DPDP Act vs GDPR: the key differences explained

Updated 26 Sep 2026 · 7min read · Reviewed by ConsentLo's DPDP audit team

Many Indian companies already have a GDPR programme, and many global companies now need DPDP compliance. The two laws share ideas, but the differences matter in practice. Here are the ones that change what you build.

Scope

The DPDP Act covers digital personal data, including offline data that is later digitised. The GDPR covers all personal data, whether digital or on paper. The DPDP Act also does not apply to personal data that a person has made publicly available themselves.

Lawful grounds for processing

The GDPR has six lawful bases, including contract and legitimate interests. The DPDP Act has two: consent, and a closed list of "legitimate uses" in Section 7. There is no general legitimate-interest ground, so more processing relies on consent in India.

Sensitive data

The GDPR has special categories of data with stricter rules. The DPDP Act has no separate sensitive category, though sensitivity is one factor in designating Significant Data Fiduciaries and in setting penalties.

Children

Under the DPDP Act a child is anyone under 18, and verifiable parental consent is required, with a ban on tracking, behavioural monitoring and targeted advertising directed at children. Under the GDPR, the age for consent to online services is 16 by default, and member states may lower it to 13.

Breach reporting

The GDPR requires notice to the regulator within 72 hours only where a breach is likely to pose a risk, and to individuals where the risk is high. The DPDP Act requires every personal data breach to be reported to the Data Protection Board and to each affected person, with a detailed report to the Board within 72 hours under the DPDP Rules.

Cross-border transfers

The GDPR allows transfers to adequate countries or under safeguards such as standard contractual clauses. The DPDP Act allows transfers by default, except to countries the Central Government restricts by notification, and stricter sectoral rules still apply.

Data Protection Officers

The GDPR requires a DPO in several situations. The DPDP Act requires a DPO based in India only for Significant Data Fiduciaries. Every other Data Fiduciary must publish the contact of a person who can answer questions about its processing.

Rights

Both laws give rights of access, correction and erasure. The DPDP Act adds a right to nominate someone to exercise your rights after death or incapacity. It has no explicit right to data portability, and no general right to object as the GDPR has. It also places duties on individuals, such as not filing false complaints.

Frequently asked questions

If we comply with GDPR, are we DPDP compliant?

Not automatically. You will need to revisit lawful bases (there is no legitimate-interest ground), children's consent up to 18, reporting every breach, Indian-language notices and the right to nominate.

Does DPDP have a legitimate interest basis like GDPR?

No. Apart from consent, processing is allowed only for the specific legitimate uses listed in Section 7, such as employment purposes, compliance with law and medical emergencies.

Which is stricter, DPDP or GDPR?

Each is stricter in places. DPDP is stricter on children's data, reporting every breach, and the narrow list of non-consent grounds. The GDPR is broader in scope and has special categories of data and data portability.

This guide is general information about the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, not legal advice.