DPDP Act vs CCPA/CPRA: Complete Comparison for Indian Companies (2026)
Last Updated: July 2026 · Author: Saurabh Gupta, CISM, CIPP/E · Founder, MYITMANAGER
DPDP Act vs CCPA/CPRA — Key Differences for Indian Companies
India’s Digital Personal Data Protection (DPDP) Act 2023 and California’s Consumer Privacy Act (CCPA), as amended and expanded by the California Privacy Rights Act (CPRA), both regulate how organisations handle personal data — but they’re built on fundamentally different models. DPDP is a consent-first regime: processing generally requires the individual’s opt-in consent. CCPA/CPRA is an opt-out regime built around the “sale or sharing” of personal information: businesses can process data by default, but must let consumers opt out of having it sold or shared, and must honour signals like the Global Privacy Control. This guide covers what Indian companies serving California customers need to know about both.
DPDP Act vs CCPA/CPRA — Quick Comparison
| Factor | India DPDP Act 2023 | California CCPA/CPRA |
|---|---|---|
| Enacted / Effective | Act passed August 2023; DPDP Rules notified 13 November 2025; full compliance deadline 13 May 2027 (phased) | CCPA effective January 2020; CPRA amendments effective January 2023; new CPRA regulations (risk assessments, cybersecurity audits, ADMT rights) effective January 2026 |
| Core Model | Consent-first — processing generally requires specific, informed, opt-in consent (or a defined “legitimate use”) | Opt-out — businesses can process and sell/share data by default; consumers must actively opt out, including via Global Privacy Control signals |
| Who Must Comply | Any entity processing digital personal data of individuals in India, including offshore processing | Businesses meeting a threshold: over $25M annual revenue, OR buying/selling/sharing data of 100,000+ California consumers/households, OR deriving 50%+ of revenue from selling personal information |
| Data Types Covered | Digital personal data only (physical/offline data excluded) | All personal information, digital and offline, including inferences drawn about a consumer |
| Sensitive Data Category | Not yet explicitly defined in the Act or Rules; children’s data (under 18) receives specific heightened protection under Section 9 | Explicitly defined “Sensitive Personal Information” — SSN, financial account details, precise geolocation, race/ethnicity, religion, genetic and biometric data, health data, sexual orientation, immigration status |
| Consumer / Data Principal Rights | Access, correction, erasure, grievance redressal, nomination (to exercise rights after death/incapacity) | Right to know, delete, correct, opt out of sale/sharing, limit use of sensitive personal information, data portability, non-discrimination for exercising rights |
| “Sale” of Data Concept | No equivalent concept — all processing and third-party sharing runs through the same consent framework | Central to the law — consumers have an explicit, standalone right to opt out of the “sale or sharing” of their personal information, including for cross-context behavioural advertising |
| Data Breach Notification | Immediate initial intimation to the Data Protection Board of India (DPBI), followed by a detailed report within 72 hours; affected data principals also notified within 72 hours | CCPA itself has no blanket breach notification duty; California’s separate breach law (Civil Code §1798.82) requires notice “without unreasonable delay” |
| DPO / Privacy Officer Requirement | Required only for Significant Data Fiduciaries (SDFs); must be India-based | No formal DPO mandate, but CPRA’s 2026 regulations require designated personnel for annual cybersecurity audits and risk assessments at qualifying businesses |
| Private Right of Action | None — enforcement runs solely through the Data Protection Board of India | Limited private right of action for certain data breaches, with statutory damages of $100–$750 per consumer per incident |
| Maximum Penalty | Up to ₹250 crore per instance for general violations; up to ₹200 crore specifically for breach notification failures | Up to $2,663 per unintentional violation, $7,988 per intentional or minor-related violation (2026 figures) — but counted per consumer, so aggregate exposure scales fast (GM’s $12.75M settlement, May 2026, is the largest CCPA fine to date) |
| Enforcement Body | Data Protection Board of India (DPBI) | California Privacy Protection Agency (CPPA), with concurrent jurisdiction held by the California Attorney General |
Key Differences That Impact Indian Companies Most
1. Opt-In Consent vs. Opt-Out Sale Rights
This is the single biggest structural difference. Under DPDP, you generally need affirmative, specific consent before processing someone’s data. Under CCPA/CPRA, you can process data by default — your obligation is to let consumers opt out of having their data sold or shared, including by honouring Global Privacy Control browser signals. An Indian company that has built a DPDP-compliant consent flow has not automatically built a CCPA-compliant opt-out flow, and vice versa — the mechanisms are structurally different, not just relabelled.
2. Revenue and Volume Thresholds Determine CCPA Applicability
Unlike DPDP, which applies to any entity processing Indian users’ digital personal data regardless of size, CCPA only applies to businesses crossing a specific threshold: over $25M in annual revenue, or handling data for 100,000+ California consumers/households annually, or deriving at least half of revenue from selling personal information. An Indian SaaS or e-commerce company with a small but growing California user base should actively track these thresholds rather than assume CCPA doesn’t apply yet.
3. CPRA’s 2026 Additions Raise the Bar Further
New CPRA regulations effective January 2026 add mandatory cybersecurity audits for certain business categories, risk assessments for automated decision-making technology (ADMT), and expanded consumer rights around algorithmic processes. Indian companies using AI-driven personalisation, credit scoring, or hiring tools for California users should treat this as a live compliance requirement, not a future one.
4. No Private Right of Action Under DPDP
DPDP enforcement runs entirely through the Data Protection Board of India — individuals cannot sue a company directly for a DPDP violation. CCPA carves out a narrow but real private right of action for data breaches involving certain categories of personal information, with statutory damages of $100–$750 per consumer. For companies with large California user bases, a single breach can mean thousands of individually actionable claims, not just a regulatory penalty.
5. Breach Notification Sits in Different Places
DPDP now has an explicit two-stage breach notification duty under the 2025 Rules — immediate initial intimation to the DPBI, then a detailed report within 72 hours, with affected individuals also notified within 72 hours. CCPA itself doesn’t set this obligation; it comes from California’s separate general breach notification statute, which requires notice “without unreasonable delay” rather than a fixed clock.
Do You Need Both DPDP and CCPA Compliance?
Indian companies need both if they: (1) process personal data of individuals in India (DPDP Act applies), AND (2) meet CCPA’s applicability thresholds for California consumers. This typically includes:
- Indian SaaS and e-commerce companies with a meaningful California customer base
- Indian companies selling consumer data, analytics, or advertising products that touch California users
- Indian companies with US subsidiaries, offices, or California-based employees
- Indian AI/ML companies whose products make automated decisions affecting California consumers
If you already have a DPDP consent framework in place, CCPA compliance is not simply an extension of it — you’ll need a separate opt-out mechanism, Global Privacy Control support, a “Do Not Sell or Share My Personal Information” pathway, and (if you meet the 2026 thresholds) risk assessment and audit documentation for automated decision-making.
Selling into California or operating under both frameworks? MYITMANAGER helps Indian companies map DPDP and CCPA/CPRA obligations side by side so you’re not building two disconnected compliance programmes. Free gap assessment in 5 business days. Talk to a compliance specialist →
Related: DPDP Act vs GDPR · DPDP Compliance Services · Virtual DPO Services · DPDP for SaaS Companies