GDPR compliance.
If you process the personal data of people in the EU or UK, GDPR applies whether or not you have an office there. We build the data map, the assessments and the processes that make that defensible.
At a glance
- Applies to
- Any organisation processing EU or UK personal data
- Timeline
- 2 to 4 months for readiness
- Key artefacts
- Data map, RoPA, DPIAs, processor agreements
- Breach obligation
- 72 hours to notify the supervisory authority
- Penalties
- Up to 4 percent of global annual turnover
What this actually is.
Most GDPR programmes fail on the first step. You cannot protect, minimise or delete data you have not mapped, and almost every organisation is processing more personal data in more places than its privacy notice claims. We start with the inventory because everything else depends on it.
What we cover.
Who needs this.
- SaaS and technology companies with any EU or UK users
- Businesses expanding into European markets
- Organisations acting as processors for EU-based controllers
- Companies whose customers are sending them Article 28 questionnaires
Frequently asked.
We are based in India. Does GDPR apply to us?
If you offer goods or services to people in the EU or UK, or monitor their behaviour, then yes, regardless of where you are established. Being a processor for an EU controller also brings direct obligations under Article 28.
Do we need a Data Protection Officer?
A DPO is mandatory for public authorities, for large-scale systematic monitoring, and for large-scale special category processing. Many organisations do not require one but benefit from a named privacy owner. We will tell you plainly which applies.
How does this relate to India's DPDP Act?
The obligations rhyme: notice, consent, purpose limitation, security safeguards and breach notification. A well-built GDPR programme covers most of the DPDP Act's requirements, and we map both together where you are subject to each.
What about international transfers?
Transfers outside the EEA or UK need a valid mechanism, most commonly Standard Contractual Clauses supported by a transfer impact assessment. We put those in place and document the assessment.
Related services.
CCPA, India's DPDP Act and the growing patchwork of state and national privacy laws. One programme built on a single data inventory, rather than a separate scramble for each jurisdiction.
CMP 02ISO 27001The international standard for information security management. Heavier than SOC 2 up front, more durable afterwards, and the one European and Asian enterprise buyers recognise immediately.
SVC 02API TestingYour mobile app and your single-page front end are just API clients. The API is the real target, and it is usually tested least. We test REST, GraphQL and the authorisation logic underneath both.
Find out what stands between you and certification.
Start with a gap assessment. You get a specific list of what is missing and a realistic timeline, whether or not you continue with us.