27 May 2026  ·  DPDPA & IT Compliance

GDPR vs DPDPA 2023 — Key Differences Every Business Must Know

Back to Blog

For organisations operating across both the European Union and India, understanding the differences between the GDPR and the DPDPA 2023 is essential to building a coherent, dual-jurisdiction compliance programme. While the two laws share common principles, they diverge significantly in their detail and practical application.

Territorial Scope

GDPR (EU)

Applies to processing of personal data of EU residents, regardless of where the processing organisation is located. Extraterritorial reach is a defining feature.

DPDPA 2023 (India)

Applies to processing of digital personal data within India, and to processing outside India where it involves offering goods or services to individuals in India.

Legal Bases for Processing

GDPR (EU)

Recognises six legal bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Legitimate interests is a widely used basis for commercial processing.

DPDPA 2023 (India)

Primarily relies on consent and "legitimate uses" (a defined category including employment, medical emergencies, and compliance with law). No equivalent to GDPR's legitimate interests basis for general commercial processing.

Data Subject / Principal Rights

GDPR (EU)

Comprehensive rights: access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making.

DPDPA 2023 (India)

Rights to access, correction, erasure, grievance redressal, and nomination. No explicit right to data portability or right to object to automated decision-making in the current text.

Data Protection Officer

GDPR (EU)

Required for public authorities, organisations engaged in large-scale systematic monitoring, or large-scale processing of special categories of data.

DPDPA 2023 (India)

Required only for Significant Data Fiduciaries as designated by the Central Government. Not a universal requirement.

Penalties

GDPR (EU)

Up to €20 million or 4% of global annual turnover, whichever is higher. Tiered penalty structure based on the nature of the violation.

DPDPA 2023 (India)

Up to ₹250 crore for failure to implement security safeguards. Penalties are fixed amounts per category of violation, not percentage-based.

Cross-Border Transfers

GDPR (EU)

Requires an adequacy decision, standard contractual clauses, binding corporate rules, or other approved transfer mechanisms for transfers outside the EEA.

DPDPA 2023 (India)

Permits transfers to all countries except those specifically restricted by Government notification. A more permissive default position than GDPR.

Children's Data

GDPR (EU)

Requires parental consent for processing data of children under 16 (or lower age set by member states, minimum 13). Prohibits profiling of children.

DPDPA 2023 (India)

Requires verifiable parental consent for processing data of children under 18. Prohibits tracking, behavioural monitoring, and targeted advertising directed at children.

Organisations subject to both the GDPR and the DPDPA should aim to build a unified compliance framework that satisfies the higher standard in each area, rather than maintaining separate programmes. Our advocates can assist in designing such a framework and advising on jurisdiction-specific requirements.

Consult Our Advocates

Advocacy A Law Firm  ·  DPDPA & IT Compliance

Advocacy A Law Firm

Your trusted advocates for corporate, civil, and compliance matters across India.

Legal Compliance

Udyam Registration

UDYAM-UP-09-0043193

GST No.

09CHFPK34641ZK

Office Hours

Mon – Sat  ·  10:00 AM – 6:00 PM IST

Data Privacy & Compliance Notice

Advocacy A Law Firm is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the Digital Personal Data Protection Act, 2023 (DPDPA) (India). Any personal information you provide through this website — including your name, email address, and contact details — is collected solely for the purpose of responding to your legal enquiries and will not be shared with third parties without your explicit consent. You have the right to access, rectify, or request deletion of your personal data at any time by contacting us at [email protected]. By submitting the contact form on this website, you consent to the processing of your personal data for the stated purpose.

Copyright © 2026 Advocacy A Law Firm — All Rights Reserved.