DPDP vs GDPR: key differences for Indian businesses (2026)
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 5 min read
What is the difference between DPDP and GDPR?
The short answer
The DPDP Act 2023 and the GDPR solve the same problem with different machinery. DPDP covers digital personal data with 2 grounds for processing, consent or certain legitimate uses, while the GDPR lists its lawful bases in Article 6(1). DPDP caps penalties per breach category at fixed rupee amounts up to Rs 250 crore, while GDPR fines scale with global turnover. DPDP treats everyone under 18 as a child and requires verifiable parental consent, subject to the exemptions under section 9(4) and Rule 12; the GDPR Article 8 baseline for consent to information society services is 16, which member states may lower to 13. DPDP has a registered Consent Manager institution with no GDPR equivalent, notifies every affected person of any breach without a risk threshold, and channels complaints through the Data Protection Board after the fiduciary's own grievance process. None of the DPDP obligations compared here is in force as at 29 September 2026: Consent Manager registration under Rule 4 and section 6(9) is computed to commence 13 November 2026 and the rest 13 May 2027, interpretation until officially confirmed, and the GDPR positions are orientation pointers to the official EUR Lex text rather than claims to rely on. A GDPR programme is a strong starting point, but it does not satisfy DPDP by default.

If your organisation already runs a GDPR programme, India's DPDP framework will feel familiar in spirit and different in machinery. This comparison maps the differences that matter operationally, with the DPDP side cited to the official Gazette text and the GDPR side given as orientation pointers to the official EUR Lex text of Regulation (EU) 2016/679.
One timing note first: the DPDP obligations compared below are not yet in force on this article's review date. Commencement notification G.S.R. 843(E) and Rule 1 of the Rules phase them in. Consent Manager registration under Rule 4 arrives 1 year from publication, computed as 13 November 2026, and the main operational provisions arrive 18 months from publication, computed as 13 May 2027. The computed calendar dates are interpretation until officially confirmed; what is actually in force in 2026 tracks the detail.
The comparison table
| Dimension | DPDP Act 2023 and Rules 2025 | GDPR (see EUR Lex) |
|---|---|---|
| What is covered | Digital personal data: collected digitally, or collected offline and digitised (section 3) | Personal data in filing systems, digital or not (Articles 2 and 4) |
| Territorial reach | Processing in India, plus processing abroad connected with offering goods or services to Data Principals in India (section 3) | Establishment in the EU, plus targeting or monitoring people in the EU (Article 3) |
| Grounds for processing | 2: consent, or certain legitimate uses listed in section 7 (sections 4 and 7) | 6 lawful bases, including contract and legitimate interests (Article 6) |
| Sensitive data tier | None. Personal data is defined once, by identifiability, and the word sensitive does not appear in the Act; sensitivity is only 1 factor in Significant Data Fiduciary notification (sections 2(t) and 10(1)(a)) | Special categories with a general prohibition and listed exceptions (Article 9) |
| Consent Managers | A registered, interoperable consent intermediary institution (section 2(g), Rule 4) | No equivalent institution |
| Breach notification | Every affected person and the Board, any breach, no risk threshold; detailed Board submission within 72 hours (Rule 7) | Authority within 72 hours unless unlikely to risk rights; individuals only on high risk (Articles 33 and 34) |
| Penalty model | Fixed rupee caps per breach category, up to Rs 250 crore (section 33 and the Schedule) | Up to EUR 20 million or 4 percent of worldwide turnover, whichever is higher (Article 83) |
| Children | Under 18; verifiable parental consent, and no tracking, behavioural monitoring or targeted advertising at children, both lifted for the classes and purposes the Fourth Schedule lists, on its conditions (sections 2(f) and 9, Rule 12) | Information society services baseline 16, member states may lower to 13 (Article 8) |
| Cross border transfers | Allowed by default except to countries the Central Government restricts by notification, plus order based requirements (section 16, Rule 15) | Restricted by default: adequacy, safeguards or derogations required (Chapter V) |
| Impact assessments and DPOs | Only Significant Data Fiduciaries must appoint an India based DPO and run periodic DPIAs and audits (section 10) | DPIA when high risk for any controller; DPO by activity type (Articles 35 and 37) |
| Complaints | Exhaust the fiduciary's grievance channel, then the Data Protection Board (section 13, Rule 14) | Direct complaint to a supervisory authority (Article 77) |
The differences that bite in practice
2 grounds, not the GDPR's longer list. The biggest structural shock for GDPR teams: DPDP has no contract basis and no legitimate interests basis. Processing runs on consent or on the specific legitimate uses section 7 enumerates, such as voluntary provision for a specified purpose, employment protections, medical emergencies and state functions. Mappings that lean on Article 6(1)(b) or 6(1)(f) need a fresh ground under DPDP.
Breach notification is broader. Rule 7 reaches any personal data breach and requires intimating every affected Data Principal, with no risk threshold in the rule's text. A GDPR calibrated process that filters by risk before notifying individuals does not carry over. Both regimes share the 72 hour number for the authority, which invites false confidence; the recipients and thresholds differ. India also runs a separate 6 hour cyber incident clock to CERT In, covered in the 2 clocks article.
There is no sensitive data tier. The Act defines personal data a single time, in section 2(t), by identifiability, and the word sensitive appears nowhere in it. Sensitivity surfaces only in section 10(1)(a), as 1 of the factors for notifying a Significant Data Fiduciary, which describes an organisation rather than a class of data. Article 9 controls built around special categories therefore have no DPDP counterpart to map onto, and the section 3(d) that circulates in its place does not exist: does the DPDP Act have a sensitive personal data category works through the official text.
Penalties are fixed amounts. The Schedule caps exposure at stated rupee figures per breach category, topping out at Rs 250 crore for failing reasonable security safeguards, rather than scaling with global turnover. For large multinationals the GDPR model can exceed DPDP exposure; for mid size Indian companies the rupee caps are the larger number relative to revenue.
18 means 18. DPDP treats anyone under 18 as a child, requires verifiable parental consent, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. Narrow exemptions exist for prescribed classes and purposes, such as health and educational settings, under section 9(4), Rule 12 and the Fourth Schedule. Age gates tuned to GDPR's 16 or 13 do not transfer.
Transfers point the other way. GDPR restricts transfers by default and opens gates through adequacy and safeguards. DPDP permits transfers by default and closes gates: the Central Government may restrict specific countries by notification and may specify, by order, requirements on making personal data available to foreign states and to persons or entities under their control. The compliance posture flips from justify every transfer to watch the notified restrictions. The mechanics, and the honest unknowns, are in cross border data transfers under DPDP.
What to do with a GDPR programme
Treat it as scaffolding, not certification. The DPDP vs GDPR gap checker walks the areas where DPDP needs separate review, from notice contents to grievance timelines, with the official sources for each. Nothing in this comparison concludes that GDPR work satisfies DPDP or the reverse; the GDPR column above is orientation for the official EUR Lex text, not a restatement to rely on.
The DPDP Act 2023, section by section →The DPDP vs GDPR gap checker tool →