DPDP vs GDPR
They share vocabulary but they are architecturally different laws. GDPR starts with the person and the rights they can assert. DPDP starts with the company and the duties it owes, with a Board that adjudicates when a duty is missed. That single design difference cascades into almost every operational choice you make: whom you notify on a breach, how you frame consent, where a DPO fits, and what happens when data leaves the country. What follows walks through the fifteen most-asked differences with the primary source next to each.
01The quick answer
If you are GDPR-compliant today, you are roughly 60 percent DPDP-compliant. If you are DPDP-compliant, you are roughly 40 percent GDPR-compliant. The gap runs in both directions.
GDPR gives more rights and stricter legal bases. DPDP has stricter language obligations, a broader children definition, a negative-list cross-border model, a nomination right that GDPR lacks, and different penalty math. Neither is a subset of the other. If you serve both India and the EU, you need both control sets.
02Fifteen differences, side by side
| Topic | DPDP Act 2023 | GDPR |
|---|---|---|
| Territorial scope | Digital personal data processed in India. Also foreign entities offering goods or services in India. | Personal data (digital or otherwise) of Data Subjects in the EU / EEA. Also foreign entities offering goods or services to EU residents, or monitoring their behaviour in the EU. |
| Data scope | Digital personal data only. Paper records outside until digitised (Sec. 3). | Personal data in any form, digital or paper (Art. 2). |
| Lawful bases | Consent (Sec. 6) plus certain legitimate uses (Sec. 7) which include State functions, medical emergency, employment, court orders, disaster response. | Six lawful bases (Art. 6): consent, contract, legal obligation, vital interests, public task, legitimate interests. |
| Consent standard | Free, specific, informed, unconditional, unambiguous, with clear affirmative action (Sec. 6(1)). | Freely given, specific, informed, unambiguous, with a clear affirmative action (Art. 4(11)). |
| Language | Notice must be available in English by default and in any of the 22 Eighth Schedule languages on request (Rule 3). | Notice must be intelligible and easily accessible; commonly given in the Data Subject's language (Art. 12). |
| Age of consent for children | 18 (Sec. 2(f), Sec. 9). Verifiable parental consent required. | 16 by default, member states may lower to 13 (Art. 8). |
| Data Subject / Principal rights | Access (Sec. 11), correction and erasure (Sec. 12), grievance (Sec. 13), nomination (Sec. 14). Four rights. | Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), automated-decision (Art. 22), notification of rectification / erasure (Art. 19). Eight rights. |
| Nomination | Yes. A Data Principal may nominate a person to exercise rights on death or incapacity (Sec. 14). | No direct equivalent. |
| Data portability | Not a stand-alone right. Access under Sec. 11 gives a summary, not a machine-readable export. | Yes. Right to receive personal data in a structured, commonly used and machine-readable format (Art. 20). |
| Automated decision-making | No explicit Data Principal right. Rule 13 imposes an algorithm due-diligence obligation on SDFs only. | Right not to be subject to solely automated decisions with significant effect (Art. 22). |
| DPO requirement | Mandatory only for designated Significant Data Fiduciaries (Rule 12). Must reside in India. Others publish a Sec. 8(9) contact person. | Mandatory for public authorities, and for entities whose core activities require large-scale monitoring or processing of special categories (Art. 37). |
| Cross-border transfer | Negative-list model. Permitted by default. Central Government may restrict specific countries (Sec. 16, Rule 15). | Whitelist and safeguards model. Prohibited unless adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or derogation applies (Arts. 44 to 49). |
| Penalty design | Fixed rupee caps per breach. Rs. 250 cr, Rs. 200 cr, Rs. 150 cr, Rs. 50 cr, Rs. 10,000 for Data Principal duties. No turnover multiplier. | Percentage of turnover. Higher of Euro 20 million or 4 percent of global annual turnover for core violations; Euro 10 million or 2 percent for lesser violations (Art. 83). |
| Regulator | Single central regulator: Data Protection Board of India. Appeals to TDSAT. | Distributed: one national supervisory authority per member state, coordinated by the European Data Protection Board (EDPB). Appeals to national courts. |
| Effective date | Phased. Some rules in force 13 Nov 2025. Substantive core from 14 May 2027. | Fully in force since 25 May 2018. |
03What carries across, what does not
If you already run a GDPR-compliant estate, this is what maps and what does not.
Carries across:
- Record of processing activities (ROPA) — Art. 30 GDPR aligns with Sec. 8 obligations.
- Access and correction handling — DPDP Sections 11 and 12 map to Arts. 15 and 16.
- Erasure workflows — DPDP Sec. 12(3) maps to Art. 17.
- Breach detection and notification muscle — GDPR 72-hour habit works for Rule 7.
- Processor contracting — DPDP Sec. 8(4) resembles Art. 28.
- Consent management platform (CMP) — with modifications for language and per-purpose granularity.
New for India:
- 22-language notice availability on request.
- Nomination handling under Sec. 14.
- Under-18 verifiable parental consent using DigiLocker under Rule 10.
- Consent Manager registration path if you plan to intermediate consent (Rule 4).
- Grievance officer publication under Sec. 8(9) with a specific Rule 3(b)(iii) link.
- Watch for any Sec. 16 restricted-country notification.
- Watch for Rule 12(4) SDF-specific data-category localisation.
If you built to DPDP first and now need to add GDPR, expect more work than the reverse direction.
Big new asks from GDPR:
- Data portability in machine-readable format (Art. 20).
- Right to object to processing based on legitimate interests (Art. 21).
- Right to restriction of processing (Art. 18).
- Right against solely automated decisions with significant effect (Art. 22).
- Six lawful bases including legitimate interest — DPDP does not have a legitimate interest basis at the same level.
- Cross-border transfer mechanism (adequacy, SCC, BCR) for every EU-outbound flow.
- DPO threshold that is broader than DPDP's SDF-only path.
- Breach notification to affected Data Subjects only when there is likely high risk (Art. 34), narrower than DPDP's every-affected-person default.
04The penalty math, illustrated
A Rs. 1,000 crore Indian company with a security failure faces Rs. 250 crore under DPDP. A Rs. 1,000 crore EU company faces up to Euro 40 million (~Rs. 360 crore) under GDPR. Similar magnitudes.
The math diverges at the extremes:
- Small startup (Rs. 10 crore revenue). DPDP cap: Rs. 250 crore, potentially existential. GDPR cap: Euro 400,000 or ~Rs. 3.5 crore. GDPR is proportional, DPDP is not.
- Large enterprise (Rs. 100,000 crore revenue). DPDP cap: Rs. 250 crore, moderate. GDPR cap: Euro 4 billion or ~Rs. 36,000 crore, existential. DPDP is proportional-ish, GDPR is not.
Practical: DPDP is harder on small operators for a serious breach. GDPR is harder on large operators. Neither is uniformly stricter.