GDPR Compliance

The EU General Data Protection Regulation (GDPR) applies to an Indian business that offers goods or services to people in the European Union, or monitors their behaviour there, even if it has no office in Europe. It also reaches Indian companies indirectly, when they process personal data for European customers under contract.

The GDPR and India’s Digital Personal Data Protection Act, 2023 overlap but are not the same. A business covered by both has to meet each: the DPDP Act for people in India, and the GDPR for people in the EU. The United Kingdom has its own version, the UK GDPR, with similar rules.

When you need it

  • When selling to customers in Europe

    A website, app or software product marketed to people in the EU brings the business within Article 3 of the GDPR.

  • When a European customer sends a data processing agreement

    IT, software and outsourcing companies are asked to sign processor terms and standard contractual clauses before work starts.

  • When European data is stored or accessed in India

    A transfer of personal data from the EU to India needs a legal mechanism, because India has no adequacy decision.

  • When answering a security questionnaire

    European customers ask their vendors for evidence of how they comply, not a statement that they do.

  • When preparing for both laws at once

    One programme can serve both the GDPR and the DPDP Act if it is designed with the differences in mind.

How the process works

Five stages. Timings are typical, not promised.

  1. 1

    Decide whether and how the GDPR applies

    About a week

    Establish whether the business targets people in the EU directly, acts as a processor for European customers, or both. The obligations differ for a controller and a processor.

    Documents

    • A description of the product and its customers
    • Contracts with European customers
    • The current privacy policy
  2. 2

    Map the data

    Two to four weeks

    Record what personal data of people in the EU is collected, for what purposes, where it is stored, who can access it and which vendors receive it.

  3. 3

    Find the gaps

    One to two weeks

    Compare current practice with the GDPR: a lawful basis for each purpose, transparency, individual rights, security, records, vendor contracts and transfers.

  4. 4

    Put the documents in place

    Three to six weeks

    Prepare or revise the privacy notice, data processing agreements, standard contractual clauses with a transfer assessment, records of processing, breach procedure and, where required, an impact assessment.

  5. 5

    Appointments and upkeep

    Ongoing

    Appoint an EU representative and a data protection officer where the GDPR requires them, brief the team, and review the programme when the product or the vendors change.

Common questions

Yes, in two situations under Article 3(2): where it offers goods or services to people in the EU, whether paid or free, or monitors their behaviour within the EU. Simply having a website that Europeans can reach is not enough; there has to be targeting.

To discuss GDPR compliance, write to info@ireniclegal.com or call +91 96547 47331. Written by Adv. Kanika Marwaha Bindal; last updated 7 October 2026.