By Girija Togarati, ISO 27001 Lead Auditor. Reviewed by Murty Nisthala, CISA, CISSP, CCSP.

Yes, GDPR can apply to Indian companies. The regulation reaches beyond Europe.

When GDPR applies

GDPR applies to an Indian company if it offers goods or services to individuals in the EU or EEA, or if it monitors their behaviour. Many Indian IT, SaaS and BPO firms meet this test through their European clients.

What it means for you

You must have a lawful basis, honour data subject rights, keep records of processing, and report breaches. Clients increasingly require proof in contracts.

Get compliant

Univate assesses whether GDPR applies to you and runs the readiness programme.

Univate Solutions delivers GDPR Compliance in India end to end. Book a free consultation and get a fixed quote. Explore data privacy and compliance.