Home / Compare / DPDP vs CCPA
Comparison · India DPDP + California CCPA / CPRA

DPDP vs CCPA

The starting positions are almost mirror images. DPDP assumes nothing is lawful until the person actively agrees; CCPA assumes processing is lawful and the person has to opt out. That inverts the default UI on a signup screen, the wording of a preference centre, even how you write your data map. Ten differences that matter operationally are below.

Verified 8 Sep 2026 DPDP + CCPA (as amended by CPRA) 7 min read

01The quick answer

DPDP is a consent regime enforced by an adjudicatory Board. CCPA is a right-of-refusal regime enforced by the California Privacy Protection Agency (CPPA) and the California Attorney General.

If your business serves both India and California residents, expect different consent flows, different opt-out mechanics, different penalty math, and different Data Subject rights. Neither framework is a superset of the other.

DPDP Act 2023. California Civil Code Sections 1798.100 to 1798.199 (CCPA as amended by CPRA).

02Ten differences, side by side

Topic DPDP Act 2023 (India) CCPA / CPRA (California)
Default posture Consent-first. No processing without free, specific, informed, unconditional and unambiguous consent (Sec. 6). Opt-out first. Processing (including sale and sharing) is presumed lawful. Consumer must exercise the right to opt out.
Scope trigger Any organisation processing digital personal data of Indian residents. No revenue or headcount threshold (Sec. 3). Businesses that meet at least one of: annual revenue over USD 25 million, buy or sell personal information of 100,000+ California residents, or derive 50%+ revenue from selling / sharing personal information.
Rights count Four Data Principal rights: access, correction and erasure, grievance, nomination (Sec. 11 to 14). Six consumer rights: know, delete, correct, opt out of sale / sharing, limit sensitive personal information use, non-discrimination.
Sensitive personal information No formal category. High-sensitivity data (financial, health, biometric, children\'s) attracts higher penalties within existing caps. Explicit category (as added by CPRA, effective 1 Jan 2023). Consumers can limit use to primary purpose (Cal Civ Code 1798.121).
Sale / sharing Not a defined category. Every downstream sharing of personal data needs Sec. 6 consent for the specific onward purpose. Distinct concepts. Sale of personal information and cross-context behavioural advertising (sharing) each need a "Do Not Sell or Share My Personal Information" link.
Age of consent for children 18. Verifiable parental consent for anyone under 18 (Sec. 9, Rule 10). Under 13, opt-in from parent. 13 to 16, opt-in from the minor. Over 16, opt-out.
Penalty design Fixed rupee caps per breach. Up to Rs. 250 crore (Sec. 33 read with the Schedule). No turnover multiplier. Civil penalties up to USD 2,663 per unintentional violation and USD 7,988 per intentional violation (inflation-adjusted for 2026). Consumer private right of action for certain breaches at USD 100 to 750 per resident per incident.
Regulator Data Protection Board of India. Appeals to TDSAT under Sec. 29. California Privacy Protection Agency (CPPA) and California Attorney General share enforcement. Consumer private right of action for certain breaches.
Effective date Phased. Some rules in force 13 Nov 2025. Substantive core from 14 May 2027. CCPA in force since 1 Jan 2020. CPRA amendments effective 1 Jan 2023. Continuous enforcement.
Dark patterns Not defined but caught by Sec. 6 consent standard. Parallel enforcement by Central Consumer Protection Authority (CCPA India, distinct from California CCPA) under 30 November 2023 Guidelines. Cal Civ Code 1798.140(l) defines "dark pattern" and provides that consent obtained via dark pattern is not consent under the CCPA.

03The two "CCPA" acronyms trap

India also has an authority called "CCPA" — the Central Consumer Protection Authority. Two different regulators, same acronym.

California's CCPA is the California Consumer Privacy Act (a statute) enforced by the CPPA (California Privacy Protection Agency, a regulator). India's CCPA is the Central Consumer Protection Authority (a regulator under the Consumer Protection Act 2019).

When you see "CCPA guidelines" in an Indian context, it almost always means the Central Consumer Protection Authority (particularly the 30 November 2023 Guidelines on Dark Patterns). When you see "CCPA" in a US context, it always means California\'s privacy statute. Do not confuse the two.

California Civil Code Sec. 1798.140 et seq. (CCPA statute). Consumer Protection Act 2019 (India CCPA regulator).

04If you serve both India and California

Consent

Two flows, not one

DPDP needs an opt-in consent capture. CCPA needs an opt-out link. Do not try to merge into a single flow. Geo-route by billing address or IP.

Notice

Different notice content

Rule 3 (DPDP) needs itemised data categories, purposes, withdrawal link, 22-language availability. CCPA needs categories of sources, purposes, third-party categories, and specific rights language.

Rights

Different rights, different SLAs

DPDP: 7 days to acknowledge, 90 days for erasure and grievance. CCPA: 45 days to respond (extendable by 45 days) for most requests.

Breach

Different notification triggers

DPDP: notify without delay for any personal data breach, comprehensive report in 72 hours. CCPA: California has a separate breach notification statute (Cal Civ Code 1798.29 / 1798.82) with a "without unreasonable delay" standard.

Serve both India and California? dcomply's multi-jurisdiction compliance stack covers DPDP + CCPA / CPRA + GDPR with a single ROPA and per-region consent flows.