TL;DR
- The DPDPA vs GDPR gap that catches Indian SMBs first is lawful grounds. Section 4 of the Digital Personal Data Protection Act, 2023 allows only two routes — consent under Section 6, or an enumerated legitimate use under Section 7. There is no GDPR Article 6(1)(f) “legitimate interests” catch-all to fall back on.
- DPDPA does not retain a “sensitive personal data” category. The SPDI Rules, 2011 tiering and GDPR Article 9 special categories have no Indian successor — health, salary and biometric data are all just personal data.
- Cookie-consent theatre is a European import. India has no ePrivacy Directive, but Section 6 consent must be unconditional and given by clear affirmative action, which kills cookie walls and pre-ticked banners anyway.
- Children are anyone under 18 under Section 9 — not 16, not 13. Verifiable parental consent, plus a flat prohibition on tracking and targeted advertising directed at children.
- Breaches run on a dual clock: CERT-In within 6 hours (Directions of 28 April 2022) and Rule 7 of the DPDP Rules, 2025 — intimation without delay, detailed report to the Board within 72 hours. Unlike GDPR, there is no risk threshold; every personal data breach is reportable.
- Most obligations bite on 13 May 2027. Maximum penalty is ₹250 crore under Section 8(5), with ₹200 crore under Section 8(6) assessed separately.
What is the real difference between DPDPA vs GDPR for an Indian SMB?
The most expensive mistake in the DPDPA vs GDPR comparison is assuming India built a lighter GDPR. It didn’t. GDPR gives controllers six lawful bases and lets them reason their way into processing via legitimate interests. DPDPA gives Data Fiduciaries a closed set: consent under Section 6, or one of the legitimate uses listed in Section 7. If your processing does not fit a Section 7 clause, you need consent.
That single difference invalidates a lot of imported paperwork. A processing register that says “legal basis: legitimate interests” for marketing analytics has nothing to map to in India.
| Dimension | GDPR (EU) | DPDPA 2023 + DPDP Rules 2025 (India) |
|---|---|---|
| Lawful grounds | Six bases, incl. legitimate interests (Art. 6) | Consent (Sec. 6) or enumerated legitimate uses (Sec. 7) only |
| Employment processing | Usually contract or legitimate interests | Section 7(i) legitimate use — employment purposes, loss/liability protection, employee benefits |
| Special categories | Article 9 special-category regime | None — no sensitive personal data tier |
| Child threshold | 16, reducible to 13 by Member State | Under 18, no reduction (Sec. 9) |
| Cross-border | Adequacy / SCCs (positive list) | Section 16 restriction model (negative list) |
| Max penalty | 4% global turnover or €20m | ₹250 crore (Sec. 8(5)); turnover-independent |
| Duties on individuals | None | Section 15 duties on Data Principals, incl. penalty for frivolous complaints |
Section 14’s right to nominate someone to exercise your rights on death or incapacity has no GDPR analogue at all — copy Europe wholesale and you will simply never build it.
Does DPDPA still use “sensitive personal data” the way GDPR does?
No — and this is where Indian SMBs waste the most money. GDPR-trained consultants arrive with a classification workshop that sorts everything into “ordinary” and “sensitive,” then applies heavier controls only to the second bucket. DPDPA deleted that distinction. There is one category: personal data.
That inverts the risk model. A customer’s phone number and a diagnostic report now attract the same Section 8(5) duty of reasonable security safeguards and the same ₹250 crore exposure.
| Data you hold | GDPR habit | DPDPA reality |
|---|---|---|
| Health records, prescriptions | Article 9 — explicit consent, extra controls | Personal data. Sec. 6 consent or Sec. 7 medical-emergency use |
| Salary, PF, bank details | Tiered as “financial data” | Personal data. Employment processing sits under Sec. 7(i) |
| Aadhaar / PAN in KYC files | Mapped to national identifier rules | Personal data. Retention and vaulting matter more than classification |
| Employee CCTV, access logs | Legitimate interests assessment | No legitimate-interests ground. Sec. 7(i) or consent |
The correct Indian response is architectural, not taxonomic. Rather than tiering fields, put identifiers behind a sealed PII vault, bind every use to a cryptographically immutable consent record, and keep an evidentiary-grade audit trail that reconstructs who accessed what, under which purpose, and when. That survives a Board inquiry; a colour-coded spreadsheet does not.
Why does GDPR-style cookie consent fail under DPDPA Section 6?
Because the European banner was never built for DPDPA. Cookie banners exist because of the ePrivacy Directive, Article 5(3) — a separate instrument from GDPR. India has no ePrivacy equivalent, so there is no standalone cookie law here.
What India does have is a stricter consent definition. Section 6 requires consent that is free, specific, informed, unconditional, unambiguous and signalled by clear affirmative action. Four common imports fail it:
- Cookie walls — conditioning site access on acceptance is neither free nor unconditional.
- Pre-ticked boxes or scroll-implied consent — not clear affirmative action.
- IAB-style “legitimate interest” vendor toggles — no such ground exists in India, so the toggle is legally meaningless here.
- Bundled purposes — Section 6 requires specificity, and the notice under Rule 3 must be standalone and itemised, in English or any language in the Eighth Schedule.
Two India-only requirements follow: withdrawal must be as easy as giving consent, and India has created Consent Managers registered with the Data Protection Board — an interoperable institution GDPR never built. For what compliant consent capture looks like operationally, see our 2027 readiness guide for Indian SMBs.
How do children’s data rules differ under DPDPA Section 9 vs GDPR?
GDPR sets the digital-consent age at 16, lets Member States lower it to 13, and applies it to information society services offered directly to a child. Section 9 sets one national threshold — under 18 — with no state-level variation and no “directly offered” carve-out.
Three consequences Indian SMBs routinely miss:
- Verifiable parental consent is mandatory before processing a child’s personal data, with identity and age verification mechanics set out in the DPDP Rules, 2025.
- Tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright under Section 9(3) — not consent-gated, prohibited.
- Exemptions are narrow and class-based — healthcare, educational institutions, childcare, safety-related location tracking. “We assumed our users were adults” is not among them.
A coaching institute, an edtech app or a paediatric clinic in India is therefore handling minors well past the age at which GDPR would have released them.
What breach clocks should Indian SMBs follow that GDPR teams usually miss?
Indian SMBs run two regimes at once, and a GDPR-trained incident runbook will miss both.
| Clock | Trigger | Deadline |
|---|---|---|
| CERT-In (IT Act Sec. 70B, Directions of 28.04.2022) | Becoming aware of a specified cyber incident | 6 hours |
| Rule 7 — affected Data Principals | Knowledge of any personal data breach | Without delay, concise description and mitigation steps |
| Rule 7 — Data Protection Board, initial | Knowledge of the breach | Without delay |
| Rule 7 — Data Protection Board, detailed | Same breach | Within 72 hours |
| GDPR Art. 33 (contrast) | Breach likely to result in risk | 72 hours to supervisory authority only |
The critical divergence is the threshold. GDPR lets you skip notification where a breach is unlikely to result in risk to individuals. Rule 7 has no such filter — every personal data breach is intimated, and every affected Data Principal is told directly. A GDPR risk-assessment step inserted before notification is, in India, just delay. NBFCs and lenders carry an RBI reporting layer on top of both; we sequence that in the dual-clock breach playbook for NBFCs.
Who owns the GDPR-to-DPDPA migration before 13 May 2027?
Migration fails when it is filed as a legal review rather than assigned as engineering and operations work. Name owners now.
| Area | Owner | Status |
|---|---|---|
| Re-map every processing activity from GDPR bases to Sec. 6 / Sec. 7 | Founder or Head of Ops | ☐ |
| Rewrite notices as standalone, itemised, Eighth Schedule languages | Marketing + Legal | ☐ |
| Replace cookie banner with Sec. 6-valid consent capture and logs | Web / Growth | ☐ |
| Move employee data onto Sec. 7(i) footing; retire legitimate-interests memos | HR | ☐ |
| Under-18 detection, verifiable parental consent, ad-targeting kill switch | Product | ☐ |
| Dual-clock incident runbook: CERT-In 6h + Rule 7 intimation + 72h report | Security / CTO | ☐ |
| Sealed PII vault, immutable consent records, audit trail retention | Engineering | ☐ |
| Confirm Significant Data Fiduciary status (Rule 13 audits apply to SDFs only) | Founder | ☐ |
That last row saves real budget: mandatory annual audits and DPIAs under Rule 13 apply to Significant Data Fiduciaries only, not to every Data Fiduciary. GDPR-trained advisors routinely sell the full audit package to a 40-person SMB that does not need it. Employers rebuilding HR data flows should start with our employee data guide for Indian employers.
Closing
Three things to do this quarter, before 13 May 2027 becomes a scramble:
- Retire your sensitive-data tiering and re-base the processing register. Every activity maps to Section 6 consent or a specific Section 7 clause. Anything unmappable is a decision, not a footnote.
- Rebuild consent capture as evidence, not UI. A banner that cannot produce a tamper-evident record of what was shown, when, and what was withdrawn is a screenshot, not a control.
- Write the dual-clock runbook and rehearse it once. Six hours to CERT-In is not enough time to first work out who calls whom.
Privigo builds the layer this depends on: a sealed PII vault, cryptographically immutable consent records, and an evidentiary-grade audit trail your auditors and the Board can both read.
Book a 30-minute DPDPA discovery call →
Frequently asked questions
Is GDPR compliance enough to make an Indian SMB DPDPA compliant?
No. GDPR gives you useful hygiene, but DPDPA has no “legitimate interests” ground — Section 4 allows processing only on consent under Section 6 or an enumerated legitimate use under Section 7, so most GDPR justification logic has to be rebuilt.
Does DPDPA still use the “sensitive personal data” category like GDPR?
No. DPDPA 2023 does not retain the sensitive personal data tier from the SPDI Rules, 2011 and has no equivalent of GDPR Article 9 special categories. Health, financial and biometric data are all simply personal data under the Act.
Does DPDPA require a GDPR-style cookie consent banner?
No. India has no ePrivacy Directive, so there is no standalone cookie rule. But where cookies process personal data, Section 6 consent must be free, specific, informed, unconditional, unambiguous and given by clear affirmative action — which rules out pre-ticked boxes, cookie walls and “legitimate interest” toggles.
Do Indian SMBs get GDPR’s 72-hour breach window?
No. Indian SMBs run a dual clock: CERT-In requires reporting within 6 hours under the 28 April 2022 Directions, while Rule 7 of the DPDP Rules, 2025 requires intimation to affected Data Principals and the Data Protection Board without delay, with a detailed report to the Board within 72 hours.
Sources
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) — Ministry of Electronics and Information Technology, Government of India.
- Digital Personal Data Protection Rules, 2025 — MeitY, notified 13 November 2025.
- Digital Personal Data Protection (DPDP) Rules, 2025 — Press Release — Press Information Bureau, Government of India.
- DPDP Rules, 2025 Notified — Press Note — Press Information Bureau, Government of India.
- Directions under Section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In, dated 28 April 2022 — Indian Computer Emergency Response Team, MeitY.
This article is general information on Indian data protection law, not legal advice. Obligations under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 depend on your specific processing activities and Data Fiduciary classification. Consult qualified counsel before acting.
