Data privacy

GDPR vs DPDP Act: key differences for teams under both

The EU's GDPR and India's DPDP Act share ideas but not rules. Here is where they differ on scope, lawful grounds, children, breaches, transfers and penalties, and what a GDPR programme still needs for India.

Short answer

GDPR vs DPDP compares two privacy laws built on similar ideas but different rules. The EU's GDPR covers all personal data and allows six lawful bases. India's DPDP Act, 2023 covers digital personal data and rests on consent or a short list of legitimate uses. GDPR compliance is a strong start but does not make you DPDP compliant.

Key takeaways

  • GDPR has six lawful bases; the DPDP Act relies on consent or certain legitimate uses, with no general legitimate interests ground.
  • Under the DPDP Act every personal data breach is reported to the Board and to each affected person.
  • The DPDP Act treats anyone under 18 as a child and bans tracking and targeted advertising aimed at children.
  • DPDP penalties reach ₹250 crore; GDPR fines reach €20 million or 4% of global turnover.

The short version

Both laws give people rights over their personal data and put duties on the organisations that use it. The General Data Protection Regulation has applied across the EU since 25 May 2018. India's Digital Personal Data Protection Act was passed in 2023, and the DPDP Rules, 2025 were notified in November 2025. The Rules apply in phases, with most remaining obligations applying around May 2027.

GDPRDPDP Act
LawRegulation (EU) 2016/679Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025
Data coveredAll personal data, including structured paper recordsPersonal data in digital form, or digitised later
Terms usedController, processor, data subjectData Fiduciary, Data Processor, Data Principal
Lawful groundsSix lawful bases, including contract and legitimate interestsConsent, or certain legitimate uses listed in the Act
Sensitive dataSpecial categories with extra conditionsNo separate sensitive category
ChildrenConsent age 16; member states may lower it to 13Under 18: verifiable parental consent; no tracking or targeted advertising
Breach reportingTo the authority within 72 hours, unless risk is unlikelyEvery breach, to the Data Protection Board and each affected person
Transfers abroadAllowed with adequacy or safeguards such as standard clausesAllowed unless the government restricts a country
RegulatorNational supervisory authorities, coordinated by the EDPBData Protection Board of India
Maximum penalty€20 million or 4% of global turnoverUp to ₹250 crore

Scope: all personal data against digital personal data

GDPR applies to personal data processed by automated means and to paper records that form part of a filing system. The DPDP Act applies to personal data collected in digital form, or collected offline and digitised later. Both reach outside their borders: GDPR when you offer goods or services to people in the EU or monitor their behaviour, the DPDP Act when processing outside India is connected with offering goods or services to people in India.

This is the difference that changes the most work. GDPR gives six lawful bases: consent, contract, legal obligation, vital interests, public task and legitimate interests. The DPDP Act allows processing with consent, given after a clear notice, or for certain legitimate uses that the Act lists, such as a purpose for which the person voluntarily provided their data, employment, legal obligations and medical emergencies. There is no general legitimate interests ground, so processing that relies on it under GDPR needs a new footing in India.

Consent under both laws must be free, specific, informed and unambiguous, and as easy to withdraw as to give. The DPDP Act adds Consent Managers: registered entities through which a person can give, manage, review and withdraw consent.

Rights of individuals

GDPR sets out eight rights, including access, rectification, erasure, restriction, portability and objection. The DPDP Act gives rights to access information about processing, to correction and erasure, to grievance redressal, and to nominate another person to exercise those rights in the event of death or incapacity. It has no right to data portability and no general right to object.

Breach reporting and children's data

GDPR asks controllers to notify the supervisory authority within 72 hours unless the breach is unlikely to result in a risk to people, and to tell individuals when the risk is high. The DPDP Act has no risk threshold: every personal data breach is reported to the Data Protection Board and to each affected Data Principal.

The DPDP Act treats anyone under 18 as a child. Processing a child's data needs verifiable consent from a parent or lawful guardian, and tracking, behavioural monitoring and advertising targeted at children are not allowed. GDPR sets the age for consent to online services at 16, which member states may lower to 13.

Extra duties for Significant Data Fiduciaries

The Indian government can notify a Data Fiduciary as significant, based on factors such as the volume and sensitivity of the data it handles. A Significant Data Fiduciary must appoint a Data Protection Officer based in India, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits. GDPR has no matching category; it requires a DPO and impact assessments by type of processing.

We already comply with GDPR. What is left for the DPDP Act?

Checklist

From GDPR to the DPDP Act

0 of 7 done

This article is general information, not legal advice. Check the Act, the Rules and current government notifications before relying on any point.

Put this into practice on QULDEX

Frequently asked questions

Is the DPDP Act the same as GDPR?

No. Both protect personal data, but the DPDP Act covers only digital personal data, relies mainly on consent and has different rules for breaches, children's data and transfers.

Does GDPR compliance cover the DPDP Act?

Not fully. Much of the groundwork carries over, but lawful grounds, breach reporting, children's data and grievance handling need changes.

Which has higher penalties, GDPR or the DPDP Act?

GDPR fines reach €20 million or 4% of global turnover. DPDP penalties reach ₹250 crore. Which is higher depends on the size of the company.

Does the DPDP Act apply outside India?

Yes, when digital personal data is processed outside India in connection with offering goods or services to people in India.

When does the DPDP Act take effect?

The DPDP Rules, 2025 were notified in November 2025 and apply in phases, with most remaining obligations applying around May 2027.

Sources

  1. Regulation (EU) 2016/679 (General Data Protection Regulation), EUR-Lex
  2. Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025, Ministry of Electronics and Information Technology
  3. EDPB guidelines, recommendations and best practices, European Data Protection Board