Compliance & Regulation

GDPR Compliance for Indian Companies Serving European Customers

When GDPR applies to an Indian company, what controllers and processors must do, how data transfers to India work and how GDPR differs from India's DPDP Act.

Purushottam Kumar Suman
Purushottam Kumar Suman
Founder & CEO, Drema AI
8 min read
Global network connections over a world map

An Indian SaaS company with customers in Germany, or a services firm handling a French client's user data, is within reach of the EU's General Data Protection Regulation even with no office in Europe. European customers will ask about it in the first procurement questionnaire.

01

When GDPR applies to you

GDPR reaches organisations outside the EU in two situations, and binds processors through contracts in a third.

Offering goods or services to people in the EUPricing in euros, EU languages, shipping to the EU or marketing aimed at EU residents
Monitoring behaviour in the EUTracking and profiling users located there
Processing for an EU clientAs a vendor, your client is the controller and you are a processor, bound by a data processing agreement
02

Controller or processor

A controller decides why and how personal data is processed. A processor acts on a controller's instructions. A B2B SaaS company is usually a processor for its customers' end-user data and a controller for its own customer contacts and website visitors. The distinction decides which duties apply.

Controller dutiesLawful basis, transparency, data subject rights, breach notification to the authority within 72 hours
Processor dutiesAct only on documented instructions, security, sub-processor approval, assist the controller, notify the controller of breaches without undue delay
BothRecords of processing and appropriate security
03

Transfers of data to India

The European Commission has not issued an adequacy decision for India, so sending EU personal data to India needs a transfer mechanism. In practice this means the Commission's Standard Contractual Clauses, plus a transfer impact assessment that considers Indian law and any supplementary safeguards.

For an Indian vendor, the SCCs and a credible transfer assessment are the price of entry to EU deals.

Standard Contractual ClausesTransfer impact assessmentEU-region hosting optionEncryption with customer-held keysAccess from India logged and limitedSub-processor list published
04

What the product needs

GDPR's principles become product features.

Lawful basis per purposeConsent is one of six; contract and legitimate interests are common for B2B
Cookie consentPrior opt-in for non-essential cookies under ePrivacy rules, with reject as easy as accept
Data subject requestsAccess, rectification, erasure, restriction, portability and objection, answered within one month
Data exportIn a structured, machine-readable format
Privacy by design and defaultCollect the minimum; private settings by default
Retention controlsCustomer-configurable retention and deletion
Audit logsFor access to personal data
05

Organisational requirements

Companies outside the EU that fall under GDPR by offering services or monitoring must appoint a representative in the EU unless processing is occasional and low risk. A Data Protection Officer is required where core activities involve large-scale monitoring or special category data. High-risk processing needs a data protection impact assessment. Fines can reach €20 million or four per cent of worldwide annual turnover, whichever is higher.

72 hours
Controller breach notification to the authority
1 month
To answer a data subject request
4%
Of global turnover: the upper tier of fines
06

GDPR and the DPDP Act side by side

Building for both at once is efficient, because GDPR is broadly the stricter regime, with some exceptions.

Legal basesGDPR has six; DPDP relies on consent plus a list of legitimate uses
Sensitive dataGDPR has special categories; DPDP treats all personal data alike
ChildrenGDPR: under 16, or lower by member state, for online services; DPDP: under 18, with a ban on tracking and targeted ads
Breach reportingGDPR: risk-based threshold; DPDP: every breach, to users and the Board
TransfersGDPR: restricted unless a mechanism applies; DPDP: allowed unless restricted
ScopeDPDP covers digital data only; GDPR covers paper filing systems too
Sources · last reviewed October 1, 2026

This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.

Purushottam Kumar Suman
Written by
Purushottam Kumar Suman
Founder & CEO, Drema AI

Founder and CEO of Drema AI. Builds AI systems, SaaS platforms and industry software — and writes about what actually survives production.

CTA Background

Got a problem like this one?

Bring it to a call with a founder.You will get a straight answer, including when the answer is no.

View Our Work
AI-First Engineering
Secure & Scalable
Built to Deliver Impact