GDPR Compliance
The EU General Data Protection Regulation (GDPR) applies to an Indian business that offers goods or services to people in the European Union, or monitors their behaviour there, even if it has no office in Europe. It also reaches Indian companies indirectly, when they process personal data for European customers under contract.
The GDPR and India’s Digital Personal Data Protection Act, 2023 overlap but are not the same. A business covered by both has to meet each: the DPDP Act for people in India, and the GDPR for people in the EU. The United Kingdom has its own version, the UK GDPR, with similar rules.
When you need it
When selling to customers in Europe
A website, app or software product marketed to people in the EU brings the business within Article 3 of the GDPR.
When a European customer sends a data processing agreement
IT, software and outsourcing companies are asked to sign processor terms and standard contractual clauses before work starts.
When European data is stored or accessed in India
A transfer of personal data from the EU to India needs a legal mechanism, because India has no adequacy decision.
When answering a security questionnaire
European customers ask their vendors for evidence of how they comply, not a statement that they do.
When preparing for both laws at once
One programme can serve both the GDPR and the DPDP Act if it is designed with the differences in mind.
How the process works
Five stages. Timings are typical, not promised.
- 1
Decide whether and how the GDPR applies
About a weekEstablish whether the business targets people in the EU directly, acts as a processor for European customers, or both. The obligations differ for a controller and a processor.
Documents
- A description of the product and its customers
- Contracts with European customers
- The current privacy policy
- 2
Map the data
Two to four weeksRecord what personal data of people in the EU is collected, for what purposes, where it is stored, who can access it and which vendors receive it.
- 3
Find the gaps
One to two weeksCompare current practice with the GDPR: a lawful basis for each purpose, transparency, individual rights, security, records, vendor contracts and transfers.
- 4
Put the documents in place
Three to six weeksPrepare or revise the privacy notice, data processing agreements, standard contractual clauses with a transfer assessment, records of processing, breach procedure and, where required, an impact assessment.
- 5
Appointments and upkeep
OngoingAppoint an EU representative and a data protection officer where the GDPR requires them, brief the team, and review the programme when the product or the vendors change.
Common questions
Yes, in two situations under Article 3(2): where it offers goods or services to people in the EU, whether paid or free, or monitors their behaviour within the EU. Simply having a website that Europeans can reach is not enough; there has to be targeting.
A controller decides why and how personal data is processed. A processor handles it on the controller’s instructions. An Indian software or outsourcing company is usually a processor for its customers’ data and a controller for its own.
India has no adequacy decision from the European Commission, so transfers normally rely on the Commission’s standard contractual clauses, together with an assessment of the transfer and any extra safeguards needed.
A business outside the EU that is caught by Article 3(2) must appoint a representative in the EU under Article 27, unless its processing is occasional, small in scale and low in risk.
The DPDP Act relies mainly on consent and a short list of legitimate uses; the GDPR has six lawful bases, including legitimate interests. The GDPR covers paper records and has special categories of data. The breach deadlines, rights and penalties also differ.
For the most serious infringements, up to twenty million euros or four per cent of worldwide annual turnover, whichever is higher. A processor can also lose European customers over a failure, which is often the more immediate risk.
A controller must notify the supervisory authority within 72 hours of becoming aware of a breach, unless it is unlikely to put people at risk. A processor must tell its controller without undue delay.
The United Kingdom has its own law, the UK GDPR with the Data Protection Act 2018, which is close to the EU regulation. A business with customers in both has to consider each, including separate transfer documents.
Related
To discuss GDPR compliance, write to info@ireniclegal.com or call +91 96547 47331. Written by Adv. Kanika Marwaha Bindal; last updated 7 October 2026.

