DPDP Audits

DPDP Act vs GDPR: Key Differences for Indian Businesses

How India's DPDP Act 2023 differs from the EU GDPR on lawful bases, children, breach notification, penalties and scope, and where GDPR compliance is not enough.

By Ram Krishan Dudeja, CISA CAIIB · Last reviewed 4 October 2026

Organisations already compliant with the EU GDPR have a head start on the DPDP Act 2023, but the two laws differ in scope, lawful bases and penalties. Assuming GDPR compliance equals DPDP compliance is a common and costly mistake.

DPDP Act vs GDPR at a glance

AreaDPDP Act 2023 (India)GDPR (EU)
Data coveredDigital personal data, including non-digital data that is later digitisedPersonal data in any form, in structured filing systems or processed electronically
Lawful basesConsent, or specified "legitimate uses"Six bases, including contract and legitimate interests
Special categoriesNone; all personal data is one categorySpecial categories, such as health and biometric data, with stricter rules
ChildrenUnder 18; verifiable parental consentAge threshold of 13 to 16, set by each member state
Breach notificationNotify the Board and every affected Data Principal; detailed Board report within 72 hoursNotify the authority within 72 hours where there is risk; individuals only for high risk
Data portabilityNo rightRight to data portability
Data Protection OfficerMandatory only for Significant Data FiduciariesMandatory in specified cases
Maximum penalty₹250 crore per breach, a fixed ceilingUp to €20 million or 4% of global turnover

Where GDPR compliance helps

Where GDPR compliance is not enough

Reach outside India

Like GDPR, the DPDP Act applies to processing outside India when it is connected to offering goods or services to people in India. A foreign company serving Indian users is a Data Fiduciary.

Start with the DPDP audit checklist, and see DPDP Act penalties for how the two penalty regimes compare in practice.

Frequently asked questions

Is GDPR compliance enough for the DPDP Act?

No. GDPR compliance helps with data inventories, processor contracts and security, but the DPDP Act has no legitimate interests basis, treats everyone under 18 as a child, requires individuals to be notified of breaches, and the Rules add itemised notices and one-year log retention.

Does the DPDP Act have a legitimate interests basis like GDPR?

No. Processing needs consent or one of the specified legitimate uses in the Act.

How do DPDP and GDPR penalties differ?

GDPR fines go up to €20 million or 4% of global turnover. The DPDP Act sets fixed ceilings, with a maximum of ₹250 crore per breach, not linked to turnover.

Does the DPDP Act cover special categories of data like GDPR?

No. The Act treats all personal data in one category, without separate special categories for health or biometric data.

Does the DPDP Act apply to foreign companies?

Yes, when processing outside India is connected to offering goods or services to people in India.

Need an independent DPDP audit?

67 controls, auditor-signed findings, and a remediation roadmap you can act on.

Book a Free Consultation

Related guides

This guide is general information, not legal advice. Refer to the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 as notified for the authoritative text.