A plain-English comparison for Indian businesses that ship to EU customers — or vice versa. ConsentHub handles both from one script tag.
| Topic | GDPR (EU) | DPDP Act (India) |
|---|---|---|
| Effective | May 2018 | Notified 2023, phased enforcement 2024–25 |
| Applies to | Anyone processing EU personal data | Anyone processing Indian personal data |
| Consent basis | One of six lawful bases | Consent-first, narrow legitimate uses |
| DSAR window | 1 month (extendable) | As prescribed (draft rules: 30 days) |
| Max penalty | €20M or 4% global turnover | ₹250 crore per violation |
| DPO required | For large / sensitive processors | Data Protection Officer for Significant DFs |
| Data localisation | No, adequacy regime | Central Govt whitelist of restricted countries |
| Children | Under 16 (member-state adjustable) | Under 18 with verifiable parental consent |
| Right to erasure | Yes | Yes (with retention exceptions) |
| Breach notice | 72 hours to supervisory authority | As soon as possible to Data Protection Board |
Ship one banner for both — geo-detected, GCM v2 wired, DPDP + GDPR templates included.