An Indian SaaS company signs its first enterprise client in Germany. The contract closes, onboarding begins, and nobody on the founding team asks whether the company needs to comply with European data protection law, since it has no office or employees in the EU. Eighteen months later, a security review by the German client’s legal team flags that the vendor has never conducted a Data Protection Impact Assessment and cannot produce a Record of Processing Activities on request. The contract is paused pending remediation.
This pattern repeats constantly. In 2025, Ireland’s Data Protection Commission fined TikTok €530 million for unlawfully transferring European user data outside the EU, a reminder that geography does not determine jurisdiction here. The European Data Protection Board separately reported that EU authorities now receive an average of 443 breach notifications daily, a 22% year-over-year increase. For Indian companies serving European customers, GDPR India compliance is an operational requirement with real financial consequences, not a theoretical exercise.
This guide covers who GDPR India obligations actually apply to, how they differ from India’s DPDPA, and what a business needs in place to process EU user data lawfully.
Who Has to Comply
GDPR applies extraterritorially. Physical presence in the EU is not the test. Under Article 3, the regulation applies to any organization, anywhere in the world, that either offers goods or services to individuals in the EU or monitors their behavior.
This catches Indian businesses that assume the law does not apply to them:
- SaaS companies with European trial signups, even without a paid EU customer
- IT services and BPO firms processing HR, payroll, or customer data for EU clients
- E-commerce businesses shipping to EU countries or pricing in euros
- Marketing platforms tracking EU website visitors through cookies or pixels
- Healthtech and fintech companies handling any EU resident’s data, even incidentally
If your Indian company processes personal data belonging to someone in the EU at the time of processing, GDPR India obligations apply, regardless of where your servers sit.
GDPR India vs. DPDPA: Where the Two Laws Diverge
Many Indian businesses assume that complying with India’s own Digital Personal Data Protection Act, 2023, automatically satisfies GDPR. It does not. The two laws share a common goal but differ enough in scope and mechanics that dual compliance requires separate attention.
| Area | GDPR | DPDPA |
| Scope of data | All personal data, digital and non-digital | Digital personal data only |
| Legal basis for processing | Six lawful bases (consent, contract, legal obligation, vital interests, public task, legitimate interests) | Primarily consent and specified legitimate uses |
| Data Protection Officer | Mandatory in specific high-risk cases | Mandatory only for Significant Data Fiduciaries |
| Breach notification | Within 72 hours to the supervisory authority | Notification to Data Protection Board and affected users, timeline set by rules |
| Cross-border transfer mechanism | Adequacy decisions, SCCs, or binding corporate rules | Blacklist model; transfers allowed except to notified restricted countries |
| Maximum penalty | Up to €20 million or 4% of global annual turnover | Up to ₹250 crore per instance |
A company building its compliance programme around DPDPA alone will find real gaps the moment it processes EU data. The reverse is also true. GDPR does not address DPDPA-specific obligations like the Consent Manager framework, so a unified approach must reference both laws individually.
The Core GDPR India Requirements Businesses Actually Need to Operationalize
Establishing a Lawful Basis
Every instance of processing EU personal data needs a documented lawful basis under Article 6. Consent is the most commonly assumed basis, but it is not always right. A B2B contract with a European client is usually better grounded in “performance of a contract,” since consent must be freely given and easily withdrawable, which fits poorly with processing core to a paid service.
Appointing an EU Representative
Under Article 27, a company subject to GDPR without an EU establishment generally must designate a representative based in a member state where affected individuals are located, acting as the point of contact for supervisory authorities and producing processing records on request. Most commercial SaaS businesses do not qualify for the low-risk exemption.
Maintaining a Record of Processing Activities
Article 30 requires most organizations to maintain a documented Record of Processing Activities, listing what personal data is collected, why, how long it is retained, and who it is shared with. This is frequently the first document a European client’s procurement team requests during vendor due diligence.
Enabling Data Subject Rights
EU data subjects hold rights to access, correct, delete, restrict, and port their data, plus the right to object to certain processing. Companies need operational workflows, not just policy language, to fulfil these requests within the one-month response window.
Securing Cross-Border Data Transfers
Since India has no adequacy decision from the European Commission, personal data cannot move freely from the EU to Indian servers based on India’s legal system alone. Most companies rely on Standard Contractual Clauses (SCCs) to create a lawful transfer mechanism. Following Schrems II, companies using SCCs also need a Transfer Impact Assessment confirming Indian law does not undermine the protections SCCs guarantee.
Common GDPR India Compliance Mistakes
Certain gaps show up repeatedly in vendor due diligence reviews and enforcement cases involving Indian processors.
- Relying on DPDPA compliance as a substitute for GDPR. The frameworks overlap but are not interchangeable.
- Using consent as the default basis for B2B processing. Contract performance is usually correct, and misclassifying it creates retention and withdrawal problems.
- No Transfer Impact Assessment behind SCCs. Signing the template alone does not satisfy Schrems II.
- Treating the RoPA as a one-time exercise. Processing activities change as products evolve, and an outdated RoPA is a common review finding.
- No incident response plan calibrated to the 72-hour window. Notifying the right authority while EU teams sleep in a different time zone is where companies most often fall short.
GDPR India Compliance Checklist
- Data mapping completed for all EU personal data collected, processed, or stored
- Lawful basis documented for every processing activity involving EU data
- Record of Processing Activities maintained and reviewed quarterly
- EU representative appointed where Article 27 applies
- Standard Contractual Clauses executed with all EU data-sending partners
- Transfer Impact Assessment completed and kept current
- Data subject rights request workflow tested and documented
- Breach notification procedure rehearsed against the 72-hour window
- Data Protection Officer appointed if the organization meets the threshold criteria
- Vendor and sub-processor agreements reviewed for GDPR-compliant data processing terms
Penalties for GDPR Non-Compliance
GDPR fines are structured in two tiers. Lower-tier violations, such as failing to maintain proper records or not appointing a required DPO, carry fines up to €10 million or 2% of global turnover. Higher-tier violations, including unlawful processing and transfer failures, carry fines up to €20 million or 4%.
The global annual turnover detail matters specifically for Indian companies. The fine calculation is based on worldwide revenue, not EU revenue alone, meaning a violation tied to a small EU client contract can still expose the entire business’s global revenue to the penalty calculation.
How Qualysec Helps With GDPR India Compliance
Most GDPR India compliance failures Qualysec encounters are not the result of companies ignoring the law. They come from treating GDPR as a one-time documentation exercise rather than an operational programme that holds up under a client security review or a regulator’s investigation.
Closing the Gap Between DPDPA and GDPR Programmes
Where companies have built compliance around DPDPA alone, Qualysec identifies the specific GDPR requirements not covered, including lawful basis documentation, Article 27 representative appointment, and Transfer Impact Assessments, without duplicating existing DPDPA work.
Making Cross-Border Transfer Mechanisms Defensible
Many companies sign SCCs without the supporting Transfer Impact Assessment Schrems II requires. Qualysec conducts the technical assessment needed to make an SCC-based transfer defensible under current EU case law, covering encryption, access controls, and government access risk under Indian law.
Preparing for Breach Notification Under Real Time Pressure
A 72-hour window leaves no room to figure out the process after an incident occurs. Qualysec builds and tests incident response procedures calibrated to GDPR’s notification timeline, including severity assessment criteria and pre-drafted notification templates ready for the relevant supervisory authority.
Talk to a cybersecurity compliance expert to build a defensible GDPR compliance programme!
Conclusion
Most Indian companies that run into GDPR trouble were never trying to violate the law. They built their compliance programme around DPDPA, the regulation they knew best, and assumed it would cover a European client relationship that arrived later and unexpectedly. GDPR India compliance is not about intent. It is about whether the company can produce a lawful basis, a processing record, and a tested breach response when an EU client’s procurement team or a supervisory authority asks for them. The businesses that treat this as infrastructure, built before the first EU contract closes, are the ones that keep those contracts.
Contact Qualysec to strengthen your organization’s GDPR India compliance before your next EU client review!
Frequently Asked Questions
1. Does GDPR apply to Indian companies without a presence in the EU?
Yes. GDPR has extraterritorial scope under Article 3, applying to any company, regardless of location, that offers goods or services to individuals in the EU or monitors their behavior. A company with no EU office or employees can still be fully subject to GDPR if it processes the data of people located in Europe.
2. What is the difference between GDPR and India’s DPDPA?
GDPR covers all personal data regardless of format, offers six lawful bases, and applies extraterritorially. DPDPA applies specifically to digital data, relies primarily on consent, and uses a blacklist approach to cross-border transfers. Compliance with one does not automatically satisfy the other.
3. What are the penalties for GDPR non-compliance for Indian businesses?
Penalties are tiered. Lower-tier violations carry fines up to €10 million or 2% of global annual turnover. Higher-tier violations, including unlawful processing and transfer failures, carry fines up to €20 million or 4% of global annual turnover, calculated against total global revenue, not just EU-attributable revenue.
4. How can Indian companies achieve GDPR compliance?
Start with a data mapping exercise, document a lawful basis for each activity, maintain a Record of Processing Activities, appoint an EU representative under Article 27 where required, implement SCCs with supporting Transfer Impact Assessments, and build a tested breach notification procedure aligned to the 72-hour window.
5. What are the GDPR data breach notification requirements for Indian companies?
Indian companies must notify the relevant EU supervisory authority within 72 hours of becoming aware of a breach that risks the rights and freedoms of affected individuals. Where risk is high, affected individuals must also be notified directly. Breaches posing no meaningful risk do not require notification, but that determination must be documented.
6. Is GDPR compliance mandatory for Indian SaaS companies serving EU customers?
Yes, if the platform is offered to individuals in the EU or processes their personal data while delivering the service. This applies even to free trial users, regardless of whether the company has any physical or legal presence in Europe. The determining factor is whether EU residents’ data is being processed.
7. What are the key GDPR requirements every Indian business should follow?
The core requirements are establishing and documenting a lawful basis for processing, maintaining a Record of Processing Activities, enabling data subject rights within the one-month response window, securing cross-border transfers through SCCs and Transfer Impact Assessments, appointing an EU representative where required, and maintaining a breach notification process calibrated to the 72-hour window.
8. How can Indian companies ensure secure cross-border data transfers under GDPR?
Since India does not hold an adequacy decision from the European Commission, Indian companies typically rely on Standard Contractual Clauses to create a lawful basis for transferring EU data outside Europe. Following Schrems II, this also requires a Transfer Impact Assessment demonstrating that SCC protections are not undermined by Indian law, including government access risk and technical safeguards like encryption.






