The India DPDP Act 2023 and the Australia Privacy Act 1988 (with its 13 Australian Privacy Principles) both regulate personal data, but they differ sharply in structure. DPDP is consent-first with a narrow set of legitimate uses, while Australia's APPs allow collection for a primary purpose without always requiring express consent. On cross-border transfers, India uses a negative-list model — transfers are open unless the government restricts specific countries — whereas Australia (APP 8) makes the sender accountable for the overseas recipient's handling. Penalties differ too: DPDP ceilings reach ₹250 crore, while Australia's serious-breach penalties are set in Australian-dollar or turnover terms. This tool compares the two obligation area by obligation area.
If your organisation handles data across India and Australia, the two regimes overlap but diverge in important ways. Pick an obligation area to see exactly where.
The clearest divergence between the India DPDP Act and the Australia Privacy Act is the role of consent. DPDP is fundamentally consent-first: under Section 6, a data fiduciary generally needs free, specific, informed and unambiguous consent to process personal data, with only a narrow set of Legitimate Uses as alternatives. There is deliberately no broad legitimate-interest basis of the kind many global privacy laws rely on. Australia's 13 Australian Privacy Principles, by contrast, allow an entity to collect personal information that is reasonably necessary for its functions or activities, reserving express consent mainly for sensitive information.
For an Indian mid-market company that also serves Australian customers, this means a single consent design will not comfortably cover both regimes. Practices that are acceptable under Australian purpose-based collection can fall short of DPDP's explicit, unbundled consent standard for Indian Data Principals. Niti Bharat helps Indian companies build a DPDP-compliant consent architecture that stands on its own, rather than assuming an existing Australian or global consent flow will carry over.
On cross-border transfers, the two regimes take genuinely different approaches. India's DPDP framework uses a negative-list (or blacklist) model: personal data may generally be transferred outside India unless the Central Government specifically restricts transfers to a notified country or territory. This is a materially different design from GDPR-style adequacy — there is no requirement to first prove that a destination country is adequate. Australia's APP 8, on the other hand, is an accountability model: the disclosing entity must take reasonable steps to ensure an overseas recipient handles the data consistently with the APPs, and often remains liable for the recipient's conduct.
The practical upshot is that an India-to-Australia data flow is straightforward under DPDP as long as Australia is not later placed on a restricted list, but an Australia-to-India flow triggers APP 8 accountability on the Australian sender. Niti Bharat maps these flows for clients with dual operations so each transfer is documented against the correct regime, ahead of India's expected May 2027 enforcement date.
A side-by-side PDF mapping DPDP against the Australian Privacy Principles across consent, transfers, breach, rights and penalties — with a dual-compliance action checklist.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.