Scope determination under Article 3
A written applicability assessment covering establishment, the offering of goods or services, and behavioural monitoring — the document that tells you which of the rest of this actually binds you.
Governance, Risk & Compliance
Article 3 reaches any organisation anywhere that offers goods or services to people in the EU or monitors their behaviour. There is no revenue floor and no headcount exemption. The first question is whether you are actually in scope — and we answer that before we sell you anything.
Most GDPR pages open with a definition of GDPR. The question an Indian company actually has is narrower and more urgent: does this apply to us at all? Article 3(2) says it applies if you offer goods or services to individuals in the EU — paid or free — or if you monitor their behaviour, which includes analytics and advertising pixels on EU visitors. An Indian SaaS product with EU sign-ups, a BPO processing EU customer records, an agency running remarketing across European traffic: all in scope, regardless of where the company is registered or where the servers sit.
There is also no GDPR certificate to buy. Article 42 provides for certification schemes, but in practice approved schemes are scarce and none of them functions as the general-purpose badge that vendors imply when they sell "GDPR certification". What you can have is a documented, evidence-backed compliance position that survives a customer’s due diligence and a regulator’s questions. That is the deliverable, and we would rather say so plainly than sell a logo.
The control almost every Indian vendor misses is the transfer mechanism. India is not the subject of an EU adequacy decision, so moving EU personal data here needs Standard Contractual Clauses or another Article 46 mechanism, plus a transfer impact assessment. It is skipped constantly, and it is one of the first things an EU enterprise buyer’s legal team asks to see.
Coverage
Scoped to what you process and why. The obligations that apply to a data controller with EU customers are not the obligations that apply to a processor working under someone else’s instructions.
A written applicability assessment covering establishment, the offering of goods or services, and behavioural monitoring — the document that tells you which of the rest of this actually binds you.
Consent, contract, legal obligation, vital interests, public task or legitimate interest — mapped activity by activity, with legitimate-interest assessments recorded where that basis is relied on.
The Article 30 register: what personal data you hold, why, where it sits, who it is shared with and how long you keep it. The first document a supervisory authority asks for.
Required before high-risk processing — large-scale monitoring, profiling with legal effects, or special-category data. Before you build the feature, not after it ships.
Working processes for access, rectification, erasure, restriction, portability and objection, within the one-month statutory deadline. A rights request is an operational test, not a policy statement.
Detection, assessment and notification to the relevant supervisory authority without undue delay and within 72 hours of becoming aware. A playbook you cannot write during an incident.
Standard Contractual Clauses or another Article 46 mechanism for every EU–India transfer, with a transfer impact assessment behind it, plus processor and sub-processor agreements under Article 28.
Encryption, resilience, and a process for regularly testing and evaluating the effectiveness of your security measures — which is a testing obligation written into the regulation itself.
Approach
The scope check comes first and can end the engagement early. If Article 3 does not reach you, we would rather tell you that in week one than build you a programme you do not need.
The Article 3 applicability test, then a data-flow inventory of every point where EU personal data enters, moves through and leaves your systems.
Current state against the obligations that actually apply to you, scored and prioritised — not a two-hundred-page checklist nobody opens twice.
Per-activity basis mapping, legitimate-interest assessments where relied upon, and impact assessments for anything high-risk.
Article 32 is not satisfied by a policy. Testing, access-control work and encryption review on the systems that actually hold EU personal data.
Records of processing, breach runbook, rights-request workflow, SCCs and processor agreements, and the policies that tie them together.
Rights requests rehearsed end to end, the breach process tabletopped, and drift detection so the evidence pack does not quietly go stale.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
A defensible answer to whether GDPR applies to you and to which processing — the document every subsequent decision rests on.
A complete Article 30 register, structured to be maintained rather than rewritten annually.
Per-activity basis with reasoning recorded, and impact assessments for high-risk processing.
The 72-hour clock, decision criteria, roles, notification templates and the escalation path — rehearsed before you need it.
Transfer mechanisms and Article 28 contracts for EU–India data movement, with transfer impact assessments.
Security testing findings tied to the technical-measures obligation, so the regulation’s testing requirement is met with evidence rather than assertion.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
If you offer goods or services to individuals in the EU, or monitor their behaviour — which includes running analytics or advertising pixels against EU visitors — then Article 3(2) applies regardless of where you are incorporated or where your servers are. There is no revenue threshold and no employee-count exemption. Establishing this properly, in writing, is the first thing we do, because everything else follows from it.
Not in any generally useful sense. Article 42 allows for approved certification schemes, but in practice approved schemes are scarce and none functions as the general-purpose badge that vendors imply when they sell one. What holds up in a customer due-diligence review is a documented, evidence-backed compliance position: records of processing, lawful bases, DPIAs, transfer mechanisms and tested technical measures.
Different regulator, different lawful bases, different breach timelines and different penalties. GDPR offers six lawful bases including legitimate interest; DPDP runs on consent plus a defined list of legitimate uses with no equivalent catch-all. GDPR gives you 72 hours to notify a supervisory authority; DPDP has its own India-specific reporting duties. Most Indian companies serving EU customers need both, which is why we scope them together but keep them distinct.
Almost certainly yes. India is not covered by an EU adequacy decision, so transferring EU personal data here requires a valid Article 46 mechanism — in practice, Standard Contractual Clauses — together with a transfer impact assessment considering the legal environment in the destination country. This is the single most commonly missing control we find at Indian vendors, and the one EU legal teams check first.
Two tiers. The upper tier reaches €20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious infringements. The lower tier reaches €10 million or 2% for administrative failures such as missing records of processing (as of August 2026). For most Indian companies the nearer-term risk is commercial rather than regulatory: EU enterprise buyers write transfer and processing compliance into contracts as a hard gate, and a failed vendor review costs the deal long before any authority is involved.
Yes, and Article 32 requires it. The regulation asks for appropriate technical measures and for a process of regularly testing and evaluating their effectiveness — a documented testing obligation. Our engagements pair the documentation work with real testing of the systems holding EU personal data, so the technical-measures requirement is evidenced rather than asserted.
No, and we are explicit about that. We are a security and compliance firm. We tell you what personal data you process, what your obligations look like operationally and where you fall short. Where a question turns on genuinely contested legal interpretation, we flag it and recommend you take that specific question to counsel rather than quietly picking an answer and presenting it as settled.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.