GDPR Art.4(11), 7(3) · DPDP Act 2023 Section 6, Rules 3, 9, 14

You already run a GDPR consent banner. Is it enough for DPDP?

If you serve customers in the EU and in India, you are running one consent stack against two frameworks. Much of the machinery transfers. Four things do not, and one of them is the reason most GDPR-first setups fail a DPDP review.

The short answer

Mostly, but not quite — and the gaps are specific rather than general.

A well-implemented GDPR consent stack already gives you purpose-level capture, script blocking before consent, a durable record, and a withdrawal path. Those are the hard parts and they carry across.

What does not carry across: the notice content requirements are different and more prescriptive in one respect, the language obligation is materially different, the rights set your preference centre points at is different, and the response deadline you have configured is a GDPR figure with no DPDP basis.

None of that requires a second platform. It requires configuration changes and, in one case, a translation budget.

Where the two frameworks genuinely overlap

If you have these, you do not need to rebuild them:

Where DPDP asks for something GDPR does not

1. The language obligation is much wider. The Act requires a notice to be available in English or any language specified in the Eighth Schedule to the Constitution — 22 languages. An English-and-two-EU-languages banner does not address an Indian user base. This is usually the largest practical change, and it is a content and translation cost more than a technical one.

2. Notice content is prescriptively itemised. Rule 3 requires the notice to be presented and understandable independently of any other information, and to give in clear and plain language at minimum an itemised description of the personal data and the specified purposes with a specific description of the goods, services or uses enabled, plus the communication link and other means to withdraw, exercise rights and complain to the Board. GDPR Article 13 requires broadly comparable information but is generally satisfied by a layered notice linking to a privacy policy. Rule 3(a)'s independence requirement is stricter than most GDPR banners are built for.

3. The rights set is different, and your preference centre points at the wrong list. DPDP grants four rights — access to information (s.11), correction and erasure (s.12), grievance redressal (s.13), nomination (s.14) — plus withdrawal (s.6(4)). GDPR's portability, restriction of processing and objection rights have no DPDP equivalent. If your Indian preference centre offers portability, you have offered a right the Act does not grant. Nomination has no GDPR equivalent and is probably missing from your setup entirely.

4. Your response clock is a GDPR number. GDPR Article 12(3) gives one month. DPDP prescribes no response deadline for access, correction, erasure or nomination. For grievances, Rule 14(3) requires you to publish your response period and caps it at ninety days. A configured “30 days, per DPDP” is wrong on its face.

And one obligation with no GDPR analogue at all: Rule 9 requires the business contact information of your DPO or contact person to be published and mentioned in every response to a rights communication.

What this means for your existing setup

A short change list rather than a migration:

ChangeEffort
Add Eighth Schedule language variants for the languages your Indian users actually readTranslation cost; the largest item
Rewrite notice content to Rule 3's itemised structure, standing independently of the privacy policyContent work with legal review
Remove portability, restriction and objection from the Indian preference centreConfiguration
Add nomination as a rights request typeConfiguration
Re-label the 30-day clock as a service commitment; publish a separate grievance periodConfiguration and a published page
Add Rule 9 contact details to every rights response templateConfiguration
Keep purpose-level capture, script blocking, consent records and the withdrawal pathNo change
Serve region-specific notices rather than a merged one. A single notice attempting to satisfy both frameworks tends to satisfy neither cleanly, and Rule 3(a)'s independence requirement makes a combined notice harder to defend than two separate ones.

What Consiva does, and what it does not

What Consiva does. DPDP-native consent: purpose-level capture with signed records, notice versioning, Rule 3-structured notice templates, banner delivery in all 22 Eighth Schedule languages, withdrawal at parity with acceptance, and rights management built to Sections 11 to 14 with no portability option. Banner format can be varied by visitor region.

What Consiva does not do, stated plainly. Consiva is not a GDPR compliance platform and does not maintain a multi-jurisdiction regulatory rule library. It will not tell you whether your EU processing is lawful, will not maintain GDPR-specific rights workflows, and does not track EU regulatory developments. Varying a banner by region is a delivery feature; it is not framework coverage, and we are not going to describe it as though it were.

So who is this for. Organisations whose EU footprint is already handled — by an existing GDPR CMP, or by counsel — and who now need the Indian side done properly rather than approximated. If you need one platform to be authoritative on both, that is a different product and probably a different vendor, and we would rather tell you that now.

Frequently asked questions

Not without changes, though less is needed than a rebuild. The core machinery — purpose-level capture, pre-consent script blocking, durable records, withdrawal — transfers. What needs changing: notice content to Rule 3's itemised and independently-presented structure, language coverage across the Eighth Schedule languages your users read, the rights set your preference centre offers (remove portability, restriction and objection; add nomination), and the response deadline, which under DPDP is unprescribed for most rights.

We recommend it. Rule 3(a) requires the DPDP notice to be presented and understandable independently of any other information, which makes a merged multi-framework notice harder to defend than two region-specific ones. Region detection can serve the right notice from one deployment, so this is a content decision rather than an infrastructure one.

The definitions are substantively close — both require freely given, specific, informed, unambiguous consent by affirmative action, and both require withdrawal to be as easy as giving. The differences are in the surrounding obligations: DPDP's notice content requirements are more prescriptively itemised and must stand independently; the language obligation spans the 22 Eighth Schedule languages; the rights set differs materially, with no portability, restriction or objection under DPDP but a nomination right that GDPR lacks; and DPDP prescribes no response deadline for most rights, against GDPR's one month.

Consiva is a DPDP-native platform and is not a GDPR compliance product. It can vary banner format by visitor region, which is a delivery capability, not regulatory coverage — Consiva does not maintain a multi-jurisdiction rule library or GDPR-specific rights workflows. If your EU obligations are already handled elsewhere and you need the Indian side done properly, that is the fit. If you need a single authoritative platform for both, we are not it, and we would rather say so before a demo than after.

Probably not, and the reason is structural rather than a matter of missing paragraphs. Rule 3(a) requires the notice to be presented and understandable independently of any other information — a banner that summarises and links to a privacy policy relies on that policy to complete the notice, which is common and defensible practice under GDPR and harder to defend here. Rule 3(b) then requires an itemised description of the personal data and a specific description of the goods, services or uses each purpose enables. Most GDPR notices are written at a higher level of generality than that.

Get the Indian side done properly

Keep your GDPR setup where it is — add DPDP-native notice, language and rights handling for your Indian users.