DPDP vs GDPR: key differences for Indian businesses (2026)
By dpdprules.org editorial team · Reviewed by dpdprules.org source verificationPublished · Last reviewed 4 min read
The short answer
The DPDP Act 2023 and the GDPR solve the same problem with different machinery. DPDP covers digital personal data with two grounds for processing, consent or certain legitimate uses, while the GDPR lists six lawful bases. DPDP caps penalties at fixed rupee amounts up to Rs 250 crore, while GDPR fines scale with global turnover. DPDP treats everyone under eighteen as a child and requires verifiable parental consent; the GDPR baseline is sixteen with member state variation. DPDP has a registered Consent Manager institution with no GDPR equivalent, notifies every affected person of any breach without a risk threshold, and channels complaints through the Data Protection Board after the fiduciary's own grievance process. A GDPR programme is a strong starting point, but it does not satisfy DPDP by default.
If your organisation already runs a GDPR programme, India's DPDP framework will feel familiar in spirit and different in machinery. This comparison maps the differences that matter operationally, with the DPDP side cited to the official Gazette text and the GDPR side given as orientation pointers to the official EUR Lex text of Regulation (EU) 2016/679.
One timing note first: the DPDP obligations compared below are not yet in force on this article's review date. Commencement notification G.S.R. 843(E) and Rule 1 of the Rules phase them in. Consent Manager registration under Rule 4 arrives one year from publication, computed as 13 November 2026, and the main operational provisions arrive eighteen months from publication, computed as 13 May 2027. The computed calendar dates are interpretation until officially confirmed; what is actually in force in 2026 tracks the detail.
The comparison table
| Dimension | DPDP Act 2023 and Rules 2025 | GDPR (see EUR Lex) |
|---|---|---|
| What is covered | Digital personal data: collected digitally, or collected offline and digitised (section 3) | Personal data in filing systems, digital or not (Articles 2 and 4) |
| Territorial reach | Processing in India, plus processing abroad connected with offering goods or services to Data Principals in India (section 3) | Establishment in the EU, plus targeting or monitoring people in the EU (Article 3) |
| Grounds for processing | Two: consent, or certain legitimate uses listed in section 7 (sections 4 and 7) | Six lawful bases, including contract and legitimate interests (Article 6) |
| Consent Managers | A registered, interoperable consent intermediary institution (section 2(g), Rule 4) | No equivalent institution |
| Breach notification | Every affected person and the Board, any breach, no risk threshold; detailed Board submission within 72 hours (Rule 7) | Authority within 72 hours unless unlikely to risk rights; individuals only on high risk (Articles 33 and 34) |
| Penalty model | Fixed rupee caps per breach category, up to Rs 250 crore (section 33 and the Schedule) | Up to EUR 20 million or 4 percent of worldwide turnover, whichever is higher (Article 83) |
| Children | Under 18; verifiable parental consent; no tracking, behavioural monitoring or targeted advertising at children (sections 2(f) and 9) | Information society services baseline 16, member states may lower to 13 (Article 8) |
| Cross border transfers | Allowed by default except to countries the Central Government restricts by notification, plus order based requirements (section 16, Rule 15) | Restricted by default: adequacy, safeguards or derogations required (Chapter V) |
| Impact assessments and DPOs | Only Significant Data Fiduciaries must appoint an India based DPO and run periodic DPIAs and audits (section 10) | DPIA when high risk for any controller; DPO by activity type (Articles 35 and 37) |
| Complaints | Exhaust the fiduciary's grievance channel, then the Data Protection Board (section 13, Rule 14) | Direct complaint to a supervisory authority (Article 77) |
The differences that bite in practice
Two grounds, not six. The biggest structural shock for GDPR teams: DPDP has no contract basis and no legitimate interests basis. Processing runs on consent or on the specific legitimate uses section 7 enumerates, such as voluntary provision for a specified purpose, employment protections, medical emergencies and state functions. Mappings that lean on Article 6(1)(b) or 6(1)(f) need a fresh ground under DPDP.
Breach notification is broader. Rule 7 reaches any personal data breach and requires intimating every affected Data Principal, with no risk threshold in the rule's text. A GDPR calibrated process that filters by risk before notifying individuals does not carry over. Both regimes share the seventy two hour number for the authority, which invites false confidence; the recipients and thresholds differ. India also runs a separate six hour cyber incident clock to CERT In, covered in the two clocks article.
Penalties are fixed amounts. The Schedule caps exposure at stated rupee figures per breach category, topping out at Rs 250 crore for failing reasonable security safeguards, rather than scaling with global turnover. For large multinationals the GDPR model can exceed DPDP exposure; for mid size Indian companies the rupee caps are the larger number relative to revenue.
Eighteen means eighteen. DPDP treats anyone under eighteen as a child, requires verifiable parental consent, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. Narrow exemptions exist for prescribed classes and purposes, such as health and educational settings, under section 9(4), Rule 12 and the Fourth Schedule. Age gates tuned to GDPR's sixteen or thirteen do not transfer.
Transfers point the other way. GDPR restricts transfers by default and opens gates through adequacy and safeguards. DPDP permits transfers by default and closes gates: the Central Government may restrict specific countries by notification and may specify, by order, requirements on making personal data available to foreign states and to persons or entities under their control. The compliance posture flips from justify every transfer to watch the notified restrictions.
What to do with a GDPR programme
Treat it as scaffolding, not certification. The DPDP vs GDPR gap checker walks the areas where DPDP needs separate review, from notice contents to grievance timelines, with the official sources for each. Nothing in this comparison concludes that GDPR work satisfies DPDP or the reverse; the GDPR column above is orientation for the official EUR Lex text, not a restatement to rely on.
The DPDP Act 2023, section by section →The DPDP vs GDPR gap checker tool →
Sources cited on this page
- [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 3, p. 3. Published 11 August 2023. Official source ↗ · Official requirement · Verified 20 August 2026Section 3: application to digital personal data within India and to processing outside India in connection with offering goods or services to Data Principals within India, with stated exclusions.
- [2]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 4, p. 4. Published 11 August 2023. Official source ↗ · Official requirement · Verified 20 August 2026Section 4: personal data may be processed only for a lawful purpose for which the Data Principal has given her consent or for certain legitimate uses; section 7 lists those uses.
- [3]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 9, p. 8. Published 11 August 2023. Official source ↗ · Official requirement · Verified 20 August 2026Section 9: verifiable consent of the parent or lawful guardian before processing a child's personal data; prohibitions on tracking, behavioural monitoring and targeted advertising directed at children, subject to exemptions for prescribed classes and purposes under section 9(4) and Rule 12. Section 2(f) defines a child as an individual who has not completed eighteen years.
- [4]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 16, p. 11. Published 11 August 2023. Official source ↗ · Official requirement · Verified 20 August 2026Section 16: the Central Government may restrict transfer of personal data to notified countries or territories; Rule 15 permits transfers subject to requirements the Central Government may specify by order in respect of making personal data available to any foreign State or to persons or entities under its control.
- [5]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 10, p. 8. Published 11 August 2023. Official source ↗ · Official requirement · Verified 20 August 2026Section 10: additional obligations of Significant Data Fiduciaries, including appointing a Data Protection Officer based in India, periodic Data Protection Impact Assessment and audit.
- [6]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), The Schedule Schedule, p. 21. Published 11 August 2023. Official source ↗ · Official requirement · Verified 20 August 2026The Schedule caps monetary penalties at fixed rupee amounts, the highest being two hundred and fifty crore rupees for failing reasonable security safeguards.
- [7]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, p. 26. Published 13 November 2025. Official source ↗ · Official requirement · Verified 20 August 2026Rule 7: intimation of any personal data breach to every affected Data Principal and to the Board, with no risk threshold in the rule's text, and detailed Board information within seventy two hours.
- [8]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 13, p. 10. Published 11 August 2023. Official source ↗ · Official requirement · Verified 20 August 2026Section 13: right of grievance redressal, with the Data Principal required to exhaust the fiduciary's grievance channel before approaching the Board.
- [9]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 4, p. 25. Published 13 November 2025. Official source ↗ · Official requirement · Verified 20 August 2026Rule 4: registration of Consent Managers with the Board and their obligations; section 2(g) of the Act defines a Consent Manager as a person registered with the Board operating an accessible, transparent and interoperable platform.
- [10]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 14, p. 29. Published 13 November 2025. Official source ↗ · Official requirement · Verified 20 August 2026Rule 14: means for exercising Data Principal rights and a published grievance redressal period not exceeding ninety days.
- [11]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), (c), p. 2. Published 13 November 2025. Official source ↗ · Official requirement · Verified 20 August 2026Notification G.S.R. 843(E) places the Act provisions compared in this article, within sections 3 to 17 and 28 to 34, in the group that comes into force eighteen months from the date of publication of the notification gazette.
- [12]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, p. 24. Published 13 November 2025. Official source ↗ · Official requirement · Verified 20 August 2026Rule 1 phases the Rules: Rule 4 comes into force one year after publication and Rules 3, 5 to 16, 22 and 23 come into force eighteen months after publication. The computed dates 13 November 2026 and 13 May 2027 are interpretation until officially confirmed.
- [13]Regulation (EU) 2016/679 (General Data Protection Regulation) (CELEX 32016R0679), Articles 2, 3, 4, 6, 8, 33, 34, 35, 37, 77, 83 and Chapter V. Official source ↗ · Plain English explanation · Verified 20 August 2026GDPR positions in this article are brief orientation pointers to the official EUR Lex text of Regulation (EU) 2016/679 for separate review; this site does not restate GDPR requirements as claims to rely on.