP Act 2023

Only two bases — (1) Consent and (2) Legitimate use (government, employment, medical, emergency purposes). No "legitimate interests" basis available.

🇪🇺 EU GDPR

Six lawful bases including legitimate interests, contract necessity, legal obligation, vital interests, public task, and consent.

IMPLICATION FOR INDIAN BUSINESSES

Under DPDP, most commercial data processing requires explicit consent — the legitimate interests shortcut that GDPR allows does not exist. Re-audit your processing activities.

3. Consent Standard

Consent
🇮🇳 DPDP Act 2023

Consent must be free, specific, informed, unconditional, and unambiguous. Must be given through a clear affirmative act. Must be separate from other terms and conditions.

🇪🇺 EU GDPR

Consent must be freely given, specific, informed, and unambiguous. "Explicit" consent required for special categories of data. No explicit "unconditional" standard.

IMPLICATION FOR INDIAN BUSINESSES

DPDP's "unconditional" standard means you cannot condition service access on consent to non-essential processing — a higher bar than GDPR in practice.

4. Children's Age Threshold

Consent
🇮🇳 DPDP Act 2023

Under 18 years (or lower age if government notifies). Verifiable parental consent is mandatory. Processing that tracks children or serves targeted advertising is prohibited. Penalty: up to ₹200 crore.

🇪🇺 EU GDPR

Under 16 years (member states may lower to 13). Parental or guardian consent required. No blanket ban on targeted advertising to minors under GDPR itself.

IMPLICATION FOR INDIAN BUSINESSES

Indian companies face a 2-year higher threshold — more users require parental consent under DPDP than under GDPR. Ed-tech and consumer apps are especially exposed.

5. Data Portability

Rights
🇮🇳 DPDP Act 2023

No right to data portability in the current version of the Act. The Act may be updated by Rules, but portability is not included in the base legislation.

🇪🇺 EU GDPR

Explicit right to receive personal data in a structured, commonly used, machine-readable format and to transmit it to another controller (Article 20).

IMPLICATION FOR INDIAN BUSINESSES

For now, DPDP is less burdensome on portability — no infrastructure required to export user data on request. This may change once detailed Rules are finalised.

6. Data Subject / Principal Rights

Rights
🇮🇳 DPDP Act 2023

5 rights: Access (information about processing), Correction, Erasure, Nomination (appoint someone to act after death or incapacity), and Grievance Redressal. No portability or right to object.

🇪🇺 EU GDPR

8 rights: Access, Rectification, Erasure, Restriction of processing, Portability, Objection, rights relating to Automated decision-making, and Data subject requests.

IMPLICATION FOR INDIAN BUSINESSES

GDPR's right to object and restriction of processing are absent in DPDP. However, Erasure and Correction carry similar operational weight. Build a single rights-request workflow that covers both.

7. Breach Notification

Key Obligations
🇮🇳 DPDP Act 2023

Notify the Data Protection Board (DPB) and all affected Data Principals "as soon as possible" — draft rules indicate a 72-hour window. ALL breaches must be reported regardless of risk level. Penalty for failure: up to ₹200 crore.

🇪🇺 EU GDPR

Notify supervisory authority within 72 hours if there is a risk to rights and freedoms. Notify affected individuals only if the breach poses a "high risk" — lower-risk breaches do not require individual notification.

IMPLICATION FOR INDIAN BUSINESSES

DPDP requires notification for ALL breaches — no risk threshold. This is stricter than GDPR and demands a mature, always-ready incident response capability.

8. Maximum Penalties

Penalties
🇮🇳 DPDP Act 2023

Up to ₹250 crore (~€27 million) per violation category. Penalties are stackable across categories. Significant Data Fiduciaries face enhanced scrutiny. The Act fixes absolute ceilings rather than turnover percentages.

🇪🇺 EU GDPR

Up to €20 million or 4% of global annual turnover (whichever is higher) — for large multinationals this can amount to billions of euros. GDPR penalties scale with company size.

IMPLICATION FOR INDIAN BUSINESSES

For large multinationals, GDPR penalties are far higher. For Indian SMEs and mid-market companies, ₹250 crore is a very significant deterrent — especially given personal liability for board members.

9. DPO Requirement

Key Obligations
🇮🇳 DPDP Act 2023

No Data Protection Officer requirement for most organisations. Consent Manager roles and additional obligations apply only to notified Significant Data Fiduciaries (SDFs). All Fiduciaries must publish a grievance officer contact.

🇪🇺 EU GDPR

Mandatory DPO for public authorities, organisations engaged in large-scale systematic monitoring, or those processing special categories of data at scale. No India-residency equivalent.

IMPLICATION FOR INDIAN BUSINESSES

Most Indian organisations avoid the formal DPO burden under DPDP — but SDFs face equivalent oversight obligations. A Grievance Officer must still be appointed and publicly named.

10. Cross-Border Data Transfers

Key Obligations
🇮🇳 DPDP Act 2023

Transfers are allowed to all countries except those on a government-notified blacklist (negative-list / restriction approach). Sectoral regulators (RBI, SEBI, IRDAI) may impose additional localisation requirements.

🇪🇺 EU GDPR

Transfers require an adequacy decision, Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or other Article 46 approved safeguards. Whitelist / positive-list approach.

IMPLICATION FOR INDIAN BUSINESSES

DPDP's transfer regime is pending notification. Once the blacklist is published, Indian companies may face sudden restrictions on sending data to specific countries — watch regulatory updates closely.

11. Records of Processing (ROPA)

Key Obligations
🇮🇳 DPDP Act 2023

No explicit requirement to maintain Records of Processing Activities in the current Act. Data Fiduciaries must be able to demonstrate compliance, but a formal ROPA is not mandated.

🇪🇺 EU GDPR

Article 30 mandates detailed ROPA for both controllers and processors: purpose, categories, recipients, transfers, retention periods, and security measures must be documented.

IMPLICATION FOR INDIAN BUSINESSES

DPDP is less administratively burdensome here — but a data inventory remains best practice for managing consent records and demonstrating accountability if the Board investigates.

12. Privacy by Design

Key Obligations
🇮🇳 DPDP Act 2023

Not explicitly mandated in the Act for general Fiduciaries. Implied through general security obligations and additional SDF requirements. The Act expects "appropriate technical and organisational measures."

🇪🇺 EU GDPR

Article 25 mandates data protection by design and by default — privacy must be built into systems from the outset, with the most privacy-protective settings as the default.

IMPLICATION FOR INDIAN BUSINESSES

Less prescriptive under DPDP, but the Act's general security obligations require the same thinking in practice. Embedding privacy into product development is the safest approach regardless.

13. Processor Direct Liability

Key Obligations
🇮🇳 DPDP Act 2023

Processors (called "Data Processors" under DPDP) are liable primarily through their contract with the Data Fiduciary. Direct enforcement by the Data Protection Board is aimed at the Fiduciary, not the Processor.

🇪🇺 EU GDPR

Processors are directly liable to supervisory authorities and data subjects in many situations — e.g., acting outside controller instructions, failing to maintain security, or violating processor-specific obligations.

IMPLICATION FOR INDIAN BUSINESSES

Under DPDP, the Data Fiduciary carries most regulatory risk — making strong Data Processing Agreements (DPAs) with vendors and cloud providers even more critical to manage liability flow-down.

14. Enforcement Body

Key Obligations
🇮🇳 DPDP Act 2023

Data Protection Board of India (DPBI) — a single, centralised enforcement body. Digital-first proceedings (complaints can be filed online). Currently being constituted; enforcement expected from May 2027.

🇪🇺 EU GDPR

27 national Data Protection Authorities (DPAs), coordinated by the European Data Protection Board (EDPB). Over 7 years of case law, significant penalties already enforced across member states.

IMPLICATION FOR INDIAN BUSINESSES

India's single enforcement body may mean faster and more consistent enforcement — but also less predictability in early decisions. GDPR enforcement patterns offer some guidance on likely priorities.

15. Right to Erasure / Be Forgotten

Rights
🇮🇳 DPDP Act 2023

Data Principals can request erasure when the purpose of processing is served or consent is withdrawn. The Fiduciary must comply unless retention is required by law. Right applies to data shared with third parties.

🇪🇺 EU GDPR

Explicit "right to be forgotten" under Article 17 — broader in scope with 6 distinct grounds for erasure including where data is no longer necessary, where consent is withdrawn, or where data was unlawfully processed.

IMPLICATION FOR INDIAN BUSINESSES

DPDP's erasure right is narrower in stated grounds but the operational impact is very similar for most organisations. Build a single deletion workflow that handles both consent-withdrawal erasure (DPDP) and the full GDPR grounds.

What if you need to comply with both DPDP and GDPR?

If you serve EU customers or have EU-origin employees, both laws apply simultaneously. Key areas where they conflict or require dual action:

  • Consent mechanisms must meet both standards — DPDP's "unconditional" requirement and GDPR's "freely given" requirement. A single consent framework can satisfy both if designed carefully.
  • Breach notification requires parallel notification to the Data Protection Board of India (DPBI) and the relevant EU Data Protection Authority — with separate content requirements for each.
  • Cross-border transfer restrictions apply under both regimes — GDPR's SCCs/adequacy decisions and DPDP's pending blacklist must both be considered before routing data internationally.
  • Children's data requires compliance with the stricter threshold — DPDP's under-18 rule effectively governs for Indian users even if GDPR's under-16 rule applies for EU users.

Our dual-compliance assessment maps your current gaps against both frameworks and produces a single prioritised action plan.

Book a Dual-Compliance Review →

Assess your DPDP compliance now

Why comparing DPDP and GDPR matters for Indian businesses

India is no longer a peripheral jurisdiction in the global data privacy conversation. The Digital Personal Data Protection Act 2023, with enforcement expected from May 2027, creates binding obligations for virtually every organisation that handles the personal data of Indian citizens — whether that organisation is based in Mumbai, Singapore, or Dublin.

For the tens of thousands of Indian IT services, SaaS, BPO, and HRMS companies that already hold GDPR compliance programmes, the instinct is to treat DPDP as a minor extension. This instinct is frequently wrong, and expensively so. The structural differences between the two laws are not cosmetic — they reflect fundamentally different legislative philosophies. GDPR operates on a permissive but heavily documented model: you may process data if you can justify it under one of six lawful bases, maintain detailed records, and meet subject rights within tight timelines. DPDP operates on a consent-or-nothing model for private-sector processing: if you cannot point to consent or one of a narrow set of statutory legitimate uses, the processing is unlawful. The "legitimate interests" balancing test that GDPR compliance teams rely on for marketing, fraud prevention, network security, and dozens of other commercial flows does not exist in Indian law.

The growth of cross-border data flows intensifies the need for this analysis. Indian companies increasingly process data generated in the EU — through EU-headquartered clients, remote European employees, and SaaS platforms serving European end-users. At the same time, Indian-headquartered companies are accumulating the personal data of Indian users at scale through HR systems, CRM platforms, fintech apps, and logistics software. Both directions of data flow now carry regulatory exposure. The 2026 landscape demands a compliance architecture that is explicitly dual-framework rather than one-law-first.

AI-driven data processing adds a further layer of complexity. Large-scale profiling, automated decision-making, and training data derived from personal information all raise distinct questions under each framework. GDPR's Article 22 on automated decision-making has no direct DPDP equivalent, but DPDP's requirement to process only for notified purposes and with consent still constrains AI use cases. Companies deploying AI on Indian user data need legal analysis under DPDP even if their GDPR AI governance is mature.

The fifteen comparisons above are designed to give compliance teams, in-house counsel, and board-level risk owners the structured framework they need to scope a dual-compliance programme — or to identify, precisely, where their GDPR controls transfer to India and where they do not.

The key DPDP innovation: Consent Manager

One of the genuinely new structures introduced by the DPDP Act is the Consent Manager — an entity interposed between Data Principals and Data Fiduciaries to help individuals manage their consents at scale. This has no direct equivalent in GDPR, which relies on controllers to manage consent directly.

What is a Consent Manager? A Consent Manager is a registered intermediary — registered with the Data Protection Board — that allows a Data Principal to give, review, and withdraw consent for multiple Fiduciaries through a single interface. The concept is modelled loosely on the DEPA (Data Empowerment and Protection Architecture) framework developed by iSPIRT, and is analogous in some ways to the Account Aggregator framework in financial services.

Consent Managers are expected to become relevant primarily for Significant Data Fiduciaries — organisations notified by the government as processing personal data at scale or of high sensitivity. SDFs will be required to work with registered Consent Managers to ensure that data principals can exercise their rights through a common interface. For most organisations, the practical impact will arrive via API integrations with registered Consent Manager platforms rather than building the infrastructure in-house.

GDPR's consent management landscape is handled through Consent Management Platforms (CMPs) which are market products rather than regulated intermediaries. The DPDP approach of formally registering and regulating Consent Managers represents a higher degree of state involvement in the consent infrastructure — and creates a new category of regulated entity in India's data economy. Companies building DPDP compliance programmes should treat Consent Manager integration as a medium-term architectural requirement, especially if they anticipate SDF designation or operate in sectors where the government is likely to prioritise enforcement.

How to approach a dual DPDP and GDPR compliance programme

For most Indian organisations that process the data of both Indian and EU users, the practical question is not "which law do I comply with?" but "how do I build one programme that satisfies both simultaneously?" The good news is that the two frameworks share enough structural DNA — rights, breach notification, data minimisation, purpose limitation — that a well-designed compliance programme can address both without doubling the effort.

The recommended approach is to start with the stricter requirement in each category. For children's data, that is DPDP's under-18 threshold. For consent, that means meeting DPDP's "unconditional" standard, which also satisfies GDPR's "freely given" requirement if designed correctly. For breach notification, build a process that can file simultaneously with both the DPBI and the relevant EU DPA within 72 hours — the timelines are aligned, though the content requirements differ.

Areas where the frameworks genuinely diverge — such as the GDPR's legitimate interests basis for data processing and the DPDP's absence of that basis — require separate documented positions for each jurisdiction. A processing activity that you justify under GDPR's Article 6(1)(f) legitimate interests must be separately re-evaluated for DPDP purposes, and likely converted to a consent basis or discontinued for Indian users.

The most operationally intensive area of divergence is data subject / Data Principal rights. Your rights management workflow must handle GDPR's 8 rights (including portability and restriction) for EU data subjects, and DPDP's 5 rights (including the unique Nomination right) for Indian Data Principals. Building a unified rights request intake form with jurisdiction-routing logic is the most practical solution.

DPDP enforcement timeline: what to expect before May 2027

The DPDP Act received Presidential assent in August 2023. Rules were notified in April 2025. The Data Protection Board of India is currently being constituted, with enforcement expected to begin from May 2027. This 18-month runway between Rule notification and enforcement is not an invitation to delay — it is the time available to complete implementation before penalties apply.

Based on GDPR's enforcement history, the first wave of DPBI enforcement actions is likely to focus on: (a) high-profile breaches where notification obligations were not met, (b) consumer-facing companies with clearly non-compliant consent collection practices, and (c) Significant Data Fiduciaries that have not met their enhanced obligations. Companies that can demonstrate good-faith compliance efforts — documented gap assessments, a remediation roadmap, updated privacy notices — are significantly better positioned even if implementation is incomplete by May 2027.

Unlike GDPR, which launched with years of existing jurisprudence from member state DPAs, DPDP will begin enforcement with a blank slate. The DPBI will develop its own enforcement priorities and interpretive positions. Companies that engage early — through compliance programmes, industry consultations, and documented accountability frameworks — will help shape that enforcement culture.

NitiBharat's DPDP readiness assessments are structured specifically to help organisations demonstrate good-faith compliance preparation — producing a scored gap analysis, a documented remediation plan, and an accountability trail that stands up to regulatory scrutiny from day one of enforcement.

Frequently asked questions: DPDP vs GDPR

Does DPDP apply to personal data of Indian citizens living abroad? The Act applies to processing of personal data "in connection with" activity in India — not specifically tied to citizenship. The detailed extraterritorial scope will be clarified by the DPBI over time.

Can a company be fined under both DPDP and GDPR for the same breach? Yes — if the breach involves both Indian and EU personal data, both the DPBI and the relevant EU DPA can independently investigate and fine the company. The penalties are separate and cumulative.

Is DPDP compliance mandatory for small businesses? The Act applies to all Data Fiduciaries regardless of size, though the government may notify different obligations for different classes of Fiduciary. Enhanced obligations (DPO equivalent, annual DPIAs, Consent Manager) apply only to Significant Data Fiduciaries.

How does DPDP treat employee data? Processing of employee data is included in the "legitimate uses" under Section 7 — meaning employers do not need individual consent for most routine HR processing (payroll, benefits, performance management). However, consent remains required for processing beyond those stated purposes.

What happens to existing consents and privacy policies after DPDP takes effect? Existing privacy policies and consent mechanisms must be updated to meet DPDP standards before the enforcement deadline. Data collected under pre-DPDP practices with consent that does not meet the new standard will technically require re-consent.

DPDP Penalty Schedule: Quick Reference

The DPDP Act sets fixed penalty ceilings per category of violation. Unlike GDPR, which scales penalties as a percentage of global turnover, DPDP uses absolute rupee caps. Below is a summary of the key penalty categories:

Violation Category Maximum Penalty (DPDP) GDPR Equivalent
Failure to implement adequate security safeguards ₹250 crore Up to €10M or 2% turnover
Failure to notify breach to Board / Data Principals ₹200 crore Up to €10M or 2% turnover
Non-compliance with children's data obligations ₹200 crore Up to €20M or 4% turnover
Non-compliance with Significant Data Fiduciary obligations ₹150 crore Up to €20M or 4% turnover
Failure to honour Data Principal rights requests ₹50 crore Up to €20M or 4% turnover
Other non-compliance with Act provisions ₹50 crore Up to €10M or 2% turnover

Penalties are per violation category and may be imposed cumulatively. The DPBI may consider the nature, gravity, duration, and previous non-compliance when determining the final penalty amount.

Quick reference: DPDP vs GDPR comparison summary

Area DPDP (India) GDPR (EU) Stricter for Indian Businesses
Territorial scope India + services to India EU residents globally Similar
Legal bases 2 (Consent + Legitimate uses) 6 including Legitimate interests DPDP stricter
Children's threshold Under 18 Under 16 (can be 13) DPDP stricter
Breach notification threshold All breaches Risk-based threshold DPDP stricter
DPO requirement SDFs only Broader categories GDPR stricter
Data portability Not required Mandatory right GDPR stricter
ROPA requirement Not mandated Mandatory (Article 30) GDPR stricter
Maximum penalty ₹250 crore (~€27M fixed) €20M or 4% global turnover Depends on company size

GET STARTED

Ready to map your DPDP compliance gaps?

Use our free tools to benchmark your current position, or speak directly with a NitiBharat expert for a tailored assessment.

Run Free Readiness Score → Book Expert Review →
Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
DPDP vs HIPAADPDP vs Singapore PDPADPDP vs UK GDPRClinical Data Retention Period CheckerSee all Reference & Checklists tools →📝 What to Do Data Breach 72 Hours DPDP📝 Dpia Under DPDP Act India