Skip to main content
For SaaS, IT services, BPO and healthtech teams in Gorakhpur

GDPR Compliance in Gorakhpur for companies serving EU customers

There is no GDPR registration to file in Gorakhpur. What your EU customer, their auditor and a supervisory authority ask for is evidence: records, contracts, a transfer file and a breach process that works. We build that pack.

  • Article 3 test run for your Gorakhpur operation
  • Article 30 records, DPAs and sub-processor terms
  • SCC module plus a transfer impact assessment
  • Breach and rights procedures drilled, not filed
IncorpX data protection expert advising a company in Gorakhpur on GDPR obligations Talk to us
Google rating
4.9/58,500+ Google reviews
Privacy and security experts
4 to 8 week programme
Reviewed by Industry Experts & Startup Specialists.
Last Updated: 
FREE ConsultationGet Started @ ₹299 ₹0

Get Expert Consultation

Talk to our business executives in minutes

Instant Response 100% Confidential Expert Advice
Zoho Authorized Partner
30EU and EEA countries covered
72 hrsBreach notification clock
4%Maximum fine, global turnover
4 to 8Weeks to a defensible programme
Why IncorpX

Your EU buyer will not ask if you comply. They will ask you to prove it.

Security questionnaires are answered with documents. We build documents for your Gorakhpur operation that survive the follow-up question, and the procedures behind them that survive an actual incident.

Scope decided first

The Article 3 test is run and written down before work starts, so a team in Gorakhpur is not paying to meet obligations that were never theirs.

Evidence, not templates

Records, notices and contracts drafted against how your product and delivery model actually process data. Generic templates fail on the first follow-up question.

The whole vendor chain

Obligations flow down to every sub-processor your engineers use. We check the terms you sign with clients are ones your own vendors can support.

Drilled, not filed

A breach procedure nobody has rehearsed fails at hour three of a 72 hour clock, especially across time zones. We run the drill and fix what it breaks.

Hear What Our Customers Have to Say

Google Logo

A highly rated startup guidance and tax consultation platform on Google.

4.9 out of 5 (8521+ ratings)
Verified
User Image

“Incorporating my Startup with IncorpX was a smooth experience. The team was highly professional, guiding us every step of the way with clear communication and prompt support. The registration process was fast, and every detail was handled with precision and accuracy. Highly recommend IncorpX for anyone starting a business.”

User Image

“Company is good and service is also smooth. I used their compliance service and the response was timely with no delay and price are also convenient. They are always available to cater your need.”

User Image

“I am very satisfied with the team of IncorpX for providing the top notch services. Team of IncorpX was giving the update on daily basis was one of the best thing which I experience in Corporate. keep doing it. Thank you!”

User Image

“Don't think twice.Got my company incorporates here. Tbh very impressed by the quality of service provided by this team. Very organized and friendly team. Had a smooth and peaceful experience. Timely regular updates were provided by the team. Overall a great experience.”

User Image

“It's rare to find a service provider who makes the process feel personal - IncorpX absolutely did. From day one, they patiently explained every detail without any jargon, making it easy to understand and stress-free. There was zero chasing, no delays-just efficient, smooth execution all the way through. I felt supported, heard, and confident at every step of registering my company EIGHTH DAY FORGE (OPC) Private Limited. Thanks to Mr. Sriram and his wonderful team.”

User Image

“IncorpX made the entire registration process for our company, EKnal Technologies, smooth and stress-free. Their team was professional, efficient, and incredibly supportive from start to finish. Highly recommend them to any founder looking for a reliable partner during the registration process. Special shoutout to Sriram and Aswin - your support, clarity, and responsiveness made the whole process incredibly smooth.”

Video Reviews

Real Clients, Real Stories

Hear directly from founders and business owners we have assisted on their registration and compliance journey.

0:42
IncorpX Client Company Registration
0:50
IncorpX Client Startup Founder
2:18
IncorpX Client Trademark & Compliance
3:38
IncorpX Client Why founders choose us
Applicability

Does the GDPR apply to a company in Gorakhpur?

Two routes bring an Indian company into scope, and they carry different duties. Establish which one applies to your Gorakhpur operation before spending a rupee on compliance work.

The scope test
The GDPR reaches companies with no office, entity or server in Europe, so a business registered and operating entirely in Gorakhpur can be squarely in scope. Article 3(2) applies it to any organisation that offers goods or services to people in the EU or EEA, or monitors their behaviour. Separately, Article 28(3) obliges every EU client to push its obligations down by contract, which is how most technology and services companies in Uttar Pradesh first meet the Regulation. The first route makes you directly accountable to a supervisory authority. The second makes you accountable to a customer whose own fine exposure sits behind every clause you are asked to sign.
  • Direct routeArticle 3(2): you target or monitor people in the EU
  • Contract routeArticle 28(3): your EU client passes obligations down
  • RepresentativeArticle 27 appointment in the EU, not in Gorakhpur
How the GDPR reaches common business models in Gorakhpur
Your businessTypical roleHow the GDPR reaches youFirst thing to build
SaaS product sold to EU businessesProcessor for customer data, controller for your ownArticle 28(3) flow-down from every EU client, plus Article 3(2) if you market into the EUDPA, sub-processor list and processor-side Article 30 record
IT services, BPO or KPO delivering from GorakhpurProcessorContract flow-down, client audits and security questionnairesDPA, SCC module Two or Three and a transfer impact assessment
D2C e-commerce shipping to the EUControllerArticle 3(2): goods offered to people in the EULawful basis review, privacy notice and Article 27 representative
App or website with EU users and analyticsControllerArticle 3(2) monitoring limb, plus national ePrivacy rules on cookiesConsent layer, cookie audit and controller-side Article 30 record
Healthtech or clinical research with EU patient dataUsually processor, sometimes controllerArticle 9 special category data raises the risk profile sharplyDPIA under Article 35, encryption and access controls
Recruitment or staffing into the EUController for candidatesArticle 3(2): services offered to people in the EURetention schedule, candidate notice and rights procedure
Offshore development centre for an EU parentProcessor within a groupIntra-group instructions plus Chapter V on every transfer to GorakhpurIntra-group agreement and one group-wide record

Two exemptions that rarely hold for a delivery team

The Article 30(5) exemption for organisations under 250 employees falls away where processing is not occasional, is likely to result in a risk, or involves special category data, which describes most continuous delivery work run from Gorakhpur. The Article 27(2) exemption from appointing an EU representative requires processing that is occasional and low risk and not large-scale special category data. Systematic, recurring processing fails both tests.

Overview

What GDPR compliance means for a Gorakhpur company

Key takeaway
The General Data Protection Regulation (EU) 2016/679 has applied since 25 May 2018 across the EU and the EEA. It is a regulation, not a certification scheme: no authority inspects a company in Gorakhpur, licenses it, or issues it a certificate. Compliance is a state you evidence on demand, through a record of what you process, a lawful basis for each purpose, contracts down the vendor chain, a documented transfer safeguard, security proportionate to the risk, and procedures that hold when a data subject writes in or a laptop goes missing. Fines reach 20 million euro or 4 percent of global annual turnover, whichever is higher, but for most vendors in Uttar Pradesh the sharper risk is commercial: failing due diligence and losing the account.
  • InstrumentRegulation (EU) 2016/679, applicable 25 May 2018
  • Reach27 EU member states plus Iceland, Liechtenstein and Norway
  • Local filingNone anywhere in India, including Gorakhpur
  • Top fine tier20 million euro or 4 percent of worldwide turnover

Companies in Gorakhpur usually meet the Regulation from the vendor side. They are not selling to European consumers; they are building or running systems for European businesses. That makes them processors, and a processor's duties are narrower than a controller's but far more visible, because they arrive as contract clauses with an audit right attached. The work is therefore less about privacy strategy and more about producing a specific set of artefacts that hold up when someone reads them line by line.

Nothing in the Regulation is decided locally. There is no state-level variation inside Uttar Pradesh, no registration with any Indian authority, and no fee to any government. What varies by company is the data: which EU personal data reaches your systems, through which client, under which instructions, and which vendors touch it after you do.

IncorpX privacy expert reviewing an EU data processing agreement with a technology team in Gorakhpur Evidence pack

What we produce, in the order buyers ask for it

Every artefact below has been asked for by an EU customer during a vendor review. They are built in dependency order, because a data processing agreement written before the data map is a promise nobody has checked you can keep.

  • Data map and Article 30 record, split by controller and processor role
  • Privacy notice, cookie and consent layer, retention schedule
  • Article 28(3) DPA, sub-processor list and flow-down terms
  • SCC module, transfer impact assessment and supplementary measures
  • Security statement mapped to Article 32, with testing evidence
  • Rights and breach procedures, plus the drill record behind them
Roles

Controller or processor: the decision that sets your duties

Almost every technology company in Gorakhpur is both, on different data sets. Getting the split right decides which obligations you carry directly and which arrive through the customer contract.

Controller and processor duties compared, GDPR
ObligationAs controllerAs processor
Decides purpose and means of processing Yes No
Keeps an Article 30 recordYes, of its own processingYes, of processing carried out for each controller
Needs a documented lawful basis (Article 6) YesNo, acts on the controller instructions
Publishes a privacy notice (Articles 13 and 14) YesOnly for its own data, such as employees
Answers data subject requestsYes, within one month under Article 12(3)Assists the controller on the DPA timeline
Notifies the supervisory authority of a breachYes, within 72 hours under Article 33Notifies the controller without undue delay
Carries out DPIAs (Article 35) YesAssists the controller
Signs an Article 28(3) contractYes, as the imposing partyYes, and mirrors it to sub-processors
Appoints an Article 27 representative if in scope Yes Yes
Direct fine exposure under Article 83Full rangeProcessor-specific duties, plus contractual liability

The label follows the facts, not the contract. If your Gorakhpur team decides what happens to the data, you are the controller for that processing whatever the paperwork says. A support tool you configure, a model you train on client data to improve your own product, or an analytics feature switched on by default can quietly move you from processor to controller, and with it comes a lawful basis you now have to justify.

Where the line usually moves without anyone noticing

Three moments turn a processor into a controller: using client data to train or improve your own product, running your own analytics across client environments, and retaining data after termination for your own purposes. Each is defensible if decided deliberately, disclosed, and given a lawful basis. None survives a customer audit when it happened by default in a product decision nobody wrote down.

Evidence pack

The documents your programme has to produce

This is the deliverable list. Each row is a document an EU customer, an auditor or a supervisory authority can ask for by name.

GDPR evidence pack for a controller or processor operating from Gorakhpur
DocumentAnchored inWho asks for itRefresh cycle
Data map and system inventoryFoundation for Article 30Internal, and auditors during scopingOn every product or vendor change
Record of processing activitiesArticle 30Supervisory authority, first requestAnnually and on change
Privacy notice and cookie policyArticles 13 and 14Public, regulators, customersAnnually and on change
Lawful basis register and balancing testsArticles 6(1)(f) and 9Regulators, enterprise buyersAnnually
Data processing agreementArticle 28(3)Every EU customerPer contract
Sub-processor list and notification commitmentArticle 28(2) and (4)Customers, continuouslyOn every addition
SCC package with the correct moduleChapter V, Decision (EU) 2021/914Customers and their counselOn relationship change
Transfer impact assessmentSchrems II, Case C-311/18Customers, regulatorsWhen the legal position moves
Security statement mapped to Article 32Article 32Security questionnairesAnnually, with test evidence
Data subject rights procedureArticles 12 to 22Regulators after a complaintAnnually
Breach runbook and drill recordArticles 33 and 34, CERT-In directionsCustomers, regulators after an incidentAnnually, drilled
Retention schedule and deletion evidenceArticle 5(1)(e)Customers at terminationAnnually
DPIA reports where triggeredArticle 35Regulators for high-risk processingPer project
Article 27 representative appointment letterArticle 27Published in the noticeOn appointment change
Training recordArticle 39(1)(b) and accountabilityCustomers and auditorsAnnually
Process

How a company in Gorakhpur becomes GDPR compliant

Ten steps in dependency order. A team of up to about 200 people with a normal SaaS or services stack completes this in 4 to 8 weeks.

01

Test whether the GDPR reaches your Gorakhpur operation

Run the Article 3 test and write the conclusion down. Offering goods or services to people in the EU or EEA, or monitoring their behaviour, puts you in scope directly. Delivering for an EU client puts you in scope through the Article 28(3) obligations passed down to you.

02

Map the data and fix your role

Inventory every system, feature, vendor and spreadsheet touching EU personal data, then decide your role per data set: processor for client data handled on instructions, controller for your own employee, recruitment, website and marketing data.

03

Build the Article 30 record

Convert the map into the formal record: purposes, categories of data subjects and data, recipients, transfers, retention periods and a description of security measures. Processors keep a separate record for each controller served.

04

Set the lawful basis and rewrite the notices

Document an Article 6 basis for each controller purpose, add an Article 9 condition for special category data, and record the balancing test wherever legitimate interests are relied on. Then align the privacy notice to Articles 13 and 14.

05

Get the contract chain right

Sign an Article 28(3) DPA with every EU client and mirror the terms to every sub-processor your team uses, including cloud, support, analytics and AI vendors. Publish a sub-processor list with a change notification commitment.

06

Build the EU to India transfer file

India has no adequacy decision. Document the safeguard: the right SCC module from Decision (EU) 2021/914, a transfer impact assessment following Schrems II, and supplementary measures such as encryption with external key control and a government access response procedure.

07

Harden security against Article 32

Encryption in transit and at rest, access control with joiner-mover-leaver discipline, logging and monitoring, patching, backup and restore testing, and vendor security review across the delivery environment. Record what you implemented and how you test it.

08

Write and rehearse the procedures

A rights procedure meeting the Article 12(3) one-month deadline, a breach procedure that notifies your controller without undue delay and supports a 72 hour Article 33 filing, a CERT-In reporting path for Indian duties, and a retention schedule that deletes on time.

09

Appoint a representative or DPO where required

Where Article 3(2) catches you and no exemption applies, appoint an Article 27 representative established in the EU and name them in your notice. Appoint a DPO where Article 37 requires one; the DPO may sit in Gorakhpur if accessibility and independence conditions are met.

10

Prove it, then keep it current

Run a breach drill against the 72 hour clock and a mock access request end to end, then hand the pack to sales for customer questionnaires. Refresh records on product and vendor change, revisit transfer assessments when the law moves, and repeat drills annually.

Not sure whether the GDPR reaches your Gorakhpur company at all?

The Article 3 test takes one conversation. We will tell you if you are out of scope, in scope through contract only, or directly accountable, and what each answer costs to act on.

Transfers

Moving EU data to Gorakhpur, lawfully

India holds no adequacy decision from the European Commission, so every export to your team needs a Chapter V safeguard and the file that proves you assessed it.

Standard Contractual Clauses modules, Commission Implementing Decision (EU) 2021/914
ModuleRelationshipTypical scenario for a Gorakhpur company
Module OneController to controllerAn EU partner sends you customer data you then use for your own purposes
Module TwoController to processorThe common case: an EU client sends data to your delivery or product team
Module ThreeProcessor to processorYour EU client is itself a processor and you act as its sub-processor
Module FourProcessor to controllerAn EU processor returns data to a non-EU controller, such as a group parent

The clauses alone are not the safeguard. After the Court of Justice's judgment in Schrems II (Case C-311/18, 16 July 2020), the exporter must assess whether the destination country's law and practice would undermine what the clauses promise, and add supplementary measures where they would. For a transfer into Gorakhpur, that assessment turns on Indian government access powers, the routes through which access can be compelled, and what your architecture does about it: encryption with keys held outside the destination, strict access segregation, and a documented procedure for responding to any access demand.

Two neighbouring facts get confused with this. The EU-US Data Privacy Framework, whose challenge the General Court dismissed in Case T-553/23 on 3 September 2025, helps only for the US leg of a chain where your sub-processor is certified under it. The UK route is separate again: the European Commission renewed UK adequacy on 19 December 2025 for six years, to 27 December 2031, after assessing the Data (Use and Access) Act 2025, while UK to India transfers use the UK International Data Transfer Agreement or the UK Addendum.

What a usable transfer impact assessment contains

Four parts: a description of the transfer including the data, purpose and onward recipients; an assessment of destination law and practice relevant to government access; the supplementary technical, contractual and organisational measures you apply; and the conclusion, with the trigger that will bring you back to review it. Customers increasingly ask for this by name, and those who do not ask still expect you to have it when their own regulator asks them.

Incidents and rights

The clocks your team has to meet

GDPR obligations are mostly deadlines, and an Indian incident can start two sets of them at once.

Response deadlines for a controller or processor in Gorakhpur
TriggerWho actsDeadlineAnchor
Personal data breach detected by a processorProcessor tells its controllerWithout undue delay, usually 24 to 48 hours by contractArticle 33(2)
Breach likely to risk individual rightsController tells the supervisory authority72 hours from becoming awareArticle 33(1)
Breach likely to result in high riskController tells the individualsWithout undue delayArticle 34(1)
Specified cyber incident on Indian infrastructureIndian entity reports to CERT-In6 hours of noticingCERT-In directions of 28 April 2022
Data subject access or erasure requestController respondsOne month, extendable by two for complex requestsArticle 12(3)
Request received by a processorProcessor forwards and assistsOn the DPA timeline, typically 3 to 5 working daysArticle 28(3)(e)
High-risk processing plannedController completes a DPIABefore processing beginsArticle 35(1)
Sub-processor changeProcessor notifies the controllerOn the DPA notice period, commonly 30 daysArticle 28(2)

Where the 72 hours actually goes

The clock starts when you become aware, not when the investigation finishes. In real incidents the first day goes on deciding whether personal data was involved at all, the second on scoping, and the notification is drafted in what is left, often across a four or five hour time difference with the client. Teams that meet the deadline decided in advance who declares an incident, which client contacts get called, what a holding notification says, and that a supervisory authority accepts phased notification under Article 33(4).

Penalties

What non-compliance costs

Two statutory fine tiers, and a commercial cost that reaches a vendor long before any regulator does.

GDPR administrative fine tiers under Article 83
FailureFine tierCeiling
Processor duties, records, security, breach notification (Articles 8, 11, 25 to 39, 42, 43)Lower tier, Article 83(4)10 million euro or 2 percent of worldwide annual turnover, whichever is higher
Principles, lawful basis and consent (Articles 5, 6, 7 and 9)Upper tier, Article 83(5)20 million euro or 4 percent of worldwide annual turnover, whichever is higher
Data subject rights (Articles 12 to 22)Upper tier, Article 83(5)20 million euro or 4 percent of worldwide annual turnover, whichever is higher
Transfers without a valid Chapter V safeguardUpper tier, Article 83(5)20 million euro or 4 percent of worldwide annual turnover, whichever is higher
Ignoring a supervisory authority order (Article 58)Upper tier, Article 83(5)20 million euro or 4 percent of worldwide annual turnover, whichever is higher

For a vendor in Gorakhpur, the statutory ceiling is rarely the operative risk. The operative risk is the chain that starts earlier: a security questionnaire you cannot answer, a deal that stalls in procurement, a client whose own regulator asks about its vendors, an indemnity clause that transfers their exposure to you, and a termination right that triggers on a material breach of the DPA. Each of those arrives years before a supervisory authority would.

India

GDPR and India's DPDP framework, side by side

Build once. A Gorakhpur company that has done GDPR properly is most of the way to the Digital Personal Data Protection Act, and the phased Rules give you dated deadlines.

GDPR compared with the Indian DPDP framework
DimensionGDPRDPDP Act, 2023 and Rules, 2025
InstrumentRegulation (EU) 2016/679, applicable 25 May 2018Act of 2023, Rules notified 13 November 2025, phased to 13 May 2027
Terms usedController, processor, data subjectData Fiduciary, Data Processor, Data Principal
Lawful basesSix under Article 6, including legitimate interestsConsent, plus specified legitimate uses; no legitimate interests test
NoticeArticles 13 and 14 information dutiesItemised notice, with a right to a notice in the Eighth Schedule languages
Cross-border transfersChapter V safeguards; India has no adequacy decisionPermitted except to countries restricted by the Central Government
Breach reporting72 hours to the supervisory authority under Article 33Intimation to the Board and affected Data Principals, per the Rules
RegulatorSupervisory authority in each member state, coordinated by the EDPBData Protection Board of India
Maximum penalty20 million euro or 4 percent of worldwide turnoverUp to 250 crore rupees per instance of breach
Extra duties at scaleDPO, DPIA and records where thresholds are metSignificant Data Fiduciary duties: DPIA, audit and a DPO in India

The overlap is large enough that running two programmes in Gorakhpur is waste. One data map, one notice and consent layer, one vendor contract set and one breach process serve both; what differs is the paperwork layered on top. The DPDP dates are now fixed: Rules notified 13 November 2025, consent manager provisions from 13 November 2026, and substantive Data Fiduciary obligations from 13 May 2027. Any GDPR work done this year should be built so those additions drop in without a rebuild.

What gets flagged

What holds up in review, and what falls over

Drawn from the questions EU customers and their auditors actually ask when they read a vendor pack line by line.

Holds up under review

  • A record of processing built from a real system inventory, where every row names an owner and a retention period
  • A DPA whose sub-processor list matches the vendors your engineers actually use in production
  • A transfer impact assessment that names the Indian access powers it considered and the measures answering them
  • Retention periods enforced by a job, with deletion evidence you can produce for a named account
  • A breach runbook with named roles across time zones, a declared decision-maker and a rehearsal in the last twelve months
  • Security claims that map one to one onto Article 32 and onto whatever certification you hold

Falls over on the follow-up question

  • A template record with generic categories, no owners, and retention marked "as required"
  • A sub-processor list that omits the analytics, support and AI tools added after the list was written
  • SCCs signed with the wrong module, or with the annexes left as unfilled placeholders
  • A transfer impact assessment concluding "no risk identified" without naming a single legal provision
  • Deletion promised in the contract while backups, logs and warehouses keep the data indefinitely
  • A breach procedure nobody has run, where the 72 hour clock is discovered mid-incident
  • A privacy notice describing processing the product stopped doing two releases ago
Key terms

GDPR terms, defined

The vocabulary that appears in customer questionnaires and contract clauses, in the sense the Regulation uses it.

Personal data
Any information relating to an identified or identifiable natural person, under Article 4(1). Device identifiers, IP addresses, support-ticket contents and pseudonymised records count where a person can still be singled out.
Processing
Any operation performed on personal data, from collection and storage to consultation, transmission, erasure and destruction. Merely hosting data is processing, which is why infrastructure vendors sit inside the chain.
Special category data
Data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data used for identification, health, sex life or sexual orientation. Article 9 prohibits processing unless a listed condition applies.
Sub-processor
Any vendor a processor engages to carry out part of the processing, from cloud hosting to a support desk or an AI feature. Article 28(4) requires the same data protection terms to flow down the chain.
Adequacy decision
A European Commission finding that a country ensures an essentially equivalent level of protection, allowing transfers without further safeguards. India does not hold one, so transfers to Gorakhpur rely on Chapter V tools.
Supervisory authority
The independent public authority in each member state that enforces the GDPR, investigates complaints and issues fines. Cross-border cases run through the lead authority mechanism coordinated by the European Data Protection Board.
Accountability
The Article 5(2) principle that a controller must not only comply but be able to demonstrate compliance. It is why evidence, and not intention, is what an audit or investigation actually measures.
Data Principal
The individual whose personal data is processed, under India's DPDP Act, 2023. The equivalent of a data subject under the GDPR, with rights exercised against the Data Fiduciary.
Guides & resources

GDPR guides and resources

Deeper reading on the Regulation as it lands on Indian companies, the DPDP framework and its phased dates, data localisation rules, and the security certifications that share the same evidence base.

FAQs

FAQs about GDPR compliance in Gorakhpur

33 questions taken from real search queries, EU customer security questionnaires, EDPB guidance and the Regulation itself.

Yes, where Article 3(2) is met: the company offers goods or services to people in the EU or EEA, or monitors their behaviour, regardless of having no office or server in Europe. It also applies through contract when a Gorakhpur team processes personal data for an EU client, because Article 28(3) requires that client to pass its obligations down to you.
No. The GDPR is European law and there is no Indian registration, licence or filing for it anywhere, including Uttar Pradesh. Enforcement sits with the supervisory authority of an EU member state, and your day-to-day accountability sits with the EU customer whose contract you signed. What you build in Gorakhpur is evidence, not a registration.
Software product and SaaS companies with EU users, IT services and engineering teams delivering for European clients, BPO and KPO operations handling European customer records, healthtech and clinical research firms touching EU patient data, and D2C brands shipping into the EU. In all of them the trigger is the same: EU personal data reaching a Gorakhpur team.
Usually both. A Gorakhpur company is a processor for the client data it handles on documented instructions, and a controller for its own employee, recruitment, website and marketing data. The split has to be decided per data set, because the duties and the direct fine exposure differ sharply between the two roles.
If Article 3(2) catches you directly, then yes: Article 27 requires a representative established in an EU member state, appointed in writing and named in your privacy notice. The representative cannot sit in Gorakhpur. If you only process for EU clients and never target EU individuals yourself, the appointment obligation usually sits with your client, not with you.
Yes. The GDPR does not require the DPO to be in the EU. It requires the DPO to be easily accessible to data subjects and supervisory authorities, to have expert knowledge, to report to the highest management level, and to be free from instructions on how to carry out the role. A DPO working from Gorakhpur satisfies that if those conditions hold.
India holds no adequacy decision from the European Commission, so every transfer needs a Chapter V safeguard. In practice that is the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, with the correct module, plus a transfer impact assessment following the Court of Justice's Schrems II judgment and supplementary measures where the assessment shows a gap.
Module Two (controller to processor) for the common case where an EU client sends data to your Gorakhpur delivery team. Module Three (processor to processor) where your client is itself a processor and you are its sub-processor. Module One covers controller to controller, and Module Four covers an EU processor returning data to a non-EU controller.

Start with the question that decides everything else

Does the GDPR apply to your Gorakhpur company, and in which role? Our privacy experts run the Article 3 test, review your contracts and data flows, and give you a scoped plan for the evidence pack your buyers keep asking for.

Latest from our Blog & Guides

Recent Articles & Guides

Stay informed with our latest insights on business, compliance, and growth strategies.

Newsletter

Stay ahead on compliance, tax & business updates

Crisp, expert-curated insights delivered to your inbox. Once a month, no spam.

Joined by 15,000+ founders & business owners

  • 100% privacy
  • 1 email / month
  • Unsubscribe anytime
Contact IncorpX
Chosen by 15,000+ Entrepreneurs

Get Expert Guidance for Your Business

Fill out the form and our team will connect with you to understand your requirements and recommend the best way forward.

Free Consultation No Obligations Expert Advice
FREE ConsultationGet Started @ ₹299 ₹0

Talk to Our Experts

Talk to our business executives in minutes

Instant Response 100% Confidential Expert Advice
FREE ConsultationGet Started @ ₹299 ₹0

Request a Free Quote

Talk to our business executives in minutes

Instant Response 100% Confidential Expert Advice
IncorpX business advisor available nowGDPR evidence pack for your Gorakhpur team 4 to 8 weeks Article 30 records DPAs and SCCs