Executive summary — Any enterprise of reasonable size now faces more than one privacy law at once — India's DPDP for domestic data, the GDPR for European customers, California's CCPA for American ones. Building a separate compliance programme for each is wasteful, but treating them as identical is dangerous, because the differences are exactly where enforcement bites. This comparison sets the three side by side on the dimensions that matter operationally, as a practical companion to eMudhra's guide to data privacy management. The good news for multi-jurisdiction compliance is that the three regimes share a common philosophy: be transparent about data, give individuals control, hold data responsibly, and be accountable. The complication is in the detail — who each law covers, what consent standard it sets, which rights it grants, and how hard it punishes failure. Get the shared principles right and you are most of the way there; miss the jurisdiction-specific differences and you are exposed precisely where you thought you were covered. The Comparison at a Glance Dimension India DPDP EU GDPR California CCPA/CPRA Who it protects Data principals (individuals in India) Data subjects in the EU/EEA California residents (consumers) Primary consent model Opt-in; free, specific, informed, revocable Opt-in; freely given, specific, informed, unambiguous Opt-out of sale/sharing; opt-in for minors Core individual rights Access, correction, erasure, grievance redressal Access, rectification, erasure, portability, objection, restriction Know, delete, correct, opt-out, limit use of sensitive data Response deadline ~45 days (per Rules) 30 days, extendable 45 days, extendable Records of processing Expected via accountability duties Article 30 RoPA required Reasonable records; risk assessments under CPRA Headline penalties Financial penalties per the Act's schedule Up to 4% of global turnover or €20m Per-violation civil penalties Comparison is a general summary as of August 2026 and simplifies complex statutes; obligations vary by circumstance. Confirm specifics with qualified counsel for your jurisdictions and use cases. Consent: Opt-In Versus Opt-Out The sharpest structural difference is the consent model. Both the DPDP framework and the GDPR are opt-in regimes: you generally need affirmative consent, or another lawful basis, before processing. The CCPA is built around opt-out: businesses may process and even sell data unless the consumer says no, with stricter opt-in rules for minors. An organisation that designs one consent flow for all three must reconcile these opposite defaults, which is why a flexible consent management platform with per-jurisdiction templates is so useful. Operating across DPDP, GDPR and CCPA? PrivaTrust applies the right rules per jurisdiction from one platform. Subject Rights and Deadlines All three grant individuals meaningful rights, but the lists and clocks differ. The GDPR is the broadest, adding portability, objection and restriction to the basics, on a thirty-day response clock. The DPDP framework and CCPA both work to roughly forty-five days. For an enterprise, the practical implication is that a single request-handling process must be able to recognise which regime a requester falls under and apply the correct rights and deadline — which is exactly what automated DSAR handling, as covered in eMudhra's guide to data subject rights, is designed to do. Penalties: Why the Differences Matter The stakes are not academic. The GDPR's penalties reach four per cent of global annual turnover or twenty million euros, whichever is higher, and have produced some very large fines. The DPDP Act sets its own schedule of financial penalties, and the CCPA imposes per-violation civil penalties that accumulate quickly across many affected consumers. Because the exposure differs, so should the rigour applied in each jurisdiction — but the underlying data map, consent records and subject-request machinery can and should be shared. One Programme, Many Jurisdictions The efficient answer to overlapping regimes is not three programmes but one privacy operation that applies jurisdiction-specific rules on a shared foundation of discovery, consent and governance. That foundation also connects to broader digital trust, since lawful processing rests on controlling who can access data — the domain of identity and access management — and on being able to prove the integrity of records, the domain of trust services. COMPLY ACROSS EVERY JURISDICTION FROM ONE PLATFORM eMudhra will help you build a shared privacy foundation that applies the right rules for DPDP, GDPR and CCPA. Explore PrivaTrust or talk to an eMudhra expert. Tags: Data Privacy About the Author eMudhra Limited eMudhra Editorial represents the collective voice of eMudhra, providing expert insights on the latest trends in digital security, cryptographic identities, and digital transformation. Our team of industry specialists curates and delivers thought-provoking content aimed at helping businesses navigate the evolving landscape of cybersecurity and trust services with confidence.