Governance, Risk & Compliance

GDPR does not care where you are incorporated.

Article 3 reaches any organisation anywhere that offers goods or services to people in the EU or monitors their behaviour. There is no revenue floor and no headcount exemption. The first question is whether you are actually in scope — and we answer that before we sell you anything.

EU data subjects SCCs + TIA Your systems India India has no EU adequacy decision so every transfer needs an Article 46 mechanism The control most Indian vendors are missing
72 hrsBreach notification window
4%Upper-tier fine ceiling
6Lawful bases under Article 6
0Official certificates available

The question nobody answers first: does it apply to us?

Most GDPR pages open with a definition of GDPR. The question an Indian company actually has is narrower and more urgent: does this apply to us at all? Article 3(2) says it applies if you offer goods or services to individuals in the EU — paid or free — or if you monitor their behaviour, which includes analytics and advertising pixels on EU visitors. An Indian SaaS product with EU sign-ups, a BPO processing EU customer records, an agency running remarketing across European traffic: all in scope, regardless of where the company is registered or where the servers sit.

There is also no GDPR certificate to buy. Article 42 provides for certification schemes, but in practice approved schemes are scarce and none of them functions as the general-purpose badge that vendors imply when they sell "GDPR certification". What you can have is a documented, evidence-backed compliance position that survives a customer’s due diligence and a regulator’s questions. That is the deliverable, and we would rather say so plainly than sell a logo.

The control almost every Indian vendor misses is the transfer mechanism. India is not the subject of an EU adequacy decision, so moving EU personal data here needs Standard Contractual Clauses or another Article 46 mechanism, plus a transfer impact assessment. It is skipped constantly, and it is one of the first things an EU enterprise buyer’s legal team asks to see.

Coverage

What GDPR actually requires of you

Scoped to what you process and why. The obligations that apply to a data controller with EU customers are not the obligations that apply to a processor working under someone else’s instructions.

Scope determination under Article 3

A written applicability assessment covering establishment, the offering of goods or services, and behavioural monitoring — the document that tells you which of the rest of this actually binds you.

Lawful basis per processing activity

Consent, contract, legal obligation, vital interests, public task or legitimate interest — mapped activity by activity, with legitimate-interest assessments recorded where that basis is relied on.

Records of Processing Activities

The Article 30 register: what personal data you hold, why, where it sits, who it is shared with and how long you keep it. The first document a supervisory authority asks for.

Data Protection Impact Assessments

Required before high-risk processing — large-scale monitoring, profiling with legal effects, or special-category data. Before you build the feature, not after it ships.

Data subject rights

Working processes for access, rectification, erasure, restriction, portability and objection, within the one-month statutory deadline. A rights request is an operational test, not a policy statement.

Breach process and 72-hour notification

Detection, assessment and notification to the relevant supervisory authority without undue delay and within 72 hours of becoming aware. A playbook you cannot write during an incident.

International transfers

Standard Contractual Clauses or another Article 46 mechanism for every EU–India transfer, with a transfer impact assessment behind it, plus processor and sub-processor agreements under Article 28.

Article 32 technical measures

Encryption, resilience, and a process for regularly testing and evaluating the effectiveness of your security measures — which is a testing obligation written into the regulation itself.

Approach

How a GDPR engagement runs

The scope check comes first and can end the engagement early. If Article 3 does not reach you, we would rather tell you that in week one than build you a programme you do not need.

  1. 01 · Scope and data mapping

    The Article 3 applicability test, then a data-flow inventory of every point where EU personal data enters, moves through and leaves your systems.

  2. 02 · Gap assessment

    Current state against the obligations that actually apply to you, scored and prioritised — not a two-hundred-page checklist nobody opens twice.

  3. 03 · Lawful basis and DPIAs

    Per-activity basis mapping, legitimate-interest assessments where relied upon, and impact assessments for anything high-risk.

  4. 04 · Technical measures

    Article 32 is not satisfied by a policy. Testing, access-control work and encryption review on the systems that actually hold EU personal data.

  5. 05 · Evidence pack

    Records of processing, breach runbook, rights-request workflow, SCCs and processor agreements, and the policies that tie them together.

  6. 06 · Operate and monitor

    Rights requests rehearsed end to end, the breach process tabletopped, and drift detection so the evidence pack does not quietly go stale.

Run against recognised standards

  • EU GDPR (2016/679)The regulation itself
  • UK GDPR & Data Protection Act 2018Where UK data subjects are also in scope
  • EDPB Guidelines 3/2018Territorial scope interpretation
  • Standard Contractual Clauses (2021)Article 46 transfer mechanism
  • ISO/IEC 27701Privacy information management extension
  • ISO/IEC 27001:2022Underlying security control baseline

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Written Article 3 scope determination

A defensible answer to whether GDPR applies to you and to which processing — the document every subsequent decision rests on.

Records of Processing Activities

A complete Article 30 register, structured to be maintained rather than rewritten annually.

Lawful-basis map and DPIA reports

Per-activity basis with reasoning recorded, and impact assessments for high-risk processing.

Breach notification runbook

The 72-hour clock, decision criteria, roles, notification templates and the escalation path — rehearsed before you need it.

SCCs and processor agreements

Transfer mechanisms and Article 28 contracts for EU–India data movement, with transfer impact assessments.

Article 32 testing evidence

Security testing findings tied to the technical-measures obligation, so the regulation’s testing requirement is met with evidence rather than assertion.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • You have EU sign-ups, EU employees or EU website visitors and have never checked whether Article 3 reaches you.
  • An EU customer has sent you a data processing agreement and you do not know whether you can sign it.
  • You transfer EU personal data to India and have no Standard Contractual Clauses in place.
  • You were sold a "GDPR certificate" and want to know what you actually bought.
  • You have a privacy policy but no records of processing behind it.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

GDPR — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

Does GDPR apply to us if we are only registered in India?

If you offer goods or services to individuals in the EU, or monitor their behaviour — which includes running analytics or advertising pixels against EU visitors — then Article 3(2) applies regardless of where you are incorporated or where your servers are. There is no revenue threshold and no employee-count exemption. Establishing this properly, in writing, is the first thing we do, because everything else follows from it.

Is there a GDPR certificate we can display?

Not in any generally useful sense. Article 42 allows for approved certification schemes, but in practice approved schemes are scarce and none functions as the general-purpose badge that vendors imply when they sell one. What holds up in a customer due-diligence review is a documented, evidence-backed compliance position: records of processing, lawful bases, DPIAs, transfer mechanisms and tested technical measures.

How is GDPR different from India’s DPDP Act?

Different regulator, different lawful bases, different breach timelines and different penalties. GDPR offers six lawful bases including legitimate interest; DPDP runs on consent plus a defined list of legitimate uses with no equivalent catch-all. GDPR gives you 72 hours to notify a supervisory authority; DPDP has its own India-specific reporting duties. Most Indian companies serving EU customers need both, which is why we scope them together but keep them distinct.

Do we need Standard Contractual Clauses if our servers are in India?

Almost certainly yes. India is not covered by an EU adequacy decision, so transferring EU personal data here requires a valid Article 46 mechanism — in practice, Standard Contractual Clauses — together with a transfer impact assessment considering the legal environment in the destination country. This is the single most commonly missing control we find at Indian vendors, and the one EU legal teams check first.

What are the actual penalties?

Two tiers. The upper tier reaches €20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious infringements. The lower tier reaches €10 million or 2% for administrative failures such as missing records of processing (as of August 2026). For most Indian companies the nearer-term risk is commercial rather than regulatory: EU enterprise buyers write transfer and processing compliance into contracts as a hard gate, and a failed vendor review costs the deal long before any authority is involved.

Do you do the technical work as well as the paperwork?

Yes, and Article 32 requires it. The regulation asks for appropriate technical measures and for a process of regularly testing and evaluating their effectiveness — a documented testing obligation. Our engagements pair the documentation work with real testing of the systems holding EU personal data, so the technical-measures requirement is evidenced rather than asserted.

Are you a law firm?

No, and we are explicit about that. We are a security and compliance firm. We tell you what personal data you process, what your obligations look like operationally and where you fall short. Where a question turns on genuinely contested legal interpretation, we flag it and recommend you take that specific question to counsel rather than quietly picking an answer and presenting it as settled.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.