EnglishEspañol

India DPDP Act vs GDPR: What Is Actually In Force (2026)

Independently fact-checkedBy Recording Law Editorial Team22 min read

Independently fact-checked against primary sources (last audited July 23, 2026). · 5 primary sources cited on this page. How we verify our legal content

India DPDP Act vs GDPR: What Is Actually In Force (2026)

Frequently Asked Questions

Is India's DPDP Act in force yet?

Only partly. Stage 1 of its commencement took effect November 13, 2025, and covers the Data Protection Board's establishment and basic rule-making machinery, not the Act's substantive consent, children's-data, cross-border, or Significant Data Fiduciary provisions. Those are scheduled to commence in Stage 3 on May 13, 2027. As of today, the Data Protection Board is constituted but not staffed, and there has been no DPDP enforcement action.

What is the difference between DPDP's Section 7 'legitimate uses' and GDPR's legitimate interests?

GDPR's legitimate-interests basis (Article 6(1)(f)) is an open balancing test: an organization can process data without consent if it can show its interest outweighs the individual's rights, applied case by case. DPDP has no equivalent open-ended basis. Instead, Section 7 lists a closed set of specific situations, such as voluntary disclosure by the individual, certain government functions, legal compliance, medical emergencies, and limited employment purposes, where consent is not required. If a processing activity does not fit one of those enumerated categories, DPDP requires consent even where a GDPR-style legitimate-interests argument might otherwise apply.

What is a Consent Manager under India's DPDP Act?

A Consent Manager is a registered intermediary, unique to DPDP with no GDPR equivalent, through which a Data Principal can grant, review, and withdraw consent to multiple Data Fiduciaries from one interoperable dashboard. Consent Managers must incorporate as an Indian company, meet minimum capital and capacity requirements, and hold independent certification, and are barred from acting as a data fiduciary or processor for the same individual or monetizing consent flows. The Consent Manager Rules are not scheduled to become operative until around November 13, 2026.

Does DPDP give Indians a right to data portability like GDPR does?

No. DPDP does not include a general right to data portability, and also has no explicit right to object to processing. Both are established GDPR rights (Articles 20 and 21) that DPDP simply omits. DPDP's erasure right is narrower too: it is tied to whether the original processing purpose has been fulfilled, rather than functioning as a freestanding right to be forgotten independent of purpose completion.

How does DPDP handle cross-border data transfers compared to GDPR?

GDPR works as a whitelist: transfers outside the EEA are prohibited unless an approved mechanism applies, such as an adequacy decision, Standard Contractual Clauses, or Binding Corporate Rules. DPDP's Section 16 works the opposite way, as a negative list: transfers are permitted by default to any country except ones the Indian government affirmatively names as restricted. No country has been placed on that restricted list so far, and Section 16 itself is not yet in force, so DPDP currently imposes no cross-border transfer restriction in practice, separate from any sector-specific rules like RBI payments-data localization.

What are the maximum penalties under DPDP compared to GDPR?

GDPR's most severe penalty tier is up to EUR 20 million or 4% of an organization's global annual turnover, whichever is higher. DPDP uses a fixed-amount Schedule instead, with no turnover-percentage concept: the ceiling for the most serious violation, such as inadequate security safeguards resulting in a breach, is roughly 250 crore rupees. The Data Protection Board weighs seven statutory factors in setting the amount under Section 33(2), but the Schedule figures are hard ceilings it cannot exceed. Only the Central Government can raise them, by notification under Section 42(1), and no such notification may more than double an originally enacted amount. No DPDP penalty has actually been assessed against any organization to date, since the relevant Schedule provisions have not yet commenced.

Does India have a data breach notification deadline right now?

Yes, but not the one most people expect. India's Computer Emergency Response Team (CERT-In) already requires reporting of cybersecurity incidents within 6 hours under a direction in force since June 2022, unrelated to DPDP. DPDP's own breach-notification duty to the Data Protection Board, once in force, is expected to require an initial alert without delay and a detailed report within 72 hours, but that DPDP provision has not yet commenced. As of today, only CERT-In's 6-hour clock actually binds organizations in India on breach reporting.

What is the age threshold for children's data under DPDP versus GDPR?

DPDP sets a single, uniform age threshold of 18 and requires verifiable parental or guardian consent for processing any minor's data under that age, with no tiering by age band. GDPR's Article 8 baseline is 16, but individual EU member states may lower it to as low as 13, so the effective age varies by country. DPDP's children's-data provisions, like most of the Act's substance, are scheduled to commence in Stage 3 on May 13, 2027 and are not yet legally binding.

Updates

Independently fact-checked against the cited primary sources

Article published. Next scheduled milestone: Stage 2 of commencement is expected around November 13, 2026, with the bulk of the Act's substantive obligations (consent, Significant Data Fiduciary duties, children's data, cross-border transfer rules, most data-principal rights) not commencing until May 13, 2027.

A corrigendum to the Digital Personal Data Protection Rules, 2025 (G.S.R. 892(E)) was issued by the Ministry of Electronics and Information Technology (MeitY) on December 10, 2025 and gazetted on December 11, 2025.

Stage 1 of the DPDPA's staged commencement took effect (Gazette of India, Extraordinary, Part II-Section 3(i), No. 757): the Data Protection Board of India was formally constituted and the Act's/Rules' skeletal machinery went live. The substantive consent, notice, children's-data, and cross-border provisions remain dormant.

Sources and References

  1. MeitY: Digital Personal Data Protection Rules, 2025 and commencement notifications (Gazette No. 757, Nov 13, 2025)(meity.gov.in).gov
  2. Regulation (EU) 2016/679 (GDPR) Full Text(eur-lex.europa.eu).gov
  3. CERT-In Directions No. 20(3)/2022-CERT-In under Section 70B of the IT Act, 2000 (28 April 2022), 6-hour reporting and Annexure I list of 20 reportable incident types(cert-in.org.in).gov
  4. Mondaq: India's Data Protection Board, The Enforcer That Isn't There Yet(mondaq.com)
  5. Internet Freedom Foundation: Statement on the DPDP Rules 2025 notification(internetfreedom.in)
  6. Medianama: Consent Manager rules under the DPDP Rules 2025(medianama.com)
  7. Bar & Bench: TDSAT as the DPDP appellate forum(barandbench.com)
  8. SIRI Law LLP: Guide to India's CERT-In 6-hour cyber incident reporting mandate(sirilawllp.com)
  9. Baker McKenzie: Global Data and Cyber Handbook, Asia Pacific breach notification summaries(resourcehub.bakermckenzie.com)
  10. MeitY circular F. No. 2(1)/2026-Pers.I, 6 May 2026, inviting applications for Chairperson (1 post) and Members (4 posts) of the Data Protection Board of India(meity.gov.in).gov
  11. Gazette of India, Extraordinary, Part II-Section 3(i), No. 757, G.S.R. 843(E), 13 November 2025, staged commencement of the DPDP Act(meity.gov.in).gov
Share: