Skip to main content
Home » Data Privacy & DPDPA » DPDPA vs GDPR: What Indian Companies Serving EU Clients Need to Know

DPDPA vs GDPR: What Indian Companies Serving EU Clients Need to Know

Hemlata Kalsha

October 7, 2026

Blog features image

Indian IT, BPO and SaaS companies that serve European clients have spent years building GDPR programmes. A common assumption follows: "We're GDPR-compliant, so DPDPA is covered." It is a reasonable starting point, but it is not the finish line. The two laws share principles, yet differ in ways that matter for day-to-day operations.

The differences at a glance

AreaGDPRDPDPA
ScopePersonal data in any formDigital personal data, and non-digital data that is later digitised
Lawful basesSix, including legitimate interestsConsent, or specified "legitimate uses"; no general legitimate-interests basis
Sensitive dataSpecial categories with extra conditionsNo separate special categories in the Act
ChildrenDigital consent age 16, member states may lower to 13Everyone under 18; verifiable parental consent; no tracking or targeted ads
Breach reportingTo authority within 72 hours unless unlikely to pose riskEvery personal data breach to the Board and affected individuals; detailed report within 72 hours
RightsIncludes portability and objectionAccess, correction, erasure, grievance redressal and nomination; no portability
DPORequired in defined casesRequired for Significant Data Fiduciaries, based in India
PenaltiesUp to €20 million or 4% of global turnoverFixed caps per breach, up to ₹250 crore
Cross-border transfersAdequacy, SCCs or other safeguardsPermitted except to countries the government restricts

Five differences that catch GDPR-ready teams out

1. No legitimate interests

Much B2B processing under GDPR, from marketing to fraud prevention to analytics, rests on legitimate interests. DPDPA has no equivalent general basis. You need consent, or the processing must fit one of the Act's specified legitimate uses, such as data a person voluntarily provided for a specified purpose, or employment-related processing. Re-map your processing activities rather than copying your GDPR register.

2. Every breach is reportable

GDPR lets you skip notifying the regulator when a breach is unlikely to create risk. DPDPA has no such threshold: affected individuals and the Data Protection Board must be informed, with a detailed report to the Board within 72 hours. Your incident playbook needs an India branch. See inside the 72-hour window.

3. The age line is 18

A 17-year-old is a child under DPDPA. Products that treat teenagers as adults under GDPR rules will need verifiable parental consent flows for Indian users. More in our guide to children's data under DPDPA.

4. Nomination is new

The right to nominate someone to exercise your rights after death or incapacity has no GDPR counterpart, so off-the-shelf global privacy portals often lack it.

5. Penalties are fixed, and they stack

Instead of turnover-based fines, DPDPA sets caps by type of breach, up to ₹250 crore for failing to maintain reasonable security safeguards. For a mid-size Indian company, that exposure can be proportionally larger than a GDPR fine. Read the real cost of waiting.

If you process EU client data from India

Here is good news for IT services and BPO firms. Section 17(1)(d) of the DPDP Act exempts processing of personal data of individuals outside India, carried out under a contract with a person outside India, from most of the Act's obligations. Your EU client's customer data, processed in India under your services contract, largely remains a GDPR matter governed by your data processing agreement.

Two caveats. First, the exemption is not total: obligations around reasonable security safeguards still apply. Second, it covers your clients' foreign data only. Your own employees, Indian customers, job applicants and vendors are Indian Data Principals, and your organisation is a Data Fiduciary for them with full DPDPA obligations.

What to reuse, and what to build

  • Reuse: data maps, records of processing, security controls, vendor contracts, retention schedules and your incident response team.
  • Adapt: lawful basis mapping, breach thresholds, children's age logic and rights portals.
  • Build new: DPDPA-format notices (with language options for Indian users), nomination handling, Data Protection Board reporting and the grievance process with its 90-day ceiling.

Timeline

Most DPDPA obligations take effect on 13 May 2027 under the current schedule, with the Consent Manager framework starting on 13 November 2026. A MeitY proposal to shorten the timeline has not been notified at the time of writing. See the full DPDPA timeline.

Close the gap faster

DAPro (Data Adhikaar), Qodequay's DPDPA compliance platform, helps GDPR-mature organisations extend their existing programme to India, with notices in 22 languages, a tamper-evident Evidence Vault and 25+ connectors to your current systems. Qodequay is ISO 27001:2022 certified. Book a gap-assessment call.

This article is for general information and is not legal advice. Confirm obligations against the official texts of the DPDP Act, the DPDP Rules and the GDPR, and consult qualified counsel for your situation.

Author profile image

Hemlata Kalsha

I am a founder director at Qodequay Technologies Pvt. Ltd., a leading digital transformation consulting firm that helps clients across industries to innovate, optimize, and grow their businesses. I have over two decades of experience in the digital domain, spanning product development, e-commerce, user experience, design thinking, web and app development, and business leadership. My core competencies include developing and executing digital transformation strategies, building teams globally, roadmaps, and solutions that leverage data, insights, and emerging technologies such as artificial intelligence, augmented reality, blockchain, and immersive experience. I also have expertise in digital commerce, supply chain integration, and product management, having worked with both B2B and B2C brands in various sectors. My mission is to create value for customers and stakeholders by delivering impactful and engaging digital experiences that drive growth and innovation.

Never miss an update

Monthly insights on AI, VR and DPDPA compliance — straight from our team to your inbox.

Have a project in mind?

Free 30-minute consultation with our team — or see our products in action.

Book a 30-min Consultation