DPDP vs GDPR: Key Differences Between India's and the EU's Data Protection Laws
A glossary-style comparison of India's Digital Personal Data Protection Act, 2023 and the EU General Data Protection Regulation.
What is the difference between DPDP and GDPR?
Why this comparison matters
Indian companies that serve EU customers, run global shared-service centres, or process data for EU controllers often need to comply with both regimes. Boards and CFOs usually ask a single question: if we are already GDPR-compliant, are we DPDP-compliant? The short answer is "mostly, but not automatically". The DPDP Act is narrower in scope but stricter on consent, it introduces roles (Consent Manager, Significant Data Fiduciary) that have no GDPR equivalent, and its compliance clock runs to May 2027 under the DPDP Rules 2025.
If the Indian framework itself is new to you, start with our plain-English guide to the DPDP Act, and see how the roles divide in Data Fiduciary vs Data Processor under the DPDP Act.
DPDP Act and GDPR: Key Terms Explained
The two laws use different words for the same actors. This is the mapping that most often trips up a team writing its first India-facing notice. For the regime the DPDP Act replaced, see DPDP Act vs IT Act SPDI Rules.
- DPDP Act
- Digital Personal Data Protection Act, 2023. Enacted 11 August 2023. Operational obligations phased in through the DPDP Rules notified 14 November 2025.
- GDPR
- General Data Protection Regulation (EU) 2016/679. In force since 25 May 2018 across the EU and EEA.
- Data Principal
- DPDP term for the individual the data relates to. GDPR calls this person the Data Subject.
- Data Fiduciary
- DPDP term for the entity that decides the purpose and means of processing. GDPR equivalent: Controller.
- Data Processor
- Entity that processes personal data on behalf of a Data Fiduciary. Same term used in both laws.
- Significant Data Fiduciary (SDF)
- A Data Fiduciary notified by the Central Government based on volume, sensitivity and risk, carrying extra obligations. No direct GDPR equivalent.
- Consent Manager
- A Board-registered Indian company that gives Data Principals a single interface to give, manage and withdraw consent. No GDPR equivalent.
- Data Protection Board of India
- The adjudicating body under the DPDP Act. GDPR equivalent: national Supervisory Authorities coordinated by the EDPB.
- Legitimate uses
- Section 7 of the DPDP Act: specified situations where processing is allowed without consent. Narrower than GDPR's legitimate interests basis.
DPDP vs GDPR Comparison Table
Sixteen dimensions, side by side. The rows that change a programme are covered in the section below.
| Dimension | DPDP Act 2023 (India) | GDPR (EU) |
|---|---|---|
| Scope of data | Digital personal data only, including offline data that is later digitised. | All personal data, digital and structured manual filing systems. |
| Sensitive data | No separate category. All personal data treated alike, apart from children's data and SDF-related risk classification. | Special categories (health, biometrics, religion, sexual orientation etc.) with stricter conditions under Article 9. |
| Lawful bases | Two: consent, or a listed "legitimate use" under Section 7. | Six: consent, contract, legal obligation, vital interests, public task, legitimate interests. |
| Consent standard | Free, specific, informed, unconditional, unambiguous, clear affirmative action; limited to the specified purpose. | Freely given, specific, informed, unambiguous; explicit consent for special categories. |
| Withdrawal of consent | Must be as easy as giving consent. Consent Managers provide a single dashboard. | Must be as easy as giving consent. No Consent Manager concept. |
| Territorial reach | Processing within India, plus processing outside India connected with offering goods or services to Data Principals in India. | Establishments in the EU, plus offering goods/services to, or monitoring, individuals in the EU. |
| Children | Under 18. Verifiable parental consent; no tracking, behavioural monitoring or targeted advertising. | Under 16 (member states may lower to 13). Parental consent for information society services. |
| Individual rights | Access, correction, erasure, grievance redressal, nomination. No explicit portability or objection right. | Access, rectification, erasure, restriction, portability, objection, and rights around automated decision-making. |
| Data Protection Officer | Mandatory only for SDFs; must be based in India and report to the board. | Mandatory for public authorities, large-scale monitoring, or large-scale special-category processing. |
| Impact assessments | Annual DPIA and independent audit for SDFs. | DPIA required where processing is likely to result in high risk. |
| Breach notification | Every breach must be reported to the Board and affected Data Principals; detailed report to the Board within 72 hours of awareness under the Rules. | To supervisory authority within 72 hours if risk to individuals; to individuals only where high risk. |
| Cross-border transfers | Allowed by default except to countries the Central Government restricts. SDFs may face additional localisation restrictions. | Restricted by default; requires adequacy decision, SCCs, BCRs or derogations. |
| Duties on individuals | Yes. Data Principals must not file false complaints or impersonate; penalty up to INR 10,000. | None. |
| Regulator | Data Protection Board of India (digital-first adjudicator). | Independent Supervisory Authority in each member state; EDPB for consistency. |
| Maximum penalty | Up to INR 250 crore per instance for failure of reasonable security safeguards; INR 200 crore for breach-notification and children’s data failures. | Up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher. |
| Private right of action | No statutory compensation route; complaints go to the Board. | Right to compensation and judicial remedy under Articles 79 and 82. |
5 Differences That Change Your Compliance Programme
Consent is the default under DPDP, not one of six lawful bases
Under the GDPR, most B2B and employment processing rests on contract or legitimate interests. The DPDP Act allows processing without consent only for listed legitimate uses (voluntary provision, State functions, employment purposes, medical emergencies, and similar). Marketing, analytics, profiling and data monetisation almost always need consent. Expect consent volumes, and therefore consent-record management, to be far higher under DPDP.
DPDP notice and consent requirements
The DPDP Rules require the notice to be a standalone, itemised description of the personal data and the purpose, with the link to withdraw consent and file a complaint. A GDPR-style layered privacy policy will not satisfy this on its own. Consent records must be retained as evidence.
Every breach is notifiable under DPDP
The GDPR has a risk threshold. The DPDP Act has none: every personal data breach must be reported to the Board and to affected individuals. This lifts the operational bar for incident detection, classification and communication templates.
Significant Data Fiduciary designation
GDPR obligations scale with risk in a self-assessed way. Under DPDP, the Central Government notifies SDFs, who must appoint an India-based DPO, run annual DPIAs and independent audits, perform algorithmic due diligence, and comply with any data-localisation restrictions. Financial services, healthcare, telecom and large platforms are the most likely candidates — Significant Data Fiduciary (SDF) explained walks through the Section 10 factors, and the SDF classifier tests your own profile against them.
Individual rights and duties under DPDP vs GDPR
The DPDP Act does not grant portability, objection or automated-decision rights. It does, however, impose duties on Data Principals, which is unusual globally. Grievance redressal SLAs are set by the Data Fiduciary but must be published.
DPDP Compliance Timeline (DPDP Rules 2025)
| Phase | Effective date | What applies |
|---|---|---|
| Phase 1 | 14 November 2025 | Definitions, Data Protection Board constitution and administrative rules in force. |
| Phase 2 | 13 November 2026 | Consent Manager registration framework operational. |
| Phase 3 | 13 May 2027 | All substantive obligations: notice, consent, security safeguards, breach reporting, Data Principal rights, SDF duties, and penalties. |
Already GDPR-Compliant? DPDP Gap Checklist
- Re-map every processing activity to either consent or a Section 7 legitimate use. Anything resting on GDPR legitimate interests needs a new basis.
- Redesign consent notices to the DPDP Rules format (itemised data, purpose, withdrawal link, complaint route, available in English and Eighth Schedule languages on request).
- Build consent records and a withdrawal workflow; assess Consent Manager integration for consumer-facing businesses.
- Remove the "risk threshold" from your breach playbook; every breach is notifiable to the Board and to individuals.
- Assess SDF exposure and pre-position a DPO in India, DPIA calendar and audit partner.
- Add Data Principal rights handling for nomination (a DPDP-specific right) and erasure on consent withdrawal.
- Review Data Processor contracts for DPDP clauses: the Data Fiduciary stays fully liable regardless of processor conduct.
- Review data retention against the Third Schedule (e-commerce, gaming and social media intermediaries above user thresholds must erase after three years of inactivity).
Frequently Asked Questions: DPDP vs GDPR
Key takeaways
- DPDP is consent-first; GDPR is basis-flexible. This is the single largest programme difference.
- DPDP has no sensitive-data category but uses SDF designation to escalate obligations by risk.
- Every breach is notifiable under DPDP; the GDPR applies a risk threshold.
- Penalties differ in structure: rupee caps per instance versus percentage of global turnover.
- Full DPDP enforcement is scheduled for 13 May 2027, with Consent Manager registration from 13 November 2026.