DPDPA vs GDPR: Why GDPR Compliance Does Not Equal DPDPA Compliance
Many Indian multinational corporations and SaaS startups believe that because they achieved GDPR readiness for European clients, they are automatically compliant with India's DPDP Act 2023.
This is a dangerous misconception. While both regimes share the foundational principles of data protection, the DPDPA contains several distinct statutory mandates that differ drastically from the European framework.
---
7 Major Differences Between DPDPA and GDPR
1. Age of Consent for Children
GDPR: Default age threshold is 16, with EU Member States permitted to lower it to 13.
DPDPA (Section 9): Absolute threshold of 18 years. Full parental consent is required for anyone under 18, and tracking/profiling is strictly prohibited even with parental consent.2. Legal Grounds for Processing
GDPR: Six lawful bases: Consent, Contractual Necessity, Legal Obligation, Vital Interests, Public Task, and Legitimate Interests.
DPDPA: Strictly limited to Consent and narrowly defined "Certain Legitimate Uses" (Section 7). Standard commercial "legitimate interest" clauses from the GDPR are not available under DPDPA.3. Penalty Calculations
GDPR: Up to €20 million or 4% of global annual turnover, whichever is higher.
DPDPA: Fixed statutory ceilings per infraction (e.g. up to ₹250 crore for security failures, ₹200 crore for children's data or breach non-disclosure).4. Language and Notice Requirements
GDPR: Concise, transparent notice in clear language.
DPDPA (Section 5): Notice must be provided in English or any of the 22 Eighth Schedule Indian languages chosen by the Data Principal.5. Consent Manager Framework
GDPR: No statutory, state-regulated Consent Manager intermediary.
DPDPA (Section 6(7)): Introduces registered Consent Managers that allow Data Principals to give, manage, review, and withdraw consent through an interoperable national platform.6. Breach Notification Timelines
GDPR: 72 hours to the supervisory authority; individuals notified only if high risk.
DPDPA & CERT-In: Dual clocks: CERT-In within 6 hours for cybersecurity events, and DPBI + all affected Data Principals within 72 hours regardless of risk threshold.7. Data Protection Officer (DPO) Mandate
GDPR: Required based on core activities involving large-scale systematic monitoring or sensitive data.
DPDPA (Section 10): Mandatory only for designated Significant Data Fiduciaries (SDFs), and the DPO must be an individual based in India.---
Summary for Tech and Legal Leaders
Indian companies processing data domestically must ensure their systems support multilingual notices, strict under-18 tracking bans, dual-clock incident notifications, and registered Consent Manager integrations.