Security HubGDPR vs India's DPDP Act: What Changes If You Already Comply

GDPR vs India's DPDP Act: What Changes If You Already Comply

Netru Compliance7 min read

India's Digital Personal Data Protection Act is often described as India's GDPR, which is close enough to be useful and wrong in the places that cost money. If you already run a GDPR programme, the good news is that most of the expensive infrastructure carries over. The differences are concentrated in a handful of areas, and every one of them is on the privacy side rather than the security side.

What carries over unchanged

Your data inventory and record of processing. Knowing what personal data you hold, where it lives, who has access and why is the single most expensive artefact in any privacy programme, and it serves both regimes without modification.

Your access, correction and erasure workflows. The rights differ in detail but the operational capability to find one person's data across your systems and act on it is the same capability.

Your processor contracts, in substance. Your breach detection and investigation capability. Your security controls in their entirety, since both regimes require appropriate technical and organisational measures without prescribing them.

If you have done GDPR properly, you have built the hard part. What follows is a delta, not a rebuild.

Lawful basis is the biggest change

GDPR gives you six lawful bases, and most commercial processing runs on consent, contract or legitimate interests. DPDP gives you consent plus a defined list of legitimate uses, and legitimate interests is not among them.

This is the change most likely to require actual work. Any processing of Indian users currently justified by legitimate interests needs to move to consent or fit a listed legitimate use, and the listed uses are narrow: data voluntarily provided for a specified purpose, employment purposes, medical emergencies, certain state functions and a few others.

Marketing and analytics are where this bites hardest, because those are the activities most commonly run on legitimate interests in Europe.

Consent and notice mechanics differ

DPDP consent must be free, specific, informed, unconditional and unambiguous, with clear affirmative action, which reads almost identically to GDPR. The notice requirements do not. The notice must be itemised and must be available in English and the languages listed in the Eighth Schedule of the Indian Constitution. If your consent flow supports one language, that is an engineering task rather than a policy update.

DPDP also creates the Consent Manager, a registered entity providing an interoperable platform through which people can grant, review and withdraw consent across organisations. Nothing in GDPR corresponds to it, and it may mean your consent records need to interoperate with a third party.

Transfers run on opposite logic

GDPR restricts transfers unless the destination has an adequacy decision or you put a transfer mechanism in place. It is a positive list: permitted destinations are named.

DPDP permits transfers to any country except those the government places on a restricted list. It is a negative list: prohibited destinations are named. In practice this is more permissive, and it means the elaborate transfer impact assessment machinery European teams have built is not the analysis DPDP asks for.

Do not simply reuse your GDPR transfer documentation and assume it satisfies DPDP. It answers a different question.

Rights, children, and enforcement

DPDP gives fewer rights. There is no data portability and no general right to object. There is access, correction, completion, erasure, grievance redressal and a nomination right allowing someone to appoint a person to exercise their rights on death or incapacity, which GDPR does not have.

On children DPDP is stricter. The threshold is 18 rather than 13 or 16, verifiable parental consent is required below it, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright rather than restricted. Any product with teenage Indian users should read this clause first.

Enforcement runs through the Data Protection Board of India, with penalties on the organisation and no individual compensation route of the kind GDPR provides. The headline maximum is 250 crore rupees per instance, which is roughly comparable in severity to GDPR's percentage-based caps for a mid-sized business.

The general lesson for multi-market compliance

This pattern repeats every time you enter a new jurisdiction. Security controls travel well, because ISO 27001, SOC 2 and the national baselines are describing broadly the same practices in different vocabularies. Privacy law does not travel, because it encodes each country's specific political choices about consent, rights, children and where data may sit.

Budget accordingly. The mistake is treating each market as a fresh programme, which is how compliance becomes ruinously expensive without making anyone safer. The work is a delta on the privacy side and evidence mapping on the security side.

Related services

Talk to an engineer

We respond to every enquiry within one business day, and return a scoped proposal with fixed pricing within 48 hours.

Book a discovery call