An Indian company with no EU establishment that offers goods or services to people in the EU, or monitors their behavior, is caught by GDPR Article 3(2) and has to appoint an EU representative under Article 27. Engage Compliance provides that representative directly from Amsterdam, named in your privacy notice and reachable by the supervisory authorities. India’s own data protection law is new and still coming into force in stages, which makes it easy to assume it already handles this, but the DPDP Act reaches inward toward India and never appoints anyone for you in the EU.
Key takeaways
- GDPR Article 27 applies to Indian companies with no EU establishment that offer goods or services to, or monitor the behavior of, people in the EU. The exemption is narrow and a SaaS, ecommerce or app business that runs on EU users rarely qualifies.
- India’s Digital Personal Data Protection Act, 2023 has extraterritorial reach of its own under section 3(b), but it reaches processing tied to India, not the EU, and it creates no general local representative.
- The “data protection officer based in India” rule is narrow. It applies only to a Significant Data Fiduciary designated by the government under section 10, it is an internal role, and it is not the EU Article 27 representative.
- Most Indian companies caught by the EU obligation are also caught by the separate UK one, and the two are appointed independently.
- We act as your EU representative directly from Amsterdam, and where you also need a DPO we keep the two roles with separate entities on the European Data Protection Board’s own reasoning.
How does an Indian company get caught by GDPR?
GDPR reaches beyond the EU through Article 3(2). A company with no EU establishment is inside the Regulation when its processing relates to either offering goods or services to people who are in the EU, whether or not payment is required, or monitoring their behavior as far as that behavior happens in the EU.
India’s large IT services, SaaS and business process outsourcing sector produces a lot of companies in exactly this position. A Bengaluru or Pune SaaS company selling subscriptions to EU consumers is offering services to people in the EU. An Indian direct-to-consumer ecommerce brand shipping to the EU is offering goods. An Indian app or gaming studio running analytics on EU users is monitoring behavior. Where an Indian outsourcing firm processes EU personal data on an EU client’s instructions, it is typically acting as a processor under Article 3(2), and a processor caught this way also needs a representative unless the narrow exemption applies.
Does Indian privacy law require an EU representative?
No. India’s Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) carries its own extraterritorial reach in section 3(b), which applies the Act to processing of digital personal data done outside India where that processing is connected to offering goods or services to Data Principals within India. That reaches into India from abroad; it does not put a representative in the EU on your behalf, and the Act creates no general local-representative obligation for foreign markets.
The India-based officer rule is the one most often overstated online, so it is worth being precise. An ordinary Data Fiduciary has a contact-point duty under section 8(9): publish the contact details of a Data Protection Officer where one applies, or of a person who can answer questions on the fiduciary’s behalf. Only a Significant Data Fiduciary, a class the Central Government designates by notification, must under section 10 appoint a Data Protection Officer based in India. That is a designation-triggered internal governance role, not a third-party representative, and being a foreign company does not trigger it by itself. None of this is the GDPR Article 27 representative, which is an EU obligation sitting outside the reach of Indian law.
One timing point matters. The DPDP Rules, 2025 were notified on 14 November 2025, and the Act and its Rules commence in phases rather than all at once. As of August 2026 the core operational compliance duties are still phasing in and are not yet fully enforceable in India. That transition changes nothing about the EU position: GDPR Article 27 already applies to an Indian company that offers goods or services to, or monitors the behavior of, people in the EU.
Who regulates this?
In the EU, the supervisory authority in the member state where your representative sits, and the wider network of authorities coordinated through the European Data Protection Board. In India, the Data Protection Board of India is the body set up to administer the DPDP Act as it comes into force. The Data Protection Board does not administer Article 27, which is the point: your Indian regulator does not stand in for an EU representative.
Do Indian companies also need a UK representative?
In most cases, yes. The UK runs its own UK GDPR with its own Article 27, enforced by the Information Commissioner’s Office, and an Indian company selling online into the EU is usually reaching the UK as well. The two obligations are separate appointments in separate territories, and an EU representative does not cover the UK. We can take both, as two mandates.
What does Engage do?
Engage Compliance acts as your EU representative under Article 27, established in the EU, named in your privacy notice, and reachable by supervisory authorities and by people in the EU on your behalf. This is a service we deliver directly from Amsterdam, with the same senior expert on your account rather than a junior handoff. There is no separate Indian representative obligation to satisfy, so nothing here runs through a local partner in India.
Where you also need a named DPO, we cannot be both for the same company. The European Data Protection Board is clear the roles can conflict, so we take one and arrange the other through a partner entity, and we say in writing which is which.
Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood sits behind the work.
What to do next
If you are an Indian company selling to or tracking people in the EU and you have not appointed an EU representative, that is an open GDPR Article 27 obligation. Read do I need an EU representative to check whether the narrow exemption could apply to you, see how the EU representative service works, or contact us and we will tell you plainly whether you are caught and what the appointment involves.
Sources and references
- GDPR Article 3, territorial scope, Regulation (EU) 2016/679, EUR-Lex
- GDPR Article 27, representatives of controllers or processors not established in the Union, Regulation (EU) 2016/679, EUR-Lex
- EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), European Data Protection Board
- Digital Personal Data Protection Act, 2023, Ministry of Electronics and Information Technology
- Digital Personal Data Protection Rules, 2025 notification, Press Information Bureau
Representative mandates
These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.
- EU GDPR Article 27 representative
- UK GDPR Article 27 representative
- Swiss FADP Article 14 representative
- DSA Article 13 legal representative
- EU AI Act GPAI authorised representative
- EU AI Act high-risk authorised representative
- NIS2 representative
- Data Act legal representative
- Data Governance Act representative
- e-Evidence legal representative
- Terrorist Content Online representative
- GPSR responsible person
- CE-marking authorised representative
- Non-EU regimes (Swiss, China, Korea, Turkey)