GDPR Readiness & Compliance Advisory
The EU's General Data Protection Regulation reaches well beyond Europe — if your company offers goods or services to people in the EU, or monitors their behaviour, it applies to you in India too. We get you ready for it: data mapping and records of processing, lawful basis and consent, data-subject-rights workflows, Article 32 security we validate the way an attacker would, and breach readiness against the 72-hour clock.
The GDPR is a law, not a certificate. CERT-In Empaneled. We make you demonstrably ready — and prove the security holds.
Europe's privacy law, and why it lands on your desk in India
The General Data Protection Regulation — Regulation (EU) 2016/679 — is the European Union's comprehensive data-protection law.
It has applied across the EU since 25 May 2018, and it governs how organizations collect, use, store, share and protect the personal data of people in the EU. Unlike a standard you adopt or a certificate you earn, the GDPR is binding law: it sets out principles you must follow, rights you must honour, obligations you must meet, and supervisory authorities that can investigate and fine you when you don't.
What makes it matter to an Indian company is reach. The GDPR is deliberately extraterritorial. Under Article 3, it applies not only to organizations established in the EU, but to any controller or processor — wherever in the world it sits — that offers goods or services to people in the EU or monitors their behaviour. A SaaS product with European users, an e-commerce site shipping into the EU, an analytics or ad-tech platform tracking EU visitors, or an IT services firm processing a European client's customer data all fall within scope. The penalties are sized to be felt: under Article 83, the most serious infringements carry administrative fines of up to €20 million, or 4% of total worldwide annual turnover — whichever is higher. Readiness is cheaper than the alternative, and far cheaper than the loss of a European customer who asks for evidence you don't have.
"There is no 'GDPR certificate' to hang on the wall. Compliance is something you must be able to demonstrate, on demand — so we build the evidence, and we test that the security behind it is real."
Does the GDPR apply to a company in India?
Often, yes — and the question is settled by Article 3, the territorial-scope provision, not by where your servers or your office are. The GDPR follows the data subject, not the data centre. Three triggers bring a company outside the EU into scope.
If you process personal data "in the context of the activities of an establishment" in the Union — a branch, subsidiary or stable arrangement — the GDPR applies, whether or not the processing itself happens in the EU.
If you target people who are in the EU — even with free services, and regardless of their nationality — you are in scope. Pricing in euros, shipping to EU countries, or offering an EU-language version are the kinds of signals that show intent to serve that market.
Tracking, profiling, analytics or behavioural advertising aimed at people whose behaviour takes place in the EU brings you into scope — common for ad-tech, product analytics and any business that follows users across the web.
If you are an IT/ITeS, BPO/KPO or SaaS provider handling a European client's personal data, you are a processor with your own direct GDPR obligations — including a compliant data-processing agreement and the security duties of Article 32.
The criterion is whether the people are in the EU — not their citizenship, and not where you are based. If any of these describe you, GDPR readiness is not optional; we scope every engagement to the triggers that actually apply to you, and to your role as controller, processor, or both.
What the GDPR actually requires
The GDPR rests on seven principles set out in Article 5 — the spirit of the whole law — and turns them into concrete obligations across the rest of the Regulation.
Master the principles and the obligations follow: a lawful basis for every processing activity, a record of what you process, rights you must honour for data subjects, an assessment of high-risk processing, security appropriate to the risk, a breach plan that runs on a clock, and lawful mechanisms for moving data out of the EU. Accountability — the seventh principle — ties it together: you must not only comply, but be able to demonstrate that you comply.
Process personal data on a valid lawful basis, fairly, and with clear notice to the people whose data it is.
Collect data for specified, explicit and legitimate purposes, and don't repurpose it in incompatible ways.
Hold only the data that is adequate, relevant and limited to what the purpose actually needs.
Keep personal data accurate and up to date; correct or erase what is wrong.
Keep data in identifiable form no longer than necessary; define and enforce retention.
Protect data with appropriate security against unauthorized access, loss or damage. This is the security principle Article 32 makes concrete.
Be responsible for, and able to demonstrate, compliance with all of the above.
How we get you ready
GDPR readiness is not a single document — it is a programme that touches your data, your contracts, your product and your security.
We run it as a clear, evidence-led path: find the data, fix the legal footing, build the rights and breach machinery, prove the security actually holds, and leave you able to demonstrate compliance and sustain it. Because the GDPR is a law and not a certificate, the goal isn't a piece of paper — it's a defensible, evidenced state of readiness you can show a customer, a partner, or a supervisory authority.
FIG. 02 — GDPR readiness lifecycle · 7 steps · step 04 is the offensive-edge step
Readiness isn't a finish line — it's a posture. We build it so you can prove it, and maintain it as your products, data and obligations evolve.
What an engagement includes
We scope to your role and your reach — controller, processor, or both; one EU market or many — and cover the work end to end.
Personal-data discovery and data-flow mapping
across systems, vendors and geographies
Record of Processing Activities (RoPA)
Article 30
Controller / processor role determination
and data-transfer inventory
Lawful-basis assessment for every processing activity
Article 6
Special-category data handling
Article 9
Consent mechanism review
and privacy / cookie notice review and drafting
Data-subject-rights (DSR) workflow design
access, rectification, erasure, restriction, portability, objection (Articles 12–23)
Request-handling procedures
within the one-month response window
Article 32 technical and organisational measures gap assessment
Penetration testing and configuration review
that validate the security controls actually work
Remediation guidance and retest
Breach detection, triage and notification playbook
72-hour clock (Articles 33–34)
Incident-response tabletop exercise
International-transfer assessment
adequacy, Standard Contractual Clauses and transfer risk assessments (Chapter V)
Data-processing agreements (DPAs) and processor due diligence
Article 28
DPIA methodology and high-risk-processing assessments
Article 35
DPO / EU-representative advisory where required
Articles 27, 37–39
Policy suite, accountability evidence pack and ongoing-compliance cadence
Article 32 says "appropriate to the risk." We prove it is.
The GDPR's security obligation isn't a checkbox — it's a standard you have to meet against real adversaries. A document review assumes your controls work. We test whether they do.
The paper view of security
Article 32 requires "appropriate technical and organisational measures" — encryption and pseudonymisation, confidentiality, integrity, availability and resilience — at a level "appropriate to the risk." Most readiness work confirms these measures are documented: there is an encryption policy, an access-control standard, a logging procedure. That satisfies the paperwork. But a written control and a control an attacker can't get past are not the same thing — and Article 32 is judged against the actual risk, not the policy binder.
The tested view of security
Intect is CERT-In Empaneled with an offensive-security heritage, so we validate the Article 32 measures by testing them — penetration testing and configuration review that turn "we have access controls and encryption" into demonstrated evidence of what an unauthorized party can and cannot reach. You walk away knowing the security behind your GDPR programme has withstood a real probe, with pentest-backed evidence to show a customer or a supervisory authority — not just an assertion that the measures exist.
Your documentation proves you have controls. Our testing proves the controls are "appropriate to the risk" — which is exactly what Article 32 asks.
PENTEST-BACKED EVIDENCEWhat you receive
Every engagement produces the accountability evidence the GDPR expects you to be able to show — and the proof that the security behind it is real.
GDPR gap assessment report
Your current state mapped against the Regulation's obligations, with a prioritized roadmap to readiness.
Data map & Record of Processing Activities (RoPA)
What personal data you hold, where it flows, and the Article 30 record that anchors everything else.
Lawful-basis & consent register
A documented lawful basis for each activity, with consent and notice review and recommended fixes.
Data-subject-rights (DSR) playbook
The workflows and templates to handle access, erasure and the other rights within the response window.
DPIA & methodology
A repeatable data-protection-impact-assessment method, plus assessments for your high-risk processing.
Breach-response plan
The 72-hour notification playbook, roles and decision tree, exercised with your team.
Transfer-mechanism pack
Transfer inventory, SCC / adequacy mapping and data-processing agreements.
Technical control validation report
Pentest-backed evidence that the Article 32 security measures genuinely work, with remediation guidance and retest.
Accountability evidence pack
The policies, records and artefacts that let you demonstrate compliance on demand.
Why teams choose Intect for GDPR
CERT-In Empaneled — A credential accredited under India's national cybersecurity authority — credibility behind both the advisory and the technical validation.
We build and we break — Most privacy consultancies stop at documents. We design the programme and then test the security like attackers, so your Article 32 evidence is proven, not asserted.
India–EU fluent — We work with the realities of an Indian company serving the EU — extraterritorial scope, transfers out of the EU, and the overlap with India's own DPDP Act — so the programme fits how you actually operate.
Researcher-led, not template-led — Senior practitioners build your programme to your real data and risk — not a copy-paste policy kit that wilts under a regulator's question.
Frequently asked questions
Is there a "GDPR certificate"? Can Intect certify us?
No. The GDPR is a law, not a certification scheme — there is no official certificate that says you are "GDPR compliant." The Regulation does provide for voluntary certification mechanisms, seals and marks (Articles 42–43), but even those, by the GDPR's own words, "do not reduce the responsibility of the controller or the processor for compliance." What Intect delivers is demonstrable readiness: the records, workflows, security validation and accountability evidence that let you show a customer, partner or supervisory authority that you meet the Regulation's obligations. We make you ready and able to prove it — we don't issue a certificate, because none exists.
We're based in India with no EU office. Does the GDPR really apply to us?
Quite possibly. Article 3 makes the GDPR extraterritorial: it applies to any company that offers goods or services to people in the EU, or monitors their behaviour — regardless of where the company is based. A SaaS product with EU users, an e-commerce site selling into Europe, an analytics platform tracking EU visitors, or an IT/BPO firm processing a European client's data are all typically in scope. We start every engagement by confirming, against Article 3, exactly how and where it applies to you.
How is GDPR different from India's DPDP Act?
They're cousins, not twins. India's Digital Personal Data Protection Act, 2023 draws on similar principles — lawful processing, consent, data-principal rights and security — but differs in scope, terminology (data fiduciary/principal vs controller/subject), specific obligations and enforcement. Many Indian companies need both: the DPDP Act for personal data in India, the GDPR for personal data of people in the EU. A well-built programme reuses much of the same data mapping and security work across the two — we scope it so you don't do it twice.
Do we need a Data Protection Officer, or an EU representative?
It depends on what you do. A DPO is mandatory under Article 37 only for certain organizations — public authorities, those whose core activities involve large-scale regular monitoring, or large-scale processing of special-category data — and recommended for many others. Separately, many controllers and processors outside the EU must appoint an EU representative under Article 27. We assess both against your actual processing and advise on what you need, rather than defaulting to "yes" or "no."
What is the 72-hour rule, and can we actually meet it?
Under Article 33, when a personal-data breach occurs you must notify the competent supervisory authority "without undue delay and, where feasible, not later than 72 hours" after becoming aware of it — unless the breach is unlikely to result in a risk to people's rights. Where the risk is high, affected individuals must be told too (Article 34). Meeting that clock is a function of preparation: we build the detection, triage and notification playbook in advance and exercise it with your team, so the 72 hours are spent acting, not deciding what to do.
What does Article 32 require, and why do you test it?
Article 32 requires "appropriate technical and organisational measures" to secure personal data — explicitly naming encryption and pseudonymisation, and confidentiality, integrity, availability and resilience — at a level "appropriate to the risk." Because the standard is the actual risk, a policy that says you have a control isn't the same as a control that works. We come from offensive security, so we validate the measures by testing them, and give you evidence they hold — which is far stronger than asserting they do.
One programme, several obligations
The data mapping and security work behind GDPR readiness powers much more than one regulation.
Ready for the EU? Let's prove it.
Tell us how you touch the EU — customers, operations or processing for someone else — and we'll scope a GDPR readiness assessment that fits, or connect you with an advisor.