Already GDPR-ready? Here is what DPDP still requires
GDPR compliance is a strong foundation — but India's DPDP Act has its own distinct rules that your EU playbook simply does not cover.
If your company processes personal data of EU residents, you have likely invested significant time and money building a GDPR compliance programme. Privacy notices, Data Processing Agreements, cookie banners, DPO appointments — the works. So when India's DPDP Act arrived, the assumption in many boardrooms was: "We are already covered."
It is an understandable assumption. Both laws protect personal data, both require consent, and both impose penalties for breaches. But the similarities are largely structural. In the specifics that determine whether an enforcement action succeeds or fails, DPDP and GDPR diverge in ways that matter enormously.
This post maps the critical deltas so you know exactly which gaps to close — before enforcement begins.
1. Consent standards are not interchangeable
Under GDPR, consent is one of six lawful bases for processing. It must be freely given, specific, informed, and unambiguous — but organisations can often sidestep consent entirely by relying on legitimate interests, contract performance, or legal obligation.
DPDP takes a narrower path. For most processing of personal data of Indian Data Principals, consent is the primary lawful basis. The Act does recognise "deemed consent" for certain legitimate uses (employment, emergency, state functions), but the scope is considerably tighter than GDPR's legitimate interests basis.
Practically, this means your existing consent flows — designed to obtain GDPR-compliant consent only where you could not rely on another basis — may be insufficient under DPDP. You need to audit every processing activity and confirm it has an explicit DPDP-recognised basis.
2. Legitimate interests does not exist under DPDP
This is the single biggest trap for GDPR-trained compliance teams. GDPR Article 6(1)(f) allows processing on the basis of legitimate interests after a three-part balancing test. Many organisations rely on this basis for analytics, fraud prevention, marketing profiling, and operational data sharing.
DPDP contains no equivalent provision. There is no legitimate interests basis. Processing that rests entirely on that foundation under GDPR needs an alternative justification — or a fresh consent mechanism — to be lawful under DPDP.
If your data map shows "legitimate interests" against a processing activity that also touches Indian Data Principals, that activity needs to be re-evaluated and re-papered before DPDP enforcement kicks in.
3. Data localisation and cross-border transfers
GDPR restricts transfers of personal data outside the European Economic Area unless an adequacy decision, Standard Contractual Clauses, or another safeguard is in place. You likely have this covered through SCCs or binding corporate rules.
DPDP takes a different approach. The Act empowers the Central Government to notify countries to which cross-border transfer of Indian personal data is restricted — effectively a blacklist model rather than GDPR's whitelist model. The list has not yet been finalised, but draft rules signal that certain jurisdictions will be blocked.
Your existing transfer mechanism under GDPR gives you no protection under DPDP. You will need to monitor the Government's notifications and ensure your data flows are mapped clearly enough that you can respond quickly when the restricted-country list is published. See our earlier post on building a DPDP-ready data map for the methodology.
4. Grievance Officer vs. Data Protection Officer
GDPR mandates a Data Protection Officer for organisations that process personal data at scale, process sensitive categories, or are public authorities. The DPO must have expert knowledge of data protection law and practice, and must be reachable by Data Subjects and supervisory authorities.
DPDP requires Significant Data Fiduciaries — and potentially all Data Fiduciaries, depending on rules — to appoint a Grievance Officer. The Grievance Officer's primary function is to handle complaints from Data Principals within prescribed timelines. The role is operationally different from a DPO: less focused on advisory and impact assessment, more focused on complaint resolution and response logging.
If your DPO is based outside India, they cannot serve as your DPDP Grievance Officer without ensuring they are reachable and accountable in India. You may need a separate appointment, separate contact details, and a separate complaint-tracking workflow.
5. Breach notification timelines differ
GDPR requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach, where feasible. This 72-hour window is well understood and most GDPR-compliant organisations have built internal escalation processes around it.
DPDP requires notification to the Data Protection Board "as soon as possible" and "in such form and manner as may be prescribed." The draft DPDP Rules specify a timeline, but the prescribed period under current drafts does not map cleanly to 72 hours. More importantly, DPDP also requires direct notification to affected Data Principals — something GDPR only mandates when the breach is likely to result in a high risk to individuals.
Your existing breach response playbook will need a DPDP-specific annex covering: the Board notification format, the Data Principal notification requirement, the content standards, and a clear escalation path that works within whatever final timeline the Rules prescribe.
6. No extraterritorial scope in the same way
GDPR has broad extraterritorial reach — it applies to any organisation that targets or monitors EU residents, regardless of where the organisation is established. This is why Indian companies processing EU data must comply with GDPR even if they have no EU office.
DPDP's territorial scope is different. It applies to processing of personal data within India, and to processing outside India if it relates to offering goods or services to Data Principals in India. If your Indian entity processes only data of non-Indian customers and has no Indian Data Principals, your GDPR programme may be sufficient for that entity alone — but you still need to assess each entity individually.
Related reading: How DPDP applies to Indian subsidiaries of MNCs and DPDP applicability for B2B SaaS companies. For the full comparison matrix, see our DPDP Rules 2025 overview.
Your practical gap-closure checklist
If you are GDPR-compliant and now assessing DPDP exposure, work through these items:
- Re-map lawful bases. Every processing activity relying on legitimate interests needs an alternative DPDP basis or fresh consent.
- Audit consent flows. Ensure consent notices meet DPDP's plain-language standard and cover all purposes.
- Appoint a Grievance Officer. Document their contact details, complaint-handling process, and response timelines.
- Review cross-border transfer flows. Identify which countries receive Indian personal data and prepare to act when the restricted-country list is notified.
- Update your breach playbook. Add a DPDP annex covering Board notification format, Data Principal notification triggers, and escalation steps.
- Map Data Principal rights. DPDP grants rights to access, correction, erasure, and grievance — ensure your fulfilment workflow handles these within prescribed timelines.
See exactly how DPDP and GDPR compare — side by side
Use our free DPDP vs GDPR comparison tool to map the key differences and identify the gaps your current programme needs to fill.
Open the DPDP vs GDPR Tool (Free)Frequently asked questions
If we have GDPR-compliant consent, does it satisfy DPDP as well?
Not automatically. GDPR consent and DPDP consent share some common elements — both must be freely given, specific, and informed — but DPDP requires the consent notice to be in plain language, offer a language choice, and be accompanied by a specific itemised list of purposes. If your GDPR consent notice was drafted for EU standards, it will likely need a DPDP-specific version for Indian Data Principals.
Can our existing DPO serve as the DPDP Grievance Officer?
In principle, one person can hold both roles if they are reachable in India and have capacity to handle complaint resolution within DPDP's timelines. In practice, many organisations are separating the functions: the DPO handles GDPR advisory and supervisory authority liaison, while the Grievance Officer handles DPDP complaint intake and resolution. The two roles have different operational demands.
When does DPDP enforcement actually begin?
The DPDP Act was notified in August 2023. The DPDP Rules are currently in final consultation. Enforcement is expected to begin after the Rules are finalised, with a grace period for compliance — the current working assumption across the industry is a May 2027 hard deadline. However, Significant Data Fiduciaries may face earlier obligations once the SDF list is published. Do not wait for the final Rules to start your gap assessment.