Live Founding Cohort open, limited seats remaining Back to main site →

DPDP vs GDPR: the four key differences

A DPO trained on GDPR will still find surprises in DPDP. This lesson maps the four biggest deltas so you do not carry GDPR assumptions into an Indian compliance decision.

Free preview 9 min read Verified
Legal basis
DPDP Act 2023 (No. 22 of 2023, assented 11 August 2023). DPDP Rules 2025 notified 13 November 2025 via Gazette Notifications G.S.R. 843(E), 844(E), 845(E) and 846(E). Sectoral overlays as in force August 2026: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); RBI Draft Data Governance Framework (15 July 2026, consultation closed 17 August 2026); SEBI CSCRF (20 August 2024); IRDAI Information and Cyber Security Guidelines 2026 (6 April 2026); Telecom Cyber Security Rules 2024 (21 November 2024); Aadhaar Data Security Regulations 2016. Constitutional context: Puttaswamy v. Union of India (2017) 10 SCC 1.

Most DPO training in India still runs on GDPR muscle memory. That is understandable. IAPP CIPP/E, ISO 27701, and every Big 4 privacy consulting practice grew up on GDPR. When DPDP arrived, the temptation was to treat it as "GDPR with Indian names". That is wrong in four specific ways, and each of the four traps a real compliance decision every month.

Difference 1. Consent is the near-universal lawful basis. No legitimate interest.

Under Article 6 of GDPR, controllers have six lawful bases including "legitimate interests" (Art. 6(1)(f)), which is used widely for direct marketing, fraud prevention, and network security. Under DPDP, Section 4 gives Data Fiduciaries only two grounds: consent under Section 6, or the specific "legitimate uses" listed exhaustively at Section 7 [L4-C1].

Section 7 has nine sub-clauses: voluntarily provided data used for the specified purpose; State subsidy/benefit/service/licence; State functions under law; disclosure required by law; compliance with judgments; medical emergency; epidemic/public health; disaster response; and employment purposes. There is no "legitimate interests" catch-all. If your processing does not fit in Section 6 (consent) or one of the nine Section 7 limbs, it is not lawful under DPDP.

Practitioner consequence: many activities that a GDPR DPO would justify under legitimate interests (behavioural analytics, cross-service personalisation, third-party data enrichment) need consent under DPDP. If your consent flow does not cover them, they stop.

Difference 2. Age of a child is 18, not 13 or 16.

GDPR Art. 8(1) sets the child threshold at 16, with Member States free to reduce to 13. Most set it at 13-14. DPDP Section 2(f) sets the child threshold at 18 for all purposes [L4-C2]. And Section 9 imposes hard restrictions on processing children's data: verifiable parental consent, no processing likely to cause detrimental effect on well-being, no tracking or behavioural monitoring, no targeted advertising directed at children.

Practitioner consequence: Indian consumer platforms that market to 16 and 17-year-olds cannot treat those users as adults. Ed-tech, gaming, streaming and social platforms all face a real age-gating and verifiable-parental-consent problem. Rule 10 mechanisms (reliable identity data already held, voluntary parent-provided ID, or Digital Locker Service Provider virtual token) become mandatory infrastructure [L4-C3].

The Fourth Schedule exempts specific classes (clinical establishments, healthcare professionals, educational institutions, creches) for narrow purposes (child safety, health services, transport tracking, subsidies, legal compliance). Ed-tech and consumer platforms are NOT in the Fourth Schedule.

Difference 3. The Consent Manager. Uniquely Indian architecture.

GDPR has no equivalent of the Consent Manager. DPDP Section 6(7)-(9) creates a registered intermediary through which a Data Principal can give, manage, review or withdraw consent across multiple Data Fiduciaries [L4-C4]. Rule 4 opens the registration window on 13 November 2026. The First Schedule requires the CM to be an India-incorporated company with net worth ≥ ₹2 crore, operate a "data-blind pipe" (route consent without reading the underlying personal data), and retain machine-readable consent logs for at least 7 years.

The architecture borrows from NITI Aayog's 2020 DEPA and the Sahamati Account Aggregator "data-blind pipe" model, both of which are proven in Indian fintech. What is unresolved: how CM consent interacts with sector-specific consent (RBI Account Aggregator flows, Aadhaar authentication consent) and whether these can be unified without regulatory arbitrage.

Practitioner consequence: from November 2026, mature Indian Data Fiduciaries will have a decision to make. Build in-house consent management, or integrate a registered Consent Manager. Global playbooks do not have a template for this decision.

Difference 4. Weaker DPO protection, but higher penalty ceilings.

GDPR Article 38(3) explicitly protects the DPO from being dismissed or penalised for performing DPO tasks. DPDP has no equivalent dismissal-protection clause. The DPO is required to be responsible to the Board of Directors under Section 10(2)(a) but nothing prevents removal [L4-C5]. This is a real weakness that senior privacy counsel in India are flagging.

On the other hand, DPDP penalty ceilings are substantially higher than GDPR base fines. GDPR Art. 83(5) sets a maximum of €20 million or 4% of worldwide annual turnover, whichever is higher. DPDP Item 1 of the Schedule sets a maximum of ₹250 crore for failure of Section 8(5) security safeguards. Item 2 sets ₹200 crore for breach notification failure. Item 3 sets ₹200 crore for children's data breaches. Item 4 sets ₹150 crore for SDF obligation failures. Item 7 residual sets ₹50 crore for any other breach [L4-C6].

The DPDP ceilings are per-breach, not turnover-linked. For a company that would sit near the €20 million GDPR ceiling, the DPDP exposure is broadly comparable in absolute terms. For a smaller Indian company, DPDP ceilings are disproportionately high compared to what a similar-sized entity would face under GDPR.

What is the same

To close the loop, the practitioner-familiar things GDPR and DPDP share:

  • Extraterritorial application (both catch offshore processing tied to in-territory users).
  • Right of access, correction, erasure (with carve-outs).
  • Data Protection Impact Assessment for high-risk processing.
  • Board-level accountability for the DPO.
  • Requirement for a valid contract with data processors.
  • Breach notification to the regulator.

The one-slide summary for your board

DPDP is not "GDPR with Indian names". Consent is the near-universal lawful basis (no legitimate interest catch-all). Age of a child is 18. Consent Managers are a uniquely Indian architecture opening 13 November 2026. DPO dismissal protection is weaker than GDPR, but per-breach penalty ceilings are much higher.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview complete You've read every free lesson in Module 1

Ready for the rest of DPDP Rules 2025 Deep Dive / DPO Practitioner?

  • All 7 paid modules (24 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹14,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
DPDP Act 2023, Section 4 (Grounds for processing personal data) L4-C1
Personal data may be processed only for a lawful purpose, either with the consent of the Data Principal, or for certain legitimate uses listed in Section 7.
DPDP Act 2023, Section 2 (Definitions) L4-C2
Defines key terms including Data Principal, Data Fiduciary, Data Processor, personal data, personal data breach, processing, Significant Data Fiduciary, Consent Manager, child, and Board.
DPDP Rules 2025, Rule 10 (Verifiable consent for children) L4-C3
Before processing personal data of a child, the Data Fiduciary must adopt appropriate technical and organisational measures to ensure verifiable consent of the parent is obtained. Verification may be by reference to reliable identity and age details already available with the Fiduciary, or voluntarily provided identity and age details or a virtual token mapped to such details issued by an entity entrusted by law or by a Digital Locker Service Provider.
DPDP Act 2023, Section 6 (Consent) L4-C4
Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to personal data necessary for the specified purpose. Withdrawal must be as easy as giving consent. Consent may be given, managed, reviewed or withdrawn through a Consent Manager registered with the Board.
DPDP Act 2023, Section 10 (Additional obligations of Significant Data Fiduciary) L4-C5
Central Government may notify any Data Fiduciary or class as Significant Data Fiduciary based on volume and sensitivity of personal data, risk to rights of Data Principals, potential impact on sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order. Every SDF must appoint an India-resident Data Protection Officer responsible to the Board of Directors, an independent Data Auditor, and undertake periodic DPIAs and audits.
DPDP Act 2023, Schedule (Penalty ceilings) L4-C6
Item 1: Failure to take reasonable security safeguards under Section 8(5) — up to two hundred and fifty crore rupees. Item 2: Failure to give breach intimation under Section 8(6) — up to two hundred crore rupees. Item 3: Failure of children's data obligations under Section 9 — up to two hundred crore rupees. Item 4: Failure of SDF obligations under Section 10 — up to one hundred and fifty crore rupees. Item 5: Data Principal duty breach under Section 15 — up to ten thousand rupees. Item 7: Residual — any other breach of Act or Rules — up to fifty crore rupees.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: The DPDP Act, the 2025 Rules, and the Commencement Calendar
Module 2: Notice, Consent, Cookies and the Consent Manager Ecosystem
  • Notice under Section 5 and Rule 3
  • The Section 6 consent test and withdrawal architecture
  • Cookies and the India grey zone
  • Consent Manager registration under Rule 4 and the MeitY six
Module 3: Data Discovery, RoPA and Retention
  • Data discovery and classification
  • Building a DPDP-fit Record of Processing Activities
  • Rule 8 retention and the Third Schedule
  • Layered retention across DPDP and sectoral rules
Module 4: Data Principal Rights and Grievance Management
  • Section 11 access and Rule 14 workflow
  • Section 12 correction, completion and erasure
  • Section 13 grievance mechanism and escalation to the Board
  • Section 14 nomination and Section 15 Data Principal duties
Module 5: Assessments: DPIA, Independent Audit and Algorithmic Due Diligence
  • SDF designation under Section 10 and the Rule 13 programme
  • Running a DPIA in practice
  • The DPO role in detail: qualifications, salary bands, reporting line
  • DPB adjudication and TDSAT appeal
Module 6: Breach Management: The Rule 7 Two-Stage Clock
  • What counts as a personal data breach
  • Rule 7 Stage 1 and Stage 2 mechanics
  • Parallel clocks: DPDP Rule 7 and CERT-In 6-hour
  • Rule 6 security safeguards
Module 7: Vendor Management, Cross-Border Transfers and Sector Overlays
  • Section 8(2) DPA and the ten non-negotiable clauses
  • Section 16 and Rule 15 cross-border transfer
  • Sector overlays: RBI, SEBI, IRDAI, Telecom, Aadhaar
  • Section 17 exemptions and the constitutional challenge
Module 8: Final Exam and Certificate