What GDPR compliance means for a Ongole company
- InstrumentRegulation (EU) 2016/679, applicable 25 May 2018
- Reach27 EU member states plus Iceland, Liechtenstein and Norway
- Local filingNone anywhere in India, including Ongole
- Top fine tier20 million euro or 4 percent of worldwide turnover
Companies in Ongole usually meet the Regulation from the vendor side. They are not selling to European consumers; they are building or running systems for European businesses. That makes them processors, and a processor's duties are narrower than a controller's but far more visible, because they arrive as contract clauses with an audit right attached. The work is therefore less about privacy strategy and more about producing a specific set of artefacts that hold up when someone reads them line by line.
Nothing in the Regulation is decided locally. There is no state-level variation inside Andhra Pradesh, no registration with any Indian authority, and no fee to any government. What varies by company is the data: which EU personal data reaches your systems, through which client, under which instructions, and which vendors touch it after you do.
Evidence pack What we produce, in the order buyers ask for it
Every artefact below has been asked for by an EU customer during a vendor review. They are built in dependency order, because a data processing agreement written before the data map is a promise nobody has checked you can keep.
- Data map and Article 30 record, split by controller and processor role
- Privacy notice, cookie and consent layer, retention schedule
- Article 28(3) DPA, sub-processor list and flow-down terms
- SCC module, transfer impact assessment and supplementary measures
- Security statement mapped to Article 32, with testing evidence
- Rights and breach procedures, plus the drill record behind them
One legal point worth being precise about
No consultant in Ongole or anywhere else can make you "GDPR certified". Article 42 allows certification schemes approved by supervisory authorities, and Europrivacy is the first approved as a European Data Protection Seal, but no EU authority issues a general compliance certificate. Any provider offering one is selling something the Regulation does not contain. What moves a deal forward is a complete, internally consistent evidence pack.
Controller or processor: the decision that sets your duties
Almost every technology company in Ongole is both, on different data sets. Getting the split right decides which obligations you carry directly and which arrive through the customer contract.
| Obligation | As controller | As processor |
|---|---|---|
| Decides purpose and means of processing | Yes | No |
| Keeps an Article 30 record | Yes, of its own processing | Yes, of processing carried out for each controller |
| Needs a documented lawful basis (Article 6) | Yes | No, acts on the controller instructions |
| Publishes a privacy notice (Articles 13 and 14) | Yes | Only for its own data, such as employees |
| Answers data subject requests | Yes, within one month under Article 12(3) | Assists the controller on the DPA timeline |
| Notifies the supervisory authority of a breach | Yes, within 72 hours under Article 33 | Notifies the controller without undue delay |
| Carries out DPIAs (Article 35) | Yes | Assists the controller |
| Signs an Article 28(3) contract | Yes, as the imposing party | Yes, and mirrors it to sub-processors |
| Appoints an Article 27 representative if in scope | Yes | Yes |
| Direct fine exposure under Article 83 | Full range | Processor-specific duties, plus contractual liability |
The label follows the facts, not the contract. If your Ongole team decides what happens to the data, you are the controller for that processing whatever the paperwork says. A support tool you configure, a model you train on client data to improve your own product, or an analytics feature switched on by default can quietly move you from processor to controller, and with it comes a lawful basis you now have to justify.
Where the line usually moves without anyone noticing
Three moments turn a processor into a controller: using client data to train or improve your own product, running your own analytics across client environments, and retaining data after termination for your own purposes. Each is defensible if decided deliberately, disclosed, and given a lawful basis. None survives a customer audit when it happened by default in a product decision nobody wrote down.
The documents your programme has to produce
This is the deliverable list. Each row is a document an EU customer, an auditor or a supervisory authority can ask for by name.
| Document | Anchored in | Who asks for it | Refresh cycle |
|---|---|---|---|
| Data map and system inventory | Foundation for Article 30 | Internal, and auditors during scoping | On every product or vendor change |
| Record of processing activities | Article 30 | Supervisory authority, first request | Annually and on change |
| Privacy notice and cookie policy | Articles 13 and 14 | Public, regulators, customers | Annually and on change |
| Lawful basis register and balancing tests | Articles 6(1)(f) and 9 | Regulators, enterprise buyers | Annually |
| Data processing agreement | Article 28(3) | Every EU customer | Per contract |
| Sub-processor list and notification commitment | Article 28(2) and (4) | Customers, continuously | On every addition |
| SCC package with the correct module | Chapter V, Decision (EU) 2021/914 | Customers and their counsel | On relationship change |
| Transfer impact assessment | Schrems II, Case C-311/18 | Customers, regulators | When the legal position moves |
| Security statement mapped to Article 32 | Article 32 | Security questionnaires | Annually, with test evidence |
| Data subject rights procedure | Articles 12 to 22 | Regulators after a complaint | Annually |
| Breach runbook and drill record | Articles 33 and 34, CERT-In directions | Customers, regulators after an incident | Annually, drilled |
| Retention schedule and deletion evidence | Article 5(1)(e) | Customers at termination | Annually |
| DPIA reports where triggered | Article 35 | Regulators for high-risk processing | Per project |
| Article 27 representative appointment letter | Article 27 | Published in the notice | On appointment change |
| Training record | Article 39(1)(b) and accountability | Customers and auditors | Annually |
How a company in Ongole becomes GDPR compliant
Ten steps in dependency order. A team of up to about 200 people with a normal SaaS or services stack completes this in 4 to 8 weeks.
Test whether the GDPR reaches your Ongole operation
Run the Article 3 test and write the conclusion down. Offering goods or services to people in the EU or EEA, or monitoring their behaviour, puts you in scope directly. Delivering for an EU client puts you in scope through the Article 28(3) obligations passed down to you.
Map the data and fix your role
Inventory every system, feature, vendor and spreadsheet touching EU personal data, then decide your role per data set: processor for client data handled on instructions, controller for your own employee, recruitment, website and marketing data.
Build the Article 30 record
Convert the map into the formal record: purposes, categories of data subjects and data, recipients, transfers, retention periods and a description of security measures. Processors keep a separate record for each controller served.
Set the lawful basis and rewrite the notices
Document an Article 6 basis for each controller purpose, add an Article 9 condition for special category data, and record the balancing test wherever legitimate interests are relied on. Then align the privacy notice to Articles 13 and 14.
Get the contract chain right
Sign an Article 28(3) DPA with every EU client and mirror the terms to every sub-processor your team uses, including cloud, support, analytics and AI vendors. Publish a sub-processor list with a change notification commitment.
Build the EU to India transfer file
India has no adequacy decision. Document the safeguard: the right SCC module from Decision (EU) 2021/914, a transfer impact assessment following Schrems II, and supplementary measures such as encryption with external key control and a government access response procedure.
Harden security against Article 32
Encryption in transit and at rest, access control with joiner-mover-leaver discipline, logging and monitoring, patching, backup and restore testing, and vendor security review across the delivery environment. Record what you implemented and how you test it.
Write and rehearse the procedures
A rights procedure meeting the Article 12(3) one-month deadline, a breach procedure that notifies your controller without undue delay and supports a 72 hour Article 33 filing, a CERT-In reporting path for Indian duties, and a retention schedule that deletes on time.
Appoint a representative or DPO where required
Where Article 3(2) catches you and no exemption applies, appoint an Article 27 representative established in the EU and name them in your notice. Appoint a DPO where Article 37 requires one; the DPO may sit in Ongole if accessibility and independence conditions are met.
Prove it, then keep it current
Run a breach drill against the 72 hour clock and a mock access request end to end, then hand the pack to sales for customer questionnaires. Refresh records on product and vendor change, revisit transfer assessments when the law moves, and repeat drills annually.
Not sure whether the GDPR reaches your Ongole company at all?
The Article 3 test takes one conversation. We will tell you if you are out of scope, in scope through contract only, or directly accountable, and what each answer costs to act on.
Moving EU data to Ongole, lawfully
India holds no adequacy decision from the European Commission, so every export to your team needs a Chapter V safeguard and the file that proves you assessed it.
| Module | Relationship | Typical scenario for a Ongole company |
|---|---|---|
| Module One | Controller to controller | An EU partner sends you customer data you then use for your own purposes |
| Module Two | Controller to processor | The common case: an EU client sends data to your delivery or product team |
| Module Three | Processor to processor | Your EU client is itself a processor and you act as its sub-processor |
| Module Four | Processor to controller | An EU processor returns data to a non-EU controller, such as a group parent |
The clauses alone are not the safeguard. After the Court of Justice's judgment in Schrems II (Case C-311/18, 16 July 2020), the exporter must assess whether the destination country's law and practice would undermine what the clauses promise, and add supplementary measures where they would. For a transfer into Ongole, that assessment turns on Indian government access powers, the routes through which access can be compelled, and what your architecture does about it: encryption with keys held outside the destination, strict access segregation, and a documented procedure for responding to any access demand.
Two neighbouring facts get confused with this. The EU-US Data Privacy Framework, whose challenge the General Court dismissed in Case T-553/23 on 3 September 2025, helps only for the US leg of a chain where your sub-processor is certified under it. The UK route is separate again: the European Commission renewed UK adequacy on 19 December 2025 for six years, to 27 December 2031, after assessing the Data (Use and Access) Act 2025, while UK to India transfers use the UK International Data Transfer Agreement or the UK Addendum.
What a usable transfer impact assessment contains
Four parts: a description of the transfer including the data, purpose and onward recipients; an assessment of destination law and practice relevant to government access; the supplementary technical, contractual and organisational measures you apply; and the conclusion, with the trigger that will bring you back to review it. Customers increasingly ask for this by name, and those who do not ask still expect you to have it when their own regulator asks them.
The clocks your team has to meet
GDPR obligations are mostly deadlines, and an Indian incident can start two sets of them at once.
| Trigger | Who acts | Deadline | Anchor |
|---|---|---|---|
| Personal data breach detected by a processor | Processor tells its controller | Without undue delay, usually 24 to 48 hours by contract | Article 33(2) |
| Breach likely to risk individual rights | Controller tells the supervisory authority | 72 hours from becoming aware | Article 33(1) |
| Breach likely to result in high risk | Controller tells the individuals | Without undue delay | Article 34(1) |
| Specified cyber incident on Indian infrastructure | Indian entity reports to CERT-In | 6 hours of noticing | CERT-In directions of 28 April 2022 |
| Data subject access or erasure request | Controller responds | One month, extendable by two for complex requests | Article 12(3) |
| Request received by a processor | Processor forwards and assists | On the DPA timeline, typically 3 to 5 working days | Article 28(3)(e) |
| High-risk processing planned | Controller completes a DPIA | Before processing begins | Article 35(1) |
| Sub-processor change | Processor notifies the controller | On the DPA notice period, commonly 30 days | Article 28(2) |
Where the 72 hours actually goes
The clock starts when you become aware, not when the investigation finishes. In real incidents the first day goes on deciding whether personal data was involved at all, the second on scoping, and the notification is drafted in what is left, often across a four or five hour time difference with the client. Teams that meet the deadline decided in advance who declares an incident, which client contacts get called, what a holding notification says, and that a supervisory authority accepts phased notification under Article 33(4).
What non-compliance costs
Two statutory fine tiers, and a commercial cost that reaches a vendor long before any regulator does.
| Failure | Fine tier | Ceiling |
|---|---|---|
| Processor duties, records, security, breach notification (Articles 8, 11, 25 to 39, 42, 43) | Lower tier, Article 83(4) | 10 million euro or 2 percent of worldwide annual turnover, whichever is higher |
| Principles, lawful basis and consent (Articles 5, 6, 7 and 9) | Upper tier, Article 83(5) | 20 million euro or 4 percent of worldwide annual turnover, whichever is higher |
| Data subject rights (Articles 12 to 22) | Upper tier, Article 83(5) | 20 million euro or 4 percent of worldwide annual turnover, whichever is higher |
| Transfers without a valid Chapter V safeguard | Upper tier, Article 83(5) | 20 million euro or 4 percent of worldwide annual turnover, whichever is higher |
| Ignoring a supervisory authority order (Article 58) | Upper tier, Article 83(5) | 20 million euro or 4 percent of worldwide annual turnover, whichever is higher |
For a vendor in Ongole, the statutory ceiling is rarely the operative risk. The operative risk is the chain that starts earlier: a security questionnaire you cannot answer, a deal that stalls in procurement, a client whose own regulator asks about its vendors, an indemnity clause that transfers their exposure to you, and a termination right that triggers on a material breach of the DPA. Each of those arrives years before a supervisory authority would.
GDPR and India's DPDP framework, side by side
Build once. A Ongole company that has done GDPR properly is most of the way to the Digital Personal Data Protection Act, and the phased Rules give you dated deadlines.
| Dimension | GDPR | DPDP Act, 2023 and Rules, 2025 |
|---|---|---|
| Instrument | Regulation (EU) 2016/679, applicable 25 May 2018 | Act of 2023, Rules notified 13 November 2025, phased to 13 May 2027 |
| Terms used | Controller, processor, data subject | Data Fiduciary, Data Processor, Data Principal |
| Lawful bases | Six under Article 6, including legitimate interests | Consent, plus specified legitimate uses; no legitimate interests test |
| Notice | Articles 13 and 14 information duties | Itemised notice, with a right to a notice in the Eighth Schedule languages |
| Cross-border transfers | Chapter V safeguards; India has no adequacy decision | Permitted except to countries restricted by the Central Government |
| Breach reporting | 72 hours to the supervisory authority under Article 33 | Intimation to the Board and affected Data Principals, per the Rules |
| Regulator | Supervisory authority in each member state, coordinated by the EDPB | Data Protection Board of India |
| Maximum penalty | 20 million euro or 4 percent of worldwide turnover | Up to 250 crore rupees per instance of breach |
| Extra duties at scale | DPO, DPIA and records where thresholds are met | Significant Data Fiduciary duties: DPIA, audit and a DPO in India |
The overlap is large enough that running two programmes in Ongole is waste. One data map, one notice and consent layer, one vendor contract set and one breach process serve both; what differs is the paperwork layered on top. The DPDP dates are now fixed: Rules notified 13 November 2025, consent manager provisions from 13 November 2026, and substantive Data Fiduciary obligations from 13 May 2027. Any GDPR work done this year should be built so those additions drop in without a rebuild.
What holds up in review, and what falls over
Drawn from the questions EU customers and their auditors actually ask when they read a vendor pack line by line.
Holds up under review
- A record of processing built from a real system inventory, where every row names an owner and a retention period
- A DPA whose sub-processor list matches the vendors your engineers actually use in production
- A transfer impact assessment that names the Indian access powers it considered and the measures answering them
- Retention periods enforced by a job, with deletion evidence you can produce for a named account
- A breach runbook with named roles across time zones, a declared decision-maker and a rehearsal in the last twelve months
- Security claims that map one to one onto Article 32 and onto whatever certification you hold
Falls over on the follow-up question
- A template record with generic categories, no owners, and retention marked "as required"
- A sub-processor list that omits the analytics, support and AI tools added after the list was written
- SCCs signed with the wrong module, or with the annexes left as unfilled placeholders
- A transfer impact assessment concluding "no risk identified" without naming a single legal provision
- Deletion promised in the contract while backups, logs and warehouses keep the data indefinitely
- A breach procedure nobody has run, where the 72 hour clock is discovered mid-incident
- A privacy notice describing processing the product stopped doing two releases ago
GDPR terms, defined
The vocabulary that appears in customer questionnaires and contract clauses, in the sense the Regulation uses it.
- Personal data
- Any information relating to an identified or identifiable natural person, under Article 4(1). Device identifiers, IP addresses, support-ticket contents and pseudonymised records count where a person can still be singled out.
- Processing
- Any operation performed on personal data, from collection and storage to consultation, transmission, erasure and destruction. Merely hosting data is processing, which is why infrastructure vendors sit inside the chain.
- Special category data
- Data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data used for identification, health, sex life or sexual orientation. Article 9 prohibits processing unless a listed condition applies.
- Sub-processor
- Any vendor a processor engages to carry out part of the processing, from cloud hosting to a support desk or an AI feature. Article 28(4) requires the same data protection terms to flow down the chain.
- Adequacy decision
- A European Commission finding that a country ensures an essentially equivalent level of protection, allowing transfers without further safeguards. India does not hold one, so transfers to Ongole rely on Chapter V tools.
- Supervisory authority
- The independent public authority in each member state that enforces the GDPR, investigates complaints and issues fines. Cross-border cases run through the lead authority mechanism coordinated by the European Data Protection Board.
- Accountability
- The Article 5(2) principle that a controller must not only comply but be able to demonstrate compliance. It is why evidence, and not intention, is what an audit or investigation actually measures.
- Data Principal
- The individual whose personal data is processed, under India's DPDP Act, 2023. The equivalent of a data subject under the GDPR, with rights exercised against the Data Fiduciary.
GDPR guides and resources
Deeper reading on the Regulation as it lands on Indian companies, the DPDP framework and its phased dates, data localisation rules, and the security certifications that share the same evidence base.
FAQs about GDPR compliance in Ongole
33 questions taken from real search queries, EU customer security questionnaires, EDPB guidance and the Regulation itself.
Start with the question that decides everything else
Does the GDPR apply to your Ongole company, and in which role? Our privacy experts run the Article 3 test, review your contracts and data flows, and give you a scoped plan for the evidence pack your buyers keep asking for.


