Discuss this page with an LLM

What This Means In Practice

Use this table to brief your legal, product and marketing teams.

Question DPDP Direction DPDP vs CCPA: Key Differences Direction Practical Impact
Can we process by default? Often consent-first Often depends on a different legal model India flows may need earlier consent design.
Is a global privacy model enough? No Not always Global privacy work does not map one-to-one to DPDP.
Are children protected differently? Under 18 Check local age thresholds Indian child-user products need stricter review.
Is breach risk enough to trigger work? Yes Yes Security, response and evidence matter in both systems.

Three Questions To Ask Internally

  1. Are we copying a non-India privacy model into an Indian product?
  2. Do our consent flows work for Indian users?
  3. Which global privacy controls can be reused, and which must be redesigned for DPDP?

If you operate across India and another market, do not assume one privacy program covers both. Use the stricter flow where user trust and evidence matter most.

Want all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.

Moving From Opt-Out to Opt-In

The CCPA is built on an opt-out model. This means businesses in California can collect data until a user asks them to stop or not to sell it. The DPDP Act uses an opt-in model. In India, you must get clear consent before you start processing digital personal data. If you use the same data collection flow for both regions, you likely violate Indian law. You cannot assume that because a user did not click “Do Not Sell,” they have consented to processing in India.

Stricter Rules for Minor Data

India has a higher age threshold for children than California. Under the DPDP Act, anyone under 18 is a child. Processing their data requires verifiable parental consent. You are also prohibited from tracking or behaviorally monitoring anyone under 18 in India. California’s CCPA generally sets the threshold at 13 for consent and 16 for the right to opt-in to data sales. This means your age-gate logic must be different for your Indian user base.

FeatureDPDP Act 2023CCPA (California)
Primary ModelOpt-in (Consent required)Opt-out (Right to stop sale)
Data ScopeDigital personal dataPersonal info of CA residents
Children’s AgeUnder 18Under 13 (and 16 for sales)
Right to DeleteRight to erasureRight to request deletion
Sale of DataCovered by general consentSpecific “Do Not Sell” rules
Notice RequirementNotice in English and 22 languagesNotice at or before collection
EnforcementData Protection BoardCalifornia Privacy Protection Agency

This week

Check your website’s tracking scripts and cookie banners. If you use a single “Do Not Sell” link for all users, update your geo-targeting logic. Ensure users with Indian IP addresses see a clear consent notice that requires an affirmative action before any non-essential tracking pixels or cookies load.

FAQ

Q: Does CCPA compliance meet DPDP requirements? A: No. CCPA is an opt-out law while DPDP requires opt-in consent for most processing. You must update your website logic for Indian users.

Q: How do age requirements differ? A: India defines a child as anyone under 18 and requires parental consent. California uses age 13 for consent and 16 for data sale restrictions.

Q: Do both laws have the same penalties? A: No. CCPA fines are calculated per violation or per person affected. DPDP uses a fixed cap of up to 250 Crore Rupees for major breaches.

Confused by the differences?

Dual compliance is tricky. Our experts can help you navigate both DPDP vs CCPA: Key Differences and DPDP requirements.

Book Strategy Call
Book clarity call