Aadit Technologies

GDPR

Compliance

General Data Protection Regulation

The General Data Protection Regulation (GDPR) is an EU regulation governing the processing of personal data within its territorial scope. It gives people rights over their data and requires controllers and processors to meet applicable duties, including lawful processing and appropriate safeguards. Organisations outside the EU may also fall within its scope in defined circumstances.

GDPR is built on principles such as lawfulness, data minimisation, purpose limitation, and accountability. It gives individuals rights including access, correction, erasure, and portability of their personal data, and it requires organisations to be able to demonstrate how they comply.

Crucially, GDPR applies to any organisation worldwide that offers goods or services to, or monitors, people in the EU — not just EU-based companies. Penalties for serious breaches can reach €20 million or 4% of global annual turnover, whichever is higher.

How GDPR works in practice

The GDPR governs processing of personal data within its applicable scope. An organisation should first understand what personal data it processes, why it processes it and the role it plays. A controller determines purposes and means; a processor processes data on a controller's behalf. Those roles can differ across activities. Map actual data flows and contracts rather than applying one role label to every business relationship.

Each processing purpose needs an appropriate lawful basis and transparent information for the people concerned. Consent is one possible basis, not a universal solution for all processing. Design processes for relevant rights requests, retention decisions and incident handling. Where a processing activity is likely to result in high risk, assess whether a data protection impact assessment is required. Legal interpretation should come from appropriately qualified advice.

Who needs to assess GDPR applicability

An organisation outside the EU can still fall within GDPR's territorial scope in particular circumstances, such as relevant offering of goods or services to people in the Union or monitoring their behaviour there. Simply using a European cloud region does not settle the issue. Equally, being based in India does not rule applicability out. Assess the business activity, people involved and legal role before choosing a compliance programme.

Customer contracts may impose data-protection responsibilities even where an organisation's own analysis differs from a customer's obligations. Review processing terms, subprocessors, security measures, deletion arrangements and cross-border transfers. Keep commercial requirements separate from claims about legal applicability. A readiness provider can help organise information and controls, but no generic certificate or website badge proves that all processing activities comply with GDPR.

Making privacy controls operational

Assign owners for processing records, requests, supplier reviews and incident decisions. Check that teams can locate relevant data across production systems, backups and third parties. Retention should reflect the purpose and applicable obligations rather than an indefinite default. Security measures need to consider the risk to people and the processing context. Access controls, encryption and logging can help, but privacy work also involves transparency and accountable decisions.

Test how a request or incident moves through the organisation. Record identity checks, responsible teams and escalation paths without collecting unnecessary additional data. A breach assessment may need legal and technical input, including consideration of any required notifications. Review the programme as products and suppliers change. For Indian operations, assess DPDP obligations separately; GDPR work does not automatically discharge duties under another jurisdiction's law.

GDPR vs. ISO 27001

AspectGDPRISO 27001
TypeEU regulation governing personal-data processing.International standard for managing information-security risk.
Scope decisionAssess people, processing activities and applicable legal obligations.Define the ISMS boundary, assets and information-security risks.

Common misconceptions

  • GDPR does not always require consent for every use of personal data. The lawful basis must be appropriate to the specific processing purpose.
  • An Indian office does not automatically exempt a business from GDPR. Territorial scope depends on the relevant establishment and processing activities.
  • GDPR compliance is not achieved by a cookie banner alone. Rights, transparency, security, retention and accountable processing decisions also matter.

Frequently asked questions

Does ISO 27001 certification mean we comply with GDPR?

No. Security management can support protection of personal data, but GDPR also sets legal duties for processing and individual rights that require separate assessment.

Can GDPR apply outside the EU?

Yes. The rules can apply to an organisation outside the EU when it offers goods or services to people in the EU or monitors their behaviour there.

Reference sources

Practical context

Using GDPR in a real decision

Definitions are most useful when they help a team decide what to scope, who should own the work, and what evidence supports the next step. Use these questions to turn the term into a practical conversation.

  • Which customers, data, services, or contracts make this requirement relevant?
  • What controls and evidence would demonstrate that the requirement is operating in practice?
  • Who is accountable for the scope, reviews, and any remediation work?