DPDP Assurance · Data Protection

DPDP Act vs GDPR: The Side-by-Side Comparison India's DPOs Actually Need

By CreativeCyber · March 2026 · 14 min read · DPOs · Privacy Officers · Legal Counsel · Compliance Leads
9
GDPR rights DPDP doesn't have
0
Legitimate interest bases in DPDP
₹250Cr
Maximum penalty under DPDP
18
Age threshold for children — no derogation

The Framing Problem

Most organizations in India have DPOs who were trained on GDPR. When DPDP arrived, the default response was: "Map GDPR controls to DPDP requirements." This is a structural error.

GDPR and DPDP are built on different legal foundations. GDPR assumes a rights-first framework — it begins with individual rights and builds compliance obligations backwards. DPDP begins with fiduciary duties — it asks whether you, as a data fiduciary, are treating data principals with care.

The two regimes overlap significantly on notice, consent, and breach response. But the architecture differs in ways that matter operationally: the lawful basis landscape is radically narrower, rights that GDPR practitioners treat as universal simply do not exist in Indian law, and the age threshold for children is higher than any comparable regime globally.

This comparison is designed to help DPOs, privacy officers, and compliance leads who understand GDPR navigate DPDP without importing assumptions that will create compliance gaps.

"The GDPR compliance programme you built over 5 years is not a liability. But if you're using it as a map for DPDP compliance, you're navigating with the wrong instrument."

Rights Comparison

GDPR and DPDP overlap on the foundational rights — access, correction, and notice. But four GDPR rights have no equivalent in Indian law, and DPDP introduces one right that GDPR does not have.

# Right / Feature GDPR DPDP Act 2023 Gap
1 Right of access (data copy) ✓ Art. 15 ✓ §11 No gap — both have it
2 Right to correction ✓ Art. 16 ✓ §12 No gap
3 Right to erasure / forgetting ✓ Art. 17 ✓ §12 (limited) DPDP narrower — only "no longer necessary for stated purpose"
4 Right to data portability ✓ Art. 20 ✗ Not in DPDP GDPR-only right — cannot be built into DPDP compliance framework
5 Right to restrict processing ✓ Art. 18 ✗ Not in DPDP GDPR-only right
6 Right to object to processing ✓ Art. 21 ✗ Not in DPDP GDPR-only right
7 Right not to be subject to automated decisions ✓ Art. 22 ✗ Not in DPDP GDPR-only right
8 Right to be informed (Notice) ✓ Art. 13–14 ✓ §5–6 Both require notice — DPDP notice must be in plain language + all 22 scheduled languages
9 Right to nominate (nominee for deceased) ✗ Not in GDPR ✓ §14 DPDP-only — no GDPR equivalent
10 Right to grievance redressal Partially via DPA ✓ §13 — directly with fiduciary DPDP — direct grievance right, specific timeline (not yet notified)
Both regimes have this right Partial / narrower in DPDP GDPR-only right DPDP-only right
The Portability Trap Article 20 of GDPR (right to data portability) has become a standard feature in many privacy management platforms. If your platform advertises "DPDP-ready" portability workflows built on GDPR Article 20, this is technically misleading. DPDP does not include portability as a data principal right. Building portability as a DPDP feature may create compliance expectations you are not legally required to fulfil — and could expose you to grievances when users invoke a right that doesn't exist in Indian law.

The Lawful Basis Chasm

This is the single most consequential structural difference between GDPR and DPDP. GDPR provides six lawful bases for processing personal data. DPDP provides two. The four GDPR bases that disappear in DPDP account for the majority of non-consent processing in most organizations' ROPAs.

GDPR 6 bases

Consent (Art. 6(1)(a))
Contract performance (Art. 6(1)(b))
Legal obligation (Art. 6(1)(c))
Vital interests (Art. 6(1)(d))
Public interest (Art. 6(1)(e))
Legitimate interest (Art. 6(1)(f)) — NOT IN DPDP

DPDP Act 2023 2 bases

Consent (§4 + §5–6) — explicit, informed, purpose-specific
Legitimate use (§7) — enumerated list only:
  • (a) State functions
  • (b) Compliance with law / court order
  • (c) Medical emergency
  • (d) Epidemic / disaster relief
  • (e) Employment-related processing
  • (f) Safeguarding minor / person under legal disability
Legitimate Interest Is Not in DPDP — This Affects Your Entire ROPA Legitimate interest (Art. 6(1)(f)) is the most commonly used GDPR basis after consent in Indian organizations' GDPR-derived compliance programmes. DPDP has NO equivalent provision. Every processing activity currently documented under "legitimate interest" in your ROPA needs to be re-assessed: either re-documented under consent (with a valid consent artifact), mapped to one of the enumerated §7 legitimate uses, or discontinued.

Children's Data

DPDP sets the children's data threshold at 18 — the highest of any major data protection regime globally. There is no Member State derogation mechanism. For any organization with consumer-facing products or services, this has significant product and UX implications.

Aspect GDPR DPDP Act 2023
Age threshold 16 (or 13 with Member State derogation) 18 — no derogation
Parental consent required Up to 16 (or lower national threshold) Up to 18, always
Behavioral tracking Prohibited for under-16 Prohibited for under-18
Targeted advertising Prohibited for under-16 Prohibited for under-18
Age verification mechanism Risk-based, not mandated in law Verifiable parental consent — mechanism not yet specified
Significant Data Fiduciary obligations Not applicable SDF must implement additional safeguards for children's data
Global comparison — children's data age thresholds India's 18-year threshold is the highest of any major data protection regime. EU: 16 / 13 (Member State derogation). UK: 13. California CCPA: 16. Brazil LGPD: 16.

Penalty Comparison

DPDP's penalty structure is tiered, with cumulative fines possible across violation types. The maximum penalty of ₹250 Cr is broadly comparable to GDPR's Tier 2 ceiling in purchasing-power-adjusted terms for Indian organizations.

Violation GDPR DPDP Act 2023
Maximum fine — Tier 1 €10M / 2% global turnover ₹50 Cr
Maximum fine — Tier 2 €20M / 4% global turnover ₹250 Cr (SDF)
Right to erasure violations Up to €20M Up to ₹50 Cr
Breach notification failure Up to €10M Up to ₹200 Cr
Processing children's data illegally Up to €20M Up to ₹200 Cr
Failure to implement security Up to €10M Up to ₹250 Cr
Cumulative penalties Per violation type Cumulative across violations
Currency-adjusted context ₹250 Cr ≈ €27M at current exchange rates. For Indian organizations, DPDP's maximum penalty is broadly comparable to GDPR's Tier 2 ceiling in purchasing-power-adjusted terms. For organizations subject to both regimes, GDPR remains the higher ceiling for global revenue-based fines.

DPO / DPO Equivalent

GDPR mandates a DPO for public authorities and organizations undertaking large-scale systematic processing. DPDP does not yet mandate an equivalent role — the Act anticipates Rules that will specify obligations for Significant Data Fiduciaries. What DPDP does require is a Grievance Officer, which is a distinct role from any internal privacy lead.

Aspect GDPR DPO DPDP Equivalent
Mandatory appointment Yes — for public authorities and certain processors Not yet notified — expected for Significant Data Fiduciaries
Independence requirement Yes — cannot be dismissed/penalized for role Not specified in Act — expected in Rules
Direct board reporting Required Not yet specified
Supervisory authority notification Must be registered in many EU countries Not applicable in current form
Named contact for data principals Yes Grievance Officer — separate from any internal DPO
Skills required Not prescribed Not prescribed — professional body standards pending
Note for GDPR-trained DPOs GDPR-trained DPOs: you are not disqualified — you are more prepared than most. But the organizational compliance programme you manage will need a DPDP-specific overlay. Most critically: the consent architecture, ROPA structure, and breach response workflows need rebuilding for Indian law, not GDPR.

Breach Notification

DPDP's breach notification framework is not yet fully specified in Rules, but the Act establishes the obligation to notify both the Data Protection Board and affected data principals. The 72-hour timeline widely adopted from GDPR is expected to be reflected in DPDP Rules.

Requirement GDPR DPDP Act 2023
Notification timeline — Authority 72 hours Not yet notified — likely 72h
Notification timeline — Data principals Without undue delay (if high risk) All affected principals if risk to rights
Content requirements Prescribed (Art. 33) Not yet prescribed in Rules
Documentation Mandatory internal register Likely to be required
Minor breach threshold If likely to cause high risk Not yet specified
Good news for GDPR breach response teams DPDP adopts the 72-hour notification standard (expected, not yet confirmed in Rules). Organizations with a GDPR-compliant breach response playbook can adapt it — the key delta is the all-principals notification obligation when rights are at risk (potentially broader than GDPR's "high risk" threshold).

5 Things Your GDPR Programme Gets Right

DPDP is not a blank-sheet exercise for organizations with mature GDPR programmes. Significant parts of your existing framework transfer directly — with targeted adjustments.

  1. 1 Consent architecture

    Consent management platforms work for both DPDP and GDPR. You need to ensure your consent artifact is DPDP-compliant: plain language, purpose-specific, withdrawal mechanism. The infrastructure transfers; the artifact content needs review.

  2. 2 ROPA discipline

    The habit of maintaining processing records is exactly what DPDP requires. The template fields need updating: remove legitimate interest, add Consent Artifact ID, add Grievance Officer. The discipline and governance process transfers directly.

  3. 3 Breach response workflow

    The incident detection, triage, and notification workflow is reusable. Timeline and notification scope may need adjustment when DPDP Rules are notified — but the playbook structure, escalation paths, and documentation habits all transfer.

  4. 4 Privacy by design

    DPDP does not prescribe PbD methods, but the discipline of embedding privacy into product development remains best practice. GDPR-trained teams with PbD habits are ahead — maintain the practice even where the mandate is less explicit.

  5. 5 Data processor contracts

    DPDP §8/§9 requires processing agreements. Your GDPR DPA templates are a starting point — adapt for DPDP-specific obligations: purpose limitation, data principal rights facilitation, sub-processor controls, and the grievance facilitation requirement.

Purpose-built for Indian data protection law. Not a GDPR tool with DPDP labels.

12 assurance modules. ROPA, DPIA, consent management, breach triage, UCL, and more. Built from the ground up for DPDP Act 2023 obligations.

Explore DPDP Assurance →

Found this useful?

Share with your DPO or legal team — assuming DPDP is "GDPR-lite" is the most common compliance mistake we see.