How India's DPDP Act 2023 differs from the EU GDPR: scope, lawful bases, Consent Managers, breach clocks, fixed rupee penalties versus turnover percentages, children's data, cross border transfers and DPIA triggers, in one table.
DPDP stands for Digital Personal Data Protection. The DPDP Act 2023 is India's data protection law and the DPDP Rules 2025 operationalise it, in force in phases from 13 November 2025.
Most ordinary businesses do not need to register as a Consent Manager: it is a registered intermediary, not consent management software. What Rule 4 actually sets up.
The two roles in one test: who decides why and how the data is used. What each role owes, why one company can hold both roles, and why responsibility never transfers.
Usually yes, twice over: as a Data Fiduciary for your own users and as a Data Processor for customer data. What each role means and what your contracts must carry.
What the Act's application section actually says, why company size does not appear in it, and the one honest caveat about future exemption notifications.
Sections 27 to 29 of the DPDP Act 2023: what triggers the Data Protection Board, how its inquiry runs, and the sixty day appeal to the Appellate Tribunal.