The DPDPA reads like GDPR edited for concision: 44 sections against 99 articles, two lawful grounds against six, one data category against a tiered system. Some of that brevity is genuine simplification, and some of it moves complexity elsewhere, into consent UX, into rules still being finalized, and into government discretion over exemptions and transfer restrictions. Mapping the deltas precisely is what lets an EU-built program serve India without either over- or under-complying.
| Axis | GDPR | DPDPA |
|---|---|---|
| Scope | All personal data | Digital personal data only |
| Sensitive data | Special categories, Art. 9 | No separate category |
| Lawful grounds | Six, incl. legitimate interests | Consent or listed legitimate uses |
| Portability / objection | Yes | No |
| Children | 13-16 (member-state choice) | Under 18, ads/tracking banned |
| Transfers | Restricted by default | Allowed except blacklisted countries |
| Max fine | EUR 20M / 4% turnover | INR 250 crore per instance |
| Texts | EUR-Lex | Act (PDF) |
The three structural differences that bite
No legitimate interests. Analytics, personalization, fraud scoring, and enrichment running on Article 6(1)(f) in Europe have no equivalent home in India unless they fit a section 7 use (voluntary provision for a specified purpose, employment, emergencies). Most land on consent, which means India-specific consent flows, not banner reuse, especially since DPDPA consent must be unconditional and purpose-minimal.
Children to 18. The EU age corridor (13-16) and the legitimate-interest workarounds for age-appropriate design do not translate. India requires verifiable parental consent for anyone under 18 and flatly prohibits tracking, behavioral monitoring, and targeted advertising directed at children, a categorical rule with no GDPR counterpart.
Inverted transfer logic. GDPR asks “is this destination approved?”; the DPDPA asks “is this destination banned?”. That makes India outbound-permissive today, while sectoral overlays like RBI payments localization impose storage mandates the DPDPA itself does not.
Convergences worth exploiting
Security-safeguard duties, breach playbooks (with the individual-notice list extended), records of processing, DPIA machinery (for Significant Data Fiduciaries), and vendor contracts all port over with light edits. One program, two profiles: GDPR as the base layer, an India profile that swaps the lawful-basis map, consent UX, children’s gates, and notification lists. The full India rulebook is in the DPDPA guide; check your collection surfaces with a free scan.