Skip to main content
Regulatory Updates

DPDP Act vs GDPR: 5 Key Differences for MNCs Operating in India

Both laws protect personal data. They differ in scope, consent models, penalty structures, and cross-border transfer rules. This is what multinational companies operating in India need to know.

By Sarthak Kalucha, Founder, CivicLayer Technologies7 min readUpdated:
On This Page

Two Frameworks. Different Architectures.

The DPDP Act 2023 and the EU’s General Data Protection Regulation (GDPR) share a common objective: protecting individuals’ personal data. But they differ in structure, scope, and implementation requirements.

Companies operating across both jurisdictions cannot assume that GDPR compliance satisfies DPDP requirements. The two frameworks overlap in principle but diverge in operational detail.

Scope and Applicability

GDPR

Applies to any organisation processing personal data of individuals in the EU/EEA, regardless of where the organisation is located. Covers both automated and manual processing of personal data in filing systems.

DPDP Act

Applies to any person processing digital personal data within India, or processing digital personal data of individuals in India (even if the processing occurs outside India). The Act is limited to digital personal data only. Manual records and non-digitised data fall outside its scope.

DimensionGDPRDPDP Act
Geographic scopeEU/EEA residentsIndividuals in India
Data formatDigital + manual filing systemsDigital only
Organisation coverageAny sizeAny size
Extraterritorial reachYesYes

Lawful Bases for Processing

GDPR

Provides six lawful bases: consent, contract, legal obligation, vital interests, public interest, and legitimate interests. Legitimate interests is widely used in commercial contexts and does not require explicit consent.

DPDP Act

Provides two primary bases: consent and “certain legitimate uses” defined in the Act. The DPDP Act does not include a general “legitimate interests” ground comparable to the GDPR.

The legitimate uses under the DPDP Act are narrowly defined:

  • Voluntary provision of data by the Data Principal for a specified purpose
  • State functions including delivery of benefits, issuance of permits, and legal obligations
  • Medical emergencies
  • Employment purposes
  • Court orders

For most commercial processing, consent is the only available lawful basis under the DPDP Act. Businesses that rely on GDPR’s legitimate interests ground will need to obtain explicit consent for the same processing activities in India.

Both frameworks require consent to be freely given, specific, informed, and unambiguous. The key differences:

RequirementGDPRDPDP Act
Consent formWritten or electronicClear affirmative action
Withdrawal easeMust be as easy as givingMust be as easy as giving
Children’s age threshold13-16 (varies by state)18
Parental consentRequired below thresholdVerifiable parental consent required
Bundled consentGenerally prohibitedExplicitly prohibited

The DPDP Act’s higher children’s age threshold (18 vs 13-16) creates significant compliance implications for businesses serving teenage users.

Data Principal / Data Subject Rights

Both frameworks grant individuals rights over their data, but with different scopes:

RightGDPRDPDP Act
Access / InformationYesYes
CorrectionYesYes
ErasureYes (right to be forgotten)Yes
Data portabilityYesNo
Restriction of processingYesNo
Object to processingYesNo
Right not to be subject to automated decisionsYesNo
Nomination (posthumous rights)NoYes
Grievance redressalSupervisory authority complaintDirect to Data Fiduciary, then Board

The DPDP Act’s rights framework is narrower than the GDPR’s. It omits data portability, the right to restrict processing, and the right to object. However, it introduces the nomination right, which has no GDPR equivalent.

For a detailed analysis of Data Principal rights, see the dedicated article.

Penalty Structure

DimensionGDPRDPDP Act
Maximum penalty€20 million or 4% global turnover₹250 crore (~€27 million)
Penalty basisRevenue-linkedFixed maximum per violation category
Penalty tiersTwo tiers based on violation typeSpecific maximums per violation category

The GDPR’s percentage-of-turnover model means penalties scale with company size. A €20 billion company faces potential fines of €800 million. The DPDP Act’s fixed maximum of ₹250 crore applies equally regardless of company size.

For detailed coverage, see DPDP penalties and enforcement.

Cross-Border Data Transfers

GDPR

Permits transfers to countries with “adequate” data protection (adequacy decisions), or through approved mechanisms: Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or derogations.

DPDP Act

Permits transfers to all countries except those specifically restricted by the Central Government through notification. As of the Act’s passage, no countries have been restricted. This is a “blacklist” approach (block specific countries) versus the GDPR’s “whitelist” approach (approve specific countries). The cross-border transfer framework covers Section 16 and Rule 15 in full.

This makes cross-border transfers simpler under the DPDP Act in the short term. But the government retains broad authority to restrict transfers at any time, creating regulatory uncertainty.

Data Protection Officer

AspectGDPRDPDP Act
AppointmentRequired for public bodies + high-risk processingRequired for Significant Data Fiduciaries only
QualificationMust have expert knowledgeMust be based in India
IndependenceMust be independent, report to highest managementActs as point of contact for Board

The DPDP Act’s DPO requirement is narrower, applying only to Significant Data Fiduciaries. Standard Data Fiduciaries are not required to appoint a DPO, though doing so voluntarily is recommended.

Breach Notification

Both frameworks mandate breach notification. The GDPR prescribes a 72-hour notification window. The DPDP Rules 2025 set the same 72-hour window for notifying the Data Protection Board of India, with notification to affected Data Principals to follow.

What This Means for Global Companies

If your company operates in both India and the EU:

  1. Do not assume GDPR compliance covers DPDP. The consent model differences alone require separate implementation.
  2. Review your lawful basis for processing. Legitimate interests claims valid under GDPR may require consent under DPDP.
  3. Adjust children’s data thresholds. The 18-year threshold in India is significantly higher than most GDPR implementations.
  4. Monitor India’s cross-border transfer notifications. The current permissive regime could change.
  5. Assess both frameworks independently. Use the free DPDP Gap Assessment to identify India-specific compliance gaps.

Frequently asked questions

Is the DPDP Act the same as GDPR?

No. The DPDP Act covers digital personal data of individuals in India with one data category; the GDPR covers EU data subjects with special categories. The GDPR offers six lawful bases including legitimate interests; the DPDP Act recognises only consent and narrowly defined legitimate uses. Penalty models, DPO requirements, and transfer mechanisms also differ.

Does GDPR compliance make a company DPDP compliant?

No. A GDPR programme is a head start, not a substitute. The DPDP Act has no general legitimate-interests ground, so processing that GDPR programmes justify without consent needs a consent basis in India. Notices must be available in English and the languages of the Eighth Schedule, breach notification runs to the Data Protection Board and affected individuals, and the DPO requirement attaches to Significant Data Fiduciaries.

How do DPDP and GDPR penalties compare?

The GDPR fines up to 20 million euros or 4 percent of global turnover, whichever is higher, so penalties scale with company size. The DPDP Act sets a fixed maximum per violation category, topping out at ₹250 crore for security safeguard failures, and that ceiling applies regardless of company size.

Who must comply with the DPDP Act?

Every person or organisation processing digital personal data of individuals in India, including foreign companies offering goods or services to individuals in India. There are no size, revenue, or sector exemptions.

How do cross-border transfer rules differ between DPDP and GDPR?

The GDPR restricts transfers by default and permits them through adequacy decisions and safeguards. The DPDP Act permits transfers to any country by default, except countries the Central Government restricts by notification. No restricted list has been published yet, so the obligation is to inventory transfers and monitor notifications.

Know where you stand on DPDP compliance

Run the free DPDP Gap Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.

Enforcement milestones, rule notifications, and deadline analysis.

One email when it matters, no more.