DPDPA · India
GDPR · EU
What's covered
Digital personal data only, including offline data later digitised
All personal data, including structured paper records
Territorial reach
Processing in India, plus offering goods or services to people in India
EU establishments, plus offering goods/services to or monitoring people in the EU
Lawful bases
Consent plus a short list of "legitimate uses" — no legitimate-interest balancing test
Six bases, including contract necessity and legitimate interests
Sensitive data
No special-category tier — one standard for all personal data
Special categories (health, biometric, beliefs) with stricter conditions
Individual rights
Access, correction, erasure, grievance redressal, nomination
Those plus portability, objection, restriction, and automated-decision rights
Children
Under 18 — verifiable parental consent; no tracking or targeted ads at children
Under 16 for online services; member states may lower to 13
Breach notification
Every breach: notify the Board and each affected individual; detailed report within 72 hours
Authority within 72 hours only if risk; individuals only if high risk
Cross-border transfers
Blacklist model — allowed unless the destination country is restricted
Whitelist model — adequacy decisions, SCCs, or binding corporate rules
DPO and assessments
DPO, independent audit and DPIA only for Significant Data Fiduciaries
DPO for many organisations; DPIA required for high-risk processing
Penalties
Fixed rupee ceilings — up to ₹250 crore per instance
Up to €20 million or 4% of global turnover, whichever is higher
Regulator
Data Protection Board of India
National supervisory authorities, coordinated by the EDPB