Confidential Dispatch
At a glance

DPDP and GDPR share a shape — both reach across borders, both run on consent plus other bases, both give people rights over their data — but the differences bite. DPDP has no separate “sensitive data” category, a closed list of non-consent “legitimate uses” (narrower than GDPR’s legitimate interest), a negative-list transfer model instead of adequacy, an under-18 children’s threshold, and fixed rupee penalty caps rather than turnover-based fines. Complying with one does not mean complying with the other.

Educational resource only. This compares India’s Digital Personal Data Protection Act, 2023 (DPDP Act) with the EU’s General Data Protection Regulation (GDPR) at a high level; it is not formal legal advice, and neither summary substitutes for the actual texts.

The situation

If you already run a GDPR programme, the tempting shortcut is to assume DPDP is “GDPR for India” and that your existing controls cover it. They cover a lot — the two laws rhyme — but the gaps are specific and they’re exactly where enforcement risk sits. Knowing where DPDP tracks GDPR and where it deliberately parts ways lets you extend what you have instead of rebuilding, without assuming compliance you don’t actually hold.

Where DPDP and GDPR line up

The architecture is familiar: extra-territorial reach, a fiduciary/controller who’s accountable, consent-and-notice, and enforceable individual rights. Both laws follow the user’s data across borders rather than stopping at their own frontier. Both put the burden on the organisation that decides why and how data is processed — DPDP’s “Data Fiduciary” is GDPR’s “controller,” and both recognise a “processor” acting on instructions. Both require a clear notice and, where consent is the basis, consent that is freely given, specific, informed and unambiguous. Both grant data principals / data subjects rights to access and correct their data and to have it erased, and both back the regime with a regulator and real penalties. A team fluent in GDPR concepts will read DPDP without needing a new vocabulary — which is precisely why the divergences are easy to miss.

Legal bases: consent, and a narrower “everything else”

Both allow processing without consent in defined cases, but DPDP’s non-consent lane is a closed list where GDPR’s is open-ended. GDPR offers six lawful bases, including “legitimate interests” — a flexible, balancing-test basis that lets a controller justify a wide range of processing if it holds up against the individual’s rights. DPDP is tighter. Outside consent, it permits only the specific “legitimate uses” enumerated in Section 7 — a defined set (such as a purpose the person voluntarily provided data for, certain employment purposes, legal obligations, and specified state functions) with no general balancing-test catch-all. The practical consequence: processing you currently justify under GDPR “legitimate interests” may have no equivalent home in DPDP and may need consent instead. Don’t assume a legitimate-interest assessment travels; check whether the activity fits one of Section 7’s listed uses, and if it doesn’t, plan to obtain consent.

No separate sensitive-data category

GDPR gives special categories of data (health, biometrics, religion, sexuality and more) extra restrictions; DPDP has no such tier at all. This is one of the cleanest divergences. Under GDPR, “special category” data triggers heightened conditions. DPDP, by contrast, applies one baseline set of obligations to all personal data — it does not define a separate class of sensitive personal data, and even the earlier Indian regime’s “sensitive personal data” concept (under the IT Act’s SPDI Rules) was not carried forward as a distinct category. In one sense that’s simpler: you apply the same rules to a health record and a phone number. But it cuts both ways — it doesn’t mean sensitive data is less protected, it means your ordinary DPDP controls have to be genuinely strong, because there’s no separate high-sensitivity regime doing extra work. A GDPR team used to gating special-category data through extra hoops shouldn’t read DPDP’s silence as permission to relax.

Rights, children, transfers, penalties: the divergences that bite

Beyond bases and sensitive data, four more differences change what you actually build:

  • Rights list. DPDP grants access, correction and erasure, grievance redressal, and a distinctive right to nominate someone to exercise rights if the person dies or is incapacitated. It does not include GDPR’s data portability, right to object, or restriction-of-processing rights. So a GDPR-style rights portal has both extra features India doesn’t require and a gap (nomination) it doesn’t cover.
  • Children. DPDP treats anyone under 18 as a child, requiring verifiable parental consent and barring tracking and targeted advertising at them. GDPR’s baseline digital-consent age is 16, which member states may lower to as low as 13. The Indian threshold is higher and its tracking/targeting ban is a flat prohibition.
  • Cross-border transfers. GDPR restricts transfers unless there’s adequacy, standard contractual clauses, or another mechanism — a permission-you-must-establish model. DPDP uses a negative list: transfers are allowed unless a destination is specifically restricted, and none currently is. Opposite defaults.
  • Penalties. GDPR fines scale to turnover (up to the higher of €20 million or 4% of global annual turnover). DPDP sets fixed rupee ceilings per type of breach (up to ₹250 crore at the top tier), not a turnover percentage — a different calculus for sizing risk.

What it means if you operate in both markets

Build to the stricter rule where they align, and handle the genuine divergences as separate India line items — don’t fold DPDP into your GDPR programme as an afterthought. For overlapping obligations (notice, security, breach discipline, access and erasure), a single high standard usually satisfies both, and there’s real efficiency in not running two parallel machines. But the places they part ways need deliberate work: re-basing legitimate-interest processing onto consent or a Section 7 use, adding the nominee right, resetting the children’s age to 18 with the tracking ban, flipping your mental model on transfers from “prove adequacy” to “watch the restricted list,” and re-sizing penalty exposure to India’s fixed caps. Treated this way, DPDP is a manageable extension of a mature GDPR programme; treated as “already covered,” it’s a set of quiet gaps waiting to be found.

FAQ

Is DPDP basically GDPR for India?

It’s structurally similar — extra-territorial reach, an accountable fiduciary, consent-and-notice, individual rights — but it diverges on legal bases, sensitive data, transfers, children’s age, rights, and penalties. Similar shape, not the same law.

Does GDPR compliance make me DPDP compliant?

No. A GDPR programme covers much of the overlap but leaves specific gaps: DPDP’s narrower non-consent bases, its under-18 children’s rule, the nomination right, the negative-list transfer model, and India-specific notice and grievance mechanics. Map DPDP separately.

Does DPDP have a sensitive personal data category like GDPR?

No. DPDP applies one baseline set of obligations to all personal data, with no separate special/sensitive category. That means your ordinary controls have to be strong across the board, since there’s no distinct high-sensitivity regime.

How do the children’s rules differ?

DPDP sets the age at 18 and requires verifiable parental consent plus a ban on tracking and targeted advertising toward children. GDPR’s digital-consent baseline is 16, which member states can lower to as low as 13. India’s threshold is higher and its behavioural-targeting ban is stricter.

How do the penalties compare?

GDPR fines are turnover-linked (up to €20 million or 4% of global annual turnover, whichever is higher). DPDP uses fixed rupee ceilings per breach type, up to ₹250 crore at the top — so risk is sized differently, not as a percentage of revenue.

Reviewed by Confidential Dispatch Editorial Team
Last updated 19 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →