India’s Digital Personal Data Protection Act, 2023 received presidential assent on 11 August 2023 and was drafted with the GDPR visibly in view. It is not a copy, and it is not equivalent. It is a shorter, narrower statute with a different theory of lawful processing, a different enforcement architecture and a materially smaller set of individual rights.
Commencement matters as much as content. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 with a staged commencement. Rules 1, 2 and 17-21, covering definitions and the Data Protection Board, took effect on publication. The Consent Manager registration regime commences twelve months after publication, in November 2026. The substantive obligations — notice, consent, children’s data, Significant Data Fiduciary duties, breach intimation, rights handling and the penalty machinery — commence eighteen months after publication, in May 2027. As of 30 July 2026, the core compliance obligations are therefore not yet enforceable. Verify this against the current gazette position before acting on it; a phased rollout is precisely the kind of fact that moves.
Key Takeaways
- The DPDP Act runs on consent plus an enumerated list of “legitimate uses”. There is no legitimate-interests balancing test.
- It covers only digital personal data, and it has no special-category regime — no equivalent of GDPR Art. 9.
- Data Principals get access, correction, erasure, grievance redressal and nomination. They do not get portability, objection, restriction or an Art. 22 automated-decision right.
- The Data Protection Board of India adjudicates penalties; it is not a supervisory authority in the Arts. 51-59 GDPR sense.
- Penalties are fixed rupee ceilings, not a percentage of turnover.
Scope
The Act applies to digital personal data processed within India, and to processing outside India where it is in connection with any activity related to offering goods or services to Data Principals within India (s. 3(b)). Compare Art. 3(2) GDPR, which has two limbs: offering goods or services, and monitoring behaviour. The DPDP Act has no monitoring limb, so its extraterritorial reach is narrower than the GDPR’s on its face.
Material scope is narrower too. The Act covers digital personal data and non-digital data that is subsequently digitised. The GDPR applies to personal data processed by automated means and to manual processing forming part of a filing system (Art. 2(1)). Paper records in a structured file are in scope in Europe and out of scope in India.
The most consequential omission is the absence of any special-category regime. The GDPR prohibits processing of health, genetic, biometric, racial, political, religious, trade-union, sex-life and sexual-orientation data unless an Art. 9(2) condition applies on top of the Art. 6 basis. The DPDP Act treats all personal data alike. For an Indian company handling European clinical trial or patient data as a processor, that is the widest gap in the whole comparison, and it is why a European sponsor’s audit will look nothing like a DPDP readiness check. Our page on the GDPR’s reach into Indian companies develops the processor position.
Lawful Processing
| DPDP Act 2023 | GDPR | |
|---|---|---|
| Model | Consent (s. 6) or a listed legitimate use (s. 7) | Six lawful bases (Art. 6) |
| Balancing basis | None | Legitimate interests, Art. 6(1)(f), with documented test |
| Contract necessity | Not a standalone ground | Art. 6(1)(b) |
| Employment | Listed legitimate use, s. 7(i) | No dedicated basis; usually contract, legal obligation or legitimate interests |
| Sensitive data | No separate regime | Art. 9 condition required in addition |
| Withdrawal | Must be as easy as giving consent (s. 6(4)-(6)) | Art. 7(3), equivalent |
Section 7 lists the legitimate uses exhaustively: data voluntarily provided for a specified purpose, State functions and the provision of subsidies, benefits, certificates and licences, compliance with law or court orders, medical emergencies and epidemics, employment purposes and safeguarding an employer from loss, and specified disaster and public-order situations. There is no residual clause. If your processing does not fit a listed use, you need consent.
That cuts both ways against Europe. An Indian employer relies on s. 7(i) for a broad range of employee processing with no balancing test; a European employer processing the same data must identify an Art. 6 basis and, where legitimate interests is used, complete and retain a documented three-part assessment. Conversely, an Indian company doing marketing analytics that does not fit s. 7 must obtain consent, where a European company might run a legitimate interests assessment instead.
Consent itself is defined in s. 6(1) as free, specific, informed, unconditional and unambiguous with a clear affirmative action — wording deliberately close to Art. 4(11) GDPR. Notice under s. 5 is itemised but considerably shorter than the Art. 13 and 14 lists, and the Rules require notice to be presented independently of other information, in clear plain language, and in any of the languages of the Eighth Schedule to the Constitution at the Data Principal’s option.
Consent Managers: No European Equivalent
The DPDP Act creates a registered intermediary, the Consent Manager, through which a Data Principal may give, manage, review and withdraw consent, via an accessible, transparent and interoperable platform (s. 6(7)-(9)). Consent Managers register with the Data Protection Board and are subject to conditions in the Rules, including a net worth requirement. Registration commences twelve months after the Rules’ publication, so from November 2026.
Nothing in the GDPR corresponds. Europe has consent management platforms as a commercial category — compared in our CMP review — but they are vendors, not licensed intermediaries with a statutory role and a regulator’s register.
Rights
| Right | DPDP Act | GDPR |
|---|---|---|
| Access | s. 11, summary of processing and identities of Data Fiduciaries with whom data was shared | Art. 15, copy of the data plus extensive information |
| Correction and completion | s. 12 | Art. 16 |
| Erasure | s. 12 | Art. 17 |
| Grievance redressal | s. 13 | No direct equivalent; Art. 77 complaint right |
| Nomination | s. 14 | None |
| Portability | Absent | Art. 20 |
| Objection | Absent | Art. 21 |
| Restriction | Absent | Art. 18 |
| Automated decisions | Absent | Art. 22 |
Two structural differences. The access right in s. 11 delivers a summary, not a copy, which is a lesser entitlement than Art. 15. And s. 15 imposes duties on Data Principals — not to impersonate, not to file false or frivolous complaints, not to suppress material information — enforceable by a penalty of up to INR 10,000. The GDPR imposes no duties on data subjects at all.
Children are treated more strictly in India in one respect: s. 9 requires verifiable parental consent for anyone under 18 and prohibits tracking, behavioural monitoring and targeted advertising directed at children. Art. 8 GDPR sets the information-society-service threshold at 16, with member states free to lower it to 13.
Enforcement Architecture
The Data Protection Board of India (ss. 18-27) is a digital-by-design adjudicating body. It determines non-compliance on complaint or reference and imposes monetary penalties; it does not issue guidance, conduct the kind of proactive supervision an EU authority does, or exercise the full Art. 58 toolkit of investigative, corrective, authorisation and advisory powers. Appeals lie to the Telecom Disputes Settlement and Appellate Tribunal.
Its members are appointed by the Central Government for two-year terms, eligible for re-appointment. Compare Arts. 51-59 GDPR, which require complete independence, security of tenure and freedom from external instruction, and the EDPB as a coordinating body. This is not a stylistic difference; it is one of the factors any future EU adequacy assessment of India would examine, alongside the Government’s exemption powers under s. 17 and its power to call for information under s. 36. Our page on India-EU data transfers explains why that matters for the transfer analysis today.
Penalties. The Schedule sets fixed ceilings: up to INR 250 crore for failing to take reasonable security safeguards, up to INR 200 crore for failing to notify a breach, up to INR 200 crore for children’s-data breaches, up to INR 150 crore for Significant Data Fiduciary obligations, and up to INR 50 crore as a residual. The GDPR’s Art. 83 works differently: EUR 20 million or 4% of worldwide annual turnover, whichever is higher. For a large multinational the European ceiling is effectively unbounded; for a mid-size Indian company the rupee figures may well be the larger number.
Breach reporting. Section 8(6) requires intimation of every personal data breach to the Board and to each affected Data Principal, with no risk threshold at all — broader than Art. 33, which exempts breaches unlikely to result in a risk. Under Rule 7 the affected Data Principals are informed without delay, the Board receives an initial intimation without delay and a detailed report within 72 hours. The 72 hours attaches to the detailed report rather than to first notice, which is the reverse of the GDPR’s structure.
Significant Data Fiduciaries. Section 10 lets the Government designate entities by notification, triggering an India-based Data Protection Officer, an independent data auditor, and periodic data protection impact assessments and audits. The GDPR’s DPO threshold in Art. 37 is self-assessed against criteria rather than conferred by notification.
Transfers
Section 16 empowers the Central Government to restrict transfers of personal data to countries it notifies — a negative list, and a reversal of the 2022 draft’s whitelist approach. Section 16(2) preserves stricter sectoral rules, which is where the real constraint sits: the Reserve Bank of India’s 2018 payment-data storage requirement, and localisation rules in insurance and securities. There is no adequacy machinery, no SCC instrument and no derogation framework of the Art. 49 kind.
The Practical Conclusion
If you process EU personal data, DPDP readiness does not get you there, and complying with the GDPR does not automatically satisfy the DPDP Act either — the notice format, language options, Consent Manager route, children’s threshold and universal breach intimation have no European counterpart. Run them as two programmes with a shared data inventory. What that looks like in tooling terms is set out in GDPR compliance software for Indian companies, and the underlying question of whether the GDPR applies outside the EU determines which of the two is your bigger problem.
FAQ
Is the DPDP Act in force?
Partly. The Act was assented on 11 August 2023 and the Rules were notified on 13 November 2025 with staged commencement: Board provisions immediately, Consent Manager registration at twelve months, and the substantive obligations at eighteen months — May 2027. As of 30 July 2026 the core duties are not yet enforceable. Check the current position before relying on this.
Does DPDP compliance help with GDPR compliance?
It helps with the shared foundations: knowing what data you hold, consent capture, breach detection and security. It does not deliver an Art. 30 record, an Art. 9 condition, a DPIA in the Art. 35 form, portability and objection workflows, or an EU representative.
Is the DPDP Act “India’s GDPR”?
No. It is a shorter statute with a different lawful-processing model, no special-category regime, fewer rights, a differently constituted regulator and fixed-value penalties. No non-EU law is equivalent to the GDPR, and describing the DPDP Act that way leads companies to under-scope their European obligations.
Which is stricter?
Neither, consistently. India is stricter on children’s age, on universal breach intimation and on Consent Manager infrastructure. The GDPR is stricter on lawful basis documentation, special-category data, rights, cross-border transfers and the size of the penalty ceiling. Assess obligation by obligation, not in the aggregate.
Legiscope automates this for you
Stop doing compliance manually. Legiscope's AI handles ROPA creation, DPA audits, and gap analysis — in minutes, not weeks.
Start free trial



