India's DPDP Act 2023 is not a copy of the GDPR. It shares a philosophy — individual rights, fiduciary accountability, purpose limitation — but differs materially in structure, rights, and obligations. For DPOs managing organisations that operate in both India and the EU, understanding these differences is essential to avoid transposing GDPR assumptions onto Indian compliance programmes.

This guide provides a structured comparison of the two frameworks at the level of detail a practitioner needs — not an academic survey.

Why This Comparison Matters

Three categories of organisations need this comparison most urgently:

  • Indian companies with EU operations or EU customers: They face dual compliance — DPDP for Indian data subjects; GDPR for EU data subjects
  • European companies operating in India: They cannot assume their GDPR programme satisfies DPDP — it does not
  • GDPR-trained DPOs now leading Indian compliance: They carry assumptions about legitimate interest, data portability, and automated decision-making rights that do not exist in DPDP

Lawful Bases — Side by Side

This is the most critical difference. DPDP Act 2023 provides four lawful bases; GDPR provides six.

Lawful BasisDPDP Act 2023GDPR
Consent✓ §6 — specific, free, informed, unambiguous✓ Art. 6(1)(a)
Contract performancePartially — subsumed under consent/legal obligation; no explicit standalone basis✓ Art. 6(1)(b) — explicit basis
Legal obligation✓ §7(b)–(e) — compliance with Indian law✓ Art. 6(1)(c)
Vital interests✓ §7(f) — emergency/life protection✓ Art. 6(1)(d)
Public task / State function✓ §7(a) — State and instrumentalities✓ Art. 6(1)(e)
Legitimate interestDoes not exist in DPDP✓ Art. 6(1)(f) — widely used in EU

Critical implication: Many processing activities that GDPR organisations rely on legitimate interest for — fraud prevention analytics, direct marketing to existing customers, intra-group data transfers, employee monitoring — require either consent or a legal obligation basis under DPDP. Review every processing activity mapped to legitimate interest in your EU ROPA — each needs a DPDP-valid basis independently assessed.

Data Subject Rights

RightDPDP Act 2023GDPR
Right to access✓ §11 — summary of data and processing✓ Art. 15 — comprehensive access
Right to correction✓ §12✓ Art. 16 (rectification)
Right to erasure✓ §12 — where purpose ceases✓ Art. 17 — broader grounds
Right to restrict processing✗ Not explicitly provided✓ Art. 18
Right to data portabilityNot in DPDP✓ Art. 20
Right to objectPartial — via consent withdrawal✓ Art. 21
Rights re: automated decisions✗ No explicit right to contest✓ Art. 22
Right to nominate✓ §14 — unique to DPDP✗ Not explicitly provided
Grievance redressal✓ §13 — mandatory + Board escalation✓ Art. 77

Implication for DPO workflow: DSAR processes designed for GDPR need adaptation for DPDP. You must not promise data portability as a legal right. You cannot rely on a "right to restrict" as a holding mechanism. But you must provide a grievance pathway that leads to the Data Protection Board — which GDPR organisations often do not operationalise.

DPO Appointment Requirements

RequirementDPDP Act 2023 (SDF)GDPR
Mandatory forSignificant Data FiduciariesPublic authorities; large-scale monitoring
Internal vs externalMust be internal KMP (SDF)Internal or external both permitted
Residency requirementMust be based in India (SDF)No residency requirement
Seniority levelKey Managerial Person (SDF)No minimum seniority specified
Protection from dismissalNot explicitly statedArt. 38(3) — explicit protection

Breach Notification Timelines

NotificationDPDP Act 2023GDPR
To supervisory authority"As soon as possible" — specific timeline not yet prescribed72 hours (Art. 33)
To affected individualsWhen Board directs, or likely significant harmWithout undue delay if high risk (Art. 34)
Threshold for notificationAll breaches (no de minimis exception explicit)Only if risk to rights and freedoms

Practical implication: Under DPDP, there is no explicit 72-hour clock in the current Rules, but "as soon as possible" must be treated as urgent. Operate on a 24–48 hour internal target to give yourself time to prepare the Board notification before submitting.

Penalty Framework

AspectDPDP Act 2023GDPR
Maximum penalty₹250 crore (approx. €27M) per violation€20M or 4% of global turnover, whichever higher
Basis for calculationPer violation — aggregate possiblePer infringement — % of global turnover
Children's data violationsUp to ₹200 croreStandard tiered penalties apply
Enforcement bodyData Protection Board of IndiaNational supervisory authority
Right of appealHigh CourtNational courts

Children's Data

AspectDPDP Act 2023GDPR
Age thresholdUnder 18 yearsUnder 16 (member states may lower to 13)
Consent requirementVerifiable parental consent — §9Parental consent for digital services (Art. 8)
Targeted advertisingProhibited to children — §9(3)Restricted, member state implementation varies

Cross-Border Data Transfers

AspectDPDP Act 2023GDPR
MechanismNegative list — transfers prohibited to notified countries (§16)Positive adequacy; SCCs/BCRs for others
Current statusNegative list not yet notified — transfers generally permissibleIndia not yet adequate
India ↔ EU data flowsIndia to EU: no DPDP prohibition currentlyEU to India requires SCCs or BCRs

Key Things GDPR Practitioners Must Unlearn

  • Legitimate interest does not exist in DPDP. Every processing activity relying on this must be re-evaluated for a valid DPDP basis — typically consent or legal obligation.
  • There is no right to data portability under DPDP. Do not offer this as a statutory right in your Indian privacy notice.
  • There is no explicit right to contest automated decisions under DPDP. Address AI/ML governance contractually, not by citing a right that does not exist.
  • The 72-hour breach notification clock does not exist in DPDP Rules (yet). Treat "as soon as possible" as urgent regardless.
  • The DPO for an SDF must be internal and India-based. A shared group DPO based in Europe does not satisfy DPDP Rules 2025.

Where DPDP Goes Further Than GDPR

  • Children's data protection is stricter. The prohibition on tracking and targeted advertising to under-18s is broader than GDPR's approach.
  • SDF obligations create a two-tier system with additional accountability. Annual Data Audits, mandatory DPIAs, KMP-level DPO requirements — GDPR has no equivalent SDF designation.
  • Right to nominate (§14) is unique to DPDP — individuals can designate someone to exercise rights posthumously.

Dual-Jurisdiction Checklist

For organisations operating under both DPDP and GDPR, validate these items:

  • All processing activities mapped separately for DPDP (Indian data subjects) and GDPR (EU data subjects) in your ROPA
  • Every instance of "legitimate interest" in your GDPR ROPA re-assessed for a valid DPDP basis
  • Privacy notices for Indian customers do not reference data portability as a legal right
  • Breach response plan has separate notification tracks: GDPR (72 hours) and DPDP (as soon as possible)
  • DPO appointment structure: separate India-based KMP DPO for SDF status, plus GDPR-compliant DPO for EU operations
  • EU-to-India data transfers have SCCs or BCRs in place
  • Training programme updated to distinguish DPDP and GDPR for relevant staff