DPDP Rules status: compliance window active. Read the update

Skip to content
Going Global · AI Policy

DPDP vs GDPR, framed for AI builders

Building an AI product for both India and Europe? The two regimes agree on the basics and then split apart exactly where AI lives — training data, public data, automated decisions. Here's a side-by-side on the points that actually matter for AI, not a generic feature list.

Educational only · not legal adviceReviewed by Sandesh Kokate, Editor
A caveat first

India's AI Governance Guidelines are soft law — they can't override the DPDP Act. So where the Act is silent or ambiguous about AI, that's an open interpretive question, not a settled rule. We flag those spots below rather than paper over them.

Six points that matter for AI

  • Legal basis for training on personal data

    DPDP (India)
    Consent-first. There is no general 'legitimate interest' basis — only a closed list of 'legitimate uses' (Section 7: legal obligations, government functions, medical emergencies, employment, etc.). Reusing data collected for another purpose to train a model generally needs fresh, specific consent.
    GDPR (EU)
    Legitimate interest (Art 6(1)(f)) can support AI training and deployment, per the EDPB's Opinion 28/2024, if it passes a three-step Legitimate Interests Assessment.
    For AI builders

    Europe offers a flexible (if conditional) basis for training; India usually pushes you back to consent.

  • Publicly available / scraped personal data

    Interpretive
    DPDP (India)
    India's DPDP Act has a broad carve-out. If someone has made their personal data publicly available themselves, or the law requires it to be public, the Act largely does not apply to it — section 3(c)(ii).
    GDPR (EU)

    The EU has moved the other way. In July 2026 the EDPB published draft guidelines saying plainly that public visibility is not a legal basis. If scraped data includes personal data, the GDPR applies to it.

    What the draft guidelines say, if you train models on scraped data:

    • Consent will not work at scale. You need legitimate interest instead, and you have to document the balancing test.
    • robots.txt, ai.txt, CAPTCHAs and login walls now count. Ignoring them weighs against you, because they show what people reasonably expected.
    • You must still publish a clear privacy notice, even if telling each person individually would be disproportionate. You must also offer a way to opt out before you collect.
    • Buying a scraped dataset from a broker does not move the problem to the broker.
    • Special-category data — health, beliefs, biometrics — is off limits unless you have an Article 9(2) exception.

    These are drafts. Consultation runs to 30 October 2026, so the wording can still change.

    For AI builders

    India and the EU now sit far apart on this.

  • Automated decisions & profiling

    DPDP gap
    DPDP (India)
    No dedicated automated-decision-making right. General duties (purpose-specific consent, data accuracy) apply, but there is no specific provision letting a person object to a solely automated decision.
    GDPR (EU)
    Article 22 gives a right not to be subject to a solely automated decision with legal or similarly significant effects, plus safeguards like human review.
    For AI builders

    Europe constrains automated decisioning head-on; India, for now, does not.

  • Research / statistical exemption

    DPDP (India)
    Processing for research, archiving or statistical purposes is exempt (Section 17(2)(b)) — but only if done to prescribed standards and NOT used to make decisions about specific individuals.
    GDPR (EU)
    Article 89 allows research processing with safeguards (data minimisation, etc.).
    For AI builders

    Both offer a research lane. India's fits a pure research model, not a deployed product that acts on individuals.

  • Children's data

    DPDP (India)
    Anyone under 18. Verifiable parental consent required; no behavioural monitoring; no targeted advertising to children.
    GDPR (EU)
    Consent age 16 for online services (member states may lower to 13); profiling of children is discouraged but not banned outright.
    For AI builders

    India is stricter and broader — if under-18s can use your product, the full regime applies. See our children's-data page.

  • Cross-border transfers

    DPDP (India)
    Transfers are allowed to every country EXCEPT those the government restricts (a blacklist) — and no restricted list has been notified yet. Sector rules (e.g. RBI localisation) still apply on top.
    GDPR (EU)
    Transfers allowed to 'adequate' countries, or with safeguards like Standard Contractual Clauses (an allowlist).
    For AI builders

    Opposite defaults — India permits by default, the EU restricts by default. See what's still pending.

Bottom line for AI builders

The two regimes are closest on children and research, and diverge most on training basis, public data, and automated decisions. India is more permissive on public and training data but currently offers individuals less on automated decisions — and several DPDP-for-AI questions remain interpretive, so treat the training-data and public-data positions as directional, not final.

Sources

Source
MeitY — DPDP Act (Gazette PDF)

DPDP Act, 2023 — Sections 3(c)(ii), 7, 9, 16 & 17(2)(b)

Status unverified — no status check recorded

Source
EUR-Lex — GDPR official text

EU GDPR — Regulation (EU) 2016/679 (Arts 6, 8, 9, 22, 89)

Status unverified — no status check recorded

Source
EDPB — Opinion 28/2024

EDPB Opinion 28/2024 on AI models

Status unverified — no status check recorded

Source
EDPB Guidelines 03/2026 on web scraping in the context of generative AI

Draft. Consultation runs to 30 October 2026, so the wording can still change.

Draft — checked 2026-08-18

Source

EDPB Guidelines 02/2026 on anonymisation

Draft. Consultation runs to 30 October 2026. Replaces the 2014 opinion and sets three tests for anonymity — no record isolation, no linkage, no inference. Whether data is anonymous can differ between two organisations holding it. No URL sourced.

Draft — checked 2026-08-18

Last updated: 4 Sep 2026 · Reviewed by Sandesh Kokate, Editor

Educational only, and a high-level comparison — not jurisdiction-specific legal advice. Re-verify against the Gazette of India and EUR-Lex before relying on anything here.

How does this apply to you?

Take the 2-minute self-check to find out whether you're a Data Fiduciary, Data Processor, or both — with your personalised action checklist.

Take the DPDP Applicability Check

Nothing you answer leaves your browser.