DPDP vs GDPR: A Side-by-Side for Companies That Do Both
A practical comparison of India's DPDP Act and the EU's GDPR for companies with users or operations in both regions, covering consent, penalties and key differences.
DPDP and GDPR both regulate personal data, but they are not interchangeable - a company compliant with one still needs to check specific gaps against the other, especially around children's data, penalty structure and the legal bases for processing.
Key facts at a glance
- DPDP's child-data threshold is 18 years; GDPR's default is 16, adjustable down to 13 by member states.
- DPDP penalties can reach up to Rs 250 crore per instance; GDPR penalties can reach up to 20 million euros or 4% of global turnover, whichever is higher.
- DPDP's Data Protection Board is India's enforcement body; GDPR is enforced by national Data Protection Authorities across EU member states.
- DPDP requires a DPO only for Significant Data Fiduciaries; GDPR requires one for a wider set of large-scale/sensitive-data processors.
- DPDP full obligations become enforceable 13 May 2027; GDPR has been enforceable since May 2018.
- Both laws require breach notification and recognise rights like access and correction for individuals.
- DPDP uses a narrower "certain legitimate uses" list; GDPR uses a broader "legitimate interest" balancing test.
Why This Comparison Matters
Many Indian companies serving global customers, and many multinational companies with an India presence, now need to satisfy both regimes at once. Assuming GDPR compliance automatically covers DPDP - or vice versa - creates real gaps, because the two laws diverge in specific, operationally significant ways.
Side-by-Side Comparison
| Aspect | DPDP Act (India) | GDPR (EU) |
|---|---|---|
| In force since | 21 November 2025 (Act); full obligations from 13 May 2027 | 25 May 2018 |
| Regulator | Data Protection Board of India | National Data Protection Authorities (per member state) |
| Child age threshold | Under 18 | Under 16 by default (13-16 depending on member state) |
| Consent standard | Clear, affirmative, specific; can be withdrawn easily | Freely given, specific, informed, unambiguous |
| Lawful basis beyond consent | Narrow list of "certain legitimate uses" | Broad "legitimate interest" balancing test, plus other bases |
| Max penalty | Up to Rs 250 crore per instance (security-safeguard failures) | Up to EUR 20 million or 4% of global turnover, whichever is higher |
| DPO requirement | Mandatory only for Significant Data Fiduciaries | Mandatory for public authorities and large-scale/sensitive processors |
| Cross-border data transfer | Government can restrict transfers to specified countries | Requires adequacy decisions or approved transfer mechanisms (e.g. SCCs) |
| Data principal/subject rights | Access, correction, erasure, grievance redressal, nomination | Access, rectification, erasure, portability, objection, and more |
Key Differences Companies Often Miss
1. Children's Data Threshold
If your GDPR compliance program treats 16 (or your local member state's threshold) as the line for parental consent, that logic will not automatically extend to India. DPDP's 18-year threshold means users your GDPR program treats as adults may still need parental consent under DPDP.
2. Legal Basis for Processing Without Consent
GDPR's legitimate-interest basis is flexible and widely used for things like fraud prevention, direct marketing to existing customers, or network security, subject to a balancing test against the individual's rights. DPDP's equivalent - "certain legitimate uses" - is a more specific, enumerated list (such as voluntarily provided data for a specified purpose, or use for employment purposes, or state functions). A processing activity justified under GDPR's legitimate interest may not fit neatly into DPDP's narrower list, and could require consent under Indian law even where it did not under EU law.
3. Penalty Structure
GDPR ties its maximum penalty to global turnover, which scales with company size. DPDP's penalty is a flat rupee ceiling per instance, tied to the nature of the violation (with the highest ceiling attached to security-safeguard failures) rather than to company revenue.
4. Cross-Border Transfer Mechanics
GDPR's transfer regime is built around adequacy decisions and standard contractual clauses for moving data out of the EU. DPDP takes a different approach, allowing transfers generally except to countries the government specifically restricts by notification - effectively a blocklist model rather than GDPR's allowlist-style adequacy system.
A Practical Gap-Check Approach
- Map data flows separately for each regime - do not assume one data inventory automatically satisfies both.
- Check your children's-data flows against the 18-year threshold, even if your GDPR program is already compliant at 16.
- Re-examine any processing relying on GDPR's legitimate interest to see if it fits DPDP's narrower legitimate-uses list, or needs consent instead.
- Confirm your DPO/contact-person structure covers both regimes' specific requirements.
- Keep breach-notification runbooks regime-aware - the recipients, timelines, and required content differ between the Data Protection Board and EU authorities.
If you are not sure how your existing GDPR program lines up against DPDP's specific requirements, ComplianceCheck's DPDP assessment gives you a clear picture in a few minutes.
Sources
- Ministry of Electronics and Information Technology, DPDP Act and Rules - meity.gov.in
- Data Protection Board of India
- European Commission, GDPR overview - ec.europa.eu
This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.
Frequently Asked Questions
- Is DPDP the same as GDPR?
- No. DPDP and GDPR share the same general goal of protecting personal data, but they differ in structure, terminology, penalty design, and specific obligations such as the children's-data age threshold and the categories of lawful processing.
- Does complying with GDPR automatically make a company DPDP-compliant?
- No, GDPR compliance is a strong foundation because many principles overlap, but DPDP has India-specific requirements - such as its 18-year child-data threshold and its own consent and breach-notification mechanics - that need to be checked separately.
- What is the child-data age threshold under each law?
- DPDP treats anyone under 18 as a child requiring parental consent, while GDPR generally uses 16 as the default threshold, though individual EU member states can lower it to as young as 13.
- How do penalties compare between DPDP and GDPR?
- DPDP penalties for security-safeguard failures can reach up to Rs 250 crore per instance, while GDPR penalties can reach up to 20 million euros or 4 percent of global annual turnover, whichever is higher, for the most serious infringements.
- Does DPDP have an equivalent to GDPR's 'legitimate interest' basis for processing?
- DPDP uses a narrower, more prescriptive list of 'certain legitimate uses' for processing without consent, rather than GDPR's broader, more open-ended legitimate-interest balancing test.
- Do both laws require a Data Protection Officer?
- GDPR requires a DPO for public authorities and organisations engaged in large-scale or systematic monitoring or sensitive-data processing, while DPDP requires a DPO specifically for organisations designated as Significant Data Fiduciaries.
- When does DPDP become fully enforceable, for planning purposes alongside GDPR compliance?
- Full substantive DPDP obligations become enforceable on 13 May 2027, so companies already GDPR-compliant have a defined window to map the gaps rather than needing to do it overnight.
Check your status
DPDP Gap Assessment
A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.