EU / UK · GDPR

GDPR & UK GDPR Compliance for India-Based Companies

If you sell to, employ or process data from people in the EU or UK, the GDPR applies to you in India. We build a defensible GDPR programme — records, lawful bases, transfers and DSARs — so European deals and audits stop stalling on privacy.

DPDPA 2023GDPR / UK GDPRBoard-accountableVetted expert network
Start here

Does the GDPR apply to an Indian company?

Yes — the GDPR reaches any organisation that offers goods or services to people in the EU, or monitors their behaviour, wherever the organisation is based. For Indian SaaS, agencies and e-commerce with European users, that means the full set of obligations: a lawful basis for every processing activity, Article 30 records, DSAR handling on a one-month clock, breach notification within 72 hours, and lawful mechanisms for moving data to India.

The UK now runs its own UK GDPR in parallel. The principles align, but transfers, representative requirements and the regulator differ — so a serious programme covers both, with a single core and market-specific overlays rather than two separate stacks.

What’s included

What a GDPR engagement covers

The artefacts European buyers, DPAs and auditors actually ask to see.

Art. 30

Records of processing

A living Article 30 record of your processing activities — the backbone every other obligation and audit hangs off.

Basis

Lawful-basis & consent

A lawful basis mapped to each activity, with GDPR-grade consent capture and withdrawal where consent is the basis.

Art. 35

DPIAs

Screening and full Data Protection Impact Assessments for high-risk processing — profiling, AI features, large-scale or special-category data.

Rights

DSAR handling

Intake, identity checks, search playbooks and SLA tracking so access, erasure and objection requests are met within one month.

Transfers

SCCs & UK IDTA

Transfer mapping, Standard Contractual Clauses, the UK IDTA/Addendum and Transfer Impact Assessments so EU/UK data can reach India lawfully.

Art. 27

EU/UK representative path

Guidance on whether you need an Article 27 representative and how to stand one up where required.

Do you need this?

When it’s required — and when it’s just smart

A quick way to place yourself, then confirm it with a readiness assessment.

Mandatory

EU/UK monitoring or special-category at scale

Large-scale monitoring, large-scale special-category processing, or a public-authority role trigger a mandatory DPO under Article 37 — wherever you’re based.

Applies extraterritorially

Selling or marketing to the EU/UK

Offer goods or services to, or monitor, people in the EU/UK and the GDPR applies to that processing in full — India base or not.

Expected

SaaS closing European deals

European procurement and DPAs increasingly gate contracts on demonstrable GDPR posture — records, DPIAs and a transfer story.

How we deliver it

One core programme, EU and UK overlays

Build the machinery once; localise the few things that genuinely differ between Brussels and London.

Map then build

We map your EU/UK data flows first, then stand up records, bases and DSAR handling around the real picture.

Transfer-ready

SCCs, UK IDTA and TIAs so India transfers are documented and defensible, not an audit surprise.

Audit evidence

DPIAs, a breach playbook on the 72-hour clock and a dashboard that answers a buyer’s security questionnaire fast.

The law behind it

Built on the GDPR and UK GDPR — including Article 37(6)

The programme is anchored in the GDPR’s core articles: Article 30 records, Article 35 DPIAs, the Article 12–23 data-subject rights, Article 33/34 breach notification, and Chapter V transfer rules (SCCs, adequacy, TIAs). Where a DPO is mandatory under Article 37, Article 37(6) expressly permits appointing one on a service contract — which is exactly how our fractional engagements are structured. The UK GDPR and Data Protection Act 2018 overlays are handled in parallel. This is decision-support, not legal advice.

Pricing

Transparent retainers, from ₹80,000 per quarter

Most engagements fold into a single accountable retainer — usually 40–60% below the cost of a full-time hire. See how the tiers map to your scope.

Answers

Questions, answered straight

We’re in India with EU customers — do we really need GDPR?

Yes. The GDPR applies extraterritorially: if you offer goods or services to people in the EU or monitor their behaviour, the regulation covers that processing regardless of where your company sits.

What’s the difference between GDPR and UK GDPR for us?

The substantive principles are closely aligned, but they’re separate regimes with different regulators, transfer tools (SCCs vs the UK IDTA/Addendum) and representative rules. A good programme shares one core and adds thin market-specific overlays.

How do we legally transfer EU data to India?

India isn’t currently an adequacy country, so transfers typically rely on Standard Contractual Clauses (or the UK IDTA for UK data) plus a Transfer Impact Assessment. We map your transfers and put the right mechanism and documentation in place.

Do we need an EU representative?

If you have no EU establishment but process EU personal data in scope of Article 3(2), you may need an Article 27 representative. We assess whether it applies and help you appoint one if so.

Is a fractional DPO acceptable under the GDPR?

Yes — Article 37(6) explicitly allows the DPO role to be fulfilled under a service contract, so a named, properly mandated fractional DPO satisfies the requirement where one is triggered.

Talk it through

Twenty minutes on your situation, your options, and realistic costs

No pitch, no obligation — just a clear read on where you stand and what an engagement would cover.

Follow DPOIndia in Google SearchAdd as a preferred source on Google