Asia-Pacific India / EU

DPDPA vs. GDPR: How India's Privacy Law Differs from the EU's

India's DPDP Act 2023 against the GDPR: lawful grounds, missing rights, children's rules, transfer models, penalties, and how to adapt an EU program for India.

Regulation

Digital Personal Data Protection Act, 2023; Regulation (EU) 2016/679

Max Penalty

DPDPA: INR 250 crore per instance; GDPR: EUR 20 million or 4% of worldwide turnover

Enforcing Authority

Data Protection Board of India; EU supervisory authorities

Official Source

www.meity.gov.in

Executive Summary

  • The DPDPA covers only digital personal data with no sensitive-data category; GDPR covers all personal data with special-category rules.
  • GDPR offers six lawful bases including legitimate interests; the DPDPA offers two, consent or enumerated legitimate uses, with no balancing-test ground.
  • GDPR grants portability, objection, and automated-decision rights; the DPDPA omits all three but adds post-death nomination and imposes duties on data principals themselves.
  • Children's rules diverge hard: DPDPA sets 18 as the age of consent with tracking and targeted ads banned outright; GDPR sets 13-16 by member state.
  • GDPR restricts transfers by default (adequacy/safeguards); the DPDPA allows them by default subject to a government blacklist.

The DPDPA reads like GDPR edited for concision: 44 sections against 99 articles, two lawful grounds against six, one data category against a tiered system. Some of that brevity is genuine simplification, and some of it moves complexity elsewhere, into consent UX, into rules still being finalized, and into government discretion over exemptions and transfer restrictions. Mapping the deltas precisely is what lets an EU-built program serve India without either over- or under-complying.

AxisGDPRDPDPA
ScopeAll personal dataDigital personal data only
Sensitive dataSpecial categories, Art. 9No separate category
Lawful groundsSix, incl. legitimate interestsConsent or listed legitimate uses
Portability / objectionYesNo
Children13-16 (member-state choice)Under 18, ads/tracking banned
TransfersRestricted by defaultAllowed except blacklisted countries
Max fineEUR 20M / 4% turnoverINR 250 crore per instance
TextsEUR-LexAct (PDF)

The three structural differences that bite

No legitimate interests. Analytics, personalization, fraud scoring, and enrichment running on Article 6(1)(f) in Europe have no equivalent home in India unless they fit a section 7 use (voluntary provision for a specified purpose, employment, emergencies). Most land on consent, which means India-specific consent flows, not banner reuse, especially since DPDPA consent must be unconditional and purpose-minimal.

Children to 18. The EU age corridor (13-16) and the legitimate-interest workarounds for age-appropriate design do not translate. India requires verifiable parental consent for anyone under 18 and flatly prohibits tracking, behavioral monitoring, and targeted advertising directed at children, a categorical rule with no GDPR counterpart.

Inverted transfer logic. GDPR asks “is this destination approved?”; the DPDPA asks “is this destination banned?”. That makes India outbound-permissive today, while sectoral overlays like RBI payments localization impose storage mandates the DPDPA itself does not.

Convergences worth exploiting

Security-safeguard duties, breach playbooks (with the individual-notice list extended), records of processing, DPIA machinery (for Significant Data Fiduciaries), and vendor contracts all port over with light edits. One program, two profiles: GDPR as the base layer, an India profile that swaps the lawful-basis map, consent UX, children’s gates, and notification lists. The full India rulebook is in the DPDPA guide; check your collection surfaces with a free scan.

Frequently Asked Questions

Can we reuse our GDPR program for India?

As scaffolding, yes: records of processing, security controls, breach playbooks, and DPO governance carry over. But three components need rebuilding: lawful-basis mapping (anything on legitimate interests must move to consent or a section 7 use), consent UX (unconditional, affirmative, 22-language notices), and children's flows (verifiable parental consent to 18, no behavioral targeting).

Which is stricter on consent?

India, structurally. GDPR consent standards are similar in quality (free, specific, informed, unambiguous), but GDPR lets most commercial processing ride other bases. Under the DPDPA, consent or a narrow legitimate use is all there is, so consent carries loads that GDPR spreads across contract necessity and legitimate interests.

How do breach notification duties compare?

GDPR: notify the authority within 72 hours if risk, individuals only when high risk. DPDPA: notify the Board and every affected data principal, no risk threshold in the act, with the draft 2025 rules adding a prompt initial report and detailed 72-hour follow-up. India's individual-notice duty is broader than the EU's.

What about DPOs and representatives?

GDPR requires DPOs conditionally and EU representatives for offshore controllers. The DPDPA requires a DPO only for Significant Data Fiduciaries, but that DPO must be based in India and report to the board of directors, a residency-and-governance requirement GDPR lacks. Non-SDF fiduciaries still need a grievance officer and a published contact for data questions.

Do fines compare in practice?

Ceilings are comparable in magnitude (INR 250 crore is roughly EUR 27-28M; GDPR reaches 4% of global turnover, higher for large firms). The difference is track record: EU authorities have issued thousands of fines including EUR 1.2 billion against Meta, while India's Board is new and its enforcement pattern unwritten. Plan to Indian caps per instance, which can stack across violations.

Is India getting EU adequacy?

No adequacy decision exists or is imminent; EEA-to-India transfers still need SCCs with a transfer impact assessment. The DPDPA's enactment strengthens India's case long-term, but gaps the EU will weigh include the broad government exemptions under section 17 and the Board's independence from the executive.

Regulatory Crosswalk

GDPRDPDPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.