If you already comply with the EU’s General Data Protection Regulation (GDPR), India’s Digital Personal Data Protection Act, 2023 (DPDP) will feel familiar — but the differences matter. Treating DPDP as “GDPR-lite” is a mistake that leads to gaps. Here are nine differences every compliance team should understand before mapping one programme onto the other.
1. Scope of data covered
GDPR covers personal data broadly and carries a special category for sensitive data (health, biometrics, religion, sexual orientation, and more) with extra conditions. DPDP applies to digital personal data and, notably, does not create a separate “sensitive data” category with heightened rules. It treats personal data more uniformly — though sectoral laws in India may still impose extra requirements.
2. Lawful bases for processing
GDPR offers six lawful bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. DPDP is narrower: processing is lawful only on the basis of consent or a defined set of “legitimate uses” (such as data voluntarily provided for a purpose, employment-related processing, and certain state functions). Crucially, DPDP has no broad “legitimate interests” basis like GDPR’s. If your GDPR programme leans on legitimate interests, you will need to rethink that processing for India.
3. The vocabulary
The roles are equivalent but renamed. GDPR’s controller is DPDP’s Data Fiduciary; the processor stays a Data Processor; and the data subject becomes the Data Principal. The language of “fiduciary” is deliberate — it frames the relationship as one of trust and duty.
4. Data Principal rights
Both laws grant rights of access, correction, and erasure. But the lists differ. GDPR includes a right to data portability and a broad right to object, plus rights around automated decision-making. DPDP does not include a general portability right or a standalone right to object, but it adds a distinctive right of nomination — letting a Data Principal nominate another person to exercise their rights in the event of death or incapacity. DPDP also formalises a right to grievance redressal.
5. Children’s data
GDPR sets the digital-consent age between 13 and 16 depending on the member state. DPDP is stricter: a child is anyone under 18, and processing their data generally requires verifiable parental consent. DPDP also restricts behavioural tracking and targeted advertising directed at children. For consumer products, this is one of the biggest operational differences.
6. Cross-border data transfers
GDPR uses an elaborate machinery — adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules — to govern transfers out of the EU. DPDP takes a lighter, blocklist approach: transfers are generally permitted except to countries the government specifically restricts. This is more permissive on its face, though other Indian sectoral rules (for example in banking) may impose stricter localisation.
7. Breach notification
Under GDPR, controllers notify the supervisory authority within 72 hours where feasible, and only notify individuals when there is a high risk to their rights. DPDP’s posture is broader: a Data Fiduciary must notify both the Data Protection Board and every affected Data Principal of a personal data breach, without the same materiality threshold. In practice, DPDP can mean more breach notifications, not fewer.
8. Enforcement and penalties
GDPR fines scale with global turnover — up to €20 million or 4% of worldwide annual revenue, whichever is higher. DPDP sets fixed monetary caps instead, with penalties up to ₹250 crore per instance, determined by the Data Protection Board of India. The structure is different: GDPR ties penalties to revenue; DPDP sets absolute ceilings.
9. Significant Data Fiduciaries vs accountability tooling
GDPR requires DPIAs, records of processing, and DPOs based on risk and scale. DPDP introduces a specific tier — the Significant Data Fiduciary — which the government can designate based on data volume, sensitivity, and risk. Those entities take on extra duties: an India-based Data Protection Officer, an independent data auditor, and periodic Data Protection Impact Assessments.
What this means for your programme
The good news: if you have a mature GDPR programme, your security safeguards, data mapping, and request-handling muscles transfer directly. The work is in the deltas:
- Re-base any processing that relied on legitimate interests.
- Add a nomination right and a formal grievance channel.
- Tighten children’s data handling to an under-18 standard.
- Adjust breach playbooks for broader notification.
- Reassess cross-border flows against India’s blocklist model and sectoral rules.
The smartest approach is a single control set that satisfies both regimes, with framework-specific overlays for the deltas above. That way one piece of evidence — an encryption control, an access review, a consent record — can serve multiple obligations at once.
Run both from one place
Comply maps DPDP and GDPR controls to a shared backbone, so you build once and satisfy both. Explore our DPDP framework and GDPR framework pages, see how consent, notices, and request workflows come together on the privacy platform, and review our transparent pricing when you are ready to plan a rollout.