When the GDPR Applies to an Indian Business

Last updated: 20 August 2026

A common misconception is that the EU’s General Data Protection Regulation (GDPR) only affects European companies. In fact, a business in India can fall within its scope even without any office in Europe. Whether it applies depends on the GDPR’s territorial scope rules.

If the business is established in the EU

Where a business has an establishment in the European Union, the GDPR applies to the processing of personal data carried out in the context of that establishment’s activities — regardless of whether the processing itself takes place inside or outside the EU.

If the business has no EU establishment

Even without an EU establishment, the GDPR can apply to a business that processes the personal data of individuals who are in the EU, where the processing relates to:

What this means in practice

An Indian business that sells to customers in the EU, or that tracks and profiles the online behaviour of people in the EU, may be within the scope of the GDPR for those activities. Importantly, the GDPR applies to the specific processing activity that is caught — not automatically to everything the business does.

Businesses that deal with EU customers or users should assess whether, and for which activities, the GDPR applies to them, in addition to their obligations under Indian law.