DPDP Act 2023, side-by-side with GDPR.
Not a copy of GDPR, but built with awareness of it. The differences that catch teams by surprise: only two lawful bases, no general legitimate-interest, a 30-day DSR window instead of one month, mandatory grievance officer even for non-SDFs, and a different set of penalty ceilings.
| Dimension | DPDP | GDPR |
|---|---|---|
| Statute | Digital Personal Data Protection Act, 2023 + DPDP Rules, 2025 | General Data Protection Regulation (EU) 2016/679 |
| Applicability | Digital personal data processed in India, plus offshore processing that offers goods or services in India. | Personal data of EU / EEA data subjects, whether processed in the EU or offshore for EU offers or monitoring. |
| Lawful bases | Two only: consent (Section 6) or certain legitimate uses (Section 7). No general "legitimate interest" ground. | Six: consent, contract, legal obligation, vital interests, public task, legitimate interest. |
| Notice content (Section 5 / Article 13-14) | Itemised data + purposes + rights + grievance officer + how to withdraw. Regional-language notice under Rule 3. | Data, purposes, legal basis, recipients, transfers, retention, rights, complaint route. Language flexibility. |
| Consent quality | Free, specific, informed, unconditional, unambiguous, clear affirmative action (Section 6). | Freely given, specific, informed, unambiguous, clear affirmative action. Same essence. |
| Right to erasure | Section 12. Applies unless retention is required by law or the purpose is ongoing. | Article 17. Similar exceptions (legal obligation, public interest, legal claims). |
| Right to access | Section 11. Summary of processing + identity of recipients + rights to correct and erase. | Article 15. Full copy of the personal data, purposes, recipients, retention, rights. |
| Right to portability | Not explicit. | Article 20. Right to receive data in a structured, machine-readable format. |
| DSR response window | 30 days under Rule 14. Extendable in limited cases. | 1 month, extendable by 2 months for complex requests (Article 12(3)). |
| Breach notification | To the Board and to affected data principals (Section 8(6), Rule 7). Format and timeline prescribed by Rule 7. | 72 hours to supervisory authority (Article 33); "without undue delay" to data subjects if high-risk (Article 34). |
| DPIA | Required for Significant Data Fiduciaries annually (Rule 12(1)(a)). | Required for high-risk processing (Article 35). Regulator consultation if high residual risk (Article 36). |
| Data Protection Officer | Required only for SDFs (Section 10(2)(a)). All Data Fiduciaries must publish a grievance officer contact under Section 8(9). | Required in specified cases: public authority, large-scale monitoring, sensitive data processing (Article 37). |
| Children | Verifiable parental consent under 18 (Section 9). Rule 11 prescribes verification methods. | Age of digital consent 13-16 (member states set). Article 8 - reasonable efforts to verify parental consent. |
| Cross-border transfers | Section 16 - the Central Government may restrict transfers to specified countries; default is permitted. | Chapter V - adequacy decision, SCCs, BCRs, derogations. Default is restricted. |
| Regulator | Data Protection Board of India (constituted 2026). Section 27-33. | National supervisory authority per member state, coordinated by EDPB. |
| Penalty ceiling | ₹250 crore per instance for Section 8 security failure. Others per Schedule. | Up to €20 million or 4% of global turnover, whichever is higher. |
| Right to compensation | Not built in. Compensation via civil courts if applicable. | Article 82 - right to compensation from controller or processor for damage. |
| Records of processing | Not statutorily named as RoPA; implied through Rules 5 and 7 and audit expectations. | Article 30 - mandatory ROPA for controllers and processors with 250+ employees or high-risk processing. |
| DPO independence, appeals, class actions | Emerging - Board procedure being defined under DPDP Rules. | Well-developed. Article 39 (DPO tasks), Article 78 (judicial remedy), Article 80 (representation). |
If you already run a GDPR programme
You have most of what DPDP needs. The gaps are usually:
- Notice re-written to itemise data + purposes as DPDP requires, and made available in the data principal's chosen language under Rule 3.
- A grievance officer named on your India-facing surface, even if you are not an SDF. This is a Section 8(9) obligation for every Data Fiduciary.
- Cross-border transfer register set up for outbound transfers. DPDP's Section 16 defaults to permitted but the Government retains the power to restrict.
- Retention rethink to reflect Indian sectoral laws (RBI KYC, PMLA, IT Act log retention). Some fields the GDPR erases, RBI requires you to keep.
- Children's data verification under Rule 11 that reflects Indian verification methods (Digilocker, video KYC), not just the EU verification patterns.
- DSR SLA tightened to 30 days.
Most teams get to DPDP-ready in 6 to 10 weeks from a mature GDPR baseline. Start with a Section 5 notice audit and the grievance officer appointment.
Doing DPDP from a GDPR baseline?
The dcomply gap assessment tool starts by asking what you already have, then produces a delta plan. Free to run.