India's DPDP Act 2023 and the UK GDPR both regulate personal data, but they differ in structure. The UK GDPR uses an adequacy and positive-list model for international transfers, while the DPDP Act uses a negative-list model — transfers abroad are generally permitted unless the government notifies a restricted country. The DPDP Act is narrower in scope (digital personal data only, no separate sensitive-data category), has a single lawful basis emphasis on consent and legitimate uses, and caps penalties at fixed rupee ceilings rather than a percentage of global turnover. This tool shows which regime applies to your India-UK operations and where the gaps are.
If you move personal data between India and the UK, both regimes may apply to you. See exactly where the DPDP Act 2023 and the UK GDPR differ, and what it means for your setup.
This is the single most misunderstood difference between the two regimes. The UK GDPR operates on a positive model: to send personal data out of the UK, you need a recognised basis — an adequacy regulation, the International Data Transfer Agreement or UK Addendum to the EU SCCs, or another approved safeguard. The default is that transfers are restricted until you put a mechanism in place. The DPDP Act 2023 inverts this. It uses a negative-list model: transfers of personal data outside India are generally permitted, and the government may notify specific countries or territories to which transfers are restricted. Until such a restriction is notified, an outbound transfer is not blocked by the transfer rule itself.
For an India-UK operation this has practical consequences. A UK entity sending data to its Indian subsidiary must still satisfy UK GDPR transfer requirements on the UK side. But the reverse flow — Indian personal data going to the UK — is governed by the DPDP Act's lighter negative-list approach, subject to any sector-specific rules and any restricted-country list the government issues. Niti Bharat helps India-UK groups map these flows so each direction is assessed under the right regime rather than defaulting to the stricter one everywhere.
Often, yes. If your India-based company offers goods or services to individuals located in the UK, or monitors their behaviour, the UK GDPR can apply extraterritorially to that processing, while the DPDP Act governs your handling of Indian personal data. Rather than trying to run two parallel compliance programmes, most mid-market companies are better served by a single register that tags each processing activity with its governing regime, lawful basis and transfer position — then applies the appropriate standard per activity.
The good news is that a strong DPDP programme — dated consent records, a published Grievance Officer, security safeguards and a data-flow map — covers much of what UK GDPR also expects. Niti Bharat's fixed-price DPDP readiness work (₹75,000–₹3.2 lakh) is built for exactly this kind of company: Indian mid-market firms with UK-facing operations that need to be defensible under both regimes before the expected May 2027 DPDP enforcement date.
A side-by-side PDF mapping every major difference between the DPDP Act 2023 and the UK GDPR — scope, transfers, lawful basis, rights, penalties — plus a dual-regime action checklist.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.