GDPR vs India's DPDP Act

A plain-English comparison for Indian businesses that ship to EU customers — or vice versa. ConsentHub handles both from one script tag.

TopicGDPR (EU)DPDP Act (India)
EffectiveMay 2018Notified 2023, phased enforcement 2024–25
Applies toAnyone processing EU personal dataAnyone processing Indian personal data
Consent basisOne of six lawful basesConsent-first, narrow legitimate uses
DSAR window1 month (extendable)As prescribed (draft rules: 30 days)
Max penalty€20M or 4% global turnover₹250 crore per violation
DPO requiredFor large / sensitive processorsData Protection Officer for Significant DFs
Data localisationNo, adequacy regimeCentral Govt whitelist of restricted countries
ChildrenUnder 16 (member-state adjustable)Under 18 with verifiable parental consent
Right to erasureYesYes (with retention exceptions)
Breach notice72 hours to supervisory authorityAs soon as possible to Data Protection Board

Ship one banner for both — geo-detected, GCM v2 wired, DPDP + GDPR templates included.