DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

The India DPDP Act 2023 and the Australia Privacy Act 1988 (with its 13 Australian Privacy Principles) both regulate personal data, but they differ sharply in structure. DPDP is consent-first with a narrow set of legitimate uses, while Australia's APPs allow collection for a primary purpose without always requiring express consent. On cross-border transfers, India uses a negative-list model — transfers are open unless the government restricts specific countries — whereas Australia (APP 8) makes the sender accountable for the overseas recipient's handling. Penalties differ too: DPDP ceilings reach ₹250 crore, while Australia's serious-breach penalties are set in Australian-dollar or turnover terms. This tool compares the two obligation area by obligation area.

India DPDP vs Australia Privacy Act — Key Differences by Obligation

If your organisation handles data across India and Australia, the two regimes overlap but diverge in important ways. Pick an obligation area to see exactly where.

Compare DPDP and the Australia Privacy Act by obligation area

India vs Australia — what a dual-regime team should verify

How does the India DPDP Act differ from the Australia Privacy Act on consent?

The clearest divergence between the India DPDP Act and the Australia Privacy Act is the role of consent. DPDP is fundamentally consent-first: under Section 6, a data fiduciary generally needs free, specific, informed and unambiguous consent to process personal data, with only a narrow set of Legitimate Uses as alternatives. There is deliberately no broad legitimate-interest basis of the kind many global privacy laws rely on. Australia's 13 Australian Privacy Principles, by contrast, allow an entity to collect personal information that is reasonably necessary for its functions or activities, reserving express consent mainly for sensitive information.

For an Indian mid-market company that also serves Australian customers, this means a single consent design will not comfortably cover both regimes. Practices that are acceptable under Australian purpose-based collection can fall short of DPDP's explicit, unbundled consent standard for Indian Data Principals. Niti Bharat helps Indian companies build a DPDP-compliant consent architecture that stands on its own, rather than assuming an existing Australian or global consent flow will carry over.

India uses a negative-list transfer model, not Australia-style accountability

On cross-border transfers, the two regimes take genuinely different approaches. India's DPDP framework uses a negative-list (or blacklist) model: personal data may generally be transferred outside India unless the Central Government specifically restricts transfers to a notified country or territory. This is a materially different design from GDPR-style adequacy — there is no requirement to first prove that a destination country is adequate. Australia's APP 8, on the other hand, is an accountability model: the disclosing entity must take reasonable steps to ensure an overseas recipient handles the data consistently with the APPs, and often remains liable for the recipient's conduct.

The practical upshot is that an India-to-Australia data flow is straightforward under DPDP as long as Australia is not later placed on a restricted list, but an Australia-to-India flow triggers APP 8 accountability on the Australian sender. Niti Bharat maps these flows for clients with dual operations so each transfer is documented against the correct regime, ahead of India's expected May 2027 enforcement date.

Get the India-Australia privacy comparison matrix (free)

A side-by-side PDF mapping DPDP against the Australian Privacy Principles across consent, transfers, breach, rights and penalties — with a dual-compliance action checklist.

Frequently Asked Questions

Does complying with the Australia Privacy Act mean I comply with DPDP?+
No. The two regimes differ on consent basis, breach triggers, transfer rules and rights. Australian purpose-based collection in particular does not satisfy DPDP's consent-first standard, so an Australia-compliant organisation still needs a separate DPDP compliance program for its Indian Data Principals.
Is Australia an 'adequate' country for DPDP transfers?+
DPDP does not use a GDPR-style adequacy list. It uses a negative-list model — transfers out of India are generally permitted unless the Central Government restricts a specific country. So the question is not whether Australia is 'adequate' but whether it has been placed on any restricted list, which is a different mechanism.
Which regime has stricter breach notification?+
In practice DPDP's notification obligation is triggered more readily. Australia's Notifiable Data Breaches scheme requires notification only where serious harm is likely, whereas DPDP under the 2025 Rules requires notification without a general harm threshold. A breach that is not notifiable in Australia may still be reportable in India.
Do I need different privacy notices for Indian and Australian users?+
Usually yes. DPDP requires a specific notice under Section 5 with particular content and, where relevant, an option in English or a Schedule language, while the APPs have their own notice expectations. A single blended notice often satisfies neither fully.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
India DPDP vs Canada PIPEDAIndia DPDP vs Japan APPIIndia DPDP vs UAE Data Law (PDPL)DPDP Data Volume Risk Calculator IndiaSee all Reference & Checklists tools →📝 How to Build DPDP Compliance Programme📝 Does DPDP Apply to B2b Data