FinHub Compliance Desk
DPDP & regulatory · 5 May 2026 · 8 min read
Last updated 16 August 2026
Many BFSI compliance teams reach for GDPR as a mental model when preparing for India's Digital Personal Data Protection Act. It's a reasonable starting point — DPDP borrows GDPR's vocabulary and structure — but treating the two as interchangeable will lead you astray. The differences are precisely the places where a GDPR-trained instinct gives the wrong answer. Here are the ones that matter for BFSI.
Fewer legal bases for processing
GDPR offers six lawful bases for processing — consent, contract, legal obligation, vital interests, public task and legitimate interests. DPDP is deliberately narrower: it relies primarily on consent, plus a defined set of 'legitimate uses' specified in the Act. There is no open-ended 'legitimate interests' basis to fall back on. For BFSI, this raises the stakes on getting consent right, because you have fewer alternative grounds when consent is absent or withdrawn.
A different, shorter set of rights
The rights catalogues don't line up. DPDP grants individuals rights to access, correction, erasure, grievance redressal and nomination. Notably, it does not include a GDPR-style right to data portability or a standalone right to object to processing. So a control you might have built for GDPR — a data-export feature for portability — isn't mandated the same way here, while nomination (letting someone act on a Data Principal's behalf) is a DPDP-specific concept with no direct GDPR twin.
Penalties are capped, not turnover-linked
This is a structural difference. GDPR fines scale with global turnover — up to 4% of worldwide annual revenue. DPDP instead specifies fixed monetary ceilings per type of violation, with the headline being up to ₹250 crore for failing to take reasonable security safeguards. For a large institution, a turnover-linked regime and a fixed-cap regime produce very different risk calculations, and your board-level framing of exposure should reflect that.
Narrower extraterritorial reach
GDPR reaches organisations outside the EU both when they offer goods or services to people in the EU and when they monitor their behaviour. DPDP's extraterritorial hook is narrower: it applies to processing outside India that's connected to offering goods or services to individuals in India, without GDPR's separate 'monitoring of behaviour' prong. The practical footprint is different, which matters for cross-border data flows and vendor arrangements.
No separate 'special category' of sensitive data
GDPR singles out special categories of personal data — health, biometrics, religion and so on — for heightened protection. DPDP, as drafted, does not create an equivalent tiered category of sensitive data with distinct rules. It does add specific protections in areas like children's data, but the overall structure treats personal data more uniformly. A GDPR-style data classification built around special categories won't map cleanly onto DPDP obligations.
What this means in practice
The terminology overlaps — DPDP's 'Data Principal' and 'Data Fiduciary' echo GDPR's 'data subject' and 'controller' — but you should map DPDP obligations directly from the Act rather than assuming your GDPR programme already covers them. In BFSI specifically, that means doubling down on consent (you have fewer fallbacks), recalibrating which data-subject-rights workflows you actually need, and reframing penalty exposure around fixed caps rather than turnover.
FinHub's DPDP Governance Platform is built to the Indian Act's own requirements — purpose-bound consent, the DPDP rights set, and audit trails mapped to DPDP obligations — so you're implementing the law that applies, not a European approximation of it.