DPDPAcademyKnow the law. Prove it.
Home/DPDP vs GDPR
DPDP Act, 2023 · Regulation (EU) 2016/679

Same Vocabulary. Different Machine.

The DPDP Act borrows GDPR's grammar - notice, consent, processors, breach reporting - and then removes the provision most GDPR programmes are actually built on. If you map one onto the other clause by clause, the mapping fails in four specific places.

Provision-levelCurrent as of 13 August 2026
Where the mapping breaks

Four differences that change the architecture

There is no legitimate interestGDPR Article 6(1)(f) carries an enormous amount of ordinary corporate processing: analytics, fraud prevention, direct marketing, intra-group transfers. The DPDP Act has no equivalent. Processing rests on consent under section 6, or on one of the nine certain legitimate uses in section 7, and that list is closed and largely State-facing.What it costs you: Anything your GDPR record of processing justifies on legitimate interests needs a fresh basis in India, and for most commercial purposes the only one available is consent.
There is no sensitive data tierGDPR Article 9 fences off health, biometrics, religion, sexual orientation and more, with a separate set of conditions. The DPDP Act regulates all digital personal data at a single standard. The outgoing SPDI Rules had a sensitive category; the Act deliberately drops it.What it costs you: Controls keyed to a special-category flag do not map. The DPDP question is not what kind of data it is, but whether you have a lawful basis and a notice for the purpose.
Three GDPR rights simply do not existThere is no right to data portability, no right to object to processing, and no right not to be subject to solely automated decisions. The DPDP Act gives four rights: access to information about processing, correction and erasure, grievance redressal, and nomination.What it costs you: A GDPR rights engine over-delivers on scope but under-delivers on one thing India adds: nomination, which lets an individual appoint someone to exercise rights on death or incapacity.
Penalties replace compensationGDPR Article 82 gives the individual a right to compensation for material or non-material damage. The DPDP Act gives the Data Protection Board a power to impose monetary penalties, and section 34 sends those sums to the Consolidated Fund of India. The individual gets a grievance route and an appeal, not damages.What it costs you: Your exposure model changes shape: fewer claimant-driven risks, one regulator-driven risk, capped by the Schedule at ₹250 crore for a security-safeguard failure.
Side by side

Fourteen dimensions, with the provisions

DimensionEU GDPRDPDP Act, 2023
Territorial reachArticle 3: establishment in the EU, or offering goods or services to, or monitoring behaviour of, people in the EU.Section 3: digital personal data processed in India, and processing outside India connected with offering goods or services to Data Principals in India. Monitoring alone is not a trigger.
Publicly available dataNo general carve-out. Public availability does not remove the data from scope.Section 3(c)(ii) excludes data the individual made public herself, or that someone was legally obliged to publish.
Lawful basesSix, including contract, legal obligation, vital interests, public task and legitimate interests.Consent, or the nine certain legitimate uses in section 7. No contract basis and no legitimate interests.
Consent standardFreely given, specific, informed, unambiguous, by clear affirmative action; withdrawable as easily as given.The same, plus unconditional, and limited to the data necessary for the purpose. Section 6(1).
Special categoriesArticle 9 fences off health, biometrics, race, religion, politics, sexual orientation, trade union membership.No tier. All digital personal data is treated at one standard.
ChildrenArticle 8 sets 16 for information society services, with member states free to lower it to no less than 13.Under 18, with verifiable parental consent. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright by section 9(3).
Individual rightsAccess, rectification, erasure, restriction, portability, objection, and rights around automated decision-making.Access to information about processing, correction and erasure, grievance redressal, and nomination. Sections 11 to 14.
Duties on the individualNone. GDPR imposes nothing on the data subject.Section 15 imposes five duties, and breaching them is a penalty head in the Schedule carrying up to ₹10,000.
Breach notificationArticle 33: to the supervisory authority within 72 hours where feasible, unless unlikely to result in risk. Article 34: to individuals only where high risk.Section 8(6): intimate the Board and every affected Data Principal, in the form and manner prescribed. The section states no materiality threshold.
DPOArticle 37: required for public authorities, large-scale systematic monitoring, or large-scale special-category processing.Only for a Significant Data Fiduciary. The DPO must be based in India and answerable to the board of directors. Section 10(2)(a).
Impact assessmentsArticle 35: triggered by high risk, whoever the controller is.Periodic Data Protection Impact Assessment, but only for a Significant Data Fiduciary. Section 10(2)(c).
Cross-border transfersPermitted where there is adequacy, or safeguards such as standard contractual clauses or binding corporate rules, or a derogation applies.Permitted by default. Section 16 lets the Central Government restrict transfers to notified countries, and preserves any stricter sectoral rule already in force.
Consent intermediariesNo statutory concept.Consent Managers, registered with the Board, through which an individual can give, manage, review and withdraw consent. Accountable to her, not to the Data Fiduciary.
Maximum exposureUp to €20 million or 4% of worldwide annual turnover, whichever is higher, plus an individual right to compensation.Up to ₹250 crore per penalty head under the Schedule. No statutory compensation route for the individual.
If you already run GDPR

What carries over, and what does not

A GDPR programme is a genuine head start, but it is a head start on the plumbing rather than on the legal analysis. The expensive part to redo is the part you did first.

Reuses well
  • Your data inventory and processing records - the underlying mapping is the same work.
  • Processor due diligence and contract machinery; section 8(2) also requires a valid contract.
  • Security engineering. Section 8(5) asks for reasonable safeguards without naming a standard, so an existing ISO 27001 or SOC 2 programme is evidence, not waste.
  • Retention and deletion tooling, which section 8(7) needs in a very similar shape.
Needs rebuilding
  • Every legitimate-interest assessment. There is nothing to map it onto.
  • Consent capture, because DPDP consent must be unconditional and itemised against a section 5 notice.
  • Breach triage, since the GDPR risk threshold does not appear in section 8(6).
  • Special-category handling, which has no counterpart and may be over-engineered for India.
  • Rights fulfilment, which needs nomination added and portability removed.
Reading this comparison honestly

The DPDP column is taken from the Act as published in the Gazette and is linked to the provision in every row you can check. The GDPR column describes Regulation (EU) 2016/679 as it stands today; its substantive obligations are unchanged, though a separate procedural regulation on cross-border enforcement came into force in January 2026 and applies to new cross-border cases from April 2027.

Most DPDP obligations are themselves not yet in force. See the commencement timeline and what still applies until then.

Regulation (EU) 2016/679 on EUR-Lex
FAQ

DPDP and GDPR, answered

Is the DPDP Act basically India's GDPR?

No. They share vocabulary and a consent-and-notice backbone, but the DPDP Act has no legitimate interests basis, no special-category tier, no portability or objection rights, and no individual right to compensation. It also does something GDPR never does: it places enforceable duties on the individual.

If we are already GDPR compliant, are we DPDP compliant?

Not automatically, and the gap is usually in the same place. Most GDPR programmes lean on legitimate interests for analytics, fraud prevention and marketing. India has no such basis, so that processing needs consent or it needs to stop.

Does the DPDP Act require data localisation?

Not as a general rule. Section 16 works the other way round from GDPR: transfers are permitted unless the Central Government notifies a country as restricted. Section 16(2) preserves stricter sectoral requirements that already exist, such as those applying to regulated financial entities.

Which is stricter?

Neither, cleanly. GDPR is broader in rights and in lawful bases. The DPDP Act is narrower on bases, which makes consent harder to avoid, and it is unusually strict on children, where tracking and targeted advertising are prohibited outright rather than risk-assessed.

Do GDPR standard contractual clauses satisfy the DPDP Act?

They are not a DPDP instrument and nothing in the Act recognises them. Because section 16 permits transfer by default, SCCs are also not usually needed for the DPDP question. They remain relevant to the GDPR side of the same transfer.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 9 August 2026 against the DPDP Act, 2023 and notified DPDP Rules, 2025. Educational information, not legal advice.

Review standards and attribution →