DPDP Act 2023, side-by-side with GDPR.

Not a copy of GDPR, but built with awareness of it. The differences that catch teams by surprise: only two lawful bases, no general legitimate-interest, a 30-day DSR window instead of one month, mandatory grievance officer even for non-SDFs, and a different set of penalty ceilings.

Dimension DPDP GDPR
StatuteDigital Personal Data Protection Act, 2023 + DPDP Rules, 2025General Data Protection Regulation (EU) 2016/679
Applicability Digital personal data processed in India, plus offshore processing that offers goods or services in India. Personal data of EU / EEA data subjects, whether processed in the EU or offshore for EU offers or monitoring.
Lawful bases Two only: consent (Section 6) or certain legitimate uses (Section 7). No general "legitimate interest" ground. Six: consent, contract, legal obligation, vital interests, public task, legitimate interest.
Notice content (Section 5 / Article 13-14) Itemised data + purposes + rights + grievance officer + how to withdraw. Regional-language notice under Rule 3. Data, purposes, legal basis, recipients, transfers, retention, rights, complaint route. Language flexibility.
Consent quality Free, specific, informed, unconditional, unambiguous, clear affirmative action (Section 6). Freely given, specific, informed, unambiguous, clear affirmative action. Same essence.
Right to erasure Section 12. Applies unless retention is required by law or the purpose is ongoing. Article 17. Similar exceptions (legal obligation, public interest, legal claims).
Right to access Section 11. Summary of processing + identity of recipients + rights to correct and erase. Article 15. Full copy of the personal data, purposes, recipients, retention, rights.
Right to portability Not explicit. Article 20. Right to receive data in a structured, machine-readable format.
DSR response window 30 days under Rule 14. Extendable in limited cases. 1 month, extendable by 2 months for complex requests (Article 12(3)).
Breach notification To the Board and to affected data principals (Section 8(6), Rule 7). Format and timeline prescribed by Rule 7. 72 hours to supervisory authority (Article 33); "without undue delay" to data subjects if high-risk (Article 34).
DPIA Required for Significant Data Fiduciaries annually (Rule 12(1)(a)). Required for high-risk processing (Article 35). Regulator consultation if high residual risk (Article 36).
Data Protection Officer Required only for SDFs (Section 10(2)(a)). All Data Fiduciaries must publish a grievance officer contact under Section 8(9). Required in specified cases: public authority, large-scale monitoring, sensitive data processing (Article 37).
Children Verifiable parental consent under 18 (Section 9). Rule 11 prescribes verification methods. Age of digital consent 13-16 (member states set). Article 8 - reasonable efforts to verify parental consent.
Cross-border transfers Section 16 - the Central Government may restrict transfers to specified countries; default is permitted. Chapter V - adequacy decision, SCCs, BCRs, derogations. Default is restricted.
Regulator Data Protection Board of India (constituted 2026). Section 27-33. National supervisory authority per member state, coordinated by EDPB.
Penalty ceiling ₹250 crore per instance for Section 8 security failure. Others per Schedule. Up to €20 million or 4% of global turnover, whichever is higher.
Right to compensation Not built in. Compensation via civil courts if applicable. Article 82 - right to compensation from controller or processor for damage.
Records of processing Not statutorily named as RoPA; implied through Rules 5 and 7 and audit expectations. Article 30 - mandatory ROPA for controllers and processors with 250+ employees or high-risk processing.
DPO independence, appeals, class actions Emerging - Board procedure being defined under DPDP Rules. Well-developed. Article 39 (DPO tasks), Article 78 (judicial remedy), Article 80 (representation).

If you already run a GDPR programme

You have most of what DPDP needs. The gaps are usually:

  • Notice re-written to itemise data + purposes as DPDP requires, and made available in the data principal's chosen language under Rule 3.
  • A grievance officer named on your India-facing surface, even if you are not an SDF. This is a Section 8(9) obligation for every Data Fiduciary.
  • Cross-border transfer register set up for outbound transfers. DPDP's Section 16 defaults to permitted but the Government retains the power to restrict.
  • Retention rethink to reflect Indian sectoral laws (RBI KYC, PMLA, IT Act log retention). Some fields the GDPR erases, RBI requires you to keep.
  • Children's data verification under Rule 11 that reflects Indian verification methods (Digilocker, video KYC), not just the EU verification patterns.
  • DSR SLA tightened to 30 days.

Most teams get to DPDP-ready in 6 to 10 weeks from a mature GDPR baseline. Start with a Section 5 notice audit and the grievance officer appointment.

Doing DPDP from a GDPR baseline?

The dcomply gap assessment tool starts by asking what you already have, then produces a delta plan. Free to run.