Most DPO training in India still runs on GDPR muscle memory. That is understandable. IAPP CIPP/E, ISO 27701, and every Big 4 privacy consulting practice grew up on GDPR. When DPDP arrived, the temptation was to treat it as "GDPR with Indian names". That is wrong in four specific ways, and each of the four traps a real compliance decision every month.
Difference 1. Consent is the near-universal lawful basis. No legitimate interest.
Under Article 6 of GDPR, controllers have six lawful bases including "legitimate interests" (Art. 6(1)(f)), which is used widely for direct marketing, fraud prevention, and network security. Under DPDP, Section 4 gives Data Fiduciaries only two grounds: consent under Section 6, or the specific "legitimate uses" listed exhaustively at Section 7 [L4-C1].
Section 7 has nine sub-clauses: voluntarily provided data used for the specified purpose; State subsidy/benefit/service/licence; State functions under law; disclosure required by law; compliance with judgments; medical emergency; epidemic/public health; disaster response; and employment purposes. There is no "legitimate interests" catch-all. If your processing does not fit in Section 6 (consent) or one of the nine Section 7 limbs, it is not lawful under DPDP.
Practitioner consequence: many activities that a GDPR DPO would justify under legitimate interests (behavioural analytics, cross-service personalisation, third-party data enrichment) need consent under DPDP. If your consent flow does not cover them, they stop.
Difference 2. Age of a child is 18, not 13 or 16.
GDPR Art. 8(1) sets the child threshold at 16, with Member States free to reduce to 13. Most set it at 13-14. DPDP Section 2(f) sets the child threshold at 18 for all purposes [L4-C2]. And Section 9 imposes hard restrictions on processing children's data: verifiable parental consent, no processing likely to cause detrimental effect on well-being, no tracking or behavioural monitoring, no targeted advertising directed at children.
Practitioner consequence: Indian consumer platforms that market to 16 and 17-year-olds cannot treat those users as adults. Ed-tech, gaming, streaming and social platforms all face a real age-gating and verifiable-parental-consent problem. Rule 10 mechanisms (reliable identity data already held, voluntary parent-provided ID, or Digital Locker Service Provider virtual token) become mandatory infrastructure [L4-C3].
The Fourth Schedule exempts specific classes (clinical establishments, healthcare professionals, educational institutions, creches) for narrow purposes (child safety, health services, transport tracking, subsidies, legal compliance). Ed-tech and consumer platforms are NOT in the Fourth Schedule.
Difference 3. The Consent Manager. Uniquely Indian architecture.
GDPR has no equivalent of the Consent Manager. DPDP Section 6(7)-(9) creates a registered intermediary through which a Data Principal can give, manage, review or withdraw consent across multiple Data Fiduciaries [L4-C4]. Rule 4 opens the registration window on 13 November 2026. The First Schedule requires the CM to be an India-incorporated company with net worth ≥ ₹2 crore, operate a "data-blind pipe" (route consent without reading the underlying personal data), and retain machine-readable consent logs for at least 7 years.
The architecture borrows from NITI Aayog's 2020 DEPA and the Sahamati Account Aggregator "data-blind pipe" model, both of which are proven in Indian fintech. What is unresolved: how CM consent interacts with sector-specific consent (RBI Account Aggregator flows, Aadhaar authentication consent) and whether these can be unified without regulatory arbitrage.
Practitioner consequence: from November 2026, mature Indian Data Fiduciaries will have a decision to make. Build in-house consent management, or integrate a registered Consent Manager. Global playbooks do not have a template for this decision.
Difference 4. Weaker DPO protection, but higher penalty ceilings.
GDPR Article 38(3) explicitly protects the DPO from being dismissed or penalised for performing DPO tasks. DPDP has no equivalent dismissal-protection clause. The DPO is required to be responsible to the Board of Directors under Section 10(2)(a) but nothing prevents removal [L4-C5]. This is a real weakness that senior privacy counsel in India are flagging.
On the other hand, DPDP penalty ceilings are substantially higher than GDPR base fines. GDPR Art. 83(5) sets a maximum of €20 million or 4% of worldwide annual turnover, whichever is higher. DPDP Item 1 of the Schedule sets a maximum of ₹250 crore for failure of Section 8(5) security safeguards. Item 2 sets ₹200 crore for breach notification failure. Item 3 sets ₹200 crore for children's data breaches. Item 4 sets ₹150 crore for SDF obligation failures. Item 7 residual sets ₹50 crore for any other breach [L4-C6].
The DPDP ceilings are per-breach, not turnover-linked. For a company that would sit near the €20 million GDPR ceiling, the DPDP exposure is broadly comparable in absolute terms. For a smaller Indian company, DPDP ceilings are disproportionately high compared to what a similar-sized entity would face under GDPR.
What is the same
To close the loop, the practitioner-familiar things GDPR and DPDP share:
- Extraterritorial application (both catch offshore processing tied to in-territory users).
- Right of access, correction, erasure (with carve-outs).
- Data Protection Impact Assessment for high-risk processing.
- Board-level accountability for the DPO.
- Requirement for a valid contract with data processors.
- Breach notification to the regulator.
The one-slide summary for your board
DPDP is not "GDPR with Indian names". Consent is the near-universal lawful basis (no legitimate interest catch-all). Age of a child is 18. Consent Managers are a uniquely Indian architecture opening 13 November 2026. DPO dismissal protection is weaker than GDPR, but per-breach penalty ceilings are much higher.