Same Vocabulary. Different Machine.
The DPDP Act borrows GDPR's grammar - notice, consent, processors, breach reporting - and then removes the provision most GDPR programmes are actually built on. If you map one onto the other clause by clause, the mapping fails in four specific places.
Four differences that change the architecture
Fourteen dimensions, with the provisions
| Dimension | EU GDPR | DPDP Act, 2023 |
|---|---|---|
| Territorial reach | Article 3: establishment in the EU, or offering goods or services to, or monitoring behaviour of, people in the EU. | Section 3: digital personal data processed in India, and processing outside India connected with offering goods or services to Data Principals in India. Monitoring alone is not a trigger. |
| Publicly available data | No general carve-out. Public availability does not remove the data from scope. | Section 3(c)(ii) excludes data the individual made public herself, or that someone was legally obliged to publish. |
| Lawful bases | Six, including contract, legal obligation, vital interests, public task and legitimate interests. | Consent, or the nine certain legitimate uses in section 7. No contract basis and no legitimate interests. |
| Consent standard | Freely given, specific, informed, unambiguous, by clear affirmative action; withdrawable as easily as given. | The same, plus unconditional, and limited to the data necessary for the purpose. Section 6(1). |
| Special categories | Article 9 fences off health, biometrics, race, religion, politics, sexual orientation, trade union membership. | No tier. All digital personal data is treated at one standard. |
| Children | Article 8 sets 16 for information society services, with member states free to lower it to no less than 13. | Under 18, with verifiable parental consent. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright by section 9(3). |
| Individual rights | Access, rectification, erasure, restriction, portability, objection, and rights around automated decision-making. | Access to information about processing, correction and erasure, grievance redressal, and nomination. Sections 11 to 14. |
| Duties on the individual | None. GDPR imposes nothing on the data subject. | Section 15 imposes five duties, and breaching them is a penalty head in the Schedule carrying up to ₹10,000. |
| Breach notification | Article 33: to the supervisory authority within 72 hours where feasible, unless unlikely to result in risk. Article 34: to individuals only where high risk. | Section 8(6): intimate the Board and every affected Data Principal, in the form and manner prescribed. The section states no materiality threshold. |
| DPO | Article 37: required for public authorities, large-scale systematic monitoring, or large-scale special-category processing. | Only for a Significant Data Fiduciary. The DPO must be based in India and answerable to the board of directors. Section 10(2)(a). |
| Impact assessments | Article 35: triggered by high risk, whoever the controller is. | Periodic Data Protection Impact Assessment, but only for a Significant Data Fiduciary. Section 10(2)(c). |
| Cross-border transfers | Permitted where there is adequacy, or safeguards such as standard contractual clauses or binding corporate rules, or a derogation applies. | Permitted by default. Section 16 lets the Central Government restrict transfers to notified countries, and preserves any stricter sectoral rule already in force. |
| Consent intermediaries | No statutory concept. | Consent Managers, registered with the Board, through which an individual can give, manage, review and withdraw consent. Accountable to her, not to the Data Fiduciary. |
| Maximum exposure | Up to €20 million or 4% of worldwide annual turnover, whichever is higher, plus an individual right to compensation. | Up to ₹250 crore per penalty head under the Schedule. No statutory compensation route for the individual. |
What carries over, and what does not
A GDPR programme is a genuine head start, but it is a head start on the plumbing rather than on the legal analysis. The expensive part to redo is the part you did first.
- Your data inventory and processing records - the underlying mapping is the same work.
- Processor due diligence and contract machinery; section 8(2) also requires a valid contract.
- Security engineering. Section 8(5) asks for reasonable safeguards without naming a standard, so an existing ISO 27001 or SOC 2 programme is evidence, not waste.
- Retention and deletion tooling, which section 8(7) needs in a very similar shape.
- Every legitimate-interest assessment. There is nothing to map it onto.
- Consent capture, because DPDP consent must be unconditional and itemised against a section 5 notice.
- Breach triage, since the GDPR risk threshold does not appear in section 8(6).
- Special-category handling, which has no counterpart and may be over-engineered for India.
- Rights fulfilment, which needs nomination added and portability removed.
The DPDP column is taken from the Act as published in the Gazette and is linked to the provision in every row you can check. The GDPR column describes Regulation (EU) 2016/679 as it stands today; its substantive obligations are unchanged, though a separate procedural regulation on cross-border enforcement came into force in January 2026 and applies to new cross-border cases from April 2027.
Most DPDP obligations are themselves not yet in force. See the commencement timeline and what still applies until then.
Regulation (EU) 2016/679 on EUR-LexDPDP and GDPR, answered
Is the DPDP Act basically India's GDPR?
No. They share vocabulary and a consent-and-notice backbone, but the DPDP Act has no legitimate interests basis, no special-category tier, no portability or objection rights, and no individual right to compensation. It also does something GDPR never does: it places enforceable duties on the individual.
If we are already GDPR compliant, are we DPDP compliant?
Not automatically, and the gap is usually in the same place. Most GDPR programmes lean on legitimate interests for analytics, fraud prevention and marketing. India has no such basis, so that processing needs consent or it needs to stop.
Does the DPDP Act require data localisation?
Not as a general rule. Section 16 works the other way round from GDPR: transfers are permitted unless the Central Government notifies a country as restricted. Section 16(2) preserves stricter sectoral requirements that already exist, such as those applying to regulated financial entities.
Which is stricter?
Neither, cleanly. GDPR is broader in rights and in lawful bases. The DPDP Act is narrower on bases, which makes consent harder to avoid, and it is unusually strict on children, where tracking and targeted advertising are prohibited outright rather than risk-assessed.
Do GDPR standard contractual clauses satisfy the DPDP Act?
They are not a DPDP instrument and nothing in the Act recognises them. Because section 16 permits transfer by default, SCCs are also not usually needed for the DPDP question. They remain relevant to the GDPR side of the same transfer.