DPDP Act vs GDPR: Key Differences for Businesses
A careful comparison of India's DPDP Act and the EU's GDPR: scope, consent, rights, penalties, and operational implications.
High-Level Comparison
| Aspect | DPDP | GDPR |
|---|---|---|
| Scope | Digital personal data in India | Personal data in EU/EEA |
| Consent-Based | Yes, primary basis | One of 6 bases |
| Legitimate Interest | Not included | Included |
| Data Subject Rights | 4 rights | 11 rights |
| Max Penalty | ₹250 crore (~$30M) | €20M or 4% revenue |
Key Differences
Lawful Basis
DPDP: Primarily consent; limited "legitimate uses"
GDPR: 6 bases including contract, legal obligation, vital interest, public task, legitimate interest
Data Subject Rights
DPDP: 4 key rights (access, correct, erase, grievance)
GDPR: 11 rights including portability, object, restrict, automated processing
Processor Obligations
DPDP: Limited direct obligations; fiduciary bears responsibility
GDPR: Extensive processor obligations; shared liability
For Businesses Operating in Both
Companies with users/operations in both India and EU must comply with both frameworks:
- GDPR applies to EU data
- DPDP applies to India data
- No conflict, but require different approaches
Key Takeaways
DPDP and GDPR are different frameworks. Don't assume GDPR compliance = DPDP compliance.
Sources & Further Reading
Digital Personal Data Protection Act, 2023
Parliament of India
https://indiacode.gov.in/act/c058fa9f-eaf0-4ca3-98f1-3443b087bca9/sectionsGDPR (EU Regulation 2016/679)
European Commission
https://ec.europa.eu/info/law/law-topic/data-protection_enBuilding your DPDP compliance infrastructure?
ConsentLog helps Indian businesses operationalize DPDP consent requirements across their systems. Learn how we're approaching consent infrastructure.