The regime at a glance
- Instrument
- Regulation (EU) 2016/679 — General Data Protection Regulation, plus each Member State's implementing law
- Regulator
- The supervisory authority of each Member State, coordinated by the European Data Protection Board
- In force since
- 25 May 2018
- Extraterritorial reach
- Yes — Article 3(2): offering goods or services to people in the Union, or monitoring their behaviour there. No establishment needed
- Breach notification
- 72h to the supervisory authority from awareness, unless unlikely to result in risk; to data subjects without undue delay where the risk is high
- DPO required
- Conditional — Article 37: public authority, large-scale regular and systematic monitoring, or large-scale special category data
- Registration required
- No general registration — but an Article 27 EU representative must be designated in writing and published where Article 3(2) applies
- Maximum penalty
- €20m or 4% of total worldwide annual turnover, whichever is higher
- Transfer mechanism
- India has no adequacy decision. EU-to-India transfers run on Article 46 safeguards — in practice the 2021 SCCs with a transfer impact assessment
02 · Does this apply to you
Article 3 is short and its consequences are not. These are the four situations in which Indian companies find themselves in scope — usually without a European entity, and often without having been told by the client who put them there.
01
You run a delivery centre for a European parent or client
You process employee, customer or claims data on documented instructions from an entity established in the Union. You are a processor under Article 28, and the direct processor obligations — security, sub-processor consent, records, breach notification to the controller — bind you, not merely your contract.
02
Your SaaS product has paying users in the Union
Euro pricing, a German-language page, an EU hosting region or shipping to Ireland all evidence an intention to offer services to people in the Union. Accessibility of the site alone does not — deliberate targeting does, and self-serve signups from Europe are usually deliberate by the time they are in your pricing page.
03
You measure the behaviour of people in Europe
Analytics SDKs, ad retargeting pixels, fraud scoring on European transactions, device fingerprinting or cohort profiling of EU visitors are monitoring under Article 3(2)(b). This catches Indian adtech, martech and risk-scoring vendors that never contract with a European customer at all.
04
You employ people who sit in Europe
A sales office in Amsterdam, a remote engineer in Poland or a branch in Frankfurt is an establishment, and processing in the context of its activities falls under Article 3(1) regardless of where the HR system runs. Member State employment-data derogations then apply on top.
03 · What it requires that DPDP does not
A well-built DPDP programme is a strong base. It is not a GDPR programme, and the gap is narrower and more specific than most vendors will tell you. Four differences carry nearly all the work.
Article 6
Six lawful bases, not one
DPDP runs on consent and a closed list of legitimate uses. GDPR asks you to select and document a basis per purpose, and if you choose legitimate interests you must record the balancing test and honour the right to object. Re-papering everything as consent is the most common and most expensive mistake.
Articles 15–22
Rights DPDP has no equivalent for
Portability in a machine-readable format, restriction of processing, objection to direct marketing at any time, and a qualified right not to be subject to solely automated decisions with legal or similarly significant effect. Each needs a workflow, not a policy line — and a one-month statutory response clock.
Articles 27, 30, 35
Artefacts a regulator can demand tomorrow
An Article 30 record in the prescribed form, a DPIA where processing is likely to be high risk with prior consultation if residual risk stays high, and a named EU representative published in your notice. DPDP's RoPA habit gets you most of Article 30 and none of the other two.
Articles 13–14
A longer notice, with retention periods in it
Retention periods or the criteria that set them, recipients or categories of recipients, transfer safeguards and how to obtain a copy of them, the legitimate interests relied on, and the right to complain to a supervisory authority. Your DPDP notice is shorter by design and will not carry these.
04 · What your DPDP programme already covers
Most of the expensive, slow work is portable. If you have run a DPDP gap assessment and closed it, you are not starting a second programme — you are extending one, and typically at a third of the effort.
Portable
Data inventory and RoPA — the spine of Article 30 is the same spine.
Portable
Processor contracts, sub-processor registers and security schedules.
Portable
Breach runbook, awareness determination and evidence discipline.
Portable
Retention and erasure schedules, and the deletion tooling behind them.
Portable
Rights intake, identity verification and the request-handling queue.
Portable
Rule 6 technical safeguards, logging and access control evidence.
05 · The cross-border position
In the other direction the constraint is real. India holds no adequacy decision, so an EU controller sending data to your Indian entity must rely on Article 46 safeguards — in practice the 2021 Standard Contractual Clauses, in the module that matches the controller-processor or controller-controller relationship.
The clauses alone are not enough. Since Schrems II the exporter must run a transfer impact assessment on Indian law — the interception powers under the Telegraph Act and the IT Act, and the absence of a redress route for EU data subjects — and add supplementary measures where the assessment demands them. Expect that assessment to arrive as a questionnaire from your client, and expect the deal to wait on your answer.
06 · Breach notification, side by side
One incident, three clocks, and only one of them lets you decide not to file. If you are in scope for both regimes, the DPDP obligations are the tighter constraint on every axis except the audience.
| Test | GDPR | DPDP R7 | CERT-In |
|---|---|---|---|
| Regulator window | 72h | Now + 72h | 6h |
| Clock starts | Awareness | Awareness | Noticing |
| Risk threshold | Yes | None | Listed types |
| Tell individuals | If high risk | Always | — |
Both regimes measure from awareness, and awareness is a finding of fact your own ticket system will settle. How the awareness date gets moved →
07 · How we help
01
Article 3 scoping opinion
A written determination of which of your processing activities are in scope, per entity and per product, with the evidence that supports each call.
02
Dual-regime uplift
Lawful basis register, Article 30 records, DPIA templates, Article 13 notices and rights workflows built once to satisfy both regimes.
03
Transfer impact assessments
SCC module selection, the Indian-law analysis your EU client's questionnaire asks for, and the supplementary measures that close it.
08 · Questions we are asked
Related
01
DPDP versus GDPR
Clause by clause, where the two regimes diverge and where they do not.
Compare02
Rule 7 in full
The Indian breach obligation both clocks in this page are measured against.
Read03
DPDP Breach Clock
Set an awareness timestamp and watch every deadline compute at once.
Open the toolNext step
Find out which of your processing activities Article 3 actually reaches.
Talk to our cross-border teamGeneral information, not legal advice. Regime positions change; confirm current status with local counsel.