If you sell to, employ or process data from people in the EU or UK, the GDPR applies to you in India. We build a defensible GDPR programme — records, lawful bases, transfers and DSARs — so European deals and audits stop stalling on privacy.
Yes — the GDPR reaches any organisation that offers goods or services to people in the EU, or monitors their behaviour, wherever the organisation is based. For Indian SaaS, agencies and e-commerce with European users, that means the full set of obligations: a lawful basis for every processing activity, Article 30 records, DSAR handling on a one-month clock, breach notification within 72 hours, and lawful mechanisms for moving data to India.
The UK now runs its own UK GDPR in parallel. The principles align, but transfers, representative requirements and the regulator differ — so a serious programme covers both, with a single core and market-specific overlays rather than two separate stacks.
The artefacts European buyers, DPAs and auditors actually ask to see.
A living Article 30 record of your processing activities — the backbone every other obligation and audit hangs off.
A lawful basis mapped to each activity, with GDPR-grade consent capture and withdrawal where consent is the basis.
Screening and full Data Protection Impact Assessments for high-risk processing — profiling, AI features, large-scale or special-category data.
Intake, identity checks, search playbooks and SLA tracking so access, erasure and objection requests are met within one month.
Transfer mapping, Standard Contractual Clauses, the UK IDTA/Addendum and Transfer Impact Assessments so EU/UK data can reach India lawfully.
Guidance on whether you need an Article 27 representative and how to stand one up where required.
A quick way to place yourself, then confirm it with a readiness assessment.
Large-scale monitoring, large-scale special-category processing, or a public-authority role trigger a mandatory DPO under Article 37 — wherever you’re based.
Offer goods or services to, or monitor, people in the EU/UK and the GDPR applies to that processing in full — India base or not.
European procurement and DPAs increasingly gate contracts on demonstrable GDPR posture — records, DPIAs and a transfer story.
Build the machinery once; localise the few things that genuinely differ between Brussels and London.
We map your EU/UK data flows first, then stand up records, bases and DSAR handling around the real picture.
SCCs, UK IDTA and TIAs so India transfers are documented and defensible, not an audit surprise.
DPIAs, a breach playbook on the 72-hour clock and a dashboard that answers a buyer’s security questionnaire fast.
The programme is anchored in the GDPR’s core articles: Article 30 records, Article 35 DPIAs, the Article 12–23 data-subject rights, Article 33/34 breach notification, and Chapter V transfer rules (SCCs, adequacy, TIAs). Where a DPO is mandatory under Article 37, Article 37(6) expressly permits appointing one on a service contract — which is exactly how our fractional engagements are structured. The UK GDPR and Data Protection Act 2018 overlays are handled in parallel. This is decision-support, not legal advice.
Most engagements fold into a single accountable retainer — usually 40–60% below the cost of a full-time hire. See how the tiers map to your scope.
Yes. The GDPR applies extraterritorially: if you offer goods or services to people in the EU or monitor their behaviour, the regulation covers that processing regardless of where your company sits.
The substantive principles are closely aligned, but they’re separate regimes with different regulators, transfer tools (SCCs vs the UK IDTA/Addendum) and representative rules. A good programme shares one core and adds thin market-specific overlays.
India isn’t currently an adequacy country, so transfers typically rely on Standard Contractual Clauses (or the UK IDTA for UK data) plus a Transfer Impact Assessment. We map your transfers and put the right mechanism and documentation in place.
If you have no EU establishment but process EU personal data in scope of Article 3(2), you may need an Article 27 representative. We assess whether it applies and help you appoint one if so.
Yes — Article 37(6) explicitly allows the DPO role to be fulfilled under a service contract, so a named, properly mandated fractional DPO satisfies the requirement where one is triggered.
No pitch, no obligation — just a clear read on where you stand and what an engagement would cover.