Short answer
GDPR vs DPDP compares two privacy laws built on similar ideas but different rules. The EU's GDPR covers all personal data and allows six lawful bases. India's DPDP Act, 2023 covers digital personal data and rests on consent or a short list of legitimate uses. GDPR compliance is a strong start but does not make you DPDP compliant.
Key takeaways
- GDPR has six lawful bases; the DPDP Act relies on consent or certain legitimate uses, with no general legitimate interests ground.
- Under the DPDP Act every personal data breach is reported to the Board and to each affected person.
- The DPDP Act treats anyone under 18 as a child and bans tracking and targeted advertising aimed at children.
- DPDP penalties reach ₹250 crore; GDPR fines reach €20 million or 4% of global turnover.
The short version
Both laws give people rights over their personal data and put duties on the organisations that use it. The General Data Protection Regulation has applied across the EU since 25 May 2018. India's Digital Personal Data Protection Act was passed in 2023, and the DPDP Rules, 2025 were notified in November 2025. The Rules apply in phases, with most remaining obligations applying around May 2027.
| GDPR | DPDP Act | |
|---|---|---|
| Law | Regulation (EU) 2016/679 | Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 |
| Data covered | All personal data, including structured paper records | Personal data in digital form, or digitised later |
| Terms used | Controller, processor, data subject | Data Fiduciary, Data Processor, Data Principal |
| Lawful grounds | Six lawful bases, including contract and legitimate interests | Consent, or certain legitimate uses listed in the Act |
| Sensitive data | Special categories with extra conditions | No separate sensitive category |
| Children | Consent age 16; member states may lower it to 13 | Under 18: verifiable parental consent; no tracking or targeted advertising |
| Breach reporting | To the authority within 72 hours, unless risk is unlikely | Every breach, to the Data Protection Board and each affected person |
| Transfers abroad | Allowed with adequacy or safeguards such as standard clauses | Allowed unless the government restricts a country |
| Regulator | National supervisory authorities, coordinated by the EDPB | Data Protection Board of India |
| Maximum penalty | €20 million or 4% of global turnover | Up to ₹250 crore |
Scope: all personal data against digital personal data
GDPR applies to personal data processed by automated means and to paper records that form part of a filing system. The DPDP Act applies to personal data collected in digital form, or collected offline and digitised later. Both reach outside their borders: GDPR when you offer goods or services to people in the EU or monitor their behaviour, the DPDP Act when processing outside India is connected with offering goods or services to people in India.
Lawful grounds: consent carries more weight in India
This is the difference that changes the most work. GDPR gives six lawful bases: consent, contract, legal obligation, vital interests, public task and legitimate interests. The DPDP Act allows processing with consent, given after a clear notice, or for certain legitimate uses that the Act lists, such as a purpose for which the person voluntarily provided their data, employment, legal obligations and medical emergencies. There is no general legitimate interests ground, so processing that relies on it under GDPR needs a new footing in India.
Consent under both laws must be free, specific, informed and unambiguous, and as easy to withdraw as to give. The DPDP Act adds Consent Managers: registered entities through which a person can give, manage, review and withdraw consent.
Rights of individuals
GDPR sets out eight rights, including access, rectification, erasure, restriction, portability and objection. The DPDP Act gives rights to access information about processing, to correction and erasure, to grievance redressal, and to nominate another person to exercise those rights in the event of death or incapacity. It has no right to data portability and no general right to object.
Breach reporting and children's data
GDPR asks controllers to notify the supervisory authority within 72 hours unless the breach is unlikely to result in a risk to people, and to tell individuals when the risk is high. The DPDP Act has no risk threshold: every personal data breach is reported to the Data Protection Board and to each affected Data Principal.
The DPDP Act treats anyone under 18 as a child. Processing a child's data needs verifiable consent from a parent or lawful guardian, and tracking, behavioural monitoring and advertising targeted at children are not allowed. GDPR sets the age for consent to online services at 16, which member states may lower to 13.
Extra duties for Significant Data Fiduciaries
The Indian government can notify a Data Fiduciary as significant, based on factors such as the volume and sensitivity of the data it handles. A Significant Data Fiduciary must appoint a Data Protection Officer based in India, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits. GDPR has no matching category; it requires a DPO and impact assessments by type of processing.
We already comply with GDPR. What is left for the DPDP Act?
Checklist
From GDPR to the DPDP Act
0 of 7 done
This article is general information, not legal advice. Check the Act, the Rules and current government notifications before relying on any point.
Put this into practice on QULDEX
Frequently asked questions
Is the DPDP Act the same as GDPR?
No. Both protect personal data, but the DPDP Act covers only digital personal data, relies mainly on consent and has different rules for breaches, children's data and transfers.
Does GDPR compliance cover the DPDP Act?
Not fully. Much of the groundwork carries over, but lawful grounds, breach reporting, children's data and grievance handling need changes.
Which has higher penalties, GDPR or the DPDP Act?
GDPR fines reach €20 million or 4% of global turnover. DPDP penalties reach ₹250 crore. Which is higher depends on the size of the company.
Does the DPDP Act apply outside India?
Yes, when digital personal data is processed outside India in connection with offering goods or services to people in India.
When does the DPDP Act take effect?
The DPDP Rules, 2025 were notified in November 2025 and apply in phases, with most remaining obligations applying around May 2027.
Sources
- Regulation (EU) 2016/679 (General Data Protection Regulation), EUR-Lex
- Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025, Ministry of Electronics and Information Technology
- EDPB guidelines, recommendations and best practices, European Data Protection Board