Organisations already compliant with the EU GDPR have a head start on the DPDP Act 2023, but the two laws differ in scope, lawful bases and penalties. Assuming GDPR compliance equals DPDP compliance is a common and costly mistake.
DPDP Act vs GDPR at a glance
| Area | DPDP Act 2023 (India) | GDPR (EU) |
|---|---|---|
| Data covered | Digital personal data, including non-digital data that is later digitised | Personal data in any form, in structured filing systems or processed electronically |
| Lawful bases | Consent, or specified "legitimate uses" | Six bases, including contract and legitimate interests |
| Special categories | None; all personal data is one category | Special categories, such as health and biometric data, with stricter rules |
| Children | Under 18; verifiable parental consent | Age threshold of 13 to 16, set by each member state |
| Breach notification | Notify the Board and every affected Data Principal; detailed Board report within 72 hours | Notify the authority within 72 hours where there is risk; individuals only for high risk |
| Data portability | No right | Right to data portability |
| Data Protection Officer | Mandatory only for Significant Data Fiduciaries | Mandatory in specified cases |
| Maximum penalty | ₹250 crore per breach, a fixed ceiling | Up to €20 million or 4% of global turnover |
Where GDPR compliance helps
- Data inventories and records of processing
- Processor contracts and vendor due diligence
- Security safeguards, access control and incident response
- Data subject request handling, which maps to Data Principal rights
Where GDPR compliance is not enough
- No legitimate interests basis. Processing that relies on legitimate interests under GDPR needs consent or a specified legitimate use in India.
- Children are anyone under 18. Age-gating and parental consent built for a lower threshold must be redesigned.
- Notifying individuals of every breach. GDPR's risk threshold for informing individuals does not apply.
- Itemised notices. The Rules require notice to describe each item of data and the specific purpose for it.
- One-year log retention. The Rules set a minimum that GDPR does not.
Reach outside India
Like GDPR, the DPDP Act applies to processing outside India when it is connected to offering goods or services to people in India. A foreign company serving Indian users is a Data Fiduciary.
Start with the DPDP audit checklist, and see DPDP Act penalties for how the two penalty regimes compare in practice.
