RISKFORTIS
Enforcement092d 01h 44m

DPDP vs GDPR

Reviewed August 2026 · Data Protection Board decisions tracked

The useful question is not how the two regimes differ in theory. It is what an organisation already running a mature GDPR programme still has to build for India.

The answer is smaller than a fresh start and larger than a mapping exercise. Roughly two thirds of your artefacts carry over with edits. The remaining third has no GDPR equivalent at all — and it includes the two obligations most likely to be tested first.

The headline differences

Three differences that change how you operate.

Not the academic ones. These three force a change to a workflow, a decision record or a piece of infrastructure you already built for GDPR.

01

No materiality threshold on breach notification

GDPR lets you weigh risk: no notification to the authority where the breach is unlikely to result in a risk to rights and freedoms, and no notification to individuals unless the risk is high. Rule 7 has no such filter. Every personal data breach goes to the Board, and every affected data principal is told.

What changes: your risk-assessment gate is removed, and your notification volume rises.

02

No legitimate interests basis in the same form

GDPR's Article 6(1)(f) is an open, balancing-test basis that carries a great deal of ordinary processing. DPDP replaces it with an enumerated list of "legitimate uses" — employment, medical emergency, State functions and a handful more. If your processing is not on the list, it needs consent.

What changes: your LIA library does not transfer. Every activity is re-based.

03

The Consent Manager has no GDPR equivalent

DPDP creates a registered intermediary through which a data principal can give, manage, review and withdraw consent across fiduciaries, from a single interface. Registration opens on 13 Nov 2026. Nothing in GDPR anticipates a third party holding the consent record.

What changes: your consent store may need to interoperate with infrastructure you do not own.

The full comparison

Theme by theme, side by side.

Colour appears only where one regime is genuinely stricter on that theme, not to decorate the table.

ThemeGDPRDPDP
ScopePersonal data, digital and structured manual filing systems. Extraterritorial where goods, services or monitoring reach the EU.Digital personal data only. Extraterritorial where processing connects to offering goods or services to data principals in India.
Lawful basesSix bases including contract, legal obligation and the open-ended legitimate interests balancing test.Consent, or an enumerated "legitimate use". No balancing test. Narrower — more processing falls to consent.
ConsentFreely given, specific, informed, unambiguous; withdrawable; controller holds the record.Same qualities, plus notice in English or any Eighth Schedule language, and an optional registered Consent Manager holding the record.
NoticeArticles 13 and 14 prescribe an extensive information set, including retention periods and recipients.Shorter itemised notice: the data, the purpose, how to exercise rights, how to complain to the Board. Must be standalone and language-accessible.
Breach notificationTo the authority within 72h unless unlikely to result in risk; to individuals only where high risk.Board and every affected principal, without delay; detailed report within 72h. Stricter — no risk threshold, no exemption.
Individual rightsAccess, rectification, erasure, restriction, portability, objection, and rights around automated decisions. Broader set.Access, correction, erasure, grievance redressal, and nomination. No portability, no objection right, no automated-decision provision.
Cross-border transfersAdequacy, SCCs, BCRs and derogations, with transfer impact assessments. Heavier machinery.Transfer permitted except to countries the Central Government restricts. Sectoral localisation rules still bite on top.
Children's dataConsent age between 13 and 16 by Member State, for information society services.Under 18, with verifiable parental consent, plus a ban on tracking and targeted advertising to children. Stricter.
DPORequired for public authorities, large-scale systematic monitoring, or large-scale special category data. May be external.Required for Significant Data Fiduciaries, based in India and reporting to the board. Others publish a contact point.
PenaltiesUp to €20M or 4% of global annual turnover, whichever is higher. Turnover-linked, so uncapped in effect.Fixed ceilings per instance: ₹250 Cr for security failures, ₹200 Cr for breach notification failures.
Enforcement bodyNational supervisory authorities, coordinated by the EDPB, with a lead authority for cross-border cases.A single Data Protection Board of India, adjudicating by inquiry. Appeals to the TDSAT. Powers live from 13 Nov 2026.

Credit where it is due

What your GDPR programme already covers.

If you have run GDPR properly for a few years, you are further along than most Indian-only organisations will be in 2027. These carry over with edits rather than rebuilds.

01

Your RoPA and data mapping

The hardest, slowest artefact to build. It transfers almost intact — you re-base the lawful basis column and add Indian processors.

02

Security safeguards and access control

Rule 6 asks for less prescription than Article 32 in some respects and more logging in others. Your control set holds.

03

Rights request machinery

Intake, identity verification, search and fulfilment. DPDP asks for a narrower set of rights, so your workflow is a superset.

04

Processor contracting discipline

You already know how to paper a processor and hold them to a notification duty. The clauses change; the muscle does not.

05

DPIA practice

The methodology transfers directly for Significant Data Fiduciary obligations. Only the trigger criteria change.

06

Governance and board reporting

A privacy function that already reports upward is most of what an SDF has to demonstrate.

The gap

What it does not cover, and what that costs you.

Seven items with no GDPR analogue, or where the GDPR artefact actively misleads you if you reuse it unchanged.

  1. 01

    Every lawful basis has to be re-decided

    Anything you run on legitimate interests — marketing analytics, fraud scoring, product telemetry — needs a new basis in India. Most of it lands on consent, which means new capture, new artefacts and a withdrawal path.

  2. 02

    Breach notification without a risk gate

    Your GDPR playbook's first decision point — is this notifiable — does not exist under Rule 7. Teams trained on the GDPR flow will pause to assess risk while the clock runs.

  3. 03

    The CERT-In six-hour clock

    No European equivalent. It closes at 8.3% of the 72h window your team is trained on, and it is the deadline most GDPR-mature organisations miss first.

  4. 04

    Notice in Eighth Schedule languages

    A standalone notice, available in English or any of twenty-two scheduled languages. This is a content and delivery problem your European notice architecture never had to solve.

  5. 05

    Consent Manager interoperability

    If your data principals use one, consent state lives partly outside your systems. That is an integration and a reconciliation process, not a policy paragraph.

  6. 06

    Children are under 18

    Verifiable parental consent to eighteen, with tracking and targeted advertising to children prohibited outright. A GDPR age gate set at 16 is not compliant here.

  7. 07

    The Indian sectoral stack sits on top

    RBI, SEBI and IRDAI retention and reporting mandates interact with DPDP erasure and notification duties. Nothing in your GDPR programme reconciles them.

You have done the hard part already. Find out what is left.

Talk to DPDP experts

Running a GCC or exporting to EU controllers? See all sectors →

General information, not legal advice.