Meet the European Standard
GDPR Compliance and European Data Protection
The GDPR is Europe's data protection law, and it reaches Indian companies that sell to or monitor people in the EU. We help you confirm whether it applies, set your lawful bases, honour data subject rights and document it all.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
The General Data Protection Regulation governs how organisations handle the personal data of people in the European Union, wherever the organisation is based. An Indian company falls under it when it offers goods or services to people in the EU or monitors their behaviour, and Indian IT and SaaS firms processing data for EU clients take on processor duties by contract. It requires a lawful basis for each processing purpose, records of processing, data subject rights, impact assessments for high-risk processing, safeguards for transfers out of the EU, and breach notification within 72 hours, backed by fines of up to 20 million euros or 4% of worldwide annual turnover. We build GDPR programmes that sit alongside DPDP Act compliance, working remotely across India from our Greater Noida and Kanpur offices.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the GDPR engagement, 6 phases in order, each one selectable. Phase 1, Data Mapping and Lawful Basis. We map your processing activities and confirm a lawful basis for each one. This is the backbone of GDPR compliance. Activities: Inventory processing activities across the business; Assign a lawful basis to each activity; Document legitimate interest assessments where used; Flag special category data and its conditions. Hands over Processing Inventory and Lawful Basis Register. Phase 2, Gap Assessment. We measure your practices against the GDPR articles and give you a prioritised action plan. Activities: Assess practices against the accountability articles; Review notices, consent, and rights handling; Check security measures against article 32; Rank gaps by fine exposure and effort. Hands over GDPR Gap Assessment and Action Plan. Phase 3, Rights and Consent Processes. We build workflows for data subject rights and, where needed, consent that meets the standard. Activities: Build workflows for access, erasure, and portability requests; Set the one-month response clock and tracking; Redesign consent capture where consent is the basis; Train frontline teams to recognise requests. Hands over Data Subject Rights Workflow. Phase 4, Records and Impact Assessments. We help you maintain records of processing and run data protection impact assessments for high-risk work. Activities: Build article 30 records of processing; Set DPIA screening criteria for new projects; Run DPIAs for existing high-risk processing; Embed the records into change management. Hands over Records of Processing and DPIA Templates. Phase 5, Transfers and Breach Readiness. We review international transfers and set up breach reporting within the 72-hour requirement. Activities: Map international transfers and their safeguards; Put Standard Contractual Clauses in place where needed; Run transfer impact assessments for key routes; Write and test the 72-hour breach procedure. Hands over Transfer Register and Breach Response Procedure. Phase 6, Readiness Review. We run a final review so you can demonstrate accountability to a customer or a supervisory authority. Activities: Test the rights workflow with sample requests; Verify remediation of gap assessment findings; Compile the accountability evidence pack; Brief leadership on residual risk. Hands over GDPR Readiness Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Data Mapping and Lawful Basis
We map your processing activities and confirm a lawful basis for each one. This is the backbone of GDPR compliance.
What Happens In This Phase
- Inventory processing activities across the business
- Assign a lawful basis to each activity
- Document legitimate interest assessments where used
- Flag special category data and its conditions
The Handover
Processing Inventory and Lawful Basis Register
The next phase starts from this.
Phase 01 Data Mapping and Lawful Basis
We map your processing activities and confirm a lawful basis for each one. This is the backbone of GDPR compliance.
What Happens In This Phase
- Inventory processing activities across the business
- Assign a lawful basis to each activity
- Document legitimate interest assessments where used
- Flag special category data and its conditions
The Handover
Processing Inventory and Lawful Basis Register
The next phase starts from this.
- 01
Data Mapping and Lawful Basis
We map your processing activities and confirm a lawful basis for each one. This is the backbone of GDPR compliance.
OutputProcessing Inventory and Lawful Basis RegisterActivities
- Inventory processing activities across the business
- Assign a lawful basis to each activity
- Document legitimate interest assessments where used
- Flag special category data and its conditions
- 02
Gap Assessment
We measure your practices against the GDPR articles and give you a prioritised action plan.
OutputGDPR Gap Assessment and Action PlanActivities
- Assess practices against the accountability articles
- Review notices, consent, and rights handling
- Check security measures against article 32
- Rank gaps by fine exposure and effort
- 03
Rights and Consent Processes
We build workflows for data subject rights and, where needed, consent that meets the standard.
OutputData Subject Rights WorkflowActivities
- Build workflows for access, erasure, and portability requests
- Set the one-month response clock and tracking
- Redesign consent capture where consent is the basis
- Train frontline teams to recognise requests
- 04
Records and Impact Assessments
We help you maintain records of processing and run data protection impact assessments for high-risk work.
OutputRecords of Processing and DPIA TemplatesActivities
- Build article 30 records of processing
- Set DPIA screening criteria for new projects
- Run DPIAs for existing high-risk processing
- Embed the records into change management
- 05
Transfers and Breach Readiness
We review international transfers and set up breach reporting within the 72-hour requirement.
OutputTransfer Register and Breach Response ProcedureActivities
- Map international transfers and their safeguards
- Put Standard Contractual Clauses in place where needed
- Run transfer impact assessments for key routes
- Write and test the 72-hour breach procedure
- 06
Readiness Review
We run a final review so you can demonstrate accountability to a customer or a supervisory authority.
OutputGDPR Readiness ReportActivities
- Test the rights workflow with sample requests
- Verify remediation of gap assessment findings
- Compile the accountability evidence pack
- Brief leadership on residual risk
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
DPDP Compass
Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.
What Is Examined, and What it Is Measured Against
Map
Map of the GDPR scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: OneTrust, Securiti, TrustArc, Microsoft Purview, BigID, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: GDPR, EDPB Guidelines, ISO/IEC 27701:2025, Standard Contractual Clauses (2021), NIST Privacy Framework.
What We Run
7 tools
- OneTrust
- Securiti
- TrustArc
- Microsoft Purview
- BigID
- Jira
- Confluence
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- GDPR
- EDPBGuidelines
- ISO/IEC 27701:2025
- SCCsEuropean Union
- NIST Privacy Framework
Deliverables
What You Receive
- Records of processing activities
- Lawful basis register
- Data subject rights workflow
- Data protection impact assessment templates
- Breach response procedure
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Does the GDPR apply to an Indian company?
It does when the company offers goods or services to people in the European Union, paid or free, or monitors their behaviour there, for example through tracking and profiling on a website or app. Being based in India does not remove the obligation, because the GDPR follows the people whose data is processed rather than the location of the business. It also reaches Indian IT services and SaaS companies indirectly: when an EU client engages you to process personal data on its behalf, you act as a processor and the client must bind you to GDPR duties by contract. A company with no EU customers, users or clients, and no monitoring of people in the EU, is usually outside its scope. We confirm applicability during scoping by looking at your markets, websites, apps and client contracts rather than assuming either way.
Do we need an EU representative?
Usually, yes, if the GDPR applies to you because you target or monitor people in the EU and you have no establishment there. Article 27 requires such controllers and processors to appoint a representative in one of the member states where the people concerned are, in writing, to act as a contact point for supervisory authorities and data subjects. There is a narrow exception for processing that is occasional, does not involve large-scale special category or criminal data, and is unlikely to create risk, but most businesses that actively sell into Europe do not fit it. The representative is not a data protection officer and does not take on your liability. We assess whether the exception applies to you, and if not, help you define the representative's role and the records they need access to, so enquiries are answered within the time the law expects.
How do we transfer EU personal data to India lawfully?
The European Commission has not issued an adequacy decision for India, so personal data leaving the EU for India needs another transfer tool. For most businesses that means the Standard Contractual Clauses adopted in June 2021, choosing the module that matches the relationship, such as controller to processor, together with a transfer impact assessment. That assessment looks at the law and practice in India that could affect the data and records the supplementary measures you use, such as encryption, access controls and pseudonymisation. Binding corporate rules are an option for large groups but take longer to approve. The same analysis applies to onward transfers to your own sub-processors. We map every flow of EU data into India and beyond, put the right clauses in place with clients and vendors, and document the assessment so it stands up when a client or authority asks for it.
What does the GDPR require from us as a processor?
As a processor you handle personal data only on your client's documented instructions, and Article 28 requires a written contract setting out the subject matter, duration, purpose and type of data, plus your obligations. Those include confidentiality commitments for your staff, appropriate security measures, engaging sub-processors only with the controller's authorisation and on equivalent terms, helping the controller respond to data subject requests and carry out impact assessments, deleting or returning data at the end of the service, and making available the information needed to show compliance, including allowing audits. You must also notify the controller of a personal data breach without undue delay and keep records of processing for your clients. Processors can be fined directly. We review your client contracts, build the processes behind each clause and prepare the evidence EU clients ask for during vendor assessments.
How fast must we report a personal data breach?
A controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to people's rights and freedoms. If notification comes later, the reasons for the delay must be given. Where the breach is likely to result in a high risk, the affected individuals must also be told without undue delay. A processor must inform its controller without undue delay after becoming aware, which in practice means within the few hours your contracts usually specify. Every breach, reportable or not, has to be documented. The 72-hour clock is short enough that decisions made during an incident decide compliance, so we build a breach procedure with clear roles, an assessment template and prepared notification drafts, and rehearse it before it is needed.
Can one programme cover both the GDPR and the DPDP Act?
Largely, yes, with care over the differences. Both laws expect you to know what personal data you hold and why, give clear notices, respect individuals' rights, secure the data, manage processors and handle breaches, so one data inventory, one records system, one rights process and one incident procedure can serve both. The differences matter, though. The DPDP Act relies mainly on consent and a short list of legitimate uses and has no general legitimate interests basis, its notice and consent rules are specific, it treats children's data differently, and its breach intimation follows the DPDP Rules, 2025 rather than the 72-hour GDPR standard. Most DPDP Act duties apply from 13 May 2027. We build a shared control set and document where each law needs its own handling, so neither programme is copied blindly from the other.
How long does a GDPR compliance programme take?
For most mid-sized Indian companies, two to four months to reach a defensible position, following our phases. Data mapping and lawful basis analysis take two to three weeks, the gap assessment two to three, rights and consent processes three to four, records and impact assessments two to four, and transfers and breach readiness two to three, with a readiness review at the end. A processor serving a handful of EU clients with well-defined services moves faster than a consumer business with many products, apps and marketing tools. What stretches the timeline is usually data mapping, because personal data turns up in analytics, support tools, spreadsheets and backups nobody listed, and contract remediation, because client and vendor agreements take time to renegotiate. We commit to a timeline after the gap assessment, once the number of processing activities and contracts is known.
What does GDPR support cost?
We do not publish a figure for GDPR work, because the scope varies too much for a range to be useful. A processor with a few EU clients and a single platform needs a fraction of the work a consumer company with EU-facing apps, marketing and analytics does. The quote depends on the number of processing activities and systems, whether you act as controller, processor or both, how many client and vendor contracts need Standard Contractual Clauses or processor terms, whether impact assessments are required, and how much documentation already exists. Some costs sit outside our fee: an EU representative service if you need one, legal review in a member state where specific local advice is required, and your own team's time. If you are also preparing for the DPDP Act, combining the two lowers the total. We scope first, then give a fixed price in writing.
Keep Moving Through Compliance
Service 10 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 27701Build a certifiable privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.