Compliance
DPDP vs GDPR: 7 Key Differences Every Indian Business Must Know
DPDP is not European GDPR with the section numbers changed. Lawful bases, DPO rules, cross-border transfers and penalties compared side-by-side.
Check your DPDP readiness — free
More on the blog
DPDP vs GDPR: 7 Key Differences Every Indian Business Must Know
When drafting privacy policies and vendor agreements, many Indian founders and legal counsels copy templates from the EU General Data Protection Regulation (GDPR). That approach creates dangerous compliance illusions. The Digital Personal Data Protection Act, 2023 is not GDPR translated into Indian rupees; it is a distinct, streamlined statute with different rules.
The seven critical differences
Relying on GDPR's "performance of a contract" or "legitimate interest" clauses in an Indian privacy policy is an admission that you have collected data without valid Section 6 consent.
- 1. Lawful Bases for Processing — GDPR provides six equal lawful bases (Consent, Contract Performance, Legal Obligation, Vital Interests, Public Task, and Legitimate Interests). DPDP recognizes only two: Consent (s.6) and narrow "Certain Legitimate Uses" (s.7), eliminating the broad commercial legitimate-interests ground.
- 2. Definition of Children — GDPR sets the baseline age of child consent between 13 and 16 years (depending on member state). The DPDP Act sets a strict national threshold at under 18 years, mandating verifiable parental consent and prohibiting behavioral tracking.
- 3. Data Protection Officer (DPO) Mandate — GDPR requires DPOs for public authorities and entities conducting regular, systematic tracking. DPDP restricts mandatory DPO appointments strictly to Significant Data Fiduciaries (SDFs) designated by the Central Government.
- 4. Right to Data Portability — GDPR Article 20 guarantees a statutory right to export personal data in a structured, machine-readable format. The DPDP Act omits an express right to data portability, limiting rights to Access, Correction, Erasure, and Nomination under Section 11.
- 5. Cross-Border Data Transfers — GDPR relies on adequacy decisions, Standard Contractual Clauses (SCCs), and Binding Corporate Rules (BCRs). India’s DPDP Act adopts a "blacklist" model under Section 16: data transfers abroad are permitted by default unless the Central Government explicitly restricts transfer to a designated foreign country.
- 6. Penalty Calculation Methodology — GDPR fines scale to 2%–4% of global turnover. DPDP enforces fixed rupee ceilings per violation head up to ₹250 crore, irrespective of company revenue.
- 7. Consent Managers — DPDP introduces an entirely novel statutory entity: the Consent Manager, an interoperable platform registered with the Board through which Indian citizens can manage and revoke consent across multiple businesses.
What this means for your contracts and policies
If your company operates in India and serves international clients, you need distinct legal artifacts. Your Indian consumer interfaces must provide Section 5 consent notices and an explicit consent mechanism under Section 6. For vendor and B2B customer contracts, replace EU standard clauses with our purpose-built Indian Vendor DPA template grounded in Section 8(5). Use our DPDP privacy policy template to ensure your disclosures align with Indian law rather than foreign statutes.
Common questions
Is the Indian DPDP Act identical to EU GDPR?
No. While both statutes protect personal data, the DPDP Act is structured differently. DPDP has fewer lawful bases for processing (relying primarily on consent and specified legitimate uses), does not contain an express right to data portability, treats children's data more strictly (under 18 threshold), and utilizes a government blacklist system for cross-border data flows.
Does the DPDP Act recognize "legitimate interests" as a processing ground?
No. Under GDPR Article 6(1)(f), businesses frequently process data under the flexible ground of 'legitimate interests'. The DPDP Act has no general legitimate interests provision; businesses must rely strictly on consent (Section 6) or narrow, enumerated 'certain legitimate uses' (Section 7).
Is appointing a Data Protection Officer (DPO) mandatory for all companies in India?
No. Under the DPDP Act, only Significant Data Fiduciaries (SDFs) notified by the Central Government are legally required to appoint a DPO. Under GDPR, any organization involved in large-scale monitoring or processing of sensitive data must appoint one.
How do DPDP penalties compare to GDPR fines?
GDPR penalties cap fines at €20 million or 4% of total worldwide annual turnover, whichever is higher. The DPDP Act uses absolute statutory rupee caps per contravention: up to ₹250 crore per violation, without linking penalties to global turnover percentages.
Related reading
- Understanding the Writing Requirement for Arbitration Agreements — Section 7 of the Arbitration and Conciliation Act mandates that arbitration agreements be in writing, and a mere venue clause does not satisfy the requirement, costing businesses delays and extra litigation if ignored
- Cost of Ignoring Internal Committee Rules Under POSH Act — Failing to set up an Internal Committee or file the required annual report can attract a fine of up to fifty thousand rupees and, on repeat, double the penalty plus possible licence cancellation, threatening a small business’s ability to operate.
- Understanding Section 73 Compensation for Breach of Contract — Section 73 limits recoverable damages to losses that naturally flow from a breach or were foreseen by the parties, excluding remote or indirect losses and reducing awards where the injured party failed to mitigate.
Written by Swaraj Layek
Founder & CEO at VidhiSar. I have watched four companies pay for the same mistake, and it was never the mistake anyone expected. VidhiSar is software, not a law firm: every answer names the section it relies on so you can check it, and anything turning on your specific facts is worth putting to a professional. More about who builds this