Bridging the Privacy Gap: A Comparative Analysis of India’s DPDP Act and the EU GDPR

May 27, 2026


Data protection has evolved from a regulatory niche into a central strategic imperative for organisations operating across jurisdictions. While the European Union’s General Data Protection Regulation (GDPR) has anchored global privacy standards since 2018, India’s Digital Personal Data Protection Act, 2023 (DPDP Act) introduces a distinct framework calibrated for a digital-first economy. For any multinational with exposure to both regimes, understanding the structural divergences is not optional — it is operationally essential.

1. Scope and Jurisdiction: Digital vs. Comprehensive

The two laws diverge fundamentally in material scope. The GDPR governs both digital and manual records, whereas the DPDP Act is confined strictly to digital personal data. On jurisdiction, the GDPR applies to any entity that targets or monitors EU residents, irrespective of geographic base. The DPDP Act, by contrast, captures non-Indian entities only where they offer goods or services to individuals within India — entities that solely monitor behaviour without a commercial offering fall outside its ambit.

2. Legal Bases: The Consent-Centric Shift

The GDPR affords organisations six distinct grounds for lawful processing — including legitimate interest and contractual necessity — conferring considerable operational flexibility. India’s framework adopts a markedly narrower approach. Processing is permissible primarily through affirmative consent or via narrowly prescribed “certain legitimate uses,” such as medical emergencies, state functions, or employment-related purposes. Standalone reliance on legitimate interest, as commonly deployed under the GDPR, has no equivalent recognition under the DPDP Act.

3. Individual Rights and Shared Responsibilities

The GDPR’s rights architecture is extensive, encompassing data portability and protections against automated decision-making — rights not explicitly provided within the DPDP Act. India’s framework instead introduces two distinctive provisions. First, the Right to Nominate enables an individual to designate a representative to exercise privacy rights in the event of death or incapacity. Second, and uniquely, the DPDP Act imposes statutory duties on individuals themselves (Data Principals), with penalties prescribed for the submission of false information or frivolous complaints.

4. Indian Innovations: Consent Managers and Age Verification

A structural innovation under Indian law is the creation of Consent Managers — registered intermediaries that serve as a single interface through which individuals can grant, manage, review, and withdraw consent. On children’s data, India maintains a more stringent threshold than the GDPR’s baseline: verifiable parental consent is mandated for all individuals under 18, with no provision for member-state discretion to lower this age, as permitted in the EU.

5. Enforcement and Financial Exposure

The penalty regimes reflect fundamentally different design philosophies. GDPR fines are risk-scaled, reaching up to 4% of an organisation’s annual global turnover. DPDP penalties are turnover-agnostic, capped at ₹250 crore (approximately €28 million) per violation. While the absolute ceiling may appear lower for large corporates, the absence of a turnover-linked floor makes the Indian regime structurally different — and the reputational consequences of a breach notification obligation remain material across both frameworks.

Conclusion

For GDPR-compliant organisations, existing governance infrastructure provides a meaningful baseline, but targeted re-engineering is required — particularly on age-gating, language localisation across 22 Indian languages, and legal-basis mapping. As the EU and India continue discussions on partial adequacy through the Trade and Technology Council, achieving interoperability between these two models will define the next frontier of data governance strategy.