An Indian company with no EU establishment that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance provides that representative directly from Amsterdam, named in your privacy notice and reachable by the supervisory authorities. India’s own data protection law is new and still coming into force in stages, which makes it easy to assume it already handles this, but the DPDP Act reaches inward toward India and never appoints anyone for you in the EU.

Key takeaways

  • GDPR Article 27 applies to Indian companies with no EU establishment that offer goods or services to, or monitor the behavior of, people in the EU. The exemption is narrow and a SaaS, ecommerce or app business that runs on EU users rarely qualifies.
  • India’s Digital Personal Data Protection Act, 2023 has extraterritorial reach of its own under section 3(b), but it reaches processing tied to India, not the EU, and it creates no general local representative.
  • The “data protection officer based in India” rule is narrow. It applies only to a Significant Data Fiduciary designated by the government under section 10, it is an internal role, and it is not the EU Article 27 representative.
  • Most Indian companies caught by the EU obligation are also caught by the separate UK one, and the two are appointed independently.
  • We act as your EU representative directly from Amsterdam, and where you also need a DPO we keep the two roles with separate entities on the European Data Protection Board’s own reasoning.

How does an Indian company get caught by GDPR?

GDPR reaches beyond the EU through Article 3(2). A company with no EU establishment is inside the Regulation when its processing relates to either offering goods or services to people who are in the EU, whether or not payment is required, or monitoring their behavior as far as that behavior happens in the EU.

India’s large IT services, SaaS and business process outsourcing sector produces a lot of companies in exactly this position. A Bengaluru or Pune SaaS company selling subscriptions to EU consumers is offering services to people in the EU. An Indian direct-to-consumer ecommerce brand shipping to the EU is offering goods. An Indian app or gaming studio running analytics on EU users is monitoring behavior. Where an Indian outsourcing firm processes EU personal data on an EU client’s instructions, it is typically acting as a processor under Article 3(2), and a processor caught this way also needs a representative unless the narrow exemption applies.

Does Indian privacy law require an EU representative?

No. India’s Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) carries its own extraterritorial reach in section 3(b), which applies the Act to processing of digital personal data done outside India where that processing is connected to offering goods or services to Data Principals within India. That reaches into India from abroad; it does not put a representative in the EU on your behalf, and the Act creates no general local-representative obligation for foreign markets.

The India-based officer rule is the one most often overstated online, so it is worth being precise. An ordinary Data Fiduciary has a contact-point duty under section 8(9): publish the contact details of a Data Protection Officer where one applies, or of a person who can answer questions on the fiduciary’s behalf. Only a Significant Data Fiduciary, a class the Central Government designates by notification, must under section 10 appoint a Data Protection Officer based in India. That is a designation-triggered internal governance role, not a third-party representative, and being a foreign company does not trigger it by itself. None of this is the GDPR Article 27 representative, which is an EU obligation sitting outside the reach of Indian law.

One timing point matters. The DPDP Rules, 2025 were notified on 14 November 2025, and the Act and its Rules commence in phases rather than all at once. As of August 2026 the core operational compliance duties are still phasing in and are not yet fully enforceable in India. That transition changes nothing about the EU position: GDPR Article 27 already applies to an Indian company that offers goods or services to, or monitors the behavior of, people in the EU.

Who regulates this?

In the EU, the supervisory authority in the member state where your representative sits, and the wider network of authorities coordinated through the European Data Protection Board. In India, the Data Protection Board of India is the body set up to administer the DPDP Act as it comes into force. The Data Protection Board does not administer Article 27, which is the point: your Indian regulator does not stand in for an EU representative.

Do Indian companies also need a UK representative?

In most cases, yes. The UK runs its own UK GDPR with its own Article 27, enforced by the Information Commissioner’s Office, and an Indian company selling online into the EU is usually reaching the UK as well. The two obligations are separate appointments in separate territories, and an EU representative does not cover the UK. We can take both, as two mandates.

What does Engage do?

Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, with the same senior expert on your account rather than a junior handoff. There is no separate Indian representative obligation to satisfy, so nothing here runs through a local partner in India.

Where you also need a named DPO, we cannot be both for the same company. The European Data Protection Board is clear the roles can conflict, so we take one and arrange the other through a partner entity, and we say in writing which is which.

Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.

What to do next

If you are an Indian company selling to or tracking people in the EU and you have not appointed an EU representative, that is an open GDPR Article 27 obligation. Read do I need an EU representative to check whether the narrow exemption could apply to you, see how the EU representative service works, or contact us and we will tell you plainly whether you are caught and what the appointment involves.

Sources and references

Representative mandates

These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.

FAQ

Frequently asked questions

Does an Indian company need an EU representative?

If your company is based in India, has no establishment in the EU, and either offers goods or services to people in the EU or monitors their behavior, then GDPR Article 27 requires you to appoint a representative established in an EU member state. The narrow exemption in Article 27(2) is for occasional, low-risk processing that does not involve large-scale special category or criminal data, and a SaaS product sold to EU consumers or an app tracking EU users rarely qualifies for it.

Doesn't India's DPDP Act 2023 cover this?

No. India's Digital Personal Data Protection Act, 2023 has its own extraterritorial reach under section 3(b), which pulls in processing done outside India where it is connected to offering goods or services to Data Principals within India. That is a reach into India, not a representative for the EU. The DPDP Act does not create a general local-representative obligation, so nothing in it stands in for the GDPR Article 27 appointment, which is a requirement of EU law.

Isn't there a rule that we need a data protection officer based in India?

That rule is narrower than it is often described. Section 10 of the DPDP Act requires a Significant Data Fiduciary, a class the Central Government designates by notification, to appoint a Data Protection Officer based in India. It is a designation-triggered internal governance role, not a third-party representative, and it is not triggered simply by being a foreign company. Ordinary Data Fiduciaries have only a contact-point duty under section 8(9), to publish the contact details of a Data Protection Officer if one applies or of a person who can answer on the fiduciary's behalf. None of this is the EU Article 27 representative.

Do Indian companies also need a UK representative?

Usually, yes. The UK runs its own UK GDPR with its own Article 27, and an Indian company selling online into the EU is in most cases also reaching people in the UK. The two obligations are separate appointments in separate territories, so meeting the EU requirement does nothing for the UK one. A company reaching both markets appoints a representative in each.

Can the same provider be our EU representative and our DPO?

No. The European Data Protection Board is clear that one provider should not hold both roles for the same company, because the representative can be addressed by the regulator on the company's behalf while the DPO has to monitor that same company independently. Where you need both, we take one and arrange the other through a partner entity, and we say in writing which is which.