Home All services
Start a project → Call Now

GDPR compliance in India

Comply with the GDPR from India — starting with why you hold the data.

The GDPR, the EU's data protection law, can reach an Indian company with no EU office. We check whether it reaches you, then fix what a regulator can check from outside: your lawful basis (legal reason) for each use of data, and the EU representative your privacy notice must name.

  • A straight answer on scope, even if it's no
  • Lawful basis before any consent banner
  • We reply within one working day.
Illustration: four blank personal data cards; three are each linked by a line of light to a purpose icon, an envelope, a shopping bag or a gear, and the fourth has no link and an amber dot

In brief

What it is
We work out whether the GDPR applies to you, then build the records, notices, contracts and breach plan it requires.
Why it matters
The law follows where people are, not your servers. It puts the burden of proof on you before anyone asks.
What you get
A scoping memo, a lawful basis register, records of your processing, transfer contracts and a rehearsed breach plan.

Does it apply to you?

You're in scope if you target people in the EU or track them there.

Article 3(2) catches you in two ways: offering goods or services to people in the EU, paid or free, or monitoring their behavior there. For the first, Recital 23 asks for evidence that you meant to.

  • Euro prices. Or a checkout that takes euros.
  • EU-language pages. German, French or Dutch, when you work in English.
  • EU marketing. Targeted ads, EU shipping, or an EU phone number in the footer.
  • Tracking EU visitors. The second way in: device-level analytics identifiers count, and so does session replay.

Not enough on its own

Being reachable from Europe doesn't put you in scope. Location counts, not nationality: an EU citizen living in Bengaluru sits outside Article 3(2); a Brazilian tourist in Lisbon sits inside it.

Controller, processor or both

Handling EU data on a client's instructions makes you a processor, bound directly by Articles 28(3), 30(2), 32 and 33(2). Selling your own product into the EU makes you a controller too (you decide why data is used), which brings Article 27.

Lawful basis first

Decide why you hold the data before you ask anyone for consent.

Article 6(1) gives six lawful bases, and you pick one in advance for each use of data. Most firms reach for consent because it feels safe. It isn't.

Under Article 4(11), consent must be freely given, specific, informed and unambiguous, and Article 7(3) makes withdrawing it as easy as giving it. You build that withdrawal route, and processing stops when someone clicks. For employee records, service delivery and most B2B work, contract (Article 6(1)(b)), legal obligation (6(1)(c)) or legitimate interests (6(1)(f)) are stronger and cheaper to run.

You can't switch later

If consent for a mailing list doesn't hold, you cannot relabel it as legitimate interests later: the basis was fixed at the start and disclosed under Article 13.

You carry the burden of proof

Article 5(1) sets six principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; and integrity and confidentiality. Article 5(2) adds accountability: you must be able to prove you meet them.

Basis mapping

Consent is the wrong default for most of what you do.

Lawful basis by processing activity
Processing activityBasis firms reach forBasis that usually holdsEvidence you have to produce
EU customer contacts in a CRMConsentArticle 6(1)(b) contract for customers, 6(1)(f) for prospectsRegister entry, plus a written balancing test for anything pre-contract
Marketing email to EU prospectsLegitimate interestsConsent in most member states, because ePrivacy Article 13 sits on top of the GDPRConsent banner configuration record and a per-recipient withdrawal trail
Employee and contractor recordsConsentArticles 6(1)(b) and 6(1)(c). Article 88 then sends you to national lawAn internal employee notice per member state where staff sit
Product telemetry and analyticsLegitimate interestsDepends on the identifier. Device-level IDs need ePrivacy consent firstCookie and tag inventory tied to purposes, not to vendor names
Health, biometric or trade union dataWhatever covers the restAn Article 6(1) basis and a separate Article 9(2) conditionData protection impact assessment (DPIA) meeting Article 35(7), and an Article 36 memo where residual risk stays high
Support tickets holding your client's customersNot our data, not our problemYou're the processor. The controller picks the basis, you record the instructionArticle 30(2) processor record and the signed Article 28(3) data processing agreement (DPA)
Why cookie consent differs by country

Cookie consent comes from Article 5(3) of the ePrivacy Directive 2002/58/EC as each member state transposed it, so France, Germany and Spain genuinely differ; the GDPR only sets the standard for valid consent. One banner set-up for all of Europe is a known enforcement trigger.

The parts that bite

You need a named EU representative and a lawful route for data sent to India.

A representative in the EU, in writing

Where Article 3(2) applies, Article 27 requires a representative established in a member state where your data subjects are, appointed in writing and named in your privacy notice. It's enforceable on its own, and anyone can check it. It's the omission we find most often among Indian firms selling into the EU, and it's cheap to close: about two weeks.

India has no adequacy decision

India is not on the European Commission's list of countries with adequate data protection; Brazil joined in January 2026 and the UK was renewed in December 2025 for six years. So every transfer of EU personal data to India needs an Article 46 safeguard: in practice the 2021 Standard Contractual Clauses (SCCs) under Decision (EU) 2021/914, with Annexes I to III completed. Pre-2021 clauses have been non-compliant since December 2022.

A transfer impact assessment written for India

The Schrems II judgment makes you check, in writing, India's government access powers, which templates written for the US skip. What makes the assessment hold is the supplementary measures: client-held encryption keys, EU-side pseudonymization, access logs you can export, and a written policy for answering government requests.

Why the 2021 SCCs partly repeat what you already owe

The 2021 clauses were drafted for importers not subject to the GDPR, so an Indian company caught by Article 3(2) signs terms that partly duplicate what it already owes. No implementing decision for a module covering GDPR-subject importers has been published. Our position: sign the existing modules and document the duplication.

Which Indian laws the transfer impact assessment covers

It covers Sections 69 and 69B of the IT Act 2000 with the 2009 Interception Rules, production powers under Section 94 BNSS, and the interception provisions of the Telecommunications Act 2023. It also records the absence of independent judicial authorization, and of a redress route for non-residents.

The Europrivacy seal, and why it doesn't fix transfers

Europrivacy is the EU-wide scheme approved as a European Data Protection Seal. In April 2026 the European Data Protection Board approved updated criteria and opened it to controllers and processors outside the European Economic Area subject to Article 3(2), so an Indian firm can pursue it in its own name. Its Article 46(2)(f) transfer route, approved in a separate opinion that month, is open only to importers not subject to the GDPR, so it doesn't close your Chapter V transfer gap.

What we are, and are not. We work remotely from India. We're a security and engineering firm, not a law firm, and we don't give legal advice. We aren't an accredited certification body, and we don't act as your Article 27 representative.

Related: India's DPDP Act, third-party risk and all our compliance work.

How we run it

Six steps, with the consent banner last, not first.

  1. Scope under Article 3, in writing

    Two weeks. We test both limbs of Article 3 against what you do, then write a scoping memo: which entities and processing are caught, which aren't, and the Recital 23 evidence.

  2. Article 30 records and the lawful basis register

    Six to ten weeks. We write separate controller and processor records under Article 30(1) and 30(2). Every activity gets an Article 6(1) basis and, where relevant, an Article 9(2) condition. Your process owners confirm the entries.

  3. Balancing tests and rewritten notices

    Four to six weeks. We write one legitimate interests assessment per activity relying on Article 6(1)(f), with purpose, necessity and balancing set out, then layered Article 13 and 14 notices in the language of the market you sell into.

  4. Article 27 appointment and the transfer pack

    Eight to sixteen weeks, in parallel. We prepare the SCC modules and annexes, a transfer impact assessment per destination, Article 28(3) DPA templates, and a third-party register with the sub-processor chains.

  5. Breach and request handling, then a rehearsal

    Six to eight weeks. We build a data subject access request workflow for the one-month clock in Article 12(3), and a breach plan whose 72-hour timer starts at awareness, not when forensics end. We add the Article 33(5) internal register, which also covers breaches you don't notify, and a retention schedule with deletion evidence. Then we run a breach tabletop exercise against the clock. Most teams miss 72 hours the first time.

  6. Accountability report to the board

    The document most often skipped: residual risks with owners and dates. If a supervisory authority asks under Article 58(1)(a), it shows Article 5(2) accountability was actually operating.

FAQ

Questions we get on the first call.

Possibly. Article 3(2) decides it, not where your servers are: it catches non-EU controllers and processors that offer goods or services to people located in the Union, paid or free, or monitor their behavior there. If you price in euros, run EU-language pages, buy EU-targeted ads or run device-level analytics on European visitors, assume you're caught and get the scoping memo written. One customer who found you and bought unprompted probably doesn't put you in scope, and we'll tell you so.

No, and nobody can in the ordinary sense: there's no GDPR certificate the way there's an ISO 27001 certificate. Article 42 certification covers named processing operations, not a company; only a body accredited under Article 43 or the competent supervisory authority may issue it; and under Article 42(4) it doesn't reduce your responsibility. SecWiz is not an accredited body. For a recognized mark, the real routes are the Europrivacy seal or an approved national scheme.

No. A generic privacy inbox in Bengaluru is not a representative. Article 27 needs one established in a member state where your data subjects are, appointed in writing with a mandate, and named in your notice so individuals and supervisory authorities can address it directly.

Only partly. As a processor you owe a processor record, security measures under Article 32(1)(a) to (d), and notice to the controller without undue delay when something goes wrong. Article 82(2) makes you liable to individuals if you act outside or against the controller's lawful instructions. A DPA brings statutory obligations, not only contract terms.

Six to nine months to a defensible baseline for a mid-sized company starting from nothing; twelve to eighteen to one that survives questioning without improvisation. Cost drivers, largest first: how many processors and sub-processors you have, since vendor contracts move at their speed; whether data mapping starts from an asset inventory or from zero, worth about two months; special category data under Article 9; HR data in several member states, since Article 88 leaves employment to national law; and marketing and adtech, usually the messiest workstream.

No. It sits in the Digital Omnibus proposal, COM(2025) 837, published in November 2025, and isn't law: Parliament and Council have not agreed a position. The AI half of that package became law as Regulation (EU) 2026/1744; the GDPR half did not. Regulators enforce seventy-two hours from awareness, and Article 33(4) already lets you notify in phases.

Procedure, not obligations. Regulation (EU) 2025/2518, the GDPR Procedural Regulation, was adopted on 26 November 2025, published on 12 December 2025 and entered into force on 1 January 2026, but applies only from 2 April 2027. It harmonizes how supervisory authorities run cross-border cases under Article 60: complaint admissibility, an early-resolution route, a right for parties under investigation to be heard on preliminary findings, and time limits of roughly fifteen months for a standard investigation and twelve for the simplified track. Nothing you owe as a controller changes.

The inventory and security work overlaps; the legal layer doesn't. India's DPDP Rules, 2025 commence in tranches, consent-manager registration first and the substantive rules on notice, safeguards, breach reporting and data principal rights last. DPDP has no legitimate interests basis, no general DPIA mandate, no materiality threshold for breach reporting, and penalties up to INR 250 crore per violation rather than turnover-linked tiers.

No. ISO 27001 is voluntary and you scope it yourself; an auditor tests whether your controls protect the information assets you declared. The GDPR is directly applicable law that scopes you: every piece of personal data you touch, including the spreadsheet on a laptop and the chat group nobody declared. No security control answers what your lawful basis is. SecWiz itself is not ISO 27001 certified.

Let's talk

Find out whether the GDPR applies to you.

Tell us what you sell, where your buyers are and which vendors touch the data. You get a straight answer on scope first. We reply within one working day.