Skip to main content
~20 Years — Continuous operations in cybersecurity and compliance

GDPR Compliance for Indian Businesses: Privacy, Security, and Audit-Ready Evidence

Your EU customers expect GDPR compliance before they sign the DPA. Security Brigade helps Indian SaaS companies, technology firms, and enterprises build the privacy controls, security evidence, and documentation that EU regulators and enterprise buyers demand.

EU GDPR
Compliance Audits
Privacy by Design
Methodology
6,700+
Assessments
Since 2008
CERT-In Empanelled

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

Does it even apply

An Indian company reaches the GDPR through Article 3(2), not through an office

Territorial scope is the first question and the one most often answered wrongly in both directions. These are the four positions.

Your positionHow the Regulation reaches youReference
You sell to people in the EU Offering goods or services to data subjects in the Union brings you within scope whether or not payment is required, and whether or not you have any establishment there. Intent matters: a site that prices in euros, ships to EU addresses or markets in an EU language is evidencing it. Article 3(2)(a)
You monitor behaviour in the EU Monitoring the behaviour of data subjects as far as it takes place within the Union is the second limb, and it catches analytics, profiling and ad-tech built for a global audience without an EU plan. Article 3(2)(b)
You process for an EU client As a processor your obligations arrive through Article 28 and the contract behind it: documented instructions, sub-processor controls, assistance with data-subject requests, breach support, and audit rights your client can exercise. Most Indian IT and BPO exposure is here. Article 28
In scope with no EU establishment Where Article 3(2) applies and you have no establishment in the Union, Article 27 requires a representative in a member state where the affected data subjects are, in writing, named in your privacy notice. Article 27

You sell to people in the EU

How the Regulation reaches you
Offering goods or services to data subjects in the Union brings you within scope whether or not payment is required, and whether or not you have any establishment there. Intent matters: a site that prices in euros, ships to EU addresses or markets in an EU language is evidencing it.
Reference
Article 3(2)(a)

You monitor behaviour in the EU

How the Regulation reaches you
Monitoring the behaviour of data subjects as far as it takes place within the Union is the second limb, and it catches analytics, profiling and ad-tech built for a global audience without an EU plan.
Reference
Article 3(2)(b)

You process for an EU client

How the Regulation reaches you
As a processor your obligations arrive through Article 28 and the contract behind it: documented instructions, sub-processor controls, assistance with data-subject requests, breach support, and audit rights your client can exercise. Most Indian IT and BPO exposure is here.
Reference
Article 28

In scope with no EU establishment

How the Regulation reaches you
Where Article 3(2) applies and you have no establishment in the Union, Article 27 requires a representative in a member state where the affected data subjects are, in writing, named in your privacy notice.
Reference
Article 27

What changes in practice

Article 32 is the one that reaches your engineering team

Most of the GDPR is answered with documents. Article 32 is answered with systems. It requires security appropriate to the risk, naming pseudonymisation and encryption, the confidentiality, integrity, availability and resilience of processing systems, the ability to restore availability after an incident, and a process for regularly testing and evaluating the effectiveness of those measures. That last clause is the one that turns a policy exercise into an engineering one: regular testing is not a recommendation attached to the article, it is part of what the article asks for, and it is the part a supervisory authority can ask you to evidence after an incident. So the useful reading of Article 32 is procedural. Which measures did you choose, what risk assessment produced that choice, when did you last test them, what did the test find, and what happened to the findings. An organisation that can answer those five questions with dates is in a materially different position from one that can produce a policy. We run the testing and structure the evidence so that the answers exist before anybody asks, and because the same testing feeds an ISO 27001 ISMS or a SOC 2 readiness programme, it is rarely worth commissioning on its own.

Where programmes fail

Four states, and the middle two are where most organisations sit

Four states, and the middle two are where most organisations sit
StateWhat it meansWhat follows
Records that match reality An Article 30 record of processing activities that describes what the systems actually do, maintained as they change. The healthy case, and the one that makes every other obligation cheaper: DPIAs, breach assessment and data-subject requests all read from it.
Records written once A record of processing built during a compliance push and never revisited, describing an estate that has since moved. Worse than none in one specific way: it is relied on during a breach assessment, and the thing it fails to mention is the thing that was breached.
Rights answered manually Access, erasure and portability handled by an engineer running queries when a request arrives. Works until volume or a deadline arrives. Article 12 timelines do not flex for the fact that the deletion path across backups, logs and analytics was never built.
Breach clock unrehearsed Article 33 gives 72 hours to notify the supervisory authority, and nobody has decided who declares, who assesses risk to data subjects, or who writes. A 72-hour clock is decided before hour one. The assessment of whether Article 34 communication to data subjects is required is the hard part, and it is not a decision to take for the first time under pressure.
Key
  • Makes everything else cheaper
  • Holds until it is tested
  • Fails in hours

What we do

The work that produces evidence, not just documents

First

Scope and territorial assessment

Establish whether and how the Regulation reaches you, and where you act as controller and where as processor. Getting this wrong in either direction is expensive, and it is an hour of work.

Article 30

Records of processing and data mapping

A record that describes the systems as they are, built from the data flows, not from interviews alone, and structured so it can be maintained instead of rebuilt.

The engineering half

Article 32 technical assessment

Testing the measures you rely on (application, API, infrastructure and access controls) so that "regularly testing and evaluating the effectiveness" has evidence behind it.

Article 28

Processor and sub-processor assurance

Due diligence on the vendors in your chain, and the contractual terms that carry your obligations to them. The duty stays with you wherever the processing happens.

Article 35

DPIAs where the threshold is met

Assessment where processing is likely to result in a high risk, covering necessity, proportionality, the risks to data subjects and the measures addressing them.

Articles 33 and 34

Breach readiness against the 72-hour clock

A rehearsed path: who declares, how risk to data subjects is assessed, what reaches the supervisory authority and when communication to individuals is required.

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade treats GDPR as a combined privacy and security engagement, not a legal checkbox exercise. We assess your data processing activities, validate your technical security controls, and produce the evidence that EU customers, DPA counterparties, and supervisory authorities expect. Our methodology is designed for Indian companies that need to demonstrate compliance to sophisticated EU enterprise buyers.

Discovery
01

Applicability and Scoping

We assess your GDPR applicability, determine your role as controller, processor, or joint controller, identify all EU data processing activities, and define the engagement scope based on your EU customer obligations and DPA requirements.

02

Data Discovery and Processing Inventory

We conduct data discovery across your systems, applications, and third-party integrations to map all personal data processing activities. This produces a comprehensive processing inventory and data-flow documentation covering collection, storage, transmission, and deletion.

Testing
03

Gap Assessment

We perform a detailed gap analysis against GDPR articles, principles, and your specific EU customer DPA obligations. This covers privacy notices, consent mechanisms, DSR workflows, breach notification readiness, vendor controls, transfer mechanisms, and technical and organisational security measures.

04

Technical Security Controls Review

Our security teams validate your technical and organisational measures: encryption, access controls, logging, retention, deletion workflows, backup practices, incident response, API security, and application-level privacy controls. This is where Security Brigade's cybersecurity depth differentiates our GDPR work from pure legal advisory.

Delivery
05

Remediation Roadmap and Implementation Support

We deliver a prioritised remediation roadmap with owners, timelines, and specific implementation guidance. Our team supports your implementation efforts through advisory sessions, template provision for RoPA, privacy notices, consent flows, and DSR procedures, and ongoing tracking through Lemon.

06

Closure Validation and Evidence Pack

After remediation, we validate that all controls are implemented and functioning. We produce the final GDPR compliance evidence pack including the assessment report, RoPA baseline, updated documentation, and closure validation report ready for customer DPA submission or audit response.

"We needed an assessment on a 3-week timeline because of a partner integration deadline. Security Brigade turned it around in 18 days, including the L2 and L3 reviews. The report was regulator-ready — we submitted it to our partner's compliance team unchanged. When speed and credibility both matter, they're the only call we make."
VP Engineering, Retail & Quick Commerce
Vice President — Engineering

Read more client stories →

Industries We Serve for GDPR Compliance

Indian companies across these industries most frequently need GDPR compliance when serving EU customers or processing EU personal data.

SaaS and Technology

Indian SaaS companies with EU customers face GDPR requirements in every enterprise deal. DPAs, vendor assessments, and data transfer mechanisms are table stakes for EU market access.

BFSI and Fintech

Banks, NBFCs, and fintech companies processing transactions or financial data for EU entities face GDPR alongside RBI and SEBI requirements, requiring coordinated compliance.

IT Services and Outsourcing

Indian IT services firms acting as processors for EU controllers must demonstrate GDPR compliance across people, processes, and technology to retain and win contracts.

Healthcare and Pharma

Health data is special category data under GDPR, triggering heightened requirements for Indian healthtech, telemedicine, clinical trial, and pharma companies working with EU counterparts.

E-Commerce and Consumer Platforms

Indian platforms serving EU consumers through websites, apps, or marketplaces trigger GDPR through offering goods or services to EU residents.

Legal and Professional Services

Indian law firms and professional services firms handling EU client data face GDPR obligations that are increasingly scrutinised by their own clients during due diligence.

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

FAQ

GDPR for Indian organisations, answered

Scope, transfers and evidence. Talk to our team about your processing.

Contact us
We have no EU office. Does the GDPR apply to us?+
It can, and an office is not the test. Article 3(2) brings you within scope if you offer goods or services to data subjects in the Union — whether or not payment is required — or if you monitor their behaviour as far as that takes place within the Union. Separately, if you process personal data on behalf of an EU client you carry processor obligations through Article 28 and the contract behind it, which is where most Indian IT and services exposure actually sits.
Do we need a European representative?+
Where Article 3(2) applies and you have no establishment in the Union, Article 27 requires one: a representative designated in writing, established in a member state where the affected data subjects are, and named in your privacy notice so supervisory authorities and individuals can address them. It is a mandate that needs to be real, and we scope whether it is triggered as part of the territorial assessment.
How do transfers to India work?+
Transfers from the EEA rely on the safeguards in Articles 44 to 49: in practice the European Commission’s Standard Contractual Clauses, and the UK International Data Transfer Agreement or the UK Addendum for UK personal data. Following Schrems II those are paired with a transfer impact assessment of the receiving country and supplementary technical measures where the assessment calls for them. Our own position is set out on our GDPR page, and where a client requires processing and access to remain in India we deliver the engagement on that basis.
Do we need a Data Protection Officer?+
Article 37 requires one where your core activities involve regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special categories of data, or where you are a public authority. Many organisations below that threshold appoint a DPO or a privacy lead anyway, because someone has to own the record of processing, the rights process and the breach path. We provide DPO advisory, helping you scope the role, establish it and equip whoever holds it.
What does Article 32 actually require us to do?+
Security appropriate to the risk, which the article illustrates with pseudonymisation and encryption, the confidentiality, integrity, availability and resilience of processing systems, the ability to restore availability after an incident, and a process for regularly testing and evaluating the effectiveness of the measures. That last element is the one organisations most often cannot evidence, and it is the reason technical testing belongs inside a GDPR programme instead of beside it.
Does ISO 27001 cover us for GDPR?+
It covers the security half well and the privacy half not at all. A certified ISMS gives you documented risk assessment, access control, supplier assurance, incident management and the testing evidence Article 32 asks for. What it does not give you is lawful basis, notice and consent, the record of processing, data-subject rights or the breach-notification assessment. That is GDPR-specific work. Article 42 also anticipates approved certification mechanisms as a way of demonstrating compliance, and ISO 27001 is not one of them.

Ready to Achieve GDPR Compliance?

Whether you need a full gap analysis, help signing your first EU customer DPA, or ongoing compliance management, Security Brigade has the expertise and platforms to get you there.

Typically responds within 1 business day · No commitment required

Request a Scoping Call