India's DPDP Act 2023 is not a copy of the GDPR. It shares a philosophy — individual rights, fiduciary accountability, purpose limitation — but differs materially in structure, rights, and obligations. For DPOs managing organisations that operate in both India and the EU, understanding these differences is essential to avoid transposing GDPR assumptions onto Indian compliance programmes.
This guide provides a structured comparison of the two frameworks at the level of detail a practitioner needs — not an academic survey.
Why This Comparison Matters
Three categories of organisations need this comparison most urgently:
- Indian companies with EU operations or EU customers: They face dual compliance — DPDP for Indian data subjects; GDPR for EU data subjects
- European companies operating in India: They cannot assume their GDPR programme satisfies DPDP — it does not
- GDPR-trained DPOs now leading Indian compliance: They carry assumptions about legitimate interest, data portability, and automated decision-making rights that do not exist in DPDP
Lawful Bases — Side by Side
This is the most critical difference. DPDP Act 2023 provides four lawful bases; GDPR provides six.
| Lawful Basis | DPDP Act 2023 | GDPR |
|---|---|---|
| Consent | ✓ §6 — specific, free, informed, unambiguous | ✓ Art. 6(1)(a) |
| Contract performance | Partially — subsumed under consent/legal obligation; no explicit standalone basis | ✓ Art. 6(1)(b) — explicit basis |
| Legal obligation | ✓ §7(b)–(e) — compliance with Indian law | ✓ Art. 6(1)(c) |
| Vital interests | ✓ §7(f) — emergency/life protection | ✓ Art. 6(1)(d) |
| Public task / State function | ✓ §7(a) — State and instrumentalities | ✓ Art. 6(1)(e) |
| Legitimate interest | ✗ Does not exist in DPDP | ✓ Art. 6(1)(f) — widely used in EU |
Critical implication: Many processing activities that GDPR organisations rely on legitimate interest for — fraud prevention analytics, direct marketing to existing customers, intra-group data transfers, employee monitoring — require either consent or a legal obligation basis under DPDP. Review every processing activity mapped to legitimate interest in your EU ROPA — each needs a DPDP-valid basis independently assessed.
Data Subject Rights
| Right | DPDP Act 2023 | GDPR |
|---|---|---|
| Right to access | ✓ §11 — summary of data and processing | ✓ Art. 15 — comprehensive access |
| Right to correction | ✓ §12 | ✓ Art. 16 (rectification) |
| Right to erasure | ✓ §12 — where purpose ceases | ✓ Art. 17 — broader grounds |
| Right to restrict processing | ✗ Not explicitly provided | ✓ Art. 18 |
| Right to data portability | ✗ Not in DPDP | ✓ Art. 20 |
| Right to object | Partial — via consent withdrawal | ✓ Art. 21 |
| Rights re: automated decisions | ✗ No explicit right to contest | ✓ Art. 22 |
| Right to nominate | ✓ §14 — unique to DPDP | ✗ Not explicitly provided |
| Grievance redressal | ✓ §13 — mandatory + Board escalation | ✓ Art. 77 |
Implication for DPO workflow: DSAR processes designed for GDPR need adaptation for DPDP. You must not promise data portability as a legal right. You cannot rely on a "right to restrict" as a holding mechanism. But you must provide a grievance pathway that leads to the Data Protection Board — which GDPR organisations often do not operationalise.
DPO Appointment Requirements
| Requirement | DPDP Act 2023 (SDF) | GDPR |
|---|---|---|
| Mandatory for | Significant Data Fiduciaries | Public authorities; large-scale monitoring |
| Internal vs external | Must be internal KMP (SDF) | Internal or external both permitted |
| Residency requirement | Must be based in India (SDF) | No residency requirement |
| Seniority level | Key Managerial Person (SDF) | No minimum seniority specified |
| Protection from dismissal | Not explicitly stated | Art. 38(3) — explicit protection |
Breach Notification Timelines
| Notification | DPDP Act 2023 | GDPR |
|---|---|---|
| To supervisory authority | "As soon as possible" — specific timeline not yet prescribed | 72 hours (Art. 33) |
| To affected individuals | When Board directs, or likely significant harm | Without undue delay if high risk (Art. 34) |
| Threshold for notification | All breaches (no de minimis exception explicit) | Only if risk to rights and freedoms |
Practical implication: Under DPDP, there is no explicit 72-hour clock in the current Rules, but "as soon as possible" must be treated as urgent. Operate on a 24–48 hour internal target to give yourself time to prepare the Board notification before submitting.
Penalty Framework
| Aspect | DPDP Act 2023 | GDPR |
|---|---|---|
| Maximum penalty | ₹250 crore (approx. €27M) per violation | €20M or 4% of global turnover, whichever higher |
| Basis for calculation | Per violation — aggregate possible | Per infringement — % of global turnover |
| Children's data violations | Up to ₹200 crore | Standard tiered penalties apply |
| Enforcement body | Data Protection Board of India | National supervisory authority |
| Right of appeal | High Court | National courts |
Children's Data
| Aspect | DPDP Act 2023 | GDPR |
|---|---|---|
| Age threshold | Under 18 years | Under 16 (member states may lower to 13) |
| Consent requirement | Verifiable parental consent — §9 | Parental consent for digital services (Art. 8) |
| Targeted advertising | Prohibited to children — §9(3) | Restricted, member state implementation varies |
Cross-Border Data Transfers
| Aspect | DPDP Act 2023 | GDPR |
|---|---|---|
| Mechanism | Negative list — transfers prohibited to notified countries (§16) | Positive adequacy; SCCs/BCRs for others |
| Current status | Negative list not yet notified — transfers generally permissible | India not yet adequate |
| India ↔ EU data flows | India to EU: no DPDP prohibition currently | EU to India requires SCCs or BCRs |
Key Things GDPR Practitioners Must Unlearn
- Legitimate interest does not exist in DPDP. Every processing activity relying on this must be re-evaluated for a valid DPDP basis — typically consent or legal obligation.
- There is no right to data portability under DPDP. Do not offer this as a statutory right in your Indian privacy notice.
- There is no explicit right to contest automated decisions under DPDP. Address AI/ML governance contractually, not by citing a right that does not exist.
- The 72-hour breach notification clock does not exist in DPDP Rules (yet). Treat "as soon as possible" as urgent regardless.
- The DPO for an SDF must be internal and India-based. A shared group DPO based in Europe does not satisfy DPDP Rules 2025.
Where DPDP Goes Further Than GDPR
- Children's data protection is stricter. The prohibition on tracking and targeted advertising to under-18s is broader than GDPR's approach.
- SDF obligations create a two-tier system with additional accountability. Annual Data Audits, mandatory DPIAs, KMP-level DPO requirements — GDPR has no equivalent SDF designation.
- Right to nominate (§14) is unique to DPDP — individuals can designate someone to exercise rights posthumously.
Dual-Jurisdiction Checklist
For organisations operating under both DPDP and GDPR, validate these items:
- All processing activities mapped separately for DPDP (Indian data subjects) and GDPR (EU data subjects) in your ROPA
- Every instance of "legitimate interest" in your GDPR ROPA re-assessed for a valid DPDP basis
- Privacy notices for Indian customers do not reference data portability as a legal right
- Breach response plan has separate notification tracks: GDPR (72 hours) and DPDP (as soon as possible)
- DPO appointment structure: separate India-based KMP DPO for SDF status, plus GDPR-compliant DPO for EU operations
- EU-to-India data transfers have SCCs or BCRs in place
- Training programme updated to distinguish DPDP and GDPR for relevant staff