All resources
Blog 5 min read
DPDP vs GDPR: the differences that actually matter
C1The Compliance One team13 September 2026
DPDP borrows the shape of modern privacy law — fiduciaries, principals, rights, breach notification — so a GDPR foundation carries a long way. But four differences will catch you out if you assume they map one-to-one.
The four that matter
- Lawful basis is narrower: consent or a closed list of legitimate uses. There is no GDPR-style 'legitimate interests' balancing test.
- Cross-border is a negative list: transfers are allowed to every country except those India restricts — the opposite of the GDPR's adequacy allow-list. Do not build a whitelist gate.
- Breach notification has no threshold: every breach is notifiable, with a 72-hour Board report, versus the GDPR's 'risk to rights and freedoms' trigger.
- Penalties are fixed rupee ceilings (up to ₹250 crore), not a percentage of global turnover.
The good news
Most of your control evidence carries over. DPDP obligations cross-map cleanly to ISO 27701 (privacy management) and ISO 27001 (security), so if you run those, DPDP is largely gap-filling and re-mapping — not starting again. That is exactly the overlap a crosswalk is built to exploit.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map Compliance One to your environment.