Foundational Divergences
DPDPA and GDPR share conceptual foundations in principles like lawfulness, purpose limitation, and data minimisation. However, they diverge fundamentally in scope and approach.
DPDPA applies exclusively to digital personal data. Paper records fall outside its scope. This is a departure from GDPR, which applies regardless of medium. The consent architecture also differs materially. While both require informed, specific consent, DPDPA prohibits conditional consent more explicitly and gives withdrawal parity statutory force.
Legitimate interests, a cornerstone GDPR processing basis, has no direct equivalent in DPDPA's "legitimate uses" framework. The Indian framework is narrower and more prescribed. Extraterritorial reach creates overlapping compliance obligations for multinationals, though DPDPA ties its territorial scope explicitly to offering goods or services rather than GDPR's broader monitoring criterion.
