Opt-in versus opt-out: the core difference
The DPDPA is opt-in. A Data Fiduciary needs a lawful basis before processing: consent under Section 6, or one of the legitimate uses in Section 7. The default is that processing does not happen without that basis.
The CCPA is largely opt-out. A business can process personal information, and the consumer’s protection is the right to opt out of the sale or sharing of their data and of certain targeted advertising. The default leans the other way.
For product design, this is decisive. A California-style “Do Not Sell or Share My Personal Information” link does not satisfy the DPDPA, which needs an affirmative consent or a legitimate use established up front.
The sale of data concept
The CCPA is organised around the sale of personal information, and later the sharing of it for cross-context behavioural advertising. Many CCPA obligations flow from whether a business sells or shares data.
The DPDPA has no concept of sale of data. It regulates processing by reference to consent and legitimate use, not by whether data is sold. A compliance programme ported from California will have controls built around a concept the DPDPA does not recognise, and gaps where the DPDPA needs consent the CCPA never required.
Side by side
The main differences in one view.
| Topic | DPDPA (India) | CCPA / CPRA (California) |
|---|---|---|
| Default basis | Opt-in consent or legitimate use | Processing allowed, opt-out of sale/share |
| Sale of data | No such concept | Central concept |
| Child age | Under 18, parental consent | Special rules around 16 |
| Regulator | Data Protection Board of India | CPPA and Attorney General |
| Headline penalty | Up to 250 crore rupees | Civil penalties per violation |
Rights: similar, not identical
Both laws give individuals access, correction and deletion rights, and both require transparency about processing. A person in either regime can ask what is held and seek deletion.
The difference is the opt-out of sale. The CCPA gives a right to opt out of the sale and sharing of personal information. The DPDPA has no equivalent, because it has no sale concept; its analogue is the ability to withdraw consent under Section 6(4), which is a different mechanism.
How AMLEGALS advises on dual compliance
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance.
The team helps businesses that already meet the CCPA identify what the DPDPA adds, build the opt-in consent and legitimate-use basis India requires, and run both regimes without one undermining the other.

