DPDP vs GDPR: What Actually Differs for Indian Companies
If you are GDPR compliant you have most of the substrate and none of the specifics. Mapping one onto the other without rereading the Rules is where the gaps open.
What carries over
The foundations transfer well: a data inventory, discipline about purpose and basis, rights handling processes, vendor management and breach procedures. If you have these, most of the hard organisational work is done.
What does not
- Breach reporting shape. GDPR has a single seventy-two hour notification to the supervisory authority. Rule 7 has three obligations: intimation to affected Data Principals without delay, an initial intimation to the Board without delay, and detailed information to the Board within seventy-two hours.
- Security specificity. GDPR Article 32 is principle-based. Rule 6 is a list, and includes a one year retention of logs and personal data that has no GDPR equivalent.
- Designation, not self-assessment. A Significant Data Fiduciary is notified by the Central Government under section 10. You do not assess yourself into the category as you might under GDPR's risk-based provisions.
- Age of a child. Rule 10(2)(a) sets adulthood at eighteen. GDPR allows member states to set the digital consent age between thirteen and sixteen. A consent design built for Europe is wrong here.
- No sensitive data category. DPDP does not replicate special category data. Health and biometric data are personal data.
- Children's advertising. Section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children outright, with no consent route.
Where DPDP is lighter
Rule 15 is more permissive on international transfer than the GDPR adequacy and safeguards regime. There is no general requirement for a data protection officer for ordinary Data Fiduciaries. And there is no equivalent of the GDPR's detailed record-keeping article, although Rules 7, 8 and 14 make a record necessary in practice.
Treat GDPR as the reason your foundations exist, then read the Indian Rules as though you had no prior view. The overlap is real, and it is not the part that will catch you out.
Infosek Team
A practical mapping exercise
- Re-run your breach runbook against Rule 7 specifically, focusing on what happens in the first hour.
- Assess your controls against the Rule 6 list rather than against Article 32, and check log retention.
- Reset your children's threshold to eighteen and re-examine any advertising to that segment.
- Check whether Rule 13(4) localisation could apply if you were notified as a Significant Data Fiduciary.
Common questions
Is DPDP the same as GDPR?
No. They share concepts such as consent, purpose limitation and rights, but differ materially on breach reporting timelines, the specificity of security requirements, how large entities are designated, the age of a child, and the absence of a sensitive personal data category in DPDP.
Does GDPR compliance mean DPDP compliance?
No. It provides a strong foundation, particularly a data inventory and rights processes, but DPDP has its own requirements including the two-stage breach intimation in Rule 7, the minimum control list in Rule 6 with one year log retention, and verifiable parental consent for anyone under eighteen.
Adapting a GDPR programme for India?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment