All resources
Blog 5 min read

DPDP vs GDPR: the differences that actually matter

C1The Compliance One team13 September 2026

DPDP borrows the shape of modern privacy law — fiduciaries, principals, rights, breach notification — so a GDPR foundation carries a long way. But four differences will catch you out if you assume they map one-to-one.

The four that matter

  • Lawful basis is narrower: consent or a closed list of legitimate uses. There is no GDPR-style 'legitimate interests' balancing test.
  • Cross-border is a negative list: transfers are allowed to every country except those India restricts — the opposite of the GDPR's adequacy allow-list. Do not build a whitelist gate.
  • Breach notification has no threshold: every breach is notifiable, with a 72-hour Board report, versus the GDPR's 'risk to rights and freedoms' trigger.
  • Penalties are fixed rupee ceilings (up to ₹250 crore), not a percentage of global turnover.

The good news

Most of your control evidence carries over. DPDP obligations cross-map cleanly to ISO 27701 (privacy management) and ISO 27001 (security), so if you run those, DPDP is largely gap-filling and re-mapping — not starting again. That is exactly the overlap a crosswalk is built to exploit.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map Compliance One to your environment.