The Framing Problem
Most organizations in India have DPOs who were trained on GDPR. When DPDP arrived, the default response was: "Map GDPR controls to DPDP requirements." This is a structural error.
GDPR and DPDP are built on different legal foundations. GDPR assumes a rights-first framework — it begins with individual rights and builds compliance obligations backwards. DPDP begins with fiduciary duties — it asks whether you, as a data fiduciary, are treating data principals with care.
The two regimes overlap significantly on notice, consent, and breach response. But the architecture differs in ways that matter operationally: the lawful basis landscape is radically narrower, rights that GDPR practitioners treat as universal simply do not exist in Indian law, and the age threshold for children is higher than any comparable regime globally.
This comparison is designed to help DPOs, privacy officers, and compliance leads who understand GDPR navigate DPDP without importing assumptions that will create compliance gaps.
"The GDPR compliance programme you built over 5 years is not a liability. But if you're using it as a map for DPDP compliance, you're navigating with the wrong instrument."
Rights Comparison
GDPR and DPDP overlap on the foundational rights — access, correction, and notice. But four GDPR rights have no equivalent in Indian law, and DPDP introduces one right that GDPR does not have.
| # | Right / Feature | GDPR | DPDP Act 2023 | Gap |
|---|---|---|---|---|
| 1 | Right of access (data copy) | ✓ Art. 15 | ✓ §11 | No gap — both have it |
| 2 | Right to correction | ✓ Art. 16 | ✓ §12 | No gap |
| 3 | Right to erasure / forgetting | ✓ Art. 17 | ✓ §12 (limited) | DPDP narrower — only "no longer necessary for stated purpose" |
| 4 | Right to data portability | ✓ Art. 20 | ✗ Not in DPDP | GDPR-only right — cannot be built into DPDP compliance framework |
| 5 | Right to restrict processing | ✓ Art. 18 | ✗ Not in DPDP | GDPR-only right |
| 6 | Right to object to processing | ✓ Art. 21 | ✗ Not in DPDP | GDPR-only right |
| 7 | Right not to be subject to automated decisions | ✓ Art. 22 | ✗ Not in DPDP | GDPR-only right |
| 8 | Right to be informed (Notice) | ✓ Art. 13–14 | ✓ §5–6 | Both require notice — DPDP notice must be in plain language + all 22 scheduled languages |
| 9 | Right to nominate (nominee for deceased) | ✗ Not in GDPR | ✓ §14 | DPDP-only — no GDPR equivalent |
| 10 | Right to grievance redressal | Partially via DPA | ✓ §13 — directly with fiduciary | DPDP — direct grievance right, specific timeline (not yet notified) |
The Lawful Basis Chasm
This is the single most consequential structural difference between GDPR and DPDP. GDPR provides six lawful bases for processing personal data. DPDP provides two. The four GDPR bases that disappear in DPDP account for the majority of non-consent processing in most organizations' ROPAs.
GDPR 6 bases
DPDP Act 2023 2 bases
- (a) State functions
- (b) Compliance with law / court order
- (c) Medical emergency
- (d) Epidemic / disaster relief
- (e) Employment-related processing
- (f) Safeguarding minor / person under legal disability
Children's Data
DPDP sets the children's data threshold at 18 — the highest of any major data protection regime globally. There is no Member State derogation mechanism. For any organization with consumer-facing products or services, this has significant product and UX implications.
| Aspect | GDPR | DPDP Act 2023 |
|---|---|---|
| Age threshold | 16 (or 13 with Member State derogation) | 18 — no derogation |
| Parental consent required | Up to 16 (or lower national threshold) | Up to 18, always |
| Behavioral tracking | Prohibited for under-16 | Prohibited for under-18 |
| Targeted advertising | Prohibited for under-16 | Prohibited for under-18 |
| Age verification mechanism | Risk-based, not mandated in law | Verifiable parental consent — mechanism not yet specified |
| Significant Data Fiduciary obligations | Not applicable | SDF must implement additional safeguards for children's data |
Penalty Comparison
DPDP's penalty structure is tiered, with cumulative fines possible across violation types. The maximum penalty of ₹250 Cr is broadly comparable to GDPR's Tier 2 ceiling in purchasing-power-adjusted terms for Indian organizations.
| Violation | GDPR | DPDP Act 2023 |
|---|---|---|
| Maximum fine — Tier 1 | €10M / 2% global turnover | ₹50 Cr |
| Maximum fine — Tier 2 | €20M / 4% global turnover | ₹250 Cr (SDF) |
| Right to erasure violations | Up to €20M | Up to ₹50 Cr |
| Breach notification failure | Up to €10M | Up to ₹200 Cr |
| Processing children's data illegally | Up to €20M | Up to ₹200 Cr |
| Failure to implement security | Up to €10M | Up to ₹250 Cr |
| Cumulative penalties | Per violation type | Cumulative across violations |
DPO / DPO Equivalent
GDPR mandates a DPO for public authorities and organizations undertaking large-scale systematic processing. DPDP does not yet mandate an equivalent role — the Act anticipates Rules that will specify obligations for Significant Data Fiduciaries. What DPDP does require is a Grievance Officer, which is a distinct role from any internal privacy lead.
| Aspect | GDPR DPO | DPDP Equivalent |
|---|---|---|
| Mandatory appointment | Yes — for public authorities and certain processors | Not yet notified — expected for Significant Data Fiduciaries |
| Independence requirement | Yes — cannot be dismissed/penalized for role | Not specified in Act — expected in Rules |
| Direct board reporting | Required | Not yet specified |
| Supervisory authority notification | Must be registered in many EU countries | Not applicable in current form |
| Named contact for data principals | Yes | Grievance Officer — separate from any internal DPO |
| Skills required | Not prescribed | Not prescribed — professional body standards pending |
Breach Notification
DPDP's breach notification framework is not yet fully specified in Rules, but the Act establishes the obligation to notify both the Data Protection Board and affected data principals. The 72-hour timeline widely adopted from GDPR is expected to be reflected in DPDP Rules.
| Requirement | GDPR | DPDP Act 2023 |
|---|---|---|
| Notification timeline — Authority | 72 hours | Not yet notified — likely 72h |
| Notification timeline — Data principals | Without undue delay (if high risk) | All affected principals if risk to rights |
| Content requirements | Prescribed (Art. 33) | Not yet prescribed in Rules |
| Documentation | Mandatory internal register | Likely to be required |
| Minor breach threshold | If likely to cause high risk | Not yet specified |
5 Things Your GDPR Programme Gets Right
DPDP is not a blank-sheet exercise for organizations with mature GDPR programmes. Significant parts of your existing framework transfer directly — with targeted adjustments.
-
1
Consent architecture
Consent management platforms work for both DPDP and GDPR. You need to ensure your consent artifact is DPDP-compliant: plain language, purpose-specific, withdrawal mechanism. The infrastructure transfers; the artifact content needs review.
-
2
ROPA discipline
The habit of maintaining processing records is exactly what DPDP requires. The template fields need updating: remove legitimate interest, add Consent Artifact ID, add Grievance Officer. The discipline and governance process transfers directly.
-
3
Breach response workflow
The incident detection, triage, and notification workflow is reusable. Timeline and notification scope may need adjustment when DPDP Rules are notified — but the playbook structure, escalation paths, and documentation habits all transfer.
-
4
Privacy by design
DPDP does not prescribe PbD methods, but the discipline of embedding privacy into product development remains best practice. GDPR-trained teams with PbD habits are ahead — maintain the practice even where the mandate is less explicit.
-
5
Data processor contracts
DPDP §8/§9 requires processing agreements. Your GDPR DPA templates are a starting point — adapt for DPDP-specific obligations: purpose limitation, data principal rights facilitation, sub-processor controls, and the grievance facilitation requirement.
Purpose-built for Indian data protection law. Not a GDPR tool with DPDP labels.
12 assurance modules. ROPA, DPIA, consent management, breach triage, UCL, and more. Built from the ground up for DPDP Act 2023 obligations.
Explore DPDP Assurance →