DPDP Act vs GDPR — Key Differences at a Glance
| Parameter | DPDP Act 2023 (India) | GDPR (EU) |
|---|---|---|
| Scope | Digital personal data processed in India | All personal data of EU residents |
| Lawful Bases | Consent + Legitimate Uses (limited) | 6 lawful bases including legitimate interest |
| Maximum Penalty | ₹250 Crore (fixed cap per violation) | 4% of global turnover or €20M |
| DPO Requirement | Only for Significant Data Fiduciaries | Required for large-scale processing |
| Cross-border Transfers | Allowed except to blacklisted countries | Requires adequacy decision or SCCs |
| Right to Portability | Not explicitly included | Explicit right under Article 20 |
| Enforcement Body | Data Protection Board of India | National DPAs (e.g., CNIL, ICO) |
Last Updated: June 9, 2026 · Author: Saurabh Gupta, CISM, CIPP/E · Founder, MYITMANAGER
Indian businesses already operating under GDPR — or those evaluating which framework to prioritise — face a natural question: how different is the DPDP Act from GDPR, and can one compliance programme satisfy both?
The answer is nuanced. The DPDP Act borrows significantly from GDPR in structure and philosophy, but diverges in several operationally important ways. This guide maps the key differences, highlights where dual-compliance is efficient, and identifies where you need India-specific controls that GDPR compliance alone does not cover.
DPDP Act vs GDPR — Quick Comparison
| Feature | DPDP Act 2023 (India) | GDPR (EU) |
|---|---|---|
| Applies to | Digital personal data of Indian residents processed in India or for Indian-resident targeting | Personal data of EU residents processed anywhere |
| Sensitive data category | No separate category — all personal data treated equally (children’s data has higher protection) | Special categories (health, biometric, racial origin, etc.) with stricter requirements |
| Legal bases for processing | Consent + 8 “certain legitimate uses” (narrower than GDPR’s 6 lawful bases) | 6 lawful bases including legitimate interests, contract, legal obligation |
| Legitimate interests | Not available as a standalone legal basis | Available — widely used for B2B marketing and analytics |
| Right to portability | Not included | Included (Article 20) |
| Right to object | Not included as a standalone right | Included (Article 21) |
| DPO requirement | Mandatory only for Significant Data Fiduciaries | Mandatory for public authorities and high-risk processing |
| DPIA requirement | Mandatory for Significant Data Fiduciaries | Required for high-risk processing (broader scope) |
| Breach notification timeline | To DPBI promptly; timeline via Rules | 72 hours to supervisory authority; without undue delay to individuals |
| Cross-border transfers | Approved country list (to be notified) | Adequacy decisions, SCCs, BCRs |
| Maximum penalty | ₹250 crore (~€28M) per violation | €20M or 4% of global annual turnover, whichever is higher |
| Enforcement body | Data Protection Board of India (DPBI) | National Data Protection Authorities (DPAs) |
7 Key Differences That Matter Operationally
1. No “Legitimate Interests” Legal Basis Under DPDP
GDPR’s legitimate interests basis (Article 6(1)(f)) is widely used for B2B marketing, fraud prevention, network security, and analytics. The DPDP Act does not provide an equivalent. Under DPDP, processing without consent requires falling under one of the Act’s “certain legitimate uses” — a narrower list that includes employment, medical emergencies, court orders, and state functions, but does not cover the broad legitimate interests processing that many businesses rely on under GDPR.
Impact: Businesses that process personal data under GDPR’s legitimate interests basis — particularly for marketing, analytics, and profiling — will need to obtain explicit consent under DPDP for the same activities. This is the most significant practical compliance gap for companies that have relied on GDPR’s legitimate interests for Indian-resident data.
2. No Separate Sensitive Data Category
GDPR’s Article 9 creates a higher-protection category for sensitive data — health, biometric, racial or ethnic origin, religious belief, sexual orientation, and genetic data — requiring explicit consent or a specific exemption. The DPDP Act treats all personal data equally, with children’s data as the only explicitly higher-protection category.
Impact: Indian businesses handling health or biometric data face lower formal barriers under DPDP than GDPR for that data category specifically. However, security obligations and breach notification requirements still apply, and sector regulators (RBI, IRDAI, healthcare regulators) may impose additional requirements. GDPR-compliant data handling for sensitive categories remains a useful benchmark even where not legally required under DPDP.
3. Consent Standard Is Stricter Under DPDP
Both frameworks require consent to be freely given, specific, informed, and withdrawable. However, DPDP’s consent standard is in some ways more demanding: consent must be “unconditional” and cannot be bundled with T&C acceptance. The Act also requires consent to be requested in plain language with a notice at the point of collection — stricter than GDPR’s notice requirements in practice.
Impact: Businesses that have implemented GDPR-grade consent may still need to redesign consent flows for DPDP compliance, particularly if they currently bundle consent with service agreements or rely on pre-ticked boxes.
4. Right to Portability Absent Under DPDP
GDPR Article 20 gives data subjects the right to receive their personal data in a structured, machine-readable format and transfer it to another controller. The DPDP Act has no equivalent right. Indian users cannot demand a data export in a portable format — they can only request access to a summary of their data.
Impact: For businesses building data portability features purely for GDPR compliance, those features are not legally required under DPDP for Indian-only users. However, portability is increasingly a product trust signal, and building it once for GDPR and extending to Indian users is efficient.
5. DPO Requirements Are Narrower Under DPDP
GDPR requires DPO appointment for all public authorities and private organisations conducting large-scale systematic monitoring or large-scale processing of special category data — a broad requirement that captures most large businesses. DPDP’s DPO requirement applies only to Significant Data Fiduciaries designated by the Central Government.
Impact: Many businesses that appointed DPOs for GDPR compliance may not be legally required to have one under DPDP (unless designated as SDF). However, voluntary DPO appointment is a credible signal of compliance commitment and useful when responding to enterprise procurement due diligence. MYITMANAGER’s DPO-as-a-Service covers both frameworks.
6. Breach Notification — Timing Differs
GDPR’s 72-hour breach notification clock to supervisory authorities is well-established. DPDP’s Rules require notification “promptly” — the precise timeline is specified in the Rules but is expected to be shorter than 72 hours for the most severe breaches. Both frameworks require notification to affected individuals where the breach is likely to cause harm.
Impact: Businesses with GDPR breach response procedures should review and adapt them for DPDP — the trigger and timeline may differ, and the DPBI notification process will be different from EU DPA procedures.
7. Penalty Structure — Per Violation vs Revenue-Based
GDPR’s penalty cap of €20M or 4% of global annual turnover means large multinationals face potentially enormous fines. DPDP’s penalties are capped per violation at fixed rupee amounts (maximum ₹250 crore), which may be proportionally lower for large companies but significant for Indian SMEs. Crucially, DPDP penalties can stack across multiple violations from a single incident.
Can GDPR Compliance Cover DPDP?
Partially — but not fully. GDPR compliance gives you a strong foundation: consent management, privacy notices, data mapping, breach response, vendor DPAs, and rights workflows are all required under both frameworks. A business that is genuinely GDPR-compliant has completed perhaps 60–70% of DPDP compliance work.
The gaps that require India-specific action:
- Redesigning any processing that relied on legitimate interests — requires explicit consent under DPDP
- Age verification and parental consent mechanisms for Indian users under 18
- DPBI breach notification procedure (separate from EU DPA notification)
- Indian-language consent notices and privacy disclosures where required
- Cross-border transfer compliance once India’s approved country list is published
- Grievance officer designation and Indian-resident rights request handling
Dual Compliance — GDPR + DPDP
For businesses operating in both the EU and India, MYITMANAGER builds integrated compliance frameworks that satisfy both GDPR and DPDP through a single programme — minimising duplication and ensuring consistent data governance across jurisdictions. Our engagements are led by Saurabh Gupta (CISM, CIPP/E) — the CIPP/E certification covers European privacy law, making him one of the few consultants in India with formal credentials in both frameworks.
The MYITMANAGER GRC Portal tracks DPDP, GDPR, ISO 27001, and SOC 2 obligations in a single dashboard — eliminating the parallel spreadsheet problem for multi-framework compliance teams.
Book a free DPDP gap assessment → Written RAG-scored report in 5 business days, covering both DPDP and your existing GDPR alignment.
Ready to Start Your DPDP Compliance Programme?
Our DPDP compliance specialists will map your gaps against the Act and give you a fixed-price implementation plan.
Get a free DPDP gap assessment →Not sure where your organisation stands on DPDP compliance?
Get a complimentary DPDP Readiness Assessment — delivered in 5 business days.