DPDP Act vs GDPR: the key differences explained
Updated 26 Sep 2026 · 7min read · Reviewed by ConsentLo's DPDP audit team
Many Indian companies already have a GDPR programme, and many global companies now need DPDP compliance. The two laws share ideas, but the differences matter in practice. Here are the ones that change what you build.
Scope
The DPDP Act covers digital personal data, including offline data that is later digitised. The GDPR covers all personal data, whether digital or on paper. The DPDP Act also does not apply to personal data that a person has made publicly available themselves.
Lawful grounds for processing
The GDPR has six lawful bases, including contract and legitimate interests. The DPDP Act has two: consent, and a closed list of "legitimate uses" in Section 7. There is no general legitimate-interest ground, so more processing relies on consent in India.
Sensitive data
The GDPR has special categories of data with stricter rules. The DPDP Act has no separate sensitive category, though sensitivity is one factor in designating Significant Data Fiduciaries and in setting penalties.
Children
Under the DPDP Act a child is anyone under 18, and verifiable parental consent is required, with a ban on tracking, behavioural monitoring and targeted advertising directed at children. Under the GDPR, the age for consent to online services is 16 by default, and member states may lower it to 13.
Breach reporting
The GDPR requires notice to the regulator within 72 hours only where a breach is likely to pose a risk, and to individuals where the risk is high. The DPDP Act requires every personal data breach to be reported to the Data Protection Board and to each affected person, with a detailed report to the Board within 72 hours under the DPDP Rules.
Cross-border transfers
The GDPR allows transfers to adequate countries or under safeguards such as standard contractual clauses. The DPDP Act allows transfers by default, except to countries the Central Government restricts by notification, and stricter sectoral rules still apply.
Data Protection Officers
The GDPR requires a DPO in several situations. The DPDP Act requires a DPO based in India only for Significant Data Fiduciaries. Every other Data Fiduciary must publish the contact of a person who can answer questions about its processing.
Rights
Both laws give rights of access, correction and erasure. The DPDP Act adds a right to nominate someone to exercise your rights after death or incapacity. It has no explicit right to data portability, and no general right to object as the GDPR has. It also places duties on individuals, such as not filing false complaints.
Penalties and Consent Managers
GDPR fines are set as a percentage of global turnover. DPDP penalties are fixed amounts per instance, up to ₹250 crore, decided by the Data Protection Board. The DPDP Act also creates registered Consent Managers, which have no GDPR equivalent.
Frequently asked questions
If we comply with GDPR, are we DPDP compliant?
Not automatically. You will need to revisit lawful bases (there is no legitimate-interest ground), children's consent up to 18, reporting every breach, Indian-language notices and the right to nominate.
Does DPDP have a legitimate interest basis like GDPR?
No. Apart from consent, processing is allowed only for the specific legitimate uses listed in Section 7, such as employment purposes, compliance with law and medical emergencies.
Which is stricter, DPDP or GDPR?
Each is stricter in places. DPDP is stricter on children's data, reporting every breach, and the narrow list of non-consent grounds. The GDPR is broader in scope and has special categories of data and data portability.