GDPR set the global standard in 2018. India's DPDPA arrived in 2023 — not as a derivative, but as a deliberate response to India's unique context. Here's what's the same, what's different, and what India got right that Europe didn't. Written by Yuvaraj S., Founder, truConsent.
Context
GDPR is the reference point. Nearly every privacy law passed since 2018 has been measured against it — Brazil's LGPD, Thailand's PDPA, Singapore's amended PDPA, and now India's DPDPA. When regulators, lawyers, and compliance teams in new jurisdictions explain their law to multinational audiences, GDPR is the common language they reach for.
But DPDPA is not a GDPR clone. It reflects India's specific regulatory philosophy: consent-first processing with minimal exceptions, a constitutional foundation in Article 21 of the Indian Constitution, and a billion-plus digital citizens at genuinely different stages of digital literacy. The law's architects made deliberate choices that diverge from GDPR — some stricter, some more permissive, and some entirely novel.
Understanding the differences isn't academic. It matters directly for Indian businesses with EU customers — who must comply with both laws simultaneously. It matters for multinational companies evaluating their India compliance posture against their existing GDPR programs. And it matters for policymakers and advocates watching how India's approach shapes the next wave of global privacy legislation.
Side-by-Side
From terminology to enforcement, here is how GDPR and DPDPA sit against each other on the dimensions that matter most for compliance practitioners.
| Dimension | GDPR (EU) | DPDPA (India) |
|---|---|---|
| 1. Terminology | Data Controller, Data Subject, Data Processor | Data Fiduciary, Data Principal, Data Processor "Fiduciary" implies a higher duty of care — it's a deliberate choice that frames the relationship as one of trust and obligation, not just control. |
| 2. Legal Grounds for Processing | 6 lawful bases — consent, contract, legal obligation, vital interests, public task, legitimate interest | 2 primary grounds — consent + "certain legitimate uses" (narrower than GDPR's legitimate interest, covering state functions, employment, medical emergencies, public safety) India's approach is more restrictive — companies cannot use "legitimate interest" as broadly as in Europe. |
| 3. Consent Standard | Freely given, specific, informed, unambiguous. Can be bundled with other consents in some cases. | Free, specific, informed, unconditional, unambiguous. Withdrawal must be as easy as giving. Cannot be conditional on a service. India's standard is marginally stricter — "unconditional" is an addition not explicit in GDPR. |
| 4. Data Portability | Explicit right — Article 20. Data in machine-readable format, right to transmit to another controller. | Not currently included. Expected in future Rules or amendments. This is the biggest gap. India's law may evolve here, especially as UPI-style data portability models mature. |
| 5. Right to Erasure | Right to be forgotten — Article 17. Multiple grounds including withdrawal of consent. | Right to erasure on withdrawal of consent or when purpose is served. Narrower grounds but functionally similar for consumer use cases. |
| 6. Children's Data | Age threshold varies by member state (13–16). Parental consent for under-16. | Age threshold is 18 — the strictest in the world. Verifiable parental consent required. Cannot create behavioral profiles of children. Cannot target advertising at children. India's position on children's data is unambiguously the strictest globally. This has significant implications for edtech, gaming, social media. |
| 7. Data Protection Officer (DPO) | Mandatory for large-scale processing, public authorities, processing of special categories. | Mandatory only for Significant Data Fiduciaries (SDFs). SDF definition is pending in Rules. Most businesses will NOT need a DPO under DPDPA unless they qualify as SDF. This is a significant compliance simplification. |
| 8. Data Protection Impact Assessment (DPIA) | Required before processing likely to result in high risk to individuals. | Required for Significant Data Fiduciaries. Also referenced in general duty of care provisions. |
| 9. Penalties | Up to €20M or 4% of global annual turnover (whichever is higher). Over €4B in total fines since 2018. | Up to ₹250 crore (~$30M) per breach instance. Not linked to global revenue. For large multinationals, GDPR penalties are higher. For Indian SMEs, ₹250 crore is substantial relative to revenue. |
| 10. Consent Manager / CMP | No equivalent. Companies deploy CMPs (consent management platforms) voluntarily — tools, not regulated entities. | Consent Manager is a licensed entity, registered with and accountable to the DPBI. Not a software tool — a regulated intermediary. This is India's most significant innovation. No other privacy law in the world has this model. |
| 11. Cross-Border Data Transfers | Positive adequacy model — transfers allowed to countries on the EU's "adequate protection" list, or via SCCs/BCRs. | Negative list model — transfers allowed everywhere EXCEPT countries the Central Government restricts. List pending in Rules. |
| 12. Enforcement Model | Data Protection Authorities (DPAs) in each member state. Proactive audits, investigations, self-initiated enforcement. | Data Protection Board of India (DPBI). Currently adjudicatory — responds to complaints. May evolve toward proactive enforcement. |
India's Innovations
India had the benefit of hindsight — seven years of watching GDPR implementation expose gaps, loopholes, and unintended consequences. These are the areas where India made the better call.
GDPR's 6 legal bases create complexity and abuse — especially "legitimate interest," which companies routinely invoke to sidestep consent requirements. DPDPA's consent-first approach with narrow legitimate uses reduces ambiguity and closes the loophole.
A licensed intermediary accountable to the regulator is architecturally superior to voluntary CMPs. It creates systemic accountability — not just at the company level, but across the consent infrastructure of the internet.
DPDPA explicitly requires notices in the language the user understands. GDPR's language provisions are weaker, leaving multinationals with discretion that often disadvantages non-English speakers.
India set 18 as the threshold, not 16 or 13. Given India's digital landscape and the documented risk to young users from behavioral profiling and targeted advertising, this is the right call — even if it creates implementation complexity for edtech and social platforms.
Gaps to Close
DPDPA Version 1.0 is not the final form of Indian privacy law. These are the areas where GDPR remains more comprehensive — and where India's law will likely evolve.
Gap 1
The ability to move your data from one service to another is a fundamental right in the digital economy. India will add this — possibly drawing on UPI's interoperability model as a template for what real-world data portability looks like.
Gap 2
GDPR explicitly identifies "special categories" — health, biometric, religious belief, political opinion, sexual orientation — with heightened protections and stricter processing grounds. DPDPA treats all personal data uniformly. This is an area for future development, particularly for healthcare, HR, and fintech.
Gap 3
GDPR's DPAs investigate without waiting for complaints. India's DPBI adjudicates. Over time, this will need to evolve — a purely reactive regulator will miss systemic violations that no individual data principal ever notices or reports.
Dual Compliance
Indian companies with EU customers — and European companies with Indian users — increasingly operate under both regimes simultaneously. Here is practical guidance on where the laws align, where they diverge, and where a single compliance program can serve both.
Consent Mechanism
You need a consent mechanism that satisfies both GDPR's "freely given" standard and DPDPA's "unconditional" standard — they are compatible. A single consent flow built to DPDPA's stricter standard will satisfy GDPR as well.
Privacy Notice / DPA
Your Privacy Policy must cover both Article 13/14 GDPR requirements and DPDPA's notice requirements. They overlap significantly — purpose, processing activities, data categories, and rights — so a well-structured notice can serve both without duplication.
Cross-Border Transfers
If you transfer EU user data to India, you need adequacy safeguards under GDPR (India is not yet on the EU adequacy list — SCCs apply). If you transfer Indian user data outside India, watch for DPDPA's negative list once it is notified by the Central Government.
Consent Manager Handles Both
A Consent Manager handling DPDPA compliance will also handle most of your GDPR consent obligations. The consent lifecycle — collection, storage, withdrawal, audit trail — is structurally identical. India's licensed Consent Manager model gives you a defensible compliance record for both regulators.
India is the only country where a Consent Manager is a licensed intermediary accountable to a regulator. truConsent is built specifically for DPDPA 2023 — consent lifecycle, data principal rights, breach management, and more.