What India's DPDP Act means for GDPR-ready companies
If your company is already GDPR-compliant, India's Digital Personal Data Protection Act, 2023 will feel familiar — and that familiarity is the danger. The DPDP Act borrows GDPR's vocabulary while changing the machinery underneath. Treating it as "GDPR with Indian spellings" produces programmes that look compliant and aren't.
Where things stand, as of June 2026
The DPDP Rules, 2025 were notified on 13 November 2025, bringing the Act into force on a phased schedule. The administrative skeleton — the Data Protection Board, Consent Manager framework definitions — is live first. The Consent Manager registration framework commences on 13 November 2026. The substantive obligations that will dominate compliance work — notice and consent standards, security safeguards, breach notification, retention limits, children's data rules, Significant Data Fiduciary duties and Data Principal rights — take effect on 13 May 2027, when the Board's penalty powers also become fully operational.
That makes 2026 the build-out window. Nothing about the phased schedule defers the work; it defers only the penalties for not having done it.
Where GDPR gives you a real head start
- Data mapping. If you maintain GDPR Article 30 records of processing, you already know what personal data you hold, where it flows and who processes it. The same inventory anchors DPDP compliance.
- Security safeguards. GDPR Article 32 technical and organisational measures map closely to the DPDP Act's "reasonable security safeguards" — the obligation carrying the Act's highest penalty, up to ₹250 crore per violation.
- Vendor discipline. GDPR-style processor contracts translate well: the DPDP Act makes Data Fiduciaries responsible for their Data Processors, so flow-down terms, audit rights and breach-assistance clauses carry over.
- Rights plumbing. Access and erasure request-handling built for GDPR can be extended to serve DPDP's Data Principal rights with workflow changes rather than new systems.
Where the regimes sharply diverge
1. Consent does almost all the work
GDPR offers six lawful bases, and mature programmes lean heavily on legitimate interests and contractual necessity. The DPDP Act recognises essentially two: consent, and a closed list of "legitimate uses" under Section 7 (voluntary provision for a specified purpose, state functions, medical emergencies, employment-related processing, and similar). There is no general legitimate-interests basis. Processing you justify in Europe without consent will, in India, frequently need consent — specific, informed, unambiguous, purpose-limited and as easy to withdraw as to give.
2. Breach notification has no risk threshold
GDPR requires notifying the authority within 72 hours unless the breach is unlikely to result in risk, and affected individuals only where risk is high. The DPDP framework requires intimating the Board and every affected Data Principal upon a personal data breach, without a materiality filter, on the timelines set in the Rules. Incident-response playbooks tuned to GDPR's thresholds need rewriting, not relabelling.
3. Transfers run on a blacklist, not a whitelist
GDPR restricts transfers unless a mechanism applies — adequacy, SCCs, BCRs. The DPDP Act inverts this: cross-border transfers are permitted except to countries the Central Government notifies as restricted, and subject to any conditions the Rules impose, with sectoral regulators (such as RBI data-localisation directions) continuing to apply. Simpler on paper; in practice, you must track government notifications rather than rely on a stable mechanism library.
4. Different rights, in both directions
DPDP grants no data-portability right and no GDPR-style right to object to processing. It adds rights GDPR lacks: a statutory right of grievance redressal on defined timelines, and a right to nominate a person to exercise rights after death or incapacity. Rights matrices need rebuilding, not copying.
5. Consent Managers exist
India is building an interoperable layer of registered Consent Managers through which individuals can give, manage and withdraw consent. Nothing comparable exists under GDPR. From 13 November 2026, entities may register as Consent Managers; businesses should track how the ecosystem develops, because integration expectations will follow it.
6. Significant Data Fiduciary designation
Where GDPR scales duties by risk of processing, the DPDP Act lets the government designate classes of fiduciaries as Significant Data Fiduciaries — attracting a DPO based in India, independent data audits and periodic data protection impact assessments. If your volumes or sectors make designation plausible, build for it now; retrofitting an India-based DPO function in 2027 will be slower than it sounds.
The sequence to follow before May 2027
- Re-run the data map for India — which processing touches Data Principals in India, under which entity, with which vendors.
- Re-basis the processing. Everything resting on legitimate interests needs a DPDP answer: consent, a Section 7 legitimate use, or stopping the processing.
- Rebuild notices and consent flows to DPDP's specificity and withdrawal standards, with itemised purposes.
- Rewrite the breach playbook for no-threshold notification to the Board and affected individuals.
- Amend processor contracts for DPDP-specific assistance, erasure and breach duties.
- Assess SDF exposure and stand up the governance it would require.
Saya & Associates