Skip to content
Back to Blog
·9 min read·compliance

GDPR Compliance Guide for Indian Companies Serving EU Customers

GDPR applies to Indian companies targeting EU residents — server location is irrelevant. Covers scope, SCCs, breach notification, and a compliance roadmap.

BR

Bachao.AI Research Team

Cybersecurity Research

Check DPDP Compliance

Compliance risk for Indian SMBs

Non-compliance with the DPDP Act 2023 carries penalties up to ₹250 crore. This post explains what's at stake and what action to take.

If your Indian company sells to EU residents, processes their personal data, or tracks their online behaviour, GDPR applies to you — regardless of where your servers sit. The EU General Data Protection Regulation (Regulation (EU) 2016/679) has explicit extraterritorial reach under Article 3(2). Non-compliance exposes your company to enforcement by EU data protection authorities, who can impose fines proportionate to global annual turnover. This guide covers when GDPR applies to an Indian business, what it requires, how it compares to India's own DPDP Act 2023, and a practical compliance roadmap.

4%Maximum fine as share of global annual turnover for Tier-1 GDPR violations (GDPR Article 83)
72hMaximum time to notify supervisory authority after discovering a personal data breach (GDPR Article 33)

Does GDPR Apply to Your Indian Company?

GDPR's territorial scope is defined in Article 3. An Indian company falls under GDPR if it meets either of two triggers — even with no EU establishment.

graph TD A[Indian Company Processes Data] --> B{EU establishment?} B -- Yes --> C[GDPR applies — Article 3-1] B -- No --> D{Offering goods or services
to EU residents?} D -- Yes --> E[GDPR applies — Article 3-2a] D -- No --> F{Monitoring behaviour
of EU residents?} F -- Yes --> G[GDPR applies — Article 3-2b] F -- No --> H[GDPR does not apply
Document this conclusion] style C fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 style E fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 style G fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style H fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style A fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style B fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style D fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style F fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0

Trigger 1 — Offering goods or services (Article 3(2)(a)): Indicators include pricing in EUR, shipping to EU addresses, EU-language websites, accepting EU payment methods, or running ads targeted at EU Member States. A free SaaS product available to EU users also qualifies.

Trigger 2 — Monitoring behaviour (Article 3(2)(b)): If you deploy analytics, cookies, tracking pixels, or any profiling mechanism that follows EU residents' online behaviour, GDPR applies even if you never intend to sell to them directly.

⚠️
WARNING
"We are an Indian company" is not a GDPR defence. EU supervisory authorities have pursued non-EU companies. If you process EU resident data, document your legal basis and appoint an EU Representative under Article 27 — failure to do so is itself a violation.

Key GDPR Obligations for Indian Controllers

Once GDPR applies, you take on the role of data controller (or processor if you act on instructions from an EU controller). The core obligations are:

1. Lawful Basis for Processing

Article 6 requires a lawful basis before processing any personal data. The six bases are consent, contract, legal obligation, vital interests, public task, and legitimate interests. For most Indian B2C companies serving EU customers, the practical choices are:

    1. Consent — must be freely given, specific, informed, and unambiguous. Pre-ticked boxes are invalid.
    2. Contract — processing is necessary to fulfil a contract with the data subject (e.g., processing a customer's shipping address to deliver an order).
    3. Legitimate interests — permitted when your interest is not overridden by the individual's rights. Requires a documented Legitimate Interests Assessment (LIA).

Where consent is your lawful basis, GDPR sets a high bar. Consent must be granular (one tick per purpose), withdrawable at any time, and as easy to withdraw as to give. Keep timestamped consent records; you must demonstrate consent was obtained lawfully if challenged.

💡
TIP
If you collect consent for both marketing emails and analytics tracking, these must be separate tick-boxes. Bundled consent is invalid under GDPR Recital 43.

3. Data Subject Rights

EU residents can exercise eight rights against your company. You have one calendar month to respond to most requests.

RightArticleWhat It Requires
Access15Provide a copy of all data held about the person
Rectification16Correct inaccurate or incomplete data within 1 month
Erasure ("Right to be Forgotten")17Delete data when no longer necessary, consent withdrawn, or objection upheld
Restriction of Processing18Pause processing while a dispute is resolved
Data Portability20Export data in machine-readable format on request
Object21Opt out of legitimate-interests or direct-marketing processing
Automated Decision-Making22Refuse decisions made solely by algorithm without human review
Lodge Complaint77Right to complain to a supervisory authority in their Member State

4. Data Protection Officer

A DPO is mandatory under Article 37 if your core activities involve large-scale systematic monitoring of individuals or large-scale processing of special category data (health, biometrics, political opinions, etc.). Many Indian SaaS companies will not meet this threshold, but should document the reasoning. Where required, the DPO must be independent, expert in data protection law, and their contact details published.

5. Breach Notification

Article 33 requires notifying the competent EU supervisory authority within 72 hours of becoming aware of a personal data breach likely to result in risk to individuals. If the breach is high-risk to the individuals themselves, you must also notify them directly under Article 34. Document all breaches — even low-risk ones — in an internal breach register.

6. Records of Processing Activities

Article 30 requires a written Record of Processing Activities (RoPA). This is a structured internal document listing every processing activity: purpose, categories of data subjects and data, recipients, retention periods, and transfers to third countries. Companies with fewer than 250 employees are partially exempt unless processing is high-risk, non-occasional, or involves special categories.


Cross-Border Data Transfers to India

India does not currently hold an EU adequacy decision (as of mid-2026). This means transferring EU personal data to India requires a transfer mechanism under Chapter V of GDPR:

    1. Standard Contractual Clauses (SCCs): The most practical mechanism. The European Commission updated SCCs in June 2021. You must use the current 2021 version and conduct a Transfer Impact Assessment (TIA) to evaluate Indian legal protections against EU standards.
    2. Binding Corporate Rules (BCRs): For multinational groups — expensive and time-consuming to obtain.
    3. Derogations under Article 49: Limited exceptions (explicit consent for specific transfer, contract performance, vital interests). Not suitable for routine commercial transfers.
🚨
DANGER
Using the pre-2021 SCC templates is no longer valid. If your DPA, sub-processor agreement, or customer contract still references the 2010 controller-processor SCCs, replace them immediately with the European Commission's June 2021 version available at ec.europa.eu.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

GDPR vs DPDP Act 2023 — Key Differences

India's Digital Personal Data Protection Act 2023 (DPDP) shares GDPR's spirit but differs in important ways. If you are building a compliance programme for both, understanding the gaps saves significant rework. Visit our DPDP compliance guide for the India-specific framework.

xychart-beta title "GDPR vs DPDP — Obligation Strength Score (1-5)" x-axis ["Consent Rules", "Data Subject Rights", "DPO Mandate", "Breach Notification", "Cross-Border Rules", "Penalty Regime"] y-axis "Score" 1 --> 5 bar [5, 5, 4, 5, 5, 5] bar [4, 3, 2, 3, 3, 4]

Bar 1 = GDPR | Bar 2 = DPDP Act 2023 (based on enacted text; Rules pending as of mid-2026)

DimensionGDPRDPDP Act 2023
ScopeAny processing of EU resident dataProcessing of digital personal data in India or data of Indian residents
Lawful BasesSix bases including legitimate interestsConsent + legitimate uses (narrower list, no general "legitimate interests")
Data Subject RightsEight distinct rightsFive rights (access, correction, erasure, grievance, nominate)
DPOMandatory in specific high-risk casesSignificant Data Fiduciaries must appoint DPO
Breach Notification72 hours to supervisory authorityTo Data Protection Board — timeline in Rules (not yet finalised)
Children's DataParental consent below 16 (or lower if Member State allows)Parental consent below 18; no processing for targeted advertising
Adequacy / TransferSCCs, BCRs, adequacy decisionsBlacklist model — Central Government will notify restricted countries
Penalty StructureUp to 4% of global annual turnoverAmong the highest penalties in Indian law — very significant for SMBs (MeitY, DPDP Act 2023)
Extraterritorial ReachExplicit (Article 3)Yes — processing data of Indian residents abroad is covered

Practical GDPR Compliance Path for an Indian Company

A realistic six-step programme for a small to mid-size Indian B2B or B2C company:

Step 1 — Scope Assessment (Week 1–2) Map every data flow involving EU residents. Answer three questions: Which EU countries do we serve? What personal data do we collect? On what legal basis? Document this before anything else.

Step 2 — Legal Basis and Consent Infrastructure (Week 2–4) Update your privacy notice to GDPR standard (Articles 13/14 requirements). Implement a compliant consent management platform (CMP) for cookies and marketing. Draft your legitimate interests assessments where applicable.

Step 3 — Records of Processing and DPO Decision (Week 3–5) Build your RoPA. Determine whether a DPO is required. If not required, designate a privacy point-of-contact internally. Appoint an EU Representative (Article 27) — a legal entity or individual resident in an EU Member State who can be contacted by supervisory authorities.

Step 4 — Data Subject Rights Workflow (Week 4–6) Build a verifiable intake process for DSARs (Data Subject Access Requests). Define a 30-day response SLA. Train your customer support and engineering teams on erasure and portability procedures.

Step 5 — Transfer Mechanism (Week 5–7) Execute updated 2021 SCCs with all EU-based customers and sub-processors. Complete Transfer Impact Assessments for data flowing to India. Maintain copies in your contract repository.

Step 6 — Incident Response Integration (Ongoing) Integrate GDPR's 72-hour breach notification requirement into your existing incident response plan. If you do not yet have a formal IR plan, a free VAPT scan is a practical first step to identify the vulnerabilities most likely to cause a breach.

🛡️
SECURITY
GDPR breach notification starts the clock when you "become aware" — not when the breach is confirmed or when legal review is complete. Train your engineering and DevOps teams to escalate potential breaches to your privacy lead the same day they are discovered, not after an internal investigation concludes.

Bachao.AI and GDPR-Adjacent Security

Regulatory compliance and security posture are inseparable under GDPR. Article 32 requires implementing "appropriate technical and organisational measures" to ensure a level of security appropriate to the risk. Bachao.AI, built by Dhisattva AI Pvt Ltd, automates vulnerability assessments that directly map to Article 32 obligations — identifying misconfigurations, exposed endpoints, and data-leakage vectors before a regulator or adversary does. GDPR-mandated penetration testing evidence is also increasingly requested during due diligence and by enterprise EU customers as a procurement requirement.


🎯Key Takeaway
GDPR applies to Indian companies the moment they target or monitor EU residents — server location is irrelevant. The non-negotiable first steps are: document your lawful basis, execute 2021-version SCCs for data transfers to India, appoint an EU Representative, and wire breach notification into your incident response plan within 72 hours.

Frequently Asked Questions

Does GDPR apply to a small Indian startup with a handful of EU users?
Yes. Article 3(2) contains no size threshold. If you are intentionally offering goods or services to EU residents — including via a free SaaS product — GDPR applies. The supervisory authorities' enforcement priorities tend toward larger processors, but the legal obligation exists from day one.
What is an EU Representative and do we actually need one?
Under Article 27, any non-EU organisation subject to GDPR must designate a representative in an EU Member State in writing. This is a legal contact point for supervisory authorities and data subjects. Exceptions apply only if processing is occasional, does not involve special categories at scale, and is unlikely to risk individuals' rights. Most Indian companies serving EU customers regularly cannot rely on this exception.
Are Standard Contractual Clauses sufficient for transferring EU data to India?
SCCs are the most practical mechanism available, since India lacks an adequacy decision. You must use the European Commission's June 2021 version and accompany them with a Transfer Impact Assessment documenting how Indian law compares to EU standards. See the official EU source at ec.europa.eu/info/law/law-topic/data-protection.
How does GDPR's breach notification requirement differ from DPDP's?
GDPR requires notification to the supervisory authority within 72 hours of awareness and to affected individuals without undue delay if the risk is high. India's DPDP Act requires notification to the Data Protection Board and to affected data principals, but the specific timelines depend on Rules that had not been finalised as of mid-2026. GDPR's 72-hour window is the stricter and currently better-defined obligation.
What counts as "monitoring behaviour" under Article 3(2)(b)?
The EDPB's Guidelines 3/2018 on territorial scope clarify that monitoring includes tracking individuals online to profile them, predict their behaviour, or serve targeted advertising. This covers analytics cookies, retargeting pixels, fingerprinting, and behavioural email automation. A one-time purchase interaction alone is unlikely to qualify; systematic profiling of EU users does.
Can we use DPDP compliance as a substitute for GDPR compliance?
No. DPDP and GDPR are parallel obligations. An Indian company with EU customers must comply with GDPR for that EU-facing processing and with DPDP for processing involving Indian residents. The frameworks overlap in intent but differ in detail — especially on transfer rules, DPO thresholds, and data subject rights scope. Treat them as separate compliance tracks with some shared infrastructure.

Sources: Regulation (EU) 2016/679 (GDPR) full text at eur-lex.europa.eu; European Data Protection Board Guidelines 3/2018 on Territorial Scope at edpb.europa.eu; Digital Personal Data Protection Act 2023 (India) at meity.gov.in; European Commission Standard Contractual Clauses (June 2021) at ec.europa.eu.

BR

Bachao.AI Research Team

Cybersecurity Research

AI-powered security research and threat intelligence from the Bachao.AI team. Covering the latest vulnerabilities, CVEs, and cybersecurity developments affecting Indian businesses.

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

See if your business is DPDP Act compliant

Free automated scan — risk score in under 2 hours. No credit card required.

Check DPDP Compliance
Find your vulnerabilitiesStart free scan →