Skip to content
SecuriFii

Regulation · EU

Does the GDPR apply to an Indian company? Scope, roles and the EU representative question

A European customer has sent you a data processing agreement, a set of Standard Contractual Clauses and a questionnaire, and somewhere in the follow-up somebody has suggested you need an EU representative. Whether that is true depends on one distinction — and it is a distinction a lot of people selling GDPR services would rather you did not draw.

Facts checked2026-09-11

Which situation are you in?

Your situationDirectly caught by the GDPR?EU representative?
You process EU personal data for an EU customer, on their instructionsUsually not directly. Your obligations arrive through the Article 28 contract.Usually no
You offer your own service to people in the EU (a product with EU users)Yes — Article 3(2), as a controller for that data.Yes, unless an exemption applies
You monitor the behaviour of people in the EU (analytics, tracking, profiling)Yes — Article 3(2).Yes, unless an exemption applies
You have an establishment in the EU and process in the context of its activitiesYes — Article 3(1).No — you are established in the Union

A summary, not advice. Scope is a legal determination on your specific facts, and the second and third rows in particular turn on details worth taking properly.

Does the GDPR apply to an Indian company?

It can, in two quite different ways, and conflating them is the root of most of the confusion.

Article 3(2) catches an organisation outside the EU directly, where its processing relates to offering goods or services to people in the Union, or to monitoring their behaviour. A Bengaluru company running a product with European users is caught this way, as a controller, regardless of having no EU office.

The second route is contractual. If you process personal data on behalf of an EU customer, on their documented instructions, your duties largely arrive through the Article 28 agreement they sign with you. The EDPB’s guidance on territorial scope draws exactly this line: a non-EU processor whose processing takes place in the context of an EU controller’s establishment becomes subject to obligations imposed by the contract, rather than being directly caught by Article 3(2) in its own right.

Which of those you are in decides almost everything that follows — including whether you need a representative in the Union.

Controller or processor, and why it is decided per activity

A controller determines the purposes and means of processing. A processor acts on the controller’s documented instructions. Most organisations are both, at the same time, for different data.

An Indian firm running a platform for a European customer is a processor for the personal data that customer puts into it — and simultaneously a controller for its own employee records, its marketing list, and the account details of the customer’s staff who log in to support the relationship.

Answer it per processing activity and write the answer down. Accepting controller obligations you do not have creates duties you cannot discharge; accepting processor terms for data you actually control leaves a real obligation unowned. Both are expensive to unpick a year later, and both start in a contract somebody signed quickly.

Do you need an EU representative?

Probably not, if you are purely a processor for EU customers — and this is worth saying plainly, because it is being sold hard.

Article 27 requires a representative in the Union from controllers and processors who are caught by Article 3(2). If your processing is on an EU controller’s instructions and does not itself amount to offering goods or services to people in the Union or monitoring them, you are generally not within Article 3(2) — and the Article 27 duty does not attach. A customer may still ask for one commercially, which is a negotiation rather than a legal requirement.

If you do offer your own service to people in the EU, or you monitor their behaviour, then you are within Article 3(2) and a representative is required unless a narrow exemption applies — broadly, processing that is occasional, does not include special category data at scale, and is unlikely to result in a risk to individuals.

The representative is a real appointment, not a mailbox: a person or firm established in a Member State where your data subjects are, named in your privacy notice, mandated to be addressed by supervisory authorities and data subjects on all issues relating to the processing.

What Article 28 actually commits you to

A processor agreement is not boilerplate, and the commitments in it are operational capabilities rather than clauses.

You process only on documented instructions. Your staff are bound to confidentiality. You implement security measures appropriate to the risk. You do not engage a sub-processor without the controller’s authorisation, and you pass the same terms down. At the end of the engagement you delete or return the data — which requires knowing where all of it went, including backups.

Then the assistance obligations, which are the ones that bite. You must help the controller respond to data subject requests, notify them of a breach without undue delay, and support their impact assessments. A processor who cannot locate one individual’s data across its systems cannot assist with an erasure request, whatever the contract says — and finding out during a live request is the wrong time.

The fines, and which tier you are actually exposed to

The GDPR has two tiers. The lower, under Article 83(4), reaches €10 million or 2% of total worldwide annual turnover, whichever is higher, and covers the obligations in Articles 25 to 39 — which is where a processor’s own direct duties sit, including the Article 28 arrangements and the Article 32 security obligations.

The upper tier, under Article 83(5), reaches €20 million or 4% and covers the basic principles, the lawful bases and consent, data subject rights, and — this is the one to notice — transfers of personal data to a third country under Articles 44 to 49.

That ordering is counter-intuitive and worth carrying away: for a firm in India, the transfer is in the more expensive tier than the processor agreement. The largest GDPR fine issued to date, €1.2 billion against Meta in 2023, was a transfers case.

Transfers, SCCs and the questionnaire you will be sent

India has no adequacy decision, so personal data moving from the EEA to India is a restricted transfer and typically relies on Standard Contractual Clauses, together with an assessment of whether the law and practice at the destination undermine the protection those clauses promise.

In practice this arrives as a schedule from your customer, and the useful thing you can do is answer it precisely rather than reassuringly: where the data physically sits, which of your staff can access it and from where, under what legal circumstances a third party could compel disclosure, and which technical measures — encryption, key custody, access control, pseudonymisation — reduce that exposure.

Prepare those answers once, accurately, and reuse them. Every European customer asks eventually, and the firms that answer well are noticeably quicker through procurement than the ones improvising each time.

What to do about it

Settle the role question per processing activity and record it. Then make the assistance obligations real: know where personal data lives, be able to find one person’s data, and have a breach process that can notify a controller inside the window their own obligation demands — which is usually far tighter in your contract than the regulation’s 72 hours.

ISO/IEC 27701 is the most direct route, because it is built around exactly these artefacts: role determination, records of processing, rights handling, processor contracts, breach procedures. It is not a finding of compliance with the GDPR — no certificate is — but it is the difference between demonstrating compliance and excavating it under time pressure.

Common questions

Does the GDPR apply to companies in India?

It can, in two ways. Directly under Article 3(2), if you offer goods or services to people in the EU or monitor their behaviour. Indirectly and far more commonly, through an Article 28 processor agreement with an EU customer, where your obligations arrive by contract rather than by regulator.

Do Indian companies need an EU representative under Article 27?

Only if you are caught directly by Article 3(2). A firm processing purely on an EU customer’s instructions is generally not within Article 3(2) and so has no Article 27 duty, though a customer may still ask commercially. If you offer your own service to people in the EU, a representative is required unless a narrow exemption applies.

What is the maximum GDPR fine?

€20 million or 4% of total worldwide annual turnover, whichever is higher, for the upper tier — basic principles, data subject rights and international transfers. The lower tier is €10 million or 2% and covers processor obligations and security measures.

Can we transfer EU personal data to India?

Yes, with a transfer mechanism. India has no adequacy decision, so transfers typically rely on Standard Contractual Clauses plus an assessment of the destination’s law and practice, and any supplementary technical measures that assessment calls for.

How quickly must a processor report a breach?

The regulation says without undue delay after becoming aware. Your contract almost certainly says something shorter — 24 hours is common — because the controller’s own 72-hour clock depends on you. Read that clause before signing rather than during an incident.

Does ISO 27701 make us GDPR compliant?

No. Compliance with a law is decided against that law, and is a question for a lawyer. ISO/IEC 27701 builds the records, processes and evidence that make demonstrating compliance straightforward, and it is recognised by the customers asking.

The bottom line

Decide your role per processing activity before anything else — it determines whether you are caught directly or by contract, and whether Article 27 applies at all. And note the tier ordering: for an Indian firm, the transfer sits in the more expensive bracket than the processor agreement.

Related insights