DPDP Act vs GDPR: Five Structural Differences That Change How You Comply
The DPDP Act borrows GDPR's vocabulary but not its architecture. Five structural differences mean a GDPR-compliant program is a starting point, not a finish line.
Two lawful bases, not six
GDPR gives controllers six lawful bases for processing, including the flexible and heavily used legitimate interest ground. The DPDP Act narrows this considerably: processing is lawful only on the basis of consent, or on one of a closed list of legitimate uses set out in Section 7, covering situations such as voluntary provision of data by the individual for a specified purpose, employment-related processing, medical emergencies, and certain state functions.
This matters in practice because organisations that lean on legitimate interest under GDPR to justify marketing analytics, fraud detection, or internal research often find no equivalent open-ended ground under the DPDP Act. Where the specific legitimate use does not fit, consent becomes the only route, which pushes far more processing activity in India through consent notices and consent-withdrawal mechanics than a comparable European program would need.
No sensitive data tier
GDPR's Article 9 creates a separate, more restrictive category for special category data, health, biometric, sexual orientation, religious belief, and similar, that requires an additional lawful condition on top of the general one. The DPDP Act does not create an equivalent tier. All personal data is treated under the same general obligations, with only children's data (Section 9) and, to a more limited extent, a Significant Data Fiduciary designation (Section 10) triggering heightened duties.
This is a genuine simplification in one sense, there is no separate special-category test to run, but it also means organisations cannot rely on the Act itself to flag which datasets deserve extra internal scrutiny. Many compliance teams choose to keep an internal sensitive-data classification for risk-management reasons even though the statute does not compel it.
A restricted-country blacklist instead of an adequacy allowlist
GDPR's cross-border transfer regime works as an allowlist: transfers outside the EEA are restricted by default and permitted only to countries the European Commission has found adequate, or under specific safeguards like standard contractual clauses. Section 16 of the DPDP Act inverts this logic. Transfers are permitted by default to any country, except those the central government notifies as restricted.
At the time of writing, no such restricted-country list had been notified, which means the practical transfer regime is more permissive than GDPR's on its face. Organisations should not treat this as a stable position, though, since a notified list could appear at any point and would immediately narrow the default permission for the countries named.
An adjudicatory Board, not a rule-making supervisory authority
GDPR's supervisory authorities, like Ireland's DPC or Germany's state-level regulators, issue binding guidance, conduct own-motion investigations broadly, and in some cases have independent rule-making input. The Data Protection Board of India, established under Section 18, is structured more narrowly as an adjudicatory body: it processes breach references and complaints, imposes penalties, and can direct remedial measures, but the detailed rule-making power sits with the central government (MeitY) rather than the Board itself.
For compliance teams this means the DPDP Board is less likely to become a source of proactive interpretive guidance the way European DPAs publish opinions and guidelines. Most of the interpretive detail is expected to come from the Rules and from government notifications rather than Board pronouncements, at least in the Act's current form.
Fixed penalty ceilings instead of turnover percentages
GDPR fines scale with global annual turnover, up to 4% for the most serious violations, which can produce enormous absolute numbers for large multinationals. The DPDP Act instead sets fixed rupee ceilings by category of failure, reported publicly in the range of up to roughly 250 crore for security safeguard failures and lower ceilings for other categories, regardless of the fiduciary's revenue.
The practical effect cuts both ways. For very large global companies, the DPDP ceilings will typically be far smaller in absolute terms than a turnover-linked GDPR fine would be. For smaller Indian entities, however, a fixed ceiling in the tens of crores can be proportionally much more severe than a GDPR fine calculated off a modest turnover base.
Where to go next
If your organisation already runs a GDPR program, the fastest way to find the gaps is to run it through the Applicability Checker and compare the lawful-basis and cross-border sections against what you have documented for Europe. The /act page also lays out Sections 7, 16, and 18 in full for direct reference.