DPDP vs GDPR for Indian startups
GDPR compliance gets you most of the way to DPDP compliance, and the gaps are specific enough to close in a sprint. The instinct to assume they are the same regime with different currency is the expensive mistake.
Here is what actually differs for a startup operating in both markets.
Check this site free — DPDP, GDPR & CCPA score in 10 seconds
No signup for the score. Takes about 10 seconds. We only read your homepage.
The differences that change your implementation
Four gaps matter more than the rest.
- Lawful bases: GDPR gives you six, including legitimate interests. DPDP gives you consent plus a narrow list of legitimate uses — there is no legitimate-interests basis for analytics or marketing
- Children: GDPR sets the digital-consent age between 13 and 16 by member state. DPDP sets it at 18 and bans behavioural tracking and targeted ads at children outright
- Consent Managers: DPDP creates a registered Consent Manager entity with no GDPR equivalent, through which Data Principals may manage consent
- Penalties: GDPR is turnover-linked (up to 4% of global turnover). DPDP uses fixed rupee ceilings per breach type
What carries over unchanged
Purpose limitation, data minimisation, breach notification discipline, processor agreements and the core rights of access, correction and erasure all map closely. If you have a working GDPR programme, you are reusing most of it.
The banner is the same banner. What changes is the category model, the notice text, the language coverage and the record you keep.
What valid consent looks like under the DPDP Act
Section 6 of the DPDP Act is unusually specific about consent. It must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited strictly to the personal data necessary for the stated purpose. Bundled consent — one checkbox covering analytics, advertising, marketing email and profiling — does not satisfy this test.
The Act also requires that withdrawal be as easy as giving consent. In practice that means if a visitor could accept tracking with one click on a banner, they must be able to withdraw it with roughly one click too, at any time, from any page. A buried link in a privacy policy is not equivalent.
- No pre-ticked boxes and no implied consent from continued browsing
- Separate opt-in per purpose: analytics, marketing, functional, advertising
- A notice, in plain language, available in English and the Eighth Schedule languages
- A standing, always-reachable way to withdraw consent
- A record of what was consented to, when, and against which notice version
You have to be able to prove it
The obligation that catches most teams out is evidentiary. Under Section 8, the Data Fiduciary — you — is responsible for demonstrating compliance, including that valid consent was obtained. If the Board asks and your answer is "our banner was live", that is not evidence.
A defensible consent record contains, at minimum: a stable visitor identifier, the categories accepted and rejected, a UTC timestamp, the version of the notice shown, the policy text hash, and enough network context to establish the request was genuine without storing raw personal identifiers. AssentRepo writes exactly this record for every consent event and one-way hashes the IP address with a server-side salt, so the log is useful to an auditor and useless to an attacker.
Frequently asked questions
Can we run one banner for both regimes?
Yes, and you should. AssentRepo geo-detects the visitor and serves DPDP, GDPR or CCPA framing from a single script and a single audit log.
Does GDPR-style legitimate interest work for analytics in India?
No. Analytics under DPDP needs consent. This is the single most common assumption that carries over incorrectly.
Get DPDP-ready in five minutes
One script tag: consent banner, audit log, DSAR queue. Free up to 1,000 consent events a month.