India DPDP Act vs GDPR: What Is Actually In Force (2026)

The single most important fact about India's Digital Personal Data Protection Act, 2023 (DPDPA) is one most comparison guides get wrong: as of today, most of it is not yet law. The Act received presidential assent in August 2023 and then sat un-commenced for more than two years. Commencement finally began on a staged, multi-year schedule set out in a gazette notification dated November 13, 2025, and the substantive rules that would actually make DPDP comparable to the GDPR on consent, children's data, cross-border transfers, and Significant Data Fiduciary duties do not take effect until May 13, 2027.
Jurisdiction scope: This article compares the EU's General Data Protection Regulation (GDPR) with India's Digital Personal Data Protection Act, 2023 (DPDPA) and its Digital Personal Data Protection Rules, 2025, including the staged commencement schedule notified November 13, 2025. It does not cover India's other technology statutes (the Information Technology Act, 2000 and its rules) except where CERT-In's separate cyber-incident reporting duty intersects directly with breach notification. For the full India privacy picture, see our India data privacy laws guide.
What Is Actually In Force Today
This is the section to read before any other, because it changes how every comparison below should be understood. Unlike the GDPR, which became enforceable everywhere in the EEA on a single date (May 25, 2018), the DPDPA commences in stages, and most of its substance is still ahead of it.
| Stage | Date | What actually goes live |
|---|---|---|
| Stage 1 | November 13, 2025 | The Data Protection Board's establishment, composition, and procedural powers; the Central Government's general rule-making authority; and a small set of definitional and procedural provisions. Of the DPDP Rules, 2025, only the short-title/definitions rule and the Board's own operating rules are in force. |
| Stage 2 | November 13, 2026 | The Consent Manager regime specifically: Section 6(9) (the right to give, manage, review and withdraw consent through a Consent Manager) and Section 27(1)(d) of the Act, plus Rule 4 (registration and obligations of Consent Managers). |
| Stage 3 | May 13, 2027 | The bulk of the Act: consent and notice duties, the closed list of legitimate uses, children's-data protections, data-principal rights (access, correction, erasure), Significant Data Fiduciary obligations, cross-border transfer rules, and the corresponding DPDP Rules covering breach notification (Rule 7), SDF audits (Rule 13), notice, security safeguards, children's data, rights, and transfers (Rules 3, 5-16, 22, 23). |
The practical upshot: as of this writing, an organization handling personal data in India is not yet legally bound by DPDP's consent rules, its children's-data protections, its cross-border transfer regime, or its breach-notification duty to the Data Protection Board. Only the Board's existence and its internal machinery are currently in force. Any article, vendor pitch, or compliance checklist that describes DPDP's substantive obligations as "in effect now" is describing the law as it will exist in 2027, not as it exists today.
Making this worse for enforcement in the near term: the Data Protection Board has been formally constituted as an entity, but it has not yet been staffed. Its Chairperson and Members had not assumed office as of mid-2026, and the Search-cum-Selection Committee responsible for appointing them has faced delays. Some Indian courts have reportedly directed complainants toward a Board that cannot yet act on their complaints. There has been no DPDP enforcement action, fine, or published order to date, which is consistent with a law that is still substantially prospective rather than operative.

Background and Legislative Context
The DPDPA received presidential assent in August 2023 after a long drafting history that included an earlier, withdrawn 2019 bill. Unlike most comparable privacy statutes, it did not take effect on assent. Section 1(2) of the Act left commencement to a future government notification, and no such notification appeared for more than two years.
That notification finally came via the Gazette of India, Extraordinary, Part II-Section 3(i), No. 757, dated November 13, 2025, alongside the Digital Personal Data Protection Rules, 2025 and a companion "Enforcement Timeline for the DPDP Act" document, both published by the Ministry of Electronics and Information Technology (MeitY). A corrigendum to the Rules, G.S.R. 892(E), was issued on December 10, 2025 and gazetted on December 11, 2025.
The GDPR, by contrast, was adopted in 2016 with a fixed two-year transition period and became directly applicable across the EEA on a single date: May 25, 2018. There was no staged rollout and no skeleton-first phase. That structural difference, a hard cutover versus a multi-year phase-in, is the backdrop for every comparison point below.

Scope
The DPDPA governs digital personal data, a narrower frame than the GDPR's broader "personal data" concept. Full detail on what falls inside and outside DPDP's scope, including its treatment of offline data digitized after collection, is covered in our India data privacy laws guide.
The GDPR applies to personal data processing carried out by organizations established in the EEA and, extraterritorially, to organizations outside the EEA that offer goods or services to individuals in the EEA or monitor their behavior (Article 3). It also reaches non-automated processing that forms part of a structured filing system, not only digital records.

At a Glance
| Feature | GDPR | India DPDPA |
|---|---|---|
| Substantive rules currently in force | Yes, fully, since May 25, 2018 | No. Only the Data Protection Board's skeleton machinery (Stage 1, Nov 13, 2025). Substantive rules commence May 13, 2027. |
| Commencement model | Single date, all provisions at once | Staged: three commencement dates over roughly 18 months |
| Enforcement to date | Billions of euros in fines since 2018 | None. The Board is constituted but not staffed. |
| Lawful bases | Six, including a general "legitimate interests" balancing test | A closed list of specific "certain legitimate uses" (Section 7); no general legitimate-interests basis |
| Consent intermediary institution | None (unregulated consent-management platforms) | Consent Managers: registered, capital-backed, independently certified intermediaries |
| Children's age threshold | 16, with member states free to lower to 13 | 18, with no age-band tiering |
| Right to data portability | Yes (Article 20) | No general right |
| Right to object to processing | Yes (Article 21) | No general right |
| Right to erasure | Broad "right to be forgotten" (Article 17) | Narrower: purpose-bound correction and erasure |
| Cross-border transfer model | Whitelist-by-mechanism: adequacy, SCCs, BCRs, other safeguards | Blacklist: transfer permitted by default except to government-notified restricted countries (none notified so far) |
| High-risk processor tier | Self-assessed "large scale processing" (Article 35) | Government-designated "Significant Data Fiduciary" status |
| Maximum penalty | EUR 20 million or 4% of global annual turnover | Roughly 250 crore rupees per contravention (fixed schedule, not turnover-based) |
| Breach notification (data-protection-specific) | 72 hours to the supervisory authority | Not yet in force; scheduled with the rest of Stage 3 |
| Separate, currently-live cyber-incident clock | Not applicable | CERT-In: 6 hours, already in force, unrelated to DPDP |

Definitions: Data Principal and Data Fiduciary vs Data Subject and Controller
DPDP uses its own vocabulary rather than borrowing GDPR's terms directly.
| Term | GDPR | India DPDPA |
|---|---|---|
| Protected individual | Data subject | Data Principal |
| Data collector / decision-maker | Controller | Data Fiduciary |
| High-risk processor tier | Self-assessed large-scale processor (Art. 35) | Significant Data Fiduciary (SDF), a status the government formally designates |
| Consent intermediary | No equivalent | Consent Manager (a registered, licensed role) |
| Privacy regulator | National DPAs + EDPB | Data Protection Board of India (DPBI) |
The Significant Data Fiduciary designation is a meaningful structural departure from GDPR's approach. Under GDPR Article 35, an organization itself assesses whether its processing is "large scale" and triggers a data protection impact assessment obligation accordingly. Under DPDP, SDF status is not self-assessed: the Central Government designates specific fiduciaries or classes of fiduciaries as Significant Data Fiduciaries, reportedly weighing factors like the volume and sensitivity of data processed and risk to sovereignty, electoral democracy, state security, or public order. Once designated, an SDF carries obligations on top of every fiduciary's baseline duties, including an India-resident Data Protection Officer who is responsible to the fiduciary's board of directors or similar governing body and serves as the point of contact for the Act's grievance redressal mechanism, the complaint route a Data Principal must exhaust before approaching the Data Protection Board (GDPR's DPO carries no residency requirement), an independent data auditor, and a periodic data protection impact assessment and audit. For the DPO comparison in full, including how it interacts with GDPR's own DPO rules, see our Data Protection Officer requirements guide.
Legal Bases: No Legitimate Interests, a Closed List Instead
The GDPR gives organizations six lawful bases for processing under Article 6: consent, contract performance, legal obligation, vital interests, public task, and legitimate interests. Legitimate interests, a flexible balancing test weighing the organization's interest against the individual's rights, is the basis most commonly relied on for direct marketing, fraud prevention, network security, and analytics.
DPDP has no legitimate-interests basis at all. In its place, Section 7 sets out a closed, enumerated list of what the Act calls "certain legitimate uses," where a Data Fiduciary may process personal data without obtaining consent. In full, the nine clauses are:
- Voluntary disclosure of data by the Data Principal for a specified purpose (the broadest and most commonly cited of the nine, generally regarded as the clause most likely to see litigation over its outer limits)
- Specified State functions, such as issuing subsidies, benefits, licenses, or certificates
- State functions performed under any law in force in India, or in the interest of the sovereignty and integrity of India or the security of the State (Section 7(c)), a broad clause with no GDPR analogue, since GDPR's public-task basis is still subject to the full balancing and rights framework
- Compliance with a statutory duty to disclose information to the State or its instrumentalities (Section 7(d))
- Compliance with law or a court order
- Responding to a medical emergency
- Public health or disaster response
- Certain employment-related purposes, including protecting the employer from loss or protecting intellectual property and trade secrets, or providing benefits sought by an employee
Because this list is closed rather than an open balancing test, a Data Fiduciary cannot invent a new "legitimate use" the way an EU controller can construct a legitimate-interests argument. Anything that does not fit one of Section 7's enumerated categories requires consent under DPDP, even where a GDPR controller might rely on legitimate interests instead.
Consent and Consent Managers
Both frameworks require consent to be freely given, specific, and capable of being withdrawn as easily as it was given. Where DPDP departs from GDPR is with Consent Managers, an institution with no GDPR equivalent.
A Consent Manager is a registered intermediary through which a Data Principal can grant, review, and withdraw consent to multiple Data Fiduciaries from a single interoperable dashboard, rather than negotiating consent separately with every organization that touches their data. Under the DPDP Rules, Consent Managers must incorporate as an Indian company, meet minimum capital and operational-capacity requirements, and obtain independent certification of their consent-management platform. Structurally, a Consent Manager is barred from acting simultaneously as a data fiduciary or processor for the same Data Principal, so it cannot both broker consent and profit from the data it is managing, and it cannot monetize consent flows or discriminate among the fiduciaries whose consent requests it routes; it must operate on a transparent, fee-based model instead.
GDPR has nothing structurally comparable. Consent-management platforms exist across the EU, but they are unregulated commercial tools, not a licensed, government-certified role built into the statute itself. The Consent Manager rules under the DPDP Rules, 2025 are not scheduled to become operative until around November 13, 2026, so as of today no Consent Manager framework is functioning in practice either.
Children's Data and Age-Gating
DPDP sets a single, bright-line age threshold: 18. Section 9 requires verifiable consent from a parent or lawful guardian for processing any personal data of a Data Principal under 18, with "verifiable" as the express statutory standard rather than an implied one. There is no tiering by age band.
GDPR's threshold is lower and more fragmented. Article 8 sets the baseline age for a child's own consent to information-society services at 16, but individual EU member states may lower that threshold to as low as 13, producing a patchwork across the bloc rather than one uniform number.
The DPDP Rules and the Act's Fourth Schedule carve out conditional, purpose-specific exemptions from the parental-consent requirement, for example limited processing in educational, healthcare, or child-welfare contexts, rather than GDPR's broader "information society services" framing. Because Section 9 sits within the Stage 3 group of provisions, this obligation, like the rest of DPDP's substantive consent architecture, is not yet legally binding.
Data Principal Rights: What DPDP Grants, and What It Leaves Out
DPDP grants a narrower set of individual rights than GDPR does, and two GDPR staples are simply absent.
| Right | GDPR | India DPDPA |
|---|---|---|
| Access | Yes (Article 15) | Yes |
| Correction | Yes (Article 16) | Yes, bundled with erasure under Section 12 |
| Erasure | Broad "right to be forgotten" (Article 17), independent of purpose completion | Narrower: erasure applies once the stated processing purpose is no longer being served and no legal retention duty applies. It is purpose-bound rather than a freestanding right |
| Data portability | Yes (Article 20) | No general right |
| Right to object | Yes (Article 21) | No general right |
| Automated-decision safeguards | Yes (Article 22) | Not established as a standalone right under the Act's core structure |
| Grievance redress | Complaint to a supervisory authority | Complaint to the Data Fiduciary first, then the Data Protection Board |
The absence of portability and objection rights is one of the clearest substantive gaps between the two regimes. Under GDPR, an individual can demand their data in a portable format for transfer to a competitor service, and can object to processing carried out on a public-task or legitimate-interests basis. DPDP offers neither mechanism. Combined with the narrower, purpose-bound erasure right, DPDP's rights architecture gives Data Principals meaningfully less leverage over their own data than GDPR gives EU data subjects, at least on paper. Since Section 12 and the surrounding rights provisions sit in the Stage 3 group, none of this is enforceable yet in practice either.
The Data Protection Board of India
The Data Protection Board of India (DPBI) is DPDP's central enforcement body, and its status right now illustrates the gap between "on the books" and "operating." The Board was formally constituted as an entity on November 13, 2025, alongside notifications establishing it and fixing the number of its members. Its own operating rules, among the very few DPDP Rules currently in force, went live the same day.
What has not happened is staffing. As of mid-2026, the Board's Chairperson and Members had not been appointed and had not assumed office; the Search-cum-Selection Committees responsible for those appointments, one chaired by the Cabinet Secretary for the Chairperson and a separate one chaired by MeitY's Secretary for the other Members (Rule 17), have faced delays. Some Indian courts have reportedly pointed complainants toward the Board even though it cannot yet adjudicate anything. There is no reported DPDP enforcement action, fine, or published Board order to date.
When the Board does become operational and begins issuing orders, appeals will not go to a dedicated privacy court. DPDP routes appeals from Board orders to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), an existing tribunal originally built for telecom disputes, within 60 days of the order, with the tribunal required to dispose of the appeal within six months and a further appeal to the Supreme Court available only on questions of law. Commentators have flagged TDSAT's telecom pedigree as an odd institutional fit for privacy adjudication, a genuinely distinctive structural choice with no GDPR parallel, since GDPR complaints and appeals run through each member state's own courts and the EDPB's cross-border consistency mechanism rather than a repurposed sector tribunal.
Cross-Border Data Transfers: A Negative List, Not a Whitelist
This is one of the sharpest structural differences between the two laws. GDPR Chapter V works as a whitelist of approved mechanisms: a transfer out of the EEA is prohibited unless it fits an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or another approved safeguard.
DPDP's Section 16 inverts that logic into a negative list: transfer of personal data outside India is permitted by default to any country or territory, except those the Central Government affirmatively names as restricted. As of this writing, the government has not notified any country as restricted, which means DPDP itself currently imposes no cross-border transfer restriction in practice. There is no adequacy-assessment requirement, no SCC-equivalent contractual mechanism, and no transfer-impact-assessment obligation built into DPDP's own text. DPDP does, however, carry a targeted localization power of its own. Rule 13(4) lets the Central Government specify categories of personal data that a Significant Data Fiduciary must keep, along with the traffic data describing its flow, inside India, and Rule 15 conditions any transfer abroad on requirements the government may set for making that data available to a foreign State. Neither takes effect before Stage 3, and no such specification has been issued.
This does not mean data can move freely out of India without any constraint at all. Sector-specific rules sit outside DPDP entirely, most notably Reserve Bank of India data-localization requirements for payments data, and those obligations are untouched by anything discussed here. For a country-by-country view of where localization duties like that apply, see our data localization laws by country guide.
The practical reading for now: DPDP's cross-border regime is, at least until a restricted-country list is actually published, considerably lighter-touch than GDPR's. That is also a moving target. A future government notification could add restricted countries at any time, and Section 16 itself does not commence until Stage 3 in any case, so today's "no restrictions" reading is both provisional on the statute taking effect and on the government's own future notifications.
Penalties: A Fixed Schedule, Not a Percentage of Turnover
GDPR's penalty structure scales with the size of the offending organization: up to EUR 20 million or 4% of global annual turnover, whichever is higher, for the most serious violations (Article 83(5)).
DPDP takes a different design entirely. Penalties are fixed rupee amounts tied to the specific type of violation, set out in a Schedule under Section 33, with no revenue-percentage concept anywhere in the Act. The headline ceiling, confirmed consistently across independent legal reporting, is roughly 250 crore rupees (in the neighborhood of USD 28-30 million) for the most serious category of violation, such as a failure to implement reasonable security safeguards that results in a data breach. The Data Protection Board can weigh seven statutory factors when setting the amount, including the nature, gravity and duration of the breach, the type of personal data affected, whether the breach was repeated, whether the person gained or avoided a loss, how promptly and effectively it was mitigated, proportionality and deterrence, and the likely impact of the penalty on the person penalised (Section 33(2)). The Schedule amounts are ceilings, and the Board has no power to exceed them. A separate provision, Section 42(1), lets the Central Government amend the Schedule by notification, but caps any increase at twice the amount originally enacted.
The Schedule has only seven line items, and the ceilings track the seriousness of the violation rather than the size of the violator:
| # | Breach | Ceiling |
|---|---|---|
| 1 | Failure of Section 8(5) reasonable security safeguards | 250 crore rupees |
| 2 | Failure to notify the Board or affected Data Principal of a breach (Section 8(6)) | 200 crore rupees |
| 3 | Breach of additional children's-data obligations (Section 9) | 200 crore rupees |
| 4 | Breach of additional Significant Data Fiduciary obligations (Section 10) | 150 crore rupees |
| 5 | Breach of a Data Principal's duties (Section 15) | 10,000 rupees |
| 6 | Breach of a voluntary undertaking (Section 32) | Up to the amount for the underlying breach |
| 7 | Any other provision of the Act or Rules | 50 crore rupees |
The CERT-In Overlay: A Live Clock That Has Nothing to Do With DPDP
This is the point practitioners most often get backwards, and it is worth stating plainly: India already has a mandatory, currently-enforceable breach reporting deadline, and it is not DPDP's.
The Indian Computer Emergency Response Team (CERT-In), operating under Section 70B of the Information Technology Act, requires reporting of cybersecurity incidents within 6 hours of an organization noting or being notified of the incident. This direction, in force since June 2022, applies broadly to service providers, intermediaries, data centers, body corporates, and government organizations, with no size threshold, and covers 20 listed categories of cyber incident, of which a data breach is only one.
DPDP's own breach-notification duty is different in design and, critically, not yet operative. Once DPDP Rule 7 commences, it will require an initial alert to the Data Protection Board "without delay," followed by a detailed report within 72 hours or longer if the Board permits, with no minimum-size threshold, meaning every personal data breach would need to be reported regardless of scale. But Rule 7 sits inside the group of Rules delayed to roughly May 2027 alongside the rest of DPDP's substantive machinery. It is not live today.
The result is a genuine, currently-existing gap: an organization that suffers a data breach in India right now has a hard 6-hour cyber-incident reporting clock running under CERT-In, but no DPDP breach-notification clock running at all, because that duty has not yet come into force. A breach-response plan built only around "72 hours" or only around "6 hours" would each describe an incomplete picture. Both regimes need to be accounted for, with CERT-In flagged as the one that actually binds Indian entities today.
Recent Developments
November 13, 2025. The Digital Personal Data Protection Rules, 2025 were notified alongside the Act's Stage 1 commencement, along with companion notifications titled "Enforcement Timeline for the DPDP Act," "Establishment of the Data Protection Board of India," and "Decision Regarding Number of Members in the Data Protection Board of India." Only the definitions rule and the Board's own operating rules took effect immediately.
December 10, 2025. MeitY issued a corrigendum to the DPDP Rules, 2025 (G.S.R. 892(E)), gazetted December 11, 2025. Organizations relying on precise Rules text should check it against the corrigendum rather than the original November PDF alone.
November 13, 2026. Stage 2: Section 6(9) and Section 27(1)(d) of the Act, together with Rule 4, bring the Consent Manager registration and obligations regime into force.
May 13, 2027. Stage 3, the commencement of the bulk of the Act's substantive obligations: consent and notice duties, the Section 7 legitimate-uses list, children's-data protections, the core data-principal rights, Significant Data Fiduciary duties, cross-border transfer rules, and the DPDP Rules covering notice, security safeguards, breach notification, children's data, SDF audits, rights and transfers.
Ongoing. As of mid-2026, the Data Protection Board of India remains constituted but unstaffed, with no Chairperson or Members yet in office and no DPDP enforcement action reported to date.
Dual-Compliance Guidance
Organizations subject to both frameworks face a compliance timeline problem as much as a substantive one: DPDP's real requirements are not yet enforceable, but they will be, and the lead time to build compliant systems is shrinking.
| Issue | GDPR Requirement | India DPDPA Position | Compliance Approach |
|---|---|---|---|
| Marketing and analytics legal basis | Legitimate interests or consent | No legitimate-interests basis; must fit Section 7's closed list or obtain consent | Build consent-first flows for India rather than relying on a balancing-test justification |
| Consent intermediary strategy | Unregulated CMPs, build or buy freely | Registered Consent Managers required once Stage 3 and the related Rule commence (expected around Nov 2026) | Track Consent Manager registration timelines; do not assume a GDPR-style CMP satisfies a future DPDP requirement |
| Children's data | Age 16, lowerable to 13 by member state | Uniform 18, verifiable parental consent required, no age-band tiering | Apply the stricter 18 threshold globally if operating in both markets, or build a India-specific age gate |
| Data subject rights UX | Must support access, correction, erasure, portability, and objection | Must support access and purpose-bound correction/erasure only; no portability or objection duty (yet) | Keep the broader GDPR rights UX in place; do not assume DPDP requires less once Stage 3 lands, since the Act may still be interpreted or amended before full commencement |
| Cross-border transfer mechanism | Adequacy, SCCs, BCRs, or another Chapter V safeguard required for every transfer | No restriction in practice today (no restricted-country list published); Section 16's negative-list regime is not yet in force | Do not build elaborate DPDP-specific transfer-approval workflows yet; monitor for both Section 16's commencement and any future restricted-country notification |
| Breach response clock | 72 hours to the supervisory authority | CERT-In's 6-hour cyber-incident clock is live now; DPDP's own Board-notification duty is not yet in force | Build breach response around CERT-In's 6-hour deadline today; do not assume DPDP's future 72-hour Board-notification duty replaces it, since the two regimes will likely run in parallel once DPDP Rule 7 commences |
| Significant Data Fiduciary readiness | Self-assess "large scale processing" under Article 35 and act accordingly | SDF status is government-designated, not self-assessed; obligations (India-resident DPO, independent audit, annual DPIA) attach only once designated and once Stage 3 commences | Do not assume SDF status or its duties apply until an actual government designation is made and the relevant provisions are in force |
For the EU side of this comparison in full detail, see our what is GDPR guide. For India's complete privacy law picture beyond this GDPR comparison, see our India data privacy laws guide.
Disclaimer
This article presents general legal information about India's Digital Personal Data Protection Act, 2023 and the EU's General Data Protection Regulation. It does not constitute legal advice. India's DPDP Act is in an active, staged commencement process, and several of the dates, section mappings, and rule details described above are subject to further government notification before they take full legal effect. Organizations subject to either framework should consult a lawyer licensed in the relevant jurisdiction for advice specific to their situation. This article reflects information available as of July 23, 2026.
Authorities Cited
- Ministry of Electronics and Information Technology (MeitY). Digital Personal Data Protection Rules, 2025, and companion commencement notifications (Gazette of India, Extraordinary, Part II-Section 3(i), No. 757, November 13, 2025). https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa
- Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 6-9, 15-22, 33-35, 45-49, 83. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
- Indian Computer Emergency Response Team (CERT-In). Direction under Section 70B of the Information Technology Act, 2000 (Direction No. 20(3)/2022-CERT-In, effective June 28, 2022) on cyber incident reporting. https://www.cert-in.org.in/
- Mondaq. "India's Data Protection Board: The Enforcer That Isn't There Yet." https://www.mondaq.com/
- Internet Freedom Foundation. Statement on the notification of the Digital Personal Data Protection Rules, 2025. https://internetfreedom.in/iffs-initial-statement-on-the-notification-of-the-digital-data-protection-rules-2025/
- Medianama. Explainer on Consent Manager rules under the DPDP Rules, 2025. https://www.medianama.com/
- Bar & Bench. Commentary on the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) as the DPDP appellate forum. https://www.barandbench.com/
- SIRI Law LLP. Guide to CERT-In's 6-hour cyber incident reporting mandate. https://sirilawllp.com/a-comprehensive-guide-to-indias-cert-in-6-hour-cyber-incident-reporting-mandate/
- Baker McKenzie Resource Hub. Global Data and Cyber Handbook: Asia Pacific comparative breach notification summaries. https://resourcehub.bakermckenzie.com/en/resources/global-data-and-cyber-handbook/asia-pacific/
Last updated: July 23, 2026. India's DPDP Act commencement is an active, staged process; readers should confirm the current commencement stage against MeitY's official notifications before relying on any date in this article for compliance purposes.
Frequently Asked Questions
Is India's DPDP Act in force yet?
Only partly. Stage 1 of its commencement took effect November 13, 2025, and covers the Data Protection Board's establishment and basic rule-making machinery, not the Act's substantive consent, children's-data, cross-border, or Significant Data Fiduciary provisions. Those are scheduled to commence in Stage 3 on May 13, 2027. As of today, the Data Protection Board is constituted but not staffed, and there has been no DPDP enforcement action.
What is the difference between DPDP's Section 7 'legitimate uses' and GDPR's legitimate interests?
GDPR's legitimate-interests basis (Article 6(1)(f)) is an open balancing test: an organization can process data without consent if it can show its interest outweighs the individual's rights, applied case by case. DPDP has no equivalent open-ended basis. Instead, Section 7 lists a closed set of specific situations, such as voluntary disclosure by the individual, certain government functions, legal compliance, medical emergencies, and limited employment purposes, where consent is not required. If a processing activity does not fit one of those enumerated categories, DPDP requires consent even where a GDPR-style legitimate-interests argument might otherwise apply.
What is a Consent Manager under India's DPDP Act?
A Consent Manager is a registered intermediary, unique to DPDP with no GDPR equivalent, through which a Data Principal can grant, review, and withdraw consent to multiple Data Fiduciaries from one interoperable dashboard. Consent Managers must incorporate as an Indian company, meet minimum capital and capacity requirements, and hold independent certification, and are barred from acting as a data fiduciary or processor for the same individual or monetizing consent flows. The Consent Manager Rules are not scheduled to become operative until around November 13, 2026.
Does DPDP give Indians a right to data portability like GDPR does?
No. DPDP does not include a general right to data portability, and also has no explicit right to object to processing. Both are established GDPR rights (Articles 20 and 21) that DPDP simply omits. DPDP's erasure right is narrower too: it is tied to whether the original processing purpose has been fulfilled, rather than functioning as a freestanding right to be forgotten independent of purpose completion.
How does DPDP handle cross-border data transfers compared to GDPR?
GDPR works as a whitelist: transfers outside the EEA are prohibited unless an approved mechanism applies, such as an adequacy decision, Standard Contractual Clauses, or Binding Corporate Rules. DPDP's Section 16 works the opposite way, as a negative list: transfers are permitted by default to any country except ones the Indian government affirmatively names as restricted. No country has been placed on that restricted list so far, and Section 16 itself is not yet in force, so DPDP currently imposes no cross-border transfer restriction in practice, separate from any sector-specific rules like RBI payments-data localization.
What are the maximum penalties under DPDP compared to GDPR?
GDPR's most severe penalty tier is up to EUR 20 million or 4% of an organization's global annual turnover, whichever is higher. DPDP uses a fixed-amount Schedule instead, with no turnover-percentage concept: the ceiling for the most serious violation, such as inadequate security safeguards resulting in a breach, is roughly 250 crore rupees. The Data Protection Board weighs seven statutory factors in setting the amount under Section 33(2), but the Schedule figures are hard ceilings it cannot exceed. Only the Central Government can raise them, by notification under Section 42(1), and no such notification may more than double an originally enacted amount. No DPDP penalty has actually been assessed against any organization to date, since the relevant Schedule provisions have not yet commenced.
Does India have a data breach notification deadline right now?
Yes, but not the one most people expect. India's Computer Emergency Response Team (CERT-In) already requires reporting of cybersecurity incidents within 6 hours under a direction in force since June 2022, unrelated to DPDP. DPDP's own breach-notification duty to the Data Protection Board, once in force, is expected to require an initial alert without delay and a detailed report within 72 hours, but that DPDP provision has not yet commenced. As of today, only CERT-In's 6-hour clock actually binds organizations in India on breach reporting.
What is the age threshold for children's data under DPDP versus GDPR?
DPDP sets a single, uniform age threshold of 18 and requires verifiable parental or guardian consent for processing any minor's data under that age, with no tiering by age band. GDPR's Article 8 baseline is 16, but individual EU member states may lower it to as low as 13, so the effective age varies by country. DPDP's children's-data provisions, like most of the Act's substance, are scheduled to commence in Stage 3 on May 13, 2027 and are not yet legally binding.
Updates
Stage 1 of the DPDPA's staged commencement took effect (Gazette of India, Extraordinary, Part II-Section 3(i), No. 757): the Data Protection Board of India was formally constituted and the Act's/Rules' skeletal machinery went live. The substantive consent, notice, children's-data, and cross-border provisions remain dormant.
A corrigendum to the Digital Personal Data Protection Rules, 2025 (G.S.R. 892(E)) was issued by the Ministry of Electronics and Information Technology (MeitY) on December 10, 2025 and gazetted on December 11, 2025.
Article published. Next scheduled milestone: Stage 2 of commencement is expected around November 13, 2026, with the bulk of the Act's substantive obligations (consent, Significant Data Fiduciary duties, children's data, cross-border transfer rules, most data-principal rights) not commencing until May 13, 2027.
Sources and References
- MeitY: Digital Personal Data Protection Rules, 2025 and commencement notifications (Gazette No. 757, Nov 13, 2025)(meity.gov.in).gov
- Regulation (EU) 2016/679 (GDPR) Full Text(eur-lex.europa.eu).gov
- CERT-In Directions No. 20(3)/2022-CERT-In under Section 70B of the IT Act, 2000 (28 April 2022), 6-hour reporting and Annexure I list of 20 reportable incident types(cert-in.org.in).gov
- Mondaq: India's Data Protection Board, The Enforcer That Isn't There Yet(mondaq.com)
- Internet Freedom Foundation: Statement on the DPDP Rules 2025 notification(internetfreedom.in)
- Medianama: Consent Manager rules under the DPDP Rules 2025(medianama.com)
- Bar & Bench: TDSAT as the DPDP appellate forum(barandbench.com)
- SIRI Law LLP: Guide to India's CERT-In 6-hour cyber incident reporting mandate(sirilawllp.com)
- Baker McKenzie: Global Data and Cyber Handbook, Asia Pacific breach notification summaries(resourcehub.bakermckenzie.com)
- MeitY circular F. No. 2(1)/2026-Pers.I, 6 May 2026, inviting applications for Chairperson (1 post) and Members (4 posts) of the Data Protection Board of India(meity.gov.in).gov
- Gazette of India, Extraordinary, Part II-Section 3(i), No. 757, G.S.R. 843(E), 13 November 2025, staged commencement of the DPDP Act(meity.gov.in).gov