GDPR Compliance for Indian Businesses: Privacy, Security, and Audit-Ready Evidence
Your EU customers expect GDPR compliance before they sign the DPA. Security Brigade helps Indian SaaS companies, technology firms, and enterprises build the privacy controls, security evidence, and documentation that EU regulators and enterprise buyers demand.
Trusted by India's leading enterprises
Does it even apply
An Indian company reaches the GDPR through Article 3(2), not through an office
Territorial scope is the first question and the one most often answered wrongly in both directions. These are the four positions.
| Your position | How the Regulation reaches you | Reference |
|---|---|---|
| You sell to people in the EU | Offering goods or services to data subjects in the Union brings you within scope whether or not payment is required, and whether or not you have any establishment there. Intent matters: a site that prices in euros, ships to EU addresses or markets in an EU language is evidencing it. | Article 3(2)(a) |
| You monitor behaviour in the EU | Monitoring the behaviour of data subjects as far as it takes place within the Union is the second limb, and it catches analytics, profiling and ad-tech built for a global audience without an EU plan. | Article 3(2)(b) |
| You process for an EU client | As a processor your obligations arrive through Article 28 and the contract behind it: documented instructions, sub-processor controls, assistance with data-subject requests, breach support, and audit rights your client can exercise. Most Indian IT and BPO exposure is here. | Article 28 |
| In scope with no EU establishment | Where Article 3(2) applies and you have no establishment in the Union, Article 27 requires a representative in a member state where the affected data subjects are, in writing, named in your privacy notice. | Article 27 |
You sell to people in the EU
- How the Regulation reaches you
- Offering goods or services to data subjects in the Union brings you within scope whether or not payment is required, and whether or not you have any establishment there. Intent matters: a site that prices in euros, ships to EU addresses or markets in an EU language is evidencing it.
- Reference
- Article 3(2)(a)
You monitor behaviour in the EU
- How the Regulation reaches you
- Monitoring the behaviour of data subjects as far as it takes place within the Union is the second limb, and it catches analytics, profiling and ad-tech built for a global audience without an EU plan.
- Reference
- Article 3(2)(b)
You process for an EU client
- How the Regulation reaches you
- As a processor your obligations arrive through Article 28 and the contract behind it: documented instructions, sub-processor controls, assistance with data-subject requests, breach support, and audit rights your client can exercise. Most Indian IT and BPO exposure is here.
- Reference
- Article 28
In scope with no EU establishment
- How the Regulation reaches you
- Where Article 3(2) applies and you have no establishment in the Union, Article 27 requires a representative in a member state where the affected data subjects are, in writing, named in your privacy notice.
- Reference
- Article 27
What changes in practice
Article 32 is the one that reaches your engineering team
Most of the GDPR is answered with documents. Article 32 is answered with systems. It requires security appropriate to the risk, naming pseudonymisation and encryption, the confidentiality, integrity, availability and resilience of processing systems, the ability to restore availability after an incident, and a process for regularly testing and evaluating the effectiveness of those measures. That last clause is the one that turns a policy exercise into an engineering one: regular testing is not a recommendation attached to the article, it is part of what the article asks for, and it is the part a supervisory authority can ask you to evidence after an incident. So the useful reading of Article 32 is procedural. Which measures did you choose, what risk assessment produced that choice, when did you last test them, what did the test find, and what happened to the findings. An organisation that can answer those five questions with dates is in a materially different position from one that can produce a policy. We run the testing and structure the evidence so that the answers exist before anybody asks, and because the same testing feeds an ISO 27001 ISMS or a SOC 2 readiness programme, it is rarely worth commissioning on its own.
Where programmes fail
Four states, and the middle two are where most organisations sit
| State | What it means | What follows |
|---|---|---|
| Records that match reality | An Article 30 record of processing activities that describes what the systems actually do, maintained as they change. | The healthy case, and the one that makes every other obligation cheaper: DPIAs, breach assessment and data-subject requests all read from it. |
| Records written once | A record of processing built during a compliance push and never revisited, describing an estate that has since moved. | Worse than none in one specific way: it is relied on during a breach assessment, and the thing it fails to mention is the thing that was breached. |
| Rights answered manually | Access, erasure and portability handled by an engineer running queries when a request arrives. | Works until volume or a deadline arrives. Article 12 timelines do not flex for the fact that the deletion path across backups, logs and analytics was never built. |
| Breach clock unrehearsed | Article 33 gives 72 hours to notify the supervisory authority, and nobody has decided who declares, who assesses risk to data subjects, or who writes. | A 72-hour clock is decided before hour one. The assessment of whether Article 34 communication to data subjects is required is the hard part, and it is not a decision to take for the first time under pressure. |
- Makes everything else cheaper
- Holds until it is tested
- Fails in hours
What we do
The work that produces evidence, not just documents
Scope and territorial assessment
Establish whether and how the Regulation reaches you, and where you act as controller and where as processor. Getting this wrong in either direction is expensive, and it is an hour of work.
Records of processing and data mapping
A record that describes the systems as they are, built from the data flows, not from interviews alone, and structured so it can be maintained instead of rebuilt.
Article 32 technical assessment
Testing the measures you rely on (application, API, infrastructure and access controls) so that "regularly testing and evaluating the effectiveness" has evidence behind it.
Article 28Processor and sub-processor assurance
Due diligence on the vendors in your chain, and the contractual terms that carry your obligations to them. The duty stays with you wherever the processing happens.
DPIAs where the threshold is met
Assessment where processing is likely to result in a high risk, covering necessity, proportionality, the risks to data subjects and the measures addressing them.
Breach readiness against the 72-hour clock
A rehearsed path: who declares, how risk to data subjects is assessed, what reaches the supervisory authority and when communication to individuals is required.
Methodology
How a compliance engagement runs
Every engagement follows this process through Lemon, our proprietary audit management platform.
Security Brigade treats GDPR as a combined privacy and security engagement, not a legal checkbox exercise. We assess your data processing activities, validate your technical security controls, and produce the evidence that EU customers, DPA counterparties, and supervisory authorities expect. Our methodology is designed for Indian companies that need to demonstrate compliance to sophisticated EU enterprise buyers.
Applicability and Scoping
We assess your GDPR applicability, determine your role as controller, processor, or joint controller, identify all EU data processing activities, and define the engagement scope based on your EU customer obligations and DPA requirements.
Data Discovery and Processing Inventory
We conduct data discovery across your systems, applications, and third-party integrations to map all personal data processing activities. This produces a comprehensive processing inventory and data-flow documentation covering collection, storage, transmission, and deletion.
Gap Assessment
We perform a detailed gap analysis against GDPR articles, principles, and your specific EU customer DPA obligations. This covers privacy notices, consent mechanisms, DSR workflows, breach notification readiness, vendor controls, transfer mechanisms, and technical and organisational security measures.
Technical Security Controls Review
Our security teams validate your technical and organisational measures: encryption, access controls, logging, retention, deletion workflows, backup practices, incident response, API security, and application-level privacy controls. This is where Security Brigade's cybersecurity depth differentiates our GDPR work from pure legal advisory.
Remediation Roadmap and Implementation Support
We deliver a prioritised remediation roadmap with owners, timelines, and specific implementation guidance. Our team supports your implementation efforts through advisory sessions, template provision for RoPA, privacy notices, consent flows, and DSR procedures, and ongoing tracking through Lemon.
Closure Validation and Evidence Pack
After remediation, we validate that all controls are implemented and functioning. We produce the final GDPR compliance evidence pack including the assessment report, RoPA baseline, updated documentation, and closure validation report ready for customer DPA submission or audit response.
"We needed an assessment on a 3-week timeline because of a partner integration deadline. Security Brigade turned it around in 18 days, including the L2 and L3 reviews. The report was regulator-ready — we submitted it to our partner's compliance team unchanged. When speed and credibility both matter, they're the only call we make."
Industries We Serve for GDPR Compliance
Indian companies across these industries most frequently need GDPR compliance when serving EU customers or processing EU personal data.
SaaS and Technology
Indian SaaS companies with EU customers face GDPR requirements in every enterprise deal. DPAs, vendor assessments, and data transfer mechanisms are table stakes for EU market access.
BFSI and Fintech
Banks, NBFCs, and fintech companies processing transactions or financial data for EU entities face GDPR alongside RBI and SEBI requirements, requiring coordinated compliance.
IT Services and Outsourcing
Indian IT services firms acting as processors for EU controllers must demonstrate GDPR compliance across people, processes, and technology to retain and win contracts.
Healthcare and Pharma
Health data is special category data under GDPR, triggering heightened requirements for Indian healthtech, telemedicine, clinical trial, and pharma companies working with EU counterparts.
E-Commerce and Consumer Platforms
Indian platforms serving EU consumers through websites, apps, or marketplaces trigger GDPR through offering goods or services to EU residents.
Legal and Professional Services
Indian law firms and professional services firms handling EU client data face GDPR obligations that are increasingly scrutinised by their own clients during due diligence.
Continuous Compliance with ShadowMap
The audit gives you a snapshot. ShadowMap gives you the always-on view.
An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.
Dark Web Monitoring
12B+ breach records indexed; monitors Telegram, paste sites, criminal forums, and ransomware leak sites for credentials, leaked data, and threat actor mentions.
Find leaked data before regulators do.
Explore on ShadowMapBrand Protection
Detects phishing domains, fake mobile apps, social media impersonation, and domain squatting — with orchestrated takedowns.
Stop impersonation before customers fall for it.
Explore on ShadowMapFAQ
GDPR for Indian organisations, answered
Scope, transfers and evidence. Talk to our team about your processing.
Contact usWe have no EU office. Does the GDPR apply to us?
Do we need a European representative?
How do transfers to India work?
Do we need a Data Protection Officer?
What does Article 32 actually require us to do?
Does ISO 27001 cover us for GDPR?
Ready to Achieve GDPR Compliance?
Whether you need a full gap analysis, help signing your first EU customer DPA, or ongoing compliance management, Security Brigade has the expertise and platforms to get you there.
Typically responds within 1 business day · No commitment required