Is the DPDP Act the same as GDPR?

No. They share a family resemblance — notice, consent, individual rights, security obligations, breach reporting — but they are different statutes with different definitions, different lawful bases, different terminology and a different regulator. A GDPR programme gives you a substantial head start on DPDP; it does not discharge it.

Jupinder Bedi

The differences that catch teams out are the ones that look cosmetic. DPDP uses Data Fiduciary and Data Principal rather than controller and data subject. Its set of non-consent bases is narrower and framed as "legitimate uses". It has its own notice-language expectation tied to the Eighth Schedule. And the Significant Data Fiduciary regime is not the same thing as GDPR's risk-based triggers.

For a company already running GDPR, the efficient approach is a gap assessment against DPDP specifically rather than an assumption of coverage.

General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.

Jupinder BediJupinder writes on data protection practice at ProtectComply, with a focus on how obligations translate into system behaviour.

Where do you stand under DPDP?

Take the free readiness check and find out in 10 minutes.

Start free readiness check →