Data Privacy & User Rights

GDPR vs DPDP: User Rights and Consent Compared

Side-by-side map of GDPR and India DPDP Act consent rules and user rights, including Article 6 versus Section 7, access, erasure clocks, and what to reuse.

Working summary: GDPR and India’s DPDP Act both demand clear affirmative consent and strong access, correction, and erasure paths. Lawful bases, right catalogues, clocks, and India commencement dates differ. Reuse tooling carefully; do not ship one notice for both.

  • Consent: Both need affirmative action and easy withdrawal. GDPR has six Article 6 bases; DPDP uses consent or Section 7 certain legitimate uses.
  • Access: GDPR Article 15 vs DPDP Section 11 summary and sharing list. A GDPR export is not automatic Section 11 compliance.
  • Clocks: GDPR generally one month (extendable); DPDP grievance period published under Rule 14(3) at most 90 days.
  • India timing: Sections 11 to 17 scheduled for once Rules and commencement are notified. GDPR has been live since 2018.
  • Reuse: Keep DSAR intake and consent logs; rewrite notices, Section 7 maps, and nomination for India.

Teams that already run GDPR programs often ask how India’s Digital Personal Data Protection Act, 2023 (DPDP Act) lines up on user rights and consent. The short answer: both laws demand clear affirmative consent and strong access, correction, and erasure paths, but the lawful bases, right catalogues, clocks, and India commencement dates differ.

This comparison is for product, privacy, and engineering leads who need a working map. It is not a substitute for counsel. For India-specific rights workflows, see the companion guide DPDP Act User Rights: A Practical Guide for Indian Websites. Tooling patterns for access, correction, and erasure are covered in How to Handle DSARs with OneTrust.

DPDP Act Sections 11 to 17 (rights and related provisions) are enacted but scheduled to become operative on once Rules and commencement are notified under forthcoming MeitY commencement notifications. GDPR has been in force since 25 May 2018.

Scope and roles at a glance

Topic GDPR (EU) DPDP Act (India)
Core text Regulation (EU) 2016/679 Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Who is protected Data subject Data Principal
Who decides purpose and means Controller Data Fiduciary
Who processes on instructions Processor Data Processor
Geographic trigger (simplified) Establishment in the EU/EEA, or offering goods/services to / monitoring people in the Union (Arts 2 to 3) Digital personal data processed in India, or processed outside India in connection with offering goods or services to Data Principals in India (Section 3)

If you sell to both EU and Indian customers, treat each law as separately binding for the people and processing it covers. Do not assume one privacy policy paragraph covers both.

GDPR: six Article 6 bases

GDPR Article 6(1) lists lawful bases: consent; contract; legal obligation; vital interests; public task; legitimate interests (with balancing). Consent is only one option. Controllers often rely on contract or legitimate interests for core service processing and reserve consent for optional uses such as marketing cookies or secondary analytics.

Article 4(11) defines consent as a freely given, specific, informed, and unambiguous indication by a statement or clear affirmative action. Meanwhile, Article 7 adds conditions: the controller must be able to demonstrate consent; consent must be distinguishable in written declarations; withdrawal must be as easy as giving consent; and withdrawal does not undo earlier lawful processing.

Recital 32 makes the UI rule plain: silence, pre-ticked boxes, and inactivity are not consent.

Section 4 allows processing only for a lawful purpose with either:

  • consent of the Data Principal, or
  • certain legitimate uses under Section 7.

Section 6(1) requires consent to be free, specific, informed, unconditional, and unambiguous, with a clear affirmative action, limited to personal data necessary for the specified purpose. The Data Principal may withdraw consent at any time under Section 6(4), with ease comparable to giving it. Sections 6(5) to (6) say withdrawal consequences sit with the principal, prior consent-based processing stays lawful, and the fiduciary must cease (and cause processors to cease) within a reasonable time unless other law or the Act still authorises processing.

Separately, Section 5 requires a notice before or with the consent request covering personal data and purpose, how to exercise rights under Section 6(4) and Section 13, and how to complain to the Board. The forthcoming DPDP Rules from MeitY, Rule 3, adds that the notice must stand on its own, use clear and plain language, itemise personal data and purposes (including goods, services, or uses enabled), and give links or other means to withdraw consent, exercise rights, and complain to the Board.

Section 7 lists certain legitimate uses (for example, voluntary provision for a specified purpose where the person has not indicated they do not consent; specified State benefits; employment-related uses; medical emergency; and other listed grounds). These are not a copy of GDPR “legitimate interests”. Map each use to the statute with counsel; do not relabel marketing as a Section 7 use without a fit.

Question GDPR DPDP Act
Affirmative action required? Yes (Art 4(11); Recital 32) Yes (Section 6(1))
Pre-ticked boxes OK? No No (clear affirmative action required)
Withdraw as easy as give? Yes (Art 7(3)) Yes (Section 6(4))
Other common bases besides consent? Five other Art 6 bases, including legitimate interests Section 7 certain legitimate uses (closed list in the Act)
Consent Manager concept? Not in GDPR Yes (Section 6(7) to (9)); registration timing staged in forthcoming MeitY commencement notifications
Notice content prescribed? Arts 12 to 14 transparency Section 5 plus forthcoming Rules Rule 3

Practical takeaway: keep purpose-specific toggles, store consent evidence, and make withdraw one click (or equivalent) in both regimes. Rebuild Indian notices for Rule 3 itemisation rather than shipping a GDPR privacy notice unchanged.

User rights compared

Access

  • GDPR Article 15: confirmation whether personal data are processed; access to the data; and listed information (purposes, categories, recipients, retention, rights, and more).
  • DPDP Act Section 11: for consent-backed processing (including Section 7(a) consent), a summary of personal data and processing activities; identities of other fiduciaries and processors with whom data was shared, plus a description of what was shared; and other prescribed information. Section 11(2) limits some sharing disclosures in law-enforcement contexts.

A GDPR data export does not automatically satisfy Section 11. Build an India summary and sharing list where Section 11 applies.

Correction / rectification

  • GDPR Article 16: rectification of inaccurate data without undue delay; complete incomplete data.
  • DPDP Act Section 12(2): correct inaccurate or misleading data; complete incomplete data; update personal data.

Erasure

  • GDPR Article 17: erasure without undue delay where listed grounds apply (including consent withdrawn and no other basis), subject to Article 17(3) exceptions (freedom of expression, legal obligation, public interest, legal claims, and others).
  • DPDP Act Section 12(3): erase on request unless retention is necessary for the specified purpose or for compliance with any law in force. Section 8(7) also drives erasure on consent withdrawal or when the specified purpose is no longer served, unless law requires retention, and requires processors to erase data you made available.

Other rights worth mapping

Right / duty GDPR DPDP Act
Restriction of processing Article 18 No direct equivalent in Chapter III
Data portability Article 20 No direct equivalent in Chapter III
Object to processing Article 21 No direct equivalent; consent withdrawal and Section 7 limits play related roles
Grievance before regulator Complaint to supervisory authority (Art 77); controller must facilitate rights (Art 12) Section 13 grievance with fiduciary or Consent Manager first; exhaust before Board
Nomination on death/incapacity Not a GDPR Chapter III right in the same form Section 14; forthcoming Rules Rule 14(4)
Principal duties Not framed like DPDP Section 15 Section 15 (no impersonation, no frivolous complaints, authentic correction/erasure info, and related duties)

forthcoming Rules Rule 14 requires fiduciaries to publish how to exercise rights and which identifiers are needed, and to publish a grievance response period not exceeding ninety days.

Response clocks

  • GDPR Article 12(3): generally respond without undue delay and within one month; extend by two further months for complex or numerous requests, with notice to the data subject.
  • DPDP Act: Section 13(2) points to a prescribed grievance response period. Rule 14(3) requires you to publish a period that is reasonable and not more than ninety days, and to put measures in place to meet it. Rights request manners are also prescribed under the Act and Rules.

Set internal SLAs tighter than the outer legal limit in both programs.

What to reuse from a GDPR stack

  1. Keep: purpose inventory, consent logs, DSAR intake, identity verification, processor contracts, retention matrix, breach runbooks.
  2. Rewrite for India: notices (Section 5 / Rule 3), consent vs Section 7 mapping, Section 11 access pack, Section 13 grievance path, Section 14 nomination, children’s rules under Section 9 when you process children’s data.
  3. Do not copy blindly: legitimate interests assessments are not a drop-in for Section 7; Article 15 packs are not automatic Section 11 packs; portability and restriction workflows may remain EU-only.

Build sequence for dual programs

  1. Tag each user and processing activity by jurisdiction (EU, India, both).
  2. Split consent banners and privacy notices so Indian users see Rule 3-ready content.
  3. Configure rights forms with request types that map to GDPR Arts 15 to 17 and DPDP Sections 11 to 14.
  4. Train support on India grievance exhaustion before Board complaints.
  5. Use the runway to once Rules and commencement are notified to test India paths while EU obligations stay live.

Sources

  • Regulation (EU) 2016/679, Articles 4(11), 6, 7, 12, 15 to 21, 77; Recital 32: EUR-Lex.
  • Digital Personal Data Protection Act, 2023, Sections 3 to 8, 11 to 15: MeitY PDF; India Code.
  • MeitY commencement notification forthcoming MeitY commencement notifications, a future MeitY notification date.
  • forthcoming DPDP Rules from MeitY, Rules 3 and 14; MeitY Rules page: DPDP forthcoming Rules.

Disclaimer

This article was prepared by Imran using publicly available information. It is for general education only and is not legal advice. Do not rely on it alone when implementing cookie compliance, DSAR handling, consent flows, privacy policies, or other privacy and data-protection controls. Consult your own legal counsel for advice that fits your business, jurisdictions, and systems.

Last updated on 8 September 2026

Share this article

Leave a Reply

Your email address will not be published. Required fields are marked *