If your GDPR programme is running well, you are perhaps sixty percent of the way to DPDPA compliance. The remaining forty percent is where the penalties live.
The two statutes agree on the shape of the problem. They disagree on the answers in ways that matter operationally: the lawful bases are not the same set, the breach clock runs differently, the extraterritorial trigger is drawn differently, and India handles transfers by exclusion where Europe handles them by adequacy.
The most expensive mistake we see is a European privacy team mapping DPDPA onto GDPR articles and assuming the gaps are cosmetic.
They are not. Here is the clause level comparison.
Why This Comparison Matters
India\'s Digital Personal Data Protection Act, 2023 received Presidential Assent on 11 August 2023. The DPDP Rules were notified on 13 November 2025 (G.S.R. 846(E)), with full enforcement beginning 13 May 2027. The Act applies to digital personal data processed within India and, extraterritorially, to processing related to offering goods or services to Data Principals in India.
The EU General Data Protection Regulation (Regulation (EU) 2016/679) has been enforceable since 25 May 2018 and has become the global benchmark against which newer data protection statutes are measured.
For multinational companies processing personal data in both jurisdictions, understanding the divergences is not academic — it is an operational necessity. Running a single compliance programme mapped only to the GDPR leaves gaps in DPDPA compliance that carry penalties of up to INR 250 crore per contravention.
The table below examines fourteen dimensions where the two statutes take materially different approaches. Each dimension represents a compliance work stream that requires separate attention.
The 14-Dimension Comparison
| Dimension | DPDPA (India) | GDPR (EU) |
|---|---|---|
| Scope | Applies to digital personal data processed within India, and to processing outside India if it involves offering goods or services to Data Principals in India. | Applies to personal data processed by controllers or processors established in the EU, or processing of EU residents' data by entities outside the EU offering goods/services or monitoring behaviour. |
| Extraterritorial Trigger | Offering goods or services to Data Principals in India. The statute does not include a separate "monitoring" trigger. | Two triggers: (a) offering goods or services to data subjects in the EU, and (b) monitoring the behaviour of data subjects in the EU (Article 3(2)). |
| Lawful Bases | Two: consent (Section 6) and legitimate uses (Section 7). The legitimate uses are an enumerated, closed list. | Six lawful bases under Article 6(1): consent, contract, legal obligation, vital interests, public interest, and legitimate interests. |
| Consent Standard | Free, specific, informed, unconditional, unambiguous, with a clear affirmative action. Must be preceded by a standalone notice in clear, plain language. Consent is purpose-limited and item-specific. | Freely given, specific, informed, unambiguous indication by statement or clear affirmative action (Article 4(11)). Additional requirements for special category data (explicit consent). |
| Legitimate Interest vs Legitimate Use | Section 7 lists specific "legitimate uses" — State functions, compliance with court orders, medical emergencies, employment purposes, corporate transactions, and publicly available data. No general balancing test. | Article 6(1)(f) allows processing where the controller's or third party's legitimate interests are not overridden by the data subject's rights. Requires a balancing test and is broadly applicable. |
| Notice Requirements | Standalone notice required at or before the point of data collection, in clear and plain language, describing the purpose and categories of data. Itemised consent where multiple purposes exist. Retrospective notice required for data collected before the Act. | Articles 13 and 14 require extensive information including controller identity, DPO contact, legal basis, retention period, rights, and cross-border transfer safeguards. Layered notices are common practice. |
| Breach Notification Timing | "Without unreasonable delay" to the Data Protection Board of India. The DPDP Rules, 2025 prescribe the form and manner; 72 hours is the operative benchmark. Separate intimation to affected Data Principals is required. | Within 72 hours to the supervisory authority (Article 33). Communication to data subjects "without undue delay" where there is a high risk (Article 34). |
| Breach Threshold | Every personal data breach must be reported to the Board. The threshold for reporting to Data Principals is determined by the Board's assessment of severity and risk. | Reporting to the supervisory authority unless the breach is "unlikely to result in a risk to the rights and freedoms of natural persons." Data subject notification only where there is "high risk." |
| Data Principal vs Data Subject Rights | Right to access, correction, erasure, grievance redressal, and nomination. No explicit right to data portability, restriction of processing, or objection to processing. | Right to access, rectification, erasure, restriction of processing, data portability, objection, and rights related to automated decision-making (Articles 15–22). |
| Children's Data and Age Threshold | Verifiable parental consent required for all individuals under 18. No tiered approach. Processing must not involve tracking, behavioural monitoring, or targeted advertising directed at children. | Parental consent required for information society services for children below 16 (member states may lower to 13). No blanket prohibition on targeted advertising — assessed under general principles. |
| DPO Trigger | No mandatory Data Protection Officer for all Data Fiduciaries. Significant Data Fiduciaries (designated by the Central Government under Section 10) must appoint a DPO based in India. | Mandatory DPO where: (a) processing is carried out by a public authority, (b) core activities require large-scale systematic monitoring, or (c) core activities involve large-scale processing of special category data (Article 37). |
| Cross-Border Transfer Mechanism | Transfer permitted to all countries by default. The Central Government may restrict transfer to specific countries or territories by notification (negative list approach). No Standard Contractual Clauses or Binding Corporate Rules framework. | Transfer permitted to countries with an adequacy decision. For others, transfer requires appropriate safeguards: Standard Contractual Clauses, Binding Corporate Rules, or derogations under Article 49. |
| Penalty Structure | Fixed slab penalties in the Schedule: up to INR 10,000 for Data Principal duty breaches, up to INR 200 crore for children's data violations, up to INR 250 crore for failure to implement security safeguards. No revenue-based calculation. | Two tiers: up to EUR 10 million or 2% of global turnover (whichever is higher), and up to EUR 20 million or 4% of global turnover (whichever is higher). Revenue linkage ensures proportionality to scale. |
| Regulator and Appeal Route | Data Protection Board of India (DPBI) — adjudicatory body, not a regulator in the traditional sense. Appeals lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT). | Independent supervisory authorities in each member state. One-stop-shop mechanism for cross-border processing. Appeals to national courts. |
The Consent Architecture Divergence
Both the DPDPA and the GDPR treat consent as a primary lawful basis for processing personal data. The similarity ends there.
Under the GDPR, consent is one of six lawful bases. A controller can often avoid consent altogether by relying on legitimate interests (Article 6(1)(f)), processing necessary for the performance of a contract, or compliance with a legal obligation. The practical result is that many European data processing operations run entirely without individual consent.
The DPDPA compresses the options. There are only two lawful bases: consent under Section 6 and legitimate uses under Section 7. The legitimate uses are an enumerated, closed list — State functions, compliance with court or tribunal orders, medical emergencies, employment purposes, certain corporate transactions, and publicly available data. There is no general legitimate interest balancing test.
This means processing activities that European teams classify under legitimate interests — analytics, fraud prevention, direct marketing to existing customers — require consent under the DPDPA unless they fall within one of the narrow Section 7 categories. The compliance gap here is not theoretical; it is the most common source of non-compliance we encounter in multinational roll-outs.
Breach Response: Different Clocks, Different Thresholds
The GDPR\'s 72-hour notification clock to the supervisory authority is well established. The DPDPA introduces a conceptually similar requirement but with distinct mechanics.
Under the DPDPA, every personal data breach must be reported to the Data Protection Board of India — there is no threshold assessment allowing non-reporting for low-risk breaches. This contrasts with the GDPR\'s carve-out for breaches "unlikely to result in a risk to the rights and freedoms of natural persons."
The DPDP Rules, 2025 prescribe the form and manner for breach notification. The operative benchmark is 72 hours for notification to the Board, with a separate requirement for intimation to affected Data Principals. The dual notification requirement — Board and Data Principal — is structurally different from the GDPR\'s tiered approach where data subject notification only arises when there is "high risk."
For organisations with a unified incident response playbook, this means maintaining separate breach assessment matrices — one for GDPR materiality and one for DPDPA\'s lower reporting threshold.
The Transfer Question: Adequacy vs Exclusion
Cross-border data transfer is where the two regimes diverge most fundamentally in their architectural approach.
The GDPR operates on a positive list model. Transfer is permitted to countries that have received an adequacy decision from the European Commission. For all others, the controller must implement appropriate safeguards — Standard Contractual Clauses, Binding Corporate Rules, or one of the derogations under Article 49. The compliance burden falls on the data exporter to demonstrate that the receiving country offers adequate protection or that contractual mechanisms fill the gap.
The DPDPA inverts this. Transfer is permitted to all countries by default. The Central Government may restrict transfer to specific countries or territories by notification — a negative list. Until such notification is issued, data can flow freely. There is no Standard Contractual Clauses framework, no Binding Corporate Rules mechanism, and no transfer impact assessment requirement built into the statute.
The practical implication is that GDPR transfer documentation does not satisfy DPDPA requirements (because the DPDPA does not require such documentation), and DPDPA transfer freedom does not satisfy GDPR requirements (because the GDPR demands affirmative safeguards). Companies transferring data between India and the EU must maintain parallel compliance documentation.
Children\'s Data: Different Age, Different Restrictions
The DPDPA sets the age of consent at 18 with no discretion for reduction. Every individual below 18 requires verifiable parental consent before their personal data can be processed. Additionally, the Act prohibits tracking, behavioural monitoring, and targeted advertising directed at children — a blanket restriction that goes beyond the GDPR\'s position.
The GDPR takes a different approach. For information society services, the default age is 16, but member states may lower it to as low as 13 under Article 8(1). There is no blanket prohibition on targeted advertising to minors — such processing is assessed under general principles of fairness and purpose limitation.
For companies operating in both jurisdictions, the children\'s data gap is significant. EdTech platforms, gaming companies, and social media services must implement India-specific age gating at 18, which may differ from their GDPR-compliant age threshold. The prohibition on targeted advertising directed at children under the DPDPA is absolute and cannot be addressed through consent or legitimate interest analysis.
Penalty Architecture: Slabs vs Turnover
The GDPR\'s penalty framework is deliberately proportional to scale — the 4% of global turnover cap ensures that penalties for the largest companies are meaningful relative to their operations. The penalty is assessed on a case-by-case basis considering factors including the nature, gravity, and duration of the infringement.
The DPDPA takes a fixed-slab approach. The Schedule to the Act lists specific penalties per type of contravention: up to INR 10,000 for Data Principal duty breaches, up to INR 200 crore for children\'s data violations, and up to INR 250 crore for failure to implement reasonable security safeguards. There is no revenue linkage.
This means a startup processing children\'s data faces the same maximum penalty (INR 200 crore) as a multinational, which creates a disproportionate risk profile for smaller organisations under the DPDPA. Conversely, for very large multinationals, the GDPR\'s 4% turnover cap can exceed the DPDPA\'s INR 250 crore maximum substantially.
Operational Takeaway
A GDPR compliance programme provides a strong foundation for DPDPA readiness, but it is not sufficient on its own. The areas requiring separate attention include:
- ▸Consent architecture: Rebuilding the lawful basis mapping for processing activities that rely on GDPR legitimate interests
- ▸Notice format: Creating DPDPA-compliant standalone notices separate from GDPR privacy policies
- ▸Breach response matrix: Maintaining dual assessment frameworks for incident severity
- ▸Children\'s data: Implementing India-specific age verification at 18 and advertising restrictions
- ▸Transfer documentation: Maintaining parallel records for GDPR and DPDPA transfer compliance
- ▸Significant Data Fiduciary assessment: Evaluating whether Central Government designation triggers apply
The cost of getting this wrong is not speculative. The DPDPA\'s enforcement date is 13 May 2027, and the Consent Manager framework becomes operational on 13 November 2026. Organisations processing Indian personal data under a GDPR-only framework will have compliance gaps that carry per-contravention penalty exposure.
Related Reading
Frequently Asked Questions
Is the DPDPA a copy of the GDPR?
No. While both statutes address personal data protection, the DPDPA diverges from the GDPR on lawful bases, breach notification timing, extraterritorial scope, cross-border transfer mechanisms, and penalty structures. GDPR compliance covers roughly sixty percent of DPDPA requirements; the remaining forty percent requires separate attention.
Does the DPDPA recognise legitimate interest as a lawful basis?
Not in the GDPR sense. The DPDPA uses the concept of "legitimate uses" under Section 7, which covers specific enumerated purposes such as State functions, medical emergencies, employment, and corporate transactions. There is no general-purpose balancing test equivalent to GDPR Article 6(1)(f).
What is the breach notification timeline under DPDPA versus GDPR?
The GDPR requires supervisory authority notification within 72 hours. The DPDPA requires notification to the Data Protection Board of India "without unreasonable delay" in such form and manner as prescribed under the DPDP Rules, 2025. The draft rules specify 72 hours for Board notification and separate intimation to affected Data Principals.
How does cross-border data transfer differ between DPDPA and GDPR?
The GDPR permits transfers to countries with an adequacy decision and allows Standard Contractual Clauses and Binding Corporate Rules for others. The DPDPA takes the opposite approach: transfer is permitted to all countries except those specifically restricted by the Central Government through a negative list.
Which statute carries higher maximum penalties?
The GDPR maximum is EUR 20 million or 4% of annual global turnover (whichever is higher). The DPDPA prescribes fixed slab penalties up to INR 250 crore (approximately EUR 27 million) per contravention. The DPDPA does not use revenue-based calculations.
Can a company comply with both DPDPA and GDPR simultaneously?
Yes, but it requires deliberate mapping. Key areas requiring separate compliance include: consent notice format (DPDPA requires standalone notices), children's data age threshold (DPDPA sets 18 versus GDPR's default 16), legitimate use versus legitimate interest analysis, and cross-border transfer documentation.
Dual-Jurisdiction Compliance Advisory
If your organisation processes personal data in both India and the EU, we can map the compliance gaps between your GDPR programme and DPDPA requirements — and build the remediation roadmap.
Schedule a Consultation