Start with DPDP and GDPR

Compare the questions before you compare the laws.

Start with what a person can do, what a team may need to build, and what practice has shown. Then inspect the complete source-led research model if you need its declared weights.

A first comparison

Three ways to read the DPDP–GDPR pair.

These short summaries orient the reader. Follow the paired essay and sources for the supporting detail.

People

What can a person do?

Both frameworks provide routes to make requests, but the wording, timing and practical evidence need to be read in their own official records.

Open the paired evidence →
Teams

What must a team build?

Both create operational questions around notices, choices, requests and records. This publication maps questions; it does not issue a compliance checklist.

Inspect team questions →
Practice

What has practice shown?

DPDP’s phased commencement means legal text, operative provisions and outcome evidence must remain visibly separate.

Read the limitation →

Evidence horizon

A law on paper is not the same as a result in practice.

We keep these four stages separate. They are a reading aid, not a ranking or score.

  1. 01Enacted text

    What the controlling law says.

  2. 02Operative provisions

    Which parts apply on the stated date.

  3. 03Observed practice

    What can be examined in real use.

  4. 04Outcomes

    What dated evidence can support a result.

Legal-status effective date and source-check date are shown separately near each editorial claim.
Advanced research modelOpen 17 factors, weights, sensitivity and raw values

This browser-only model preserves URL-state behaviour. Its values measure how directly current official sources resolve selected research questions—not legal quality, effectiveness, compliance or a winner.

Transparent weighted comparison · model v1.0.0

See what changes under declared weights.

This model compares how directly current official sources resolve seventeen research questions. It does not measure which law is better, certify compliance or recommend a jurisdiction.

Modelv1.0.0Reviewed 2026-08-30

A broad starting model that gives extra attention to clarity, implementation burden, interoperability and maturity without hiding the weights.

Seventeen factor weights

Set any factor from 0 (excluded) to 10 (highest attention). Keyboard arrows, Home and End work on every control.

Score and ordering view

Values, coverage and the missing record

Every value is editorial, dated and source-resolved.

Rank 5

DPDP

7.39

76% comparable weight

Coverage-qualified

Rank 1

GDPR

8.43

100% comparable weight

Coverage-qualified

Rank 4

CCPA

7.53

90% comparable weight

Coverage-qualified

Rank 2

PDPA

7.73

96% comparable weight

Coverage-qualified

Rank 3

LGPD

7.62

100% comparable weight

Coverage-qualified

Under these weights: score, comparable coverage and ordering status. This table is the semantic alternative to the constellation.
FrameworkEditorial value / 10Comparable weightOrderingMissing or non-comparable
India · DPDP Act and Rules7.3976%Rank 5Automated decision and algorithmic accountability; Regulator design and procedural digitisation; MSME implementation burden; Enforcement maturity and published guidance
European Union · GDPR8.43100%Rank 1None at selected weights
California · CCPA/CPRA7.5390%Rank 4Permitted grounds and processing architecture; Cross-border transfer model
Singapore · PDPA7.7396%Rank 2Automated decision and algorithmic accountability
Brazil · LGPD7.62100%Rank 3None at selected weights

Strong case + counterargument

Why each outcome appears—and what could defeat it

The selected weights choose the most consequential cited factor for each side.

DPDP · under these weights

India · DPDP Act and Rules

Strongest supporting case

The Act and Rule 3 publish detailed notice and consent mechanics.

Inspect source
Strongest counterargument

Concision is not used as a proxy for low cost.

Inspect source

GDPR · under these weights

European Union · GDPR

Strongest supporting case

The regulation has applied since 2018 within an extensive supervisory ecosystem.

Inspect source
Strongest counterargument

Detailed recitals, cross-references, national law and guidance can increase the reading burden.

Inspect source

CCPA · under these weights

California · CCPA/CPRA

Strongest supporting case

The statute details notice at collection and consumer-control disclosures, supplemented by regulations.

Inspect source
Strongest counterargument

An architectural difference is not converted into a zero.

Inspect source

PDPA · under these weights

Singapore · PDPA

Strongest supporting case

The official consolidation and obligations guide provide complementary statute and plain-language entry points.

Inspect source
Strongest counterargument

Sectoral guidance may exist, so missing evidence is not a zero.

Inspect source

LGPD · under these weights

Brazil · LGPD

Strongest supporting case

The LGPD states transparency principles, consent conditions and information rights.

Inspect source
Strongest counterargument

The Portuguese text controls and the English translation may lag later amendments.

Inspect source

Sensitivity view

Which assumption can change the visible outcome?

Each row removes one positive-weight factor, recalculates the model and reports the largest shift.

Leave-one-factor-out sensitivity under the current weights.
Factor removedRemoved weightLeader after removalLeader changes?Largest value shift
MSME implementation burden8GDPRNo0.24
Accessibility and drafting clarity8GDPRNo0.20
Notice and consent usability7GDPRNo0.12
Enforcement maturity and published guidance7GDPRNo0.11
Regulator design and procedural digitisation6GDPRNo0.10
Scope and extra-territorial reach5GDPRNo0.09
Children and guardian treatment5GDPRNo0.09
Data protection impact and risk duties5GDPRNo0.09
Cross-border transfer model5GDPRNo0.09
Permitted grounds and processing architecture6GDPRNo0.08
Withdrawal and preference control7GDPRNo0.06
Security and breach response7GDPRNo0.06
Individual rights and grievance pathways7GDPRNo0.05
Penalty design5GDPRNo0.04
Interoperability and ecosystem potential7GDPRNo0.04
Processor and accountability architecture6GDPRNo0.03
Automated decision and algorithmic accountability4GDPRNo0.02

Separate research tool

Now decide what you want to investigate first.

The reading-priority explorer reorders questions only. It never inherits or disguises the editorial comparison as a legal recommendation.

17-factor research-priority explorer

Decide what to investigate first.

These controls reorder your research questions. They do not score a law, recommend a jurisdiction or produce a compliance conclusion.

Methodv2.3.0Reviewed 30.08.26

A broad starting lens that keeps deployability and maturity visible without treating either as decisive.

01Readable rulesHow the legal architecture can be found, understood and translated into a research plan.
Accessibility and drafting clarityHow easily a reader can locate and understand the relevant rule.0How much interpretation is needed before a team can identify the rule that governs its activity?
Evidence guide
Look for
Controlling text, amendment history, commencement records and an issue-specific reading path.
Do not infer
Shorter text is not automatically clearer, safer or cheaper to implement.
Scope and extra-territorial reachWho, what data and which cross-border activities the framework covers.0Which entities, people, data and overseas activities fall inside the framework?
Evidence guide
Look for
Definitions, territorial provisions, exclusions, coverage thresholds and relevant official guidance.
Do not infer
A national market presence does not by itself prove that a specific activity is covered.
Permitted grounds and processing architectureThe legal routes available for processing personal data.0Which processing grounds exist, and how does an organisation document the one it relies on?
Evidence guide
Look for
Operative ground or exception, purpose record, applicable conditions and supporting documentation.
Do not infer
Matching labels across laws do not make processing grounds interchangeable.
Notice and consent usabilityHow the framework structures clear information and meaningful choice.0What must a person be told, when, and in what form before data is used?
Evidence guide
Look for
Operative notice duties, delivery context, language or accessibility rules and tested user comprehension.
Do not infer
Publishing a notice does not prove that people saw or understood it.
02Individual agencyWhat people can understand, choose, contest and ask organisations to do.
Withdrawal and preference controlHow a person can revise a choice or stop consent-based processing.0Can a person reverse a choice through a practical, understandable route?
Evidence guide
Look for
Operative withdrawal rule, interface steps, downstream propagation and documented exceptions.
Do not infer
A stated right to withdraw does not prove that the practical route is equivalent to giving consent.
Individual rights and grievance pathwaysRights, complaint routes and routes to correction or redress.0Which rights exist, and what must happen before a person can obtain a remedy?
Evidence guide
Look for
Operative right, identity and timing rules, refusal grounds, escalation path and outcome evidence.
Do not infer
A longer catalogue of rights does not by itself show that remedies are more accessible.
Children and guardian treatmentSpecial rules and safeguards for children and people represented by guardians.0How does the framework recognise age, guardianship and risks to younger people?
Evidence guide
Look for
Age definition, guardian mechanism, applicable safeguards, exceptions and child-facing design evidence.
Do not infer
A single age threshold does not capture the whole child-safety or guardian model.
Automated decision and algorithmic accountabilityRules and recourse connected with automated or profiled outcomes.0What transparency or recourse applies when automated processing affects a person?
Evidence guide
Look for
Scope of covered decisions, explanation or notice duties, contest route and evidence of human review.
Do not infer
Generic transparency language does not establish a right against every automated outcome.
03Organisational architectureHow duties, safeguards, risk processes and transfer mechanisms are organised.
Processor and accountability architectureHow responsibility is divided across organisations and service providers.0Who remains accountable when processing is delegated or shared?
Evidence guide
Look for
Role definitions, contracts, instruction boundaries, onward delegation and responsibility for failures.
Do not infer
Vendor terminology in one framework cannot be copied directly into another role system.
Security and breach responseSafeguard duties and incident-notification pathways.0Which safeguards and breach steps are specified, and when are they triggered?
Evidence guide
Look for
Operative safeguard standard, trigger tests, notification recipients, timing and incident records.
Do not infer
A detailed checklist does not prove effective security or consistent breach response.
Data protection impact and risk dutiesStructured assessment duties for higher-risk processing.0When must an organisation investigate and document risk before processing?
Evidence guide
Look for
Trigger criteria, required assessment content, reviewer or consultation route and retained decision record.
Do not infer
Using an impact-assessment template does not prove that the relevant risks were identified.
Cross-border transfer modelHow overseas transfers are permitted, restricted or documented.0Which transfer routes exist, and what continuing safeguards travel with the data?
Evidence guide
Look for
Destination, transfer route, restrictions, contract or assessment record and onward-transfer controls.
Do not infer
A permitted destination does not remove continuing security or accountability duties.
MSME implementation burdenThe implementation work a smaller organisation may need to investigate.0Which obligations create fixed costs, and what tailoring exists for smaller organisations?
Evidence guide
Look for
Role-specific task inventory, exemptions or tailoring, recurring workload and organisation-level cost evidence.
Do not infer
Concise legislation does not prove low implementation cost for a smaller organisation.
Interoperability and ecosystem potentialPotential for reusable, documented technical and procedural patterns.0Could teams implement the rule through portable patterns without weakening legal context?
Evidence guide
Look for
Compatible definitions, documented interfaces, governance ownership and tests across real operating contexts.
Do not infer
Technical reuse does not make the underlying legal requirements equivalent.
04Institutions and remedyHow rules are supervised, enforced, explained and tested through practice.
Regulator design and procedural digitisationInstitutional structure, powers and accessible procedures.0How can people and organisations reach the institution, and what can it do?
Evidence guide
Look for
Operative mandate, procedure, access route, published powers and evidence of actual use.
Do not infer
A digital portal or broad statutory power does not prove timely or accessible resolution.
Penalty designThe published structure for sanctions and procedural safeguards.0How are sanctions linked to conduct, context and due process?
Evidence guide
Look for
Operative penalty provisions, decision factors, appeal route and dated enforcement records.
Do not infer
A higher maximum penalty does not automatically mean stronger protection or enforcement.
Enforcement maturity and published guidanceThe observed record of guidance, decisions and implementation practice.0What has the framework's operation, guidance and enforcement record actually demonstrated?
Evidence guide
Look for
Dated guidance, decisions, enforcement records, appeal outcomes and evidence about access in practice.
Do not infer
Age or publication volume alone is not a measure of institutional quality.

Read the paired records

Four essays, one symmetrical structure.

Each essay asks the same five questions and exposes sources for both sides.

01IN ↔ EU

Reviewed 2026-08-20

DPDP vs GDPR: simplicity, rights and accountability are different questions

One text is younger and substantially phased; the other has applied since 2018. Compare legal architecture without turning age, detail or concision into a verdict.

  • Shared groundBoth texts address consent, individual-facing rights, organisational duties and extra-territorial situations. Those shared headings do not make the mechanics equivalent.
  • Material differenceThe operative position is asymmetric. GDPR applies now; many core DPDP processing duties and rights have a notified date of 13 May 2027.
Open symmetrical comparison
02IN ↔ CA

Reviewed 2026-08-20

DPDP vs California: two different routes to individual control

DPDP's Data Fiduciary/Data Principal terminology and California's covered-business and consumer-rights model organise responsibility differently.

  • Shared groundBoth frameworks foreground notice and individual-facing controls, while preserving context-specific exceptions and organisational duties.
  • Material differenceDPDP's enacted model uses consent and specified certain legitimate uses. California generally centres statutory notice, proportionality and defined consumer controls within a threshold- and role-specific statute.
Open symmetrical comparison
03IN ↔ SG

Reviewed 2026-08-20

DPDP vs Singapore: consent-and-accountability models at different stages

Both frameworks connect consent, organisational responsibility and regulator processes, but their operative histories are very different.

  • Shared groundBoth texts combine consent with statutory alternatives and place responsibility on organisations that determine or carry out processing.
  • Material differenceSingapore's principal framework, breach notification and guidance ecosystem are operative. DPDP's core consent, breach, children's-data and individual-rights provisions are enacted but not yet commenced.
Open symmetrical comparison
04IN ↔ BR

Reviewed 2026-08-20

DPDP vs LGPD: similar ambitions, different legal machinery

Both are national privacy frameworks for large digital economies. That context is a research prompt, not a legal category or proof of equivalence.

  • Shared groundBoth texts have extra-territorial elements and address individual rights, organisational duties, security and overseas data movement.
  • Material differenceDPDP is limited to digital personal data and relies on a smaller enacted set of processing routes. LGPD governs personal-data processing more broadly and enumerates multiple legal bases within an operative framework.
Open symmetrical comparison

Five framework records

Inspect each context independently.

Read the evidence rules
01IN · ACT 22/2023

India

DPDP

Digital Personal Data Protection Act, 2023 and final Rules, 2025

Partially commenced

Enacted in 2023 and partially commenced. Institutional and rulemaking provisions are operative; most substantive processing duties and Data Principal rights have notified future dates.

02EU · 2016/679

European Union

GDPR

Regulation (EU) 2016/679

Applicable since 2018

A directly applicable EU regulation with multiple lawful bases, detailed rights, controller and processor duties, and supervision through national authorities and EU cooperation mechanisms.

03CA · CIV. CODE 1798

California

CCPA

California Consumer Privacy Act, as amended by the CPRA and later legislation

Current statute and regulations

A consumer-privacy statute centred on notice, proportionality and defined consumer controls. Applicability, business roles and current rulemaking must be checked for the specific activity.

04SG · ACT 26/2012

Singapore

PDPA

Personal Data Protection Act 2012

Current amended regime

A current, amended regime combining consent and statutory alternatives with organisational accountability, access and correction, protection, retention, transfer and breach-notification duties.

05BR · LEI 13.709

Brazil

LGPD

Lei Geral de Proteção de Dados Pessoais, Law 13.709/2018

Operative framework

An operative general data-protection law with multiple legal bases, data-subject rights, controller and operator duties, security duties and regulated transfer mechanisms.

Before you infer a winner

Read the argument that could defeat the thesis.

Phased commencement, institutional uncertainty and missing outcome evidence remain first-order constraints.

Open counterargument

Source record

Source record

Authority
Pinpoint
Legal status
Checked
Basis

Official guidance can explain a rule, but it does not replace the controlling legal text.