Last updated: 6 August 2026
Businesses that handle the personal data of individuals in both the European Union and India may need to comply with two different laws: the EU’s General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection Act, 2023 (DPDP Act). They share broad aims but differ in important ways.
The GDPR refers to the “data controller” and the “data subject”. The DPDP Act uses “Data Fiduciary” and “Data Principal” for broadly similar roles.
The GDPR applies to personal data in general, including certain structured manual records, not only digital data. The DPDP Act applies to digital personal data — data collected in digital form, or collected on paper and later digitised.
The GDPR sets out several lawful bases for processing (such as consent, contract, legal obligation, vital interests, public task, and legitimate interests). The DPDP Act relies principally on consent, together with a defined set of “legitimate uses” for which consent is not required.
The GDPR recognises “special categories” of personal data (such as health, biometric, or religious data) that attract stricter protection. The DPDP Act does not, in the Act itself, create a separate category of sensitive personal data.
Both laws give individuals rights over their data, but the GDPR provides a broader set — including the right to data portability and the right to object to certain processing. The DPDP Act provides the rights to access, correction and erasure, grievance redressal, and nomination, but does not include a general right to data portability.
The GDPR restricts transfers of personal data outside the European Economic Area unless certain safeguards are met. The DPDP Act takes a different approach, generally permitting transfers except to countries or territories that the Central Government may restrict.
Under the GDPR, a Data Protection Officer must be appointed in defined circumstances. Under the DPDP Act, appointing a Data Protection Officer is an obligation specifically for Significant Data Fiduciaries.
The GDPR provides for fines of up to €20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious infringements. The DPDP Act provides for financial penalties of up to ₹250 crore, depending on the nature of the breach.
For a business operating across both regions, the practical step is to map its data processing against each law separately, since compliance with one does not automatically mean compliance with the other.