RISKFORTIS
Enforcement087d 02h 18m

European Union · EDPB & Member State DPAs

GDPR for Indian companies

Reviewed August 2026 · EDPB guidance tracked

If your company sells into the Union, monitors people there, or processes data for an EU client or parent, GDPR binds you directly — with no office in Europe, no European revenue threshold and no grace period.

The regime at a glance

Instrument
Regulation (EU) 2016/679 — General Data Protection Regulation, plus each Member State's implementing law
Regulator
The supervisory authority of each Member State, coordinated by the European Data Protection Board
In force since
25 May 2018
Extraterritorial reach
Yes — Article 3(2): offering goods or services to people in the Union, or monitoring their behaviour there. No establishment needed
Breach notification
72h to the supervisory authority from awareness, unless unlikely to result in risk; to data subjects without undue delay where the risk is high
DPO required
Conditional — Article 37: public authority, large-scale regular and systematic monitoring, or large-scale special category data
Registration required
No general registration — but an Article 27 EU representative must be designated in writing and published where Article 3(2) applies
Maximum penalty
€20m or 4% of total worldwide annual turnover, whichever is higher
Transfer mechanism
India has no adequacy decision. EU-to-India transfers run on Article 46 safeguards — in practice the 2021 SCCs with a transfer impact assessment

02 · Does this apply to you

Article 3 is short and its consequences are not. These are the four situations in which Indian companies find themselves in scope — usually without a European entity, and often without having been told by the client who put them there.

01

You run a delivery centre for a European parent or client

You process employee, customer or claims data on documented instructions from an entity established in the Union. You are a processor under Article 28, and the direct processor obligations — security, sub-processor consent, records, breach notification to the controller — bind you, not merely your contract.

02

Your SaaS product has paying users in the Union

Euro pricing, a German-language page, an EU hosting region or shipping to Ireland all evidence an intention to offer services to people in the Union. Accessibility of the site alone does not — deliberate targeting does, and self-serve signups from Europe are usually deliberate by the time they are in your pricing page.

03

You measure the behaviour of people in Europe

Analytics SDKs, ad retargeting pixels, fraud scoring on European transactions, device fingerprinting or cohort profiling of EU visitors are monitoring under Article 3(2)(b). This catches Indian adtech, martech and risk-scoring vendors that never contract with a European customer at all.

04

You employ people who sit in Europe

A sales office in Amsterdam, a remote engineer in Poland or a branch in Frankfurt is an establishment, and processing in the context of its activities falls under Article 3(1) regardless of where the HR system runs. Member State employment-data derogations then apply on top.

03 · What it requires that DPDP does not

A well-built DPDP programme is a strong base. It is not a GDPR programme, and the gap is narrower and more specific than most vendors will tell you. Four differences carry nearly all the work.

Article 6

Six lawful bases, not one

DPDP runs on consent and a closed list of legitimate uses. GDPR asks you to select and document a basis per purpose, and if you choose legitimate interests you must record the balancing test and honour the right to object. Re-papering everything as consent is the most common and most expensive mistake.

Articles 15–22

Rights DPDP has no equivalent for

Portability in a machine-readable format, restriction of processing, objection to direct marketing at any time, and a qualified right not to be subject to solely automated decisions with legal or similarly significant effect. Each needs a workflow, not a policy line — and a one-month statutory response clock.

Articles 27, 30, 35

Artefacts a regulator can demand tomorrow

An Article 30 record in the prescribed form, a DPIA where processing is likely to be high risk with prior consultation if residual risk stays high, and a named EU representative published in your notice. DPDP's RoPA habit gets you most of Article 30 and none of the other two.

Articles 13–14

A longer notice, with retention periods in it

Retention periods or the criteria that set them, recipients or categories of recipients, transfer safeguards and how to obtain a copy of them, the legitimate interests relied on, and the right to complain to a supervisory authority. Your DPDP notice is shorter by design and will not carry these.

04 · What your DPDP programme already covers

Most of the expensive, slow work is portable. If you have run a DPDP gap assessment and closed it, you are not starting a second programme — you are extending one, and typically at a third of the effort.

Portable

Data inventory and RoPA — the spine of Article 30 is the same spine.

Portable

Processor contracts, sub-processor registers and security schedules.

Portable

Breach runbook, awareness determination and evidence discipline.

Portable

Retention and erasure schedules, and the deletion tooling behind them.

Portable

Rights intake, identity verification and the request-handling queue.

Portable

Rule 6 technical safeguards, logging and access control evidence.

05 · The cross-border position

In the other direction the constraint is real. India holds no adequacy decision, so an EU controller sending data to your Indian entity must rely on Article 46 safeguards — in practice the 2021 Standard Contractual Clauses, in the module that matches the controller-processor or controller-controller relationship.

The clauses alone are not enough. Since Schrems II the exporter must run a transfer impact assessment on Indian law — the interception powers under the Telegraph Act and the IT Act, and the absence of a redress route for EU data subjects — and add supplementary measures where the assessment demands them. Expect that assessment to arrive as a questionnaire from your client, and expect the deal to wait on your answer.

06 · Breach notification, side by side

One incident, three clocks, and only one of them lets you decide not to file. If you are in scope for both regimes, the DPDP obligations are the tighter constraint on every axis except the audience.

TestGDPRDPDP R7CERT-In
Regulator window72hNow + 72h6h
Clock startsAwarenessAwarenessNoticing
Risk thresholdYesNoneListed types
Tell individualsIf high riskAlways

Both regimes measure from awareness, and awareness is a finding of fact your own ticket system will settle. How the awareness date gets moved →

07 · How we help

01

Article 3 scoping opinion

A written determination of which of your processing activities are in scope, per entity and per product, with the evidence that supports each call.

02

Dual-regime uplift

Lawful basis register, Article 30 records, DPIA templates, Article 13 notices and rights workflows built once to satisfy both regimes.

03

Transfer impact assessments

SCC module selection, the Indian-law analysis your EU client's questionnaire asks for, and the supplementary measures that close it.

08 · Questions we are asked

Related

01

DPDP versus GDPR

Clause by clause, where the two regimes diverge and where they do not.

Compare

02

Rule 7 in full

The Indian breach obligation both clocks in this page are measured against.

Read

03

DPDP Breach Clock

Set an awareness timestamp and watch every deadline compute at once.

Open the tool

Next step

Find out which of your processing activities Article 3 actually reaches.

Talk to our cross-border team

General information, not legal advice. Regime positions change; confirm current status with local counsel.