DPDPA vs GDPR: What Indian Companies Serving EU Clients Need to Know
October 7, 2026
Indian IT, BPO and SaaS companies that serve European clients have spent years building GDPR programmes. A common assumption follows: "We're GDPR-compliant, so DPDPA is covered." It is a reasonable starting point, but it is not the finish line. The two laws share principles, yet differ in ways that matter for day-to-day operations.
| Area | GDPR | DPDPA |
|---|---|---|
| Scope | Personal data in any form | Digital personal data, and non-digital data that is later digitised |
| Lawful bases | Six, including legitimate interests | Consent, or specified "legitimate uses"; no general legitimate-interests basis |
| Sensitive data | Special categories with extra conditions | No separate special categories in the Act |
| Children | Digital consent age 16, member states may lower to 13 | Everyone under 18; verifiable parental consent; no tracking or targeted ads |
| Breach reporting | To authority within 72 hours unless unlikely to pose risk | Every personal data breach to the Board and affected individuals; detailed report within 72 hours |
| Rights | Includes portability and objection | Access, correction, erasure, grievance redressal and nomination; no portability |
| DPO | Required in defined cases | Required for Significant Data Fiduciaries, based in India |
| Penalties | Up to €20 million or 4% of global turnover | Fixed caps per breach, up to ₹250 crore |
| Cross-border transfers | Adequacy, SCCs or other safeguards | Permitted except to countries the government restricts |
Much B2B processing under GDPR, from marketing to fraud prevention to analytics, rests on legitimate interests. DPDPA has no equivalent general basis. You need consent, or the processing must fit one of the Act's specified legitimate uses, such as data a person voluntarily provided for a specified purpose, or employment-related processing. Re-map your processing activities rather than copying your GDPR register.
GDPR lets you skip notifying the regulator when a breach is unlikely to create risk. DPDPA has no such threshold: affected individuals and the Data Protection Board must be informed, with a detailed report to the Board within 72 hours. Your incident playbook needs an India branch. See inside the 72-hour window.
A 17-year-old is a child under DPDPA. Products that treat teenagers as adults under GDPR rules will need verifiable parental consent flows for Indian users. More in our guide to children's data under DPDPA.
The right to nominate someone to exercise your rights after death or incapacity has no GDPR counterpart, so off-the-shelf global privacy portals often lack it.
Instead of turnover-based fines, DPDPA sets caps by type of breach, up to ₹250 crore for failing to maintain reasonable security safeguards. For a mid-size Indian company, that exposure can be proportionally larger than a GDPR fine. Read the real cost of waiting.
Here is good news for IT services and BPO firms. Section 17(1)(d) of the DPDP Act exempts processing of personal data of individuals outside India, carried out under a contract with a person outside India, from most of the Act's obligations. Your EU client's customer data, processed in India under your services contract, largely remains a GDPR matter governed by your data processing agreement.
Two caveats. First, the exemption is not total: obligations around reasonable security safeguards still apply. Second, it covers your clients' foreign data only. Your own employees, Indian customers, job applicants and vendors are Indian Data Principals, and your organisation is a Data Fiduciary for them with full DPDPA obligations.
Most DPDPA obligations take effect on 13 May 2027 under the current schedule, with the Consent Manager framework starting on 13 November 2026. A MeitY proposal to shorten the timeline has not been notified at the time of writing. See the full DPDPA timeline.
DAPro (Data Adhikaar), Qodequay's DPDPA compliance platform, helps GDPR-mature organisations extend their existing programme to India, with notices in 22 languages, a tamper-evident Evidence Vault and 25+ connectors to your current systems. Qodequay is ISO 27001:2022 certified. Book a gap-assessment call.
This article is for general information and is not legal advice. Confirm obligations against the official texts of the DPDP Act, the DPDP Rules and the GDPR, and consult qualified counsel for your situation.
Monthly insights on AI, VR and DPDPA compliance — straight from our team to your inbox.
Free 30-minute consultation with our team — or see our products in action.