India's DPDP Act 2023 and US state privacy laws such as California's CCPA/CPRA take fundamentally different approaches. The DPDP Act is a single national law built on an opt-in consent model — you generally need affirmative consent (or a defined legitimate use) before processing. US state laws are a patchwork with no federal statute, and most (including California, Virginia and Colorado) use an opt-out model for many uses, especially the sale or sharing of data and targeted advertising. On transfers, the DPDP Act uses a negative-list model (generally permitted unless restricted), whereas US state laws impose few cross-border transfer restrictions at all. This tool shows which obligations apply to your India-US operation.
India has one national law; the US has a growing patchwork of state laws. If you serve US consumers or have a US parent, see exactly how the DPDP Act and US state laws differ.
The defining difference between the DPDP Act 2023 and US state privacy laws is the permission model. The DPDP Act is an opt-in regime: as a general rule you must obtain affirmative, specific and unambiguous consent — or rely on a defined legitimate use — before processing an individual's personal data. Most US state laws, led by California's CCPA/CPRA and followed by Virginia, Colorado and others, use an opt-out model: businesses may process data with appropriate notice, and consumers have the right to opt out of the sale or sharing of their data and of targeted advertising, often via a Do Not Sell or Share My Personal Information mechanism.
For a company operating in both markets, the same activity can require different mechanics. Targeted advertising to an Indian user needs a valid consent basis under the DPDP Act before it happens; the same advertising to a Californian consumer is permitted with notice but must offer an opt-out. This is why region-aware consent and preference management — not a single global setting — is usually the right architecture for India-US operations.
On cross-border transfers, the two systems are unusually aligned in their permissiveness, though for different reasons. US state laws generally do not impose location-based restrictions on where personal data may be sent. The DPDP Act uses a negative-list model under which transfers of personal data out of India are generally permitted unless the government notifies a restricted country. As a result, the flow of data between India and the US is rarely constrained by transfer rules themselves — the binding constraints are the consent model, downstream-use disclosures and sector-specific requirements.
Penalties diverge more sharply. US state penalties are typically assessed per violation (for example, statutory amounts per affected consumer, which can aggregate into large sums), enforced by state attorneys general or the California Privacy Protection Agency. The DPDP Act uses fixed rupee ceilings up to ₹250 crore for the most serious failures. Niti Bharat helps India-US companies — especially SaaS products and GCCs with a US parent — build a single compliance architecture that satisfies the DPDP Act opt-in standard for Indian users while respecting the opt-out rights US consumers expect, ahead of the expected May 2027 DPDP enforcement date.
A side-by-side PDF comparing the DPDP Act with CCPA/CPRA and other US state laws — opt-in vs opt-out, transfers, rights, sensitive data and penalties — with a dual-market checklist.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.