DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

India's DPDP Act 2023 and US state privacy laws such as California's CCPA/CPRA take fundamentally different approaches. The DPDP Act is a single national law built on an opt-in consent model — you generally need affirmative consent (or a defined legitimate use) before processing. US state laws are a patchwork with no federal statute, and most (including California, Virginia and Colorado) use an opt-out model for many uses, especially the sale or sharing of data and targeted advertising. On transfers, the DPDP Act uses a negative-list model (generally permitted unless restricted), whereas US state laws impose few cross-border transfer restrictions at all. This tool shows which obligations apply to your India-US operation.

DPDP vs US State Privacy Laws (CCPA and Others)

India has one national law; the US has a growing patchwork of state laws. If you serve US consumers or have a US parent, see exactly how the DPDP Act and US state laws differ.

Which obligations apply to your India-US operation?

DPDP Act vs US state privacy laws — what actually differs

Opt-in vs opt-out — the core DPDP vs US state law difference

The defining difference between the DPDP Act 2023 and US state privacy laws is the permission model. The DPDP Act is an opt-in regime: as a general rule you must obtain affirmative, specific and unambiguous consent — or rely on a defined legitimate use — before processing an individual's personal data. Most US state laws, led by California's CCPA/CPRA and followed by Virginia, Colorado and others, use an opt-out model: businesses may process data with appropriate notice, and consumers have the right to opt out of the sale or sharing of their data and of targeted advertising, often via a Do Not Sell or Share My Personal Information mechanism.

For a company operating in both markets, the same activity can require different mechanics. Targeted advertising to an Indian user needs a valid consent basis under the DPDP Act before it happens; the same advertising to a Californian consumer is permitted with notice but must offer an opt-out. This is why region-aware consent and preference management — not a single global setting — is usually the right architecture for India-US operations.

How do transfers and penalties compare for India-US data flows?

On cross-border transfers, the two systems are unusually aligned in their permissiveness, though for different reasons. US state laws generally do not impose location-based restrictions on where personal data may be sent. The DPDP Act uses a negative-list model under which transfers of personal data out of India are generally permitted unless the government notifies a restricted country. As a result, the flow of data between India and the US is rarely constrained by transfer rules themselves — the binding constraints are the consent model, downstream-use disclosures and sector-specific requirements.

Penalties diverge more sharply. US state penalties are typically assessed per violation (for example, statutory amounts per affected consumer, which can aggregate into large sums), enforced by state attorneys general or the California Privacy Protection Agency. The DPDP Act uses fixed rupee ceilings up to ₹250 crore for the most serious failures. Niti Bharat helps India-US companies — especially SaaS products and GCCs with a US parent — build a single compliance architecture that satisfies the DPDP Act opt-in standard for Indian users while respecting the opt-out rights US consumers expect, ahead of the expected May 2027 DPDP enforcement date.

Get the DPDP vs US state laws comparison guide (free)

A side-by-side PDF comparing the DPDP Act with CCPA/CPRA and other US state laws — opt-in vs opt-out, transfers, rights, sensitive data and penalties — with a dual-market checklist.

Frequently Asked Questions

Is there a US federal law equivalent to the DPDP Act?+
No. Unlike India's single national DPDP Act, the US has no comprehensive federal privacy law. Instead it has a growing patchwork of state laws (California, Virginia, Colorado, Connecticut, Utah and others), each with its own thresholds, definitions and rights.
Does the CCPA apply to an Indian company?+
It can, if the company meets the CCPA/CPRA applicability thresholds in relation to California consumers (for example, revenue or data-volume thresholds, or deriving revenue from selling personal information). If it does not meet those thresholds and has no California exposure, the CCPA generally will not apply.
Can I use one consent banner for both India and the US?+
It is usually better to use a region-aware approach. Indian users need affirmative opt-in consent under the DPDP Act, while US consumers under most state laws need an opt-out (for sale, sharing and targeted advertising). A single global banner risks either over-collecting consent in the US or under-collecting it in India.
Are cross-border transfers a problem for India-US data flows?+
Rarely, in themselves. US state laws impose few location-based transfer restrictions, and the DPDP Act permits transfers unless a country is restricted by government notification. The practical constraints are usually the consent model and downstream-use disclosures, not the transfer rules.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
DPDP Whistleblowing & ComplaintsDPDP अनुपालन कैलेंडरDPDP अनुपालन चेकलिस्टConsent Validity Period CalculatorSee all Reference & Checklists tools →📝 How to Implement Data Retention Deletion DPDP📝 DPDP for Payment Aggregators