India's DPDP Act: What It Means If You Have Indian Customers
India passed the Digital Personal Data Protection Act in 2023, and it reaches well beyond Indian borders. If you offer goods or services to people in India, it applies to you whether or not you have an office, a subsidiary or a single employee there. Most organisations discover this during a procurement questionnaire rather than from a regulator, which is the expensive way to find out. This is what the Act requires, where it diverges from GDPR in ways that will catch you out, and what genuinely transfers if you already run a GDPR programme.
Who it applies to, which is probably you
The Act covers digital personal data processed within India, and processing outside India where it is connected with offering goods or services to people in India. That second limb is the one that matters for a UK, EU or US business. There is no establishment test and no local presence requirement. If Indian users can sign up to your product, you are in scope.
It only covers digital personal data. Paper records that are never digitised sit outside it, which is a narrower scope than GDPR. There is also no separate category of sensitive personal data, so health, biometric and financial data carry the same baseline obligations as anything else. That sounds permissive until you notice the penalties.
The vocabulary differs from GDPR and it is worth learning, because Indian counterparties will use it. The individual is a Data Principal, not a data subject. The organisation deciding how and why data is processed is a Data Fiduciary, not a controller. The word fiduciary is doing real work: the framing is that you hold data on someone else's behalf, and Indian commentary leans on that duty of care more heavily than European commentary leans on accountability.
Consent, and the Consent Manager nobody outside India has heard of
DPDP is consent-first to a degree GDPR is not. Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and it must be accompanied or preceded by an itemised notice. That notice has to be available in English and in the languages listed in the Eighth Schedule of the Indian Constitution, which is a genuine engineering task if your consent flow was built for one language.
Where GDPR gives you six lawful bases, DPDP gives you consent plus a defined set of legitimate uses: data voluntarily provided for a stated purpose, employment purposes, medical emergencies, certain state functions, and a short list of others. There is no legitimate interests basis of the kind European marketers rely on. If your lawful basis for processing Indian users is legitimate interests, you do not have one under DPDP.
The Act also creates the Consent Manager, an entity registered with the Data Protection Board that gives Data Principals a single interoperable place to grant, review and withdraw consent across the organisations they deal with. Nothing in GDPR corresponds to it. It is a structural bet that consent should be portable and centrally manageable rather than scattered across a thousand cookie banners, and it means your consent records may need to interoperate with a third party you did not choose.
Where it diverges from GDPR, and why that catches people out
The most consequential difference is cross-border transfer. GDPR works on a positive list: transfers are restricted unless the destination has adequacy or you put a mechanism in place. DPDP works the other way round. Transfers are permitted to any country except those the government places on a restricted list. That is more permissive in principle, but it is also less predictable, because a country can be added to a blacklist in a way that adequacy decisions are not typically withdrawn overnight.
Several GDPR rights simply do not appear. There is no right to data portability and no general right to object to processing. Data Principals get access, correction, completion, erasure, grievance redressal and nomination, that last one letting someone nominate a person to exercise their rights if they die or become incapacitated, which has no GDPR equivalent.
There is also no route for an individual to claim compensation. Enforcement runs through the Data Protection Board of India, and the penalties are levied on the Data Fiduciary rather than paid to the affected people. The headline figure is up to 250 crore rupees per instance, roughly 23 million pounds, with a specific penalty for failing to prevent a breach and another for breaching children's data obligations.
On children, DPDP is stricter than GDPR in one specific way. The threshold is 18, not 13 or 16, and verifiable parental consent is required below it. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright rather than merely restricted. If your product has any teenage users in India, this is the clause to read first.
Significant Data Fiduciaries, and whether you might become one
The government can designate an organisation a Significant Data Fiduciary based on the volume and sensitivity of data it processes, risk to Data Principals, risk to electoral democracy, security of the state and public order. The designation is not something you opt into or self-assess: it is applied to you.
The additional obligations are substantial. You must appoint a Data Protection Officer based in India who reports to the board or equivalent governing body. You must appoint an independent data auditor. You must carry out periodic Data Protection Impact Assessments and periodic audits. For a company with no Indian entity, the India-based DPO requirement alone can force a structural decision about local presence.
The practical planning point is that designation criteria are discretionary and volume-linked. If your Indian user base is growing quickly, treat SDF designation as a foreseeable event rather than a remote one, and know in advance what it would cost you.
What transfers if you already comply with GDPR
A functioning GDPR programme gets you a long way, and it is worth being precise about which parts. Your record of processing activities, your data inventory, your access and erasure workflows, your processor contracts, your breach detection and your security controls all carry over in substance. The machinery of knowing what data you hold, where it is and who touches it is the expensive part, and you have already built it.
What does not carry over is the lawful basis analysis, the notice content and languages, the consent capture and withdrawal mechanics, breach notification to a different regulator on different timelines, and the transfer analysis, which runs on opposite logic. If you have mapped GDPR to your controls, the honest estimate is that DPDP is a delta rather than a rebuild, concentrated almost entirely on the privacy side rather than the security side.
That pattern holds generally when expanding into new jurisdictions. Security controls travel well, because ISO 27001, SOC 2 and the various national baselines are all describing broadly the same practices. Privacy law does not travel, because it encodes each country's specific choices about consent, rights and where data may sit. Budgeting as though the whole programme must be rebuilt for every market is how compliance becomes ruinously expensive for no additional protection.
What to do now
Start by establishing whether you actually have Indian Data Principals, which is a question about your user base rather than your sales strategy. Many organisations find they already do, through self-serve signups nobody targeted deliberately.
Then check your lawful basis. If you rely on legitimate interests for anything involving those users, that basis does not exist under DPDP and you need consent or a listed legitimate use instead. Review your notice next: itemised, in English plus the scheduled languages, presented at or before the point of consent.
Look at your breach process and confirm it can notify a second regulator on a different timetable without redesigning the whole procedure. Then model whether growth would plausibly make you a Significant Data Fiduciary, because the India-based DPO obligation has a lead time you cannot compress.
One caveat worth stating plainly: the Act passed in 2023 and the subordinate rules have been working through consultation and phased implementation since. Specific timelines and procedural detail have moved and may move again, so verify the current position on anything date-sensitive rather than relying on a guide, including this one.
Related services
Talk to an engineer
We respond to every enquiry within one business day, and return a scoped proposal with fixed pricing within 48 hours.
Book a discovery call