DPDPA Phase II enforcement 13 November 2026 — penalties up to ₹250 crore. Check your readiness →
Book a Demo
Regulatory

DPDPA vs GDPR: What Global SaaS Teams Must Change for India

Data Adhikaar Editorial Team 6 July 2026 2 min read

If you run a GDPR programme, roughly 60% of your DPDPA work is conceptually done — data mapping, consent tooling, rights workflows and vendor governance all carry over. The remaining 40% is where teams get burnt, because the two laws diverge on fundamentals.

The differences that bite

1. No legitimate-interest basis. GDPR's Article 6(1)(f) workhorse does not exist in India. DPDPA recognises consent and a closed list of "certain legitimate uses" (Section 7) — voluntary provision for a specified purpose, employment, medical emergencies, State functions and a few others. Every processing activity currently riding on "legitimate interests" needs a new home: consent, or a specific Section 7 ground.

2. Every breach is notifiable. GDPR notifies the regulator only when a breach is likely to result in risk. DPDPA has no threshold: every personal data breach goes to the Board and to affected Data Principals. Your global incident triage tree needs an India branch that skips the risk assessment step. See the 72-hour playbook.

3. A child is under 18 — not 13–16 as under GDPR/COPPA. Verifiable parental consent plus a ban on tracking and targeted ads at children (Section 9). For consumer SaaS this can reshape onboarding.

4. No special-category regime — but higher stakes everywhere. DPDPA doesn't formally distinguish "sensitive" data; instead it applies strong duties to all digital personal data, with the ₹250 crore security ceiling looming over everything.

5. Fixed penalty ceilings, per instance. Not 4% of global turnover — but ₹250 crore (~$30M) per instance stacks quickly across repeated failures. See how penalties work.

6. Fewer rights, tighter grievance loop. No portability or objection rights, but access, correction, erasure, grievance redressal and nomination (unique to India) — with response windows set by the Rules.

7. Consent language. Notices must be available in English and the 22 languages of the Eighth Schedule — a real product and localisation task, not a legal memo.

The pragmatic path

Run one privacy programme with an India overlay: shared data inventory, shared security controls; India-specific legal-basis mapping, notice/language layer, breach branch and children's rules. Data Adhikaar implements the overlay natively — see DPDPA for SaaS and the full DPDPA vs GDPR guide.

#dpdpa-vs-gdpr#saas#global-privacy#dpdpa

Data Adhikaar Editorial Team

DPDPA Compliance Specialists, Qodequay Technologies

Get DPDPA-ready before the enforcement window closes.

Start with a free readiness assessment, or book a demo of the Data Adhikaar agent fabric.

Or call +91 98226 28174