Why This Comparison Is Relevant for Businesses in India
The Digital Personal Data Protection Act 2023 — also known as the DPDP Act — came into being thanks to the efforts of the Indian Parliament back on 11 August 2023. When the compliance crew start comparing this one to the GDPR, the EU's General Data Protection Regulation, the first port of call is bound to be the latter — which famously kicked in on 25 May 2018. The one thing that the DPDP Act and the GDPR do have in common is the core idea of safeguarding individual rights over their own personal info, but beyond that the two are as different as chalk and cheese.
Two kinds of Indian businesses need to get this right. The first is any company handling data belonging to both Indian and EU/EEA residents — they have to satisfy both laws at once. The second is companies operating purely within India, whose compliance teams still need to know which GDPR concepts carry over to DPDP and which simply don't apply. Treating GDPR compliance as automatic DPDP compliance, or the reverse, is a mistake that gets expensive fast.
What follows is a section-by-section analysis of both statutes, with citations provided to relevant provisions throughout: "According to DPDP Act 2023, Section X".
What Is the DPDP Act 2023?
The Digital Personal Data Protection Act 2023 is the first comprehensive data protection statute in India. It was notified in the Official Gazette on 11 August 2023. The DPDP Act covers the processing of digital personal data, which is defined in Section 2(t) of the Act as data that has been collected using any electronic means of communication or that has been subsequently converted to an electronic form.
Territorial scope (Section 3): The DPDP Act reaches out to cover personal data processed inside India, and also catches any data processing that takes place outside India but is aimed at people in India who are buying goods or services from the companies handling the data. This is reminiscent of the way the GDPR stretches across borders to regulate data held about people in the EU, as laid out in Article 3.
There are three key people involved under this Act: the Data Fiduciary — the person or organisation that decides what they're going to use the data for and how it gets used — which is similar to what the GDPR calls a "data controller". Then there's the Data Principal — the person whose data is being handled, and the Data Processor — the people or organisation doing the actual processing on behalf of the Data Fiduciary. Depending on how much data is involved, and how sensitive it might be, the government can label some of these Data Fiduciaries as Significant Data Fiduciaries and hit them with stricter rules.
A few of the other key bits of the Act are: Section 4 (when you're allowed to process data), Section 5 (having to let people know what you're doing), Section 6 (getting someone's permission to use their data), Section 7 (when you don't need permission, and why), Sections 8–9 (Data Fiduciaries have to do certain things), Sections 11–14 (Data Principals have some rights), Section 17 (where there are special cases that might not apply), Section 25 (there's a Data Protection Board of India looking out for things), and Section 33 (fines for breaking the rules — as spelled out in a special schedule).
What Is GDPR?
The General Data Protection Regulation (GDPR) (EU) 2016/679 was first introduced on 24 May 2016, but it took two whole years after that before it was actually given some teeth. This law has got a pretty broad reach, covering all of the EU countries, plus a few other bits of Europe that get classed as part of the European Economic Area (in other words Norway, Iceland and Liechtenstein). Just like the DPDP Act, GDPR's got its sights set on regulating data whatever country you're processing it in.
There are seven key principles to the GDPR, all laid out in Article 5: like, you've got to process the data in a way that's fair and upfront (lawfulness, fairness and transparency); make sure you know what the data is going to be used for; only collect the minimum amount you need to get the job done; make sure the data is accurate; don't hold onto it for longer than you need to; make sure it's all kept safe and private; and you've got to be able to explain what you've done. Then there's the thing about when you're allowed to process data in the first place — and the GDPR's got a few different options for this.
These are spelled out in Article 6, and cover things like someone giving permission, the data being needed for a contract, it being a legal requirement, or if it's about keeping people safe, doing some public task, or if there's a legitimate business reason for it. The EDPB (European Data Protection Board) keeps an eye on how the GDPR gets implemented, while the various national regulatory bodies in each country do their own investigations, tweaking and fining companies that don't play by the rules.
Side-by-Side Comparison: DPDP Act vs GDPR
| Aspect | DPDP Act 2023 (India) | EU GDPR |
|---|---|---|
| Year Enacted | 2023 (notified Aug 11, 2023) | 2016 (applicable May 25, 2018) |
| Scope | Digital personal data in India; cross-border if related to Indian data principals | Any personal data of EU/EEA residents, regardless of processor location |
| Consent Standard | Free, specific, informed, unconditional, unambiguous (Section 6) | Freely given, specific, informed, unambiguous (Article 7); withdrawable at any time |
| Legitimate Interest | Not available — no equivalent of GDPR Art. 6(1)(f) | Available (Article 6(1)(f)) — subject to balancing test |
| Data Principal Rights | Access (S.11), Correction & Erasure (S.12), Grievance Redressal (S.13), Nomination (S.14), Consent Withdrawal (S.6(4)) | Access (Art.15), Rectification (Art.16), Erasure (Art.17), Restriction (Art.18), Portability (Art.20), Object (Art.21), Automated Decisions (Art.22) |
| Data Portability | Not explicitly provided | Yes — Article 20 (machine-readable format) |
| DPO Requirement | Not mandated generally; Significant Data Fiduciaries must appoint a DPO | Mandatory for public bodies; private entities processing large-scale sensitive data or systematic monitoring |
| Breach Notification | To Data Protection Board (timeline in Rules); CERT-In 6-hour rule applies separately | 72 hours to supervisory authority; without undue delay to data subjects if high risk |
| Children's Data | Under 18; verifiable parental consent; no tracking or behavioural monitoring (Section 9) | Under 16 (or lower per member state, min 13); parental consent for information society services (Article 8) |
| Data Localisation | Certain categories via government notification (Section 16) | No blanket requirement; transfers require adequacy decision or safeguards (Chapter V) |
| Maximum Penalties | Up to ₹250 Crore per category of violation (Schedule) | Up to €20M or 4% global annual turnover, whichever is higher |
| Regulatory Body | Data Protection Board of India (Section 25) | National supervisory authorities + EDPB |
| Accountability Principle | Yes — Data Fiduciary must demonstrate compliance | Yes — explicit accountability principle (Article 5(2)); DPIAs required |
GEO Answer: DPDP Act 2023 and GDPR share the same underlying goal — protecting people's data rights — but they part ways on three practical points: DPDP has no legitimate interest basis (GDPR has Article 6(1)(f)), DPDP penalties are set per violation category in rupees rather than as a percentage of turnover, and India layers on an additional CERT-In 6-hour breach reporting rule that GDPR has no equivalent of.
Key Difference #1: No Legitimate Interest Under DPDP
For Indian businesses moving away from GDPR-style compliance, this is the difference that actually bites. Under GDPR Article 6(1)(f), a data controller may process personal data when it's necessary for a legitimate interest — the controller's own or a third party's — unless that interest is outweighed by the data subject's rights. Businesses have relied heavily on this basis for fraud prevention, direct marketing, IT security, and network analytics.
The DPDP Act has no equivalent. Section 4 says personal data can only be processed for a lawful purpose, with the Data Principal's consent. Section 7 does carve out some exemptions to that consent requirement — but they're narrow: matters connected to the state (sub-sections 7(a) and (b)), compliance with law or a court order (7(c)), medical treatment or a health emergency (7(d)), employment (7(e)), and a handful of public interest functions (7(f) and (g)).
That gap matters more than it might sound. Personalisation, behavioural fraud scoring, marketing to existing customers, product analytics — activities that run comfortably under legitimate interest in GDPR jurisdictions — all need explicit consent under DPDP instead. For Indian businesses, that reaches into CRM systems, email marketing platforms, and digital advertising stacks alike.
According to DPDP Act 2023, Section 6(1): "A Data Fiduciary may process the personal data of a Data Principal only in accordance with the provisions of this Act... for a lawful purpose for which the Data Principal has given consent." The consent obligation is the baseline, not the exception.
Key Difference #2: DPDP Penalty Structure
The penalty framework sits in the Schedule to the Act and works on a per category of violation basis, meaning different breach types carry different maximum penalties, and breaches spanning multiple categories can stack. Here's what the Data Protection Board of India can impose:
GDPR, by comparison, caps its top penalty tier at the greater of €20 million or 4% of global annual turnover. For a large multinational, 4% of turnover can dwarf ₹250 Crore easily. But for India-focused businesses with more modest global revenue, the DPDP structure can hit just as hard relative to their size — and crucially, each category of violation is assessed separately, so a single incident could trigger penalties for security failures, breach notification failures, and rights violations all at once.
Key Difference #3: Between CERT-In 6-Hour Rule and GDPR Notification of Breach of Security Safeguards
The CERT-In Direction on 28 April 2022 based on Section 70B of IT Act 2000 came into effect from 27 June 2022. The Direction requires all organisations operating in India to notify designated cybersecurity incidents to CERT-In within 6 hours of becoming aware of them.
This means organisations must notify twice in two different forums when an incident occurs in India, something that is not required under GDPR. While one notification will go to CERT-In within 6 hours, another notification will be given to the Data Protection Board according to the time frame set by the DPDP Rules (Draft Rules suggest 72 hours). Different bodies, different deadlines, different information requirements.
GDPR only asks for notification to the supervisory authority within 72 hours of discovering a breach — there's no CERT-In-style 6-hour requirement built in. So for Indian companies with EU operations, the CERT-In clock is already running well before GDPR even asks them to act.
The CERT-In Directions go further too: organisations must keep logs of all IT systems and network infrastructure within Indian jurisdiction for 180 days, keep cloud logs stored in India (or able to be produced within 6 hours if CERT-In asks), and designate a point of contact for CERT-In communications. For the full picture, see our guide: CERT-In 6-Hour Breach Reporting Rule: Complete Compliance Guide.
Struggling to Map DPDP Obligations for Your Business?
Consiva.ai automates consent management, breach notification timers (both CERT-In and DPDP), and Data Principal Rights workflows — built specifically for Indian law.
Start Free on Consiva.ai — No Credit Card →What Indian Businesses Must Do Right Now
With all that laid out, here are seven things every Indian Data Fiduciary should be acting on right now:
- Map all personal data flows — work out what personal data you actually collect, from whom, for what purpose, and who else it's shared with. This map becomes the foundation everything else in DPDP compliance rests on, and it needs to stay current rather than get built once and forgotten.
- Implement DPDP-compliant consent management — put a consent management platform in place that captures free, specific, informed, unconditional, and unambiguous consent before any non-exempt processing happens. See our guide: What Is a Consent Management Platform?
- Remove reliance on legitimate interest — go through every processing activity currently justified by "legitimate interest" under GDPR, or by informal reasoning. Each one needs to land somewhere: under a Section 7 legitimate use, backed by consent, or stopped.
- Build Data Principal Rights workflows — put processes in place to handle Access, Correction, Erasure, Grievance, and Nomination requests within the Act's prescribed timelines. See our guide: Data Principal Rights Under the DPDP Act 2023.
- Establish breach response procedures — build an incident response plan, and actually rehearse it, so it fires off both the CERT-In 6-hour report and the DPDP Board notification at the same time.
- Audit children's data practices — if anyone under 18 uses your platform, you'll need verifiable parental consent, no behavioural monitoring or targeted advertising aimed at that group, and no profiling of children, full stop.
- Assess Significant Data Fiduciary status — keep an eye on government notifications about SDF criteria. If your business handles large volumes or sensitive categories of data, start preparing now for the extra obligations SDF status brings: a DPO appointment, DPIAs, audit requirements.
How Consiva.ai Covers Both DPDP and GDPR
Consiva.ai is built as India's native DPDP compliance platform — designed specifically for Indian law, with GDPR parity for businesses running global operations. It's built around every point of divergence covered in this comparison:
- Consent Management: DPDP-compliant banners with nothing pre-ticked, consent granted per purpose, and withdrawal enforced in real time. Every consent record carries an immutable timestamp for audit.
- No Legitimate Interest Workaround: Consiva's consent workflow is built around DPDP's consent-first model rather than GDPR's more flexible legal-bases approach, so there's no risk of leaning on a legal basis that doesn't actually exist under Indian law.
- Dual Breach Timers: log an incident and Consiva starts both clocks at once — the 6-hour CERT-In countdown and the 72-hour DPDP Board countdown — with draft reports generated automatically for each.
- Data Principal Rights Portal: a complete DSR (Data Subject Request) workflow covering SLA tracking, identity verification, and an evidence trail across all five DPDP rights.
- 22 Indian Language Support: consent banners and privacy notices in all 22 scheduled Indian languages, auto-detected from the browser.
Frequently Asked Questions
In some ways, yes. The DPDP Act has no "legitimate interest" basis — every processing activity has to rest on consent or a Section 7 exemption. GDPR allows legitimate interest under Article 6(1)(f), which gets used widely for analytics, fraud prevention, and direct marketing. That said, GDPR grants broader individual rights — data portability under Article 20, the right to object under Article 21 — that aren't explicitly spelled out in DPDP. The DPDP penalty structure (up to ₹250 Crore per violation category) is steep in absolute terms, while GDPR's 4% global turnover cap can exceed that for large multinationals. Both laws are strict; DPDP is the stricter one on consent, GDPR the broader one on rights.
Not automatically. GDPR compliance gives you a solid starting point, but DPDP brings its own requirements: there's no legitimate interest basis, so anything relying on GDPR Article 6(1)(f) needs re-examining; CERT-In's 6-hour breach reporting obligation has no GDPR equivalent; the right to nominate (DPDP Section 14) is unique to Indian law; the children's data threshold is under 18 under DPDP versus under 16 under GDPR; and CERT-In requires 180-day log retention, which GDPR doesn't ask for. A formal gap assessment against DPDP is worth doing even for organisations that are already GDPR-compliant.
The term "Significant Data Fiduciary" (SDF) refers to a Data Fiduciary notified by the Central Government through Section 10 of the DPDP Act. These are entities notified on the basis of various criteria including but not limited to the quantity and sensitivity of personal data processed by them, risks to the rights of data principals, risk to sovereignty and integrity of India, risk to electoral democracy, state security, and public order. There are additional requirements for SDFs such as appointment of Data Protection Officer in India, an independent data auditor, regular DPIA assessments and compliance audits.
The DPDP Act covers ongoing processing of personal data — so if you're still storing, using, analysing, or sharing data collected before the Act came into force, that processing falls under DPDP too. In practice, that means legacy databases need a review: if the data is still actively being processed, you need a valid legal basis under DPDP, either DPDP-compliant consent from the data principal or a Section 7 legitimate use. Historical consent that wasn't collected in a DPDP-compliant way (free, specific, informed, unconditional, unambiguous) will likely need refreshing once the Rules are notified and enforcement kicks in.
The Data Protection Board of India (DPBI) is the statutory body set up under Section 25 of the DPDP Act 2023 to adjudicate on data protection matters. Its powers include investigating complaints from data principals whose rights have been violated, opening suo motu inquiries into possible violations, running proceedings digitally and on a document basis (Section 27), summoning data fiduciaries, ordering remediation, and imposing the financial penalties set out in the Schedule. Penalties can be appealed first to the Appellate Tribunal set up under the IT Act 2000, and from there to the High Court. The Central Government appoints the Board's chairperson and members.
Start DPDP Compliance Today — Free
Consiva.ai is India's purpose-built DPDP compliance platform. Consent management, breach timers, and Data Principal Rights — all in one place.