| Scope | Personal data, digital and structured manual filing systems. Extraterritorial where goods, services or monitoring reach the EU. | Digital personal data only. Extraterritorial where processing connects to offering goods or services to data principals in India. |
|---|
| Lawful bases | Six bases including contract, legal obligation and the open-ended legitimate interests balancing test. | Consent, or an enumerated "legitimate use". No balancing test. Narrower — more processing falls to consent. |
|---|
| Consent | Freely given, specific, informed, unambiguous; withdrawable; controller holds the record. | Same qualities, plus notice in English or any Eighth Schedule language, and an optional registered Consent Manager holding the record. |
|---|
| Notice | Articles 13 and 14 prescribe an extensive information set, including retention periods and recipients. | Shorter itemised notice: the data, the purpose, how to exercise rights, how to complain to the Board. Must be standalone and language-accessible. |
|---|
| Breach notification | To the authority within 72h unless unlikely to result in risk; to individuals only where high risk. | Board and every affected principal, without delay; detailed report within 72h. Stricter — no risk threshold, no exemption. |
|---|
| Individual rights | Access, rectification, erasure, restriction, portability, objection, and rights around automated decisions. Broader set. | Access, correction, erasure, grievance redressal, and nomination. No portability, no objection right, no automated-decision provision. |
|---|
| Cross-border transfers | Adequacy, SCCs, BCRs and derogations, with transfer impact assessments. Heavier machinery. | Transfer permitted except to countries the Central Government restricts. Sectoral localisation rules still bite on top. |
|---|
| Children's data | Consent age between 13 and 16 by Member State, for information society services. | Under 18, with verifiable parental consent, plus a ban on tracking and targeted advertising to children. Stricter. |
|---|
| DPO | Required for public authorities, large-scale systematic monitoring, or large-scale special category data. May be external. | Required for Significant Data Fiduciaries, based in India and reporting to the board. Others publish a contact point. |
|---|
| Penalties | Up to €20M or 4% of global annual turnover, whichever is higher. Turnover-linked, so uncapped in effect. | Fixed ceilings per instance: ₹250 Cr for security failures, ₹200 Cr for breach notification failures. |
|---|
| Enforcement body | National supervisory authorities, coordinated by the EDPB, with a lead authority for cross-border cases. | A single Data Protection Board of India, adjudicating by inquiry. Appeals to the TDSAT. Powers live from 13 Nov 2026. |
|---|