AMLEGALS — Strategic Lawyering
← All Insights
Article

DPDPA Consent vs GDPR Consent: 9 Critical Differences Every Dual-Regime Company Must Understand

Anandaday MisshraAugust 2026
DPDPA Consent vs GDPR Consent: 9 Critical Differences Every Dual-Regime Company Must Understand

The Assumption That Consent Is Consent

Companies operating under both the GDPR and the DPDPA routinely assume that a GDPR-compliant consent mechanism will satisfy Indian law. This assumption is structurally incorrect. While both regimes require informed, specific, unambiguous consent, they differ in nine fundamental ways that affect implementation architecture.

1. Legal Basis Hierarchy

The GDPR provides six legal bases for processing (Article 6), of which consent is merely one. The DPDPA reduces this to two: consent (Section 6) and legitimate uses (Section 7). Companies that process Indian data under GDPR's "legitimate interests" basis (Article 6(1)(f)) have no equivalent under DPDPA — legitimate interests is not a recognised ground. This alone invalidates many dual-regime processing architectures.

2. Consent Withdrawal Architecture

Under Article 7(3) GDPR, withdrawal must be "as easy as" giving consent. Section 6(4) of the DPDPA goes further — withdrawal must be possible at any time and the Data Fiduciary must stop processing within a reasonable period. But the DPDPA adds a consequence GDPR does not: under Section 6(5), withdrawal of consent triggers an obligation to erase all personal data unless retention is required under another law. GDPR has no automatic erasure trigger on withdrawal.

3. Children's Consent Threshold

GDPR sets the threshold at 16 years (with Member State flexibility to lower to 13). The DPDPA sets it at 18 years with no flexibility. Platforms that use a 13-year threshold under GDPR must implement a separate, higher threshold for Indian users — requiring dual age-verification architectures.

4. Granularity of Purpose Specification

Both laws require purpose-specific consent. But the DPDPA's Section 5 notice requirements are more prescriptive — every processing purpose must be itemised with the specific personal data to be collected. GDPR's "specified, explicit and legitimate purposes" (Article 5(1)(b)) permits a degree of purpose aggregation that DPDPA does not.

5. Consent Record Obligations

GDPR requires controllers to demonstrate consent was obtained (Article 7(1)). The DPDPA, through Rule 4 and the Consent Manager framework, creates an institutional infrastructure for consent record-keeping that has no GDPR equivalent. Consent Managers registered under Rule 4 must maintain records for seven years.

6. Cross-Border Consent Portability

A GDPR consent obtained in Germany does not automatically satisfy DPDPA requirements for the same processing of the same data principal's data in India. Consent is jurisdiction-specific. Companies must obtain fresh DPDPA-compliant consent for Indian processing, even if the data principal previously consented under GDPR.

7. Affirmative Action Standard

Both laws require "clear affirmative action." But the DPDPA, through its subordinate rules, prescribes specific formats for consent notices and withdrawal mechanisms. GDPR provides principles; DPDPA provides formats. Non-compliance with format requirements is a contravention even if the underlying consent was genuine.

8. Bundled Consent Prohibition

GDPR restricts consent bundling through Article 7(4) (cannot make service conditional on consent to unnecessary processing). The DPDPA goes further — Section 6(3) requires that consent be limited to personal data necessary for the specified purpose. Any data collection beyond what is necessary for the stated purpose is non-compliant, regardless of whether the user agreed.

9. Penalty Asymmetry

GDPR penalties for consent violations reach €20 million or 4% of global turnover. DPDPA penalties for non-compliance with Section 6 consent requirements reach ₹250 crore (approximately €27 million at current rates). For a mid-size company, the DPDPA penalty cap may actually exceed the GDPR calculation.

Implementation Implications

Dual-regime companies cannot use a single consent management platform configured for GDPR compliance and assume DPDPA compliance follows. The consent architecture must be jurisdiction-aware, with Indian data principals receiving DPDPA-specific notices, purpose itemisation, and withdrawal mechanisms that comply with Indian format requirements.

Need guidance on this topic?

We advise organisations across India on DPDPA compliance, AI governance and cross border data transfers.

Get in Touch →