A founder’s map of the data protection and compliance rules that decide whether you can legally take a customer’s data, region by region.
TL;DR
The moment you take on a customer in a new region, you inherit that region’s data laws. India’s DPDP Act, the EU’s GDPR, the UAE’s PDPL, and a patchwork of APAC regimes each have their own regulator and penalties, but they rhyme: get consent, protect the data, report breaches, respect individual rights, and prove it all.
Because they share that spine, the winning move is to build one strong security programme and map its evidence to each framework, rather than starting over five times. SOC 2 and ISO 27001 are how you package that proof.
On this page
Data protection compliance starts with the thing nobody tells you
Data laws follow the person, not your office. If you are a SaaS company in Bengaluru with a customer in Germany, EU law applies to that customer’s data even though you never set foot in Europe. This extraterritorial reach is why a young startup can find itself answerable to several regulators at once, and why founders get blindsided when a deal stalls on a compliance question they had not planned for.
The good news is that these frameworks share a spine. Learn it once and each new region becomes a variation rather than a fresh start.
India: the DPDP Act
India’s Digital Personal Data Protection Act (DPDP Act) passed in 2023, but for two years it sat without the operational rules that give it teeth. That changed in November 2025, when the government notified the DPDP Rules and set a phased enforcement calendar. If you handle the personal data of people in India, this is now your baseline.
For an Indian startup, the practical read is simple. You have real runway to get this right, but “reasonable security safeguards” is a standard you build toward continuously. The startups that struggle are the ones that treat it as paperwork; the ones that sail through already run the controls the Act expects.
The European Union: GDPR and the growing stack around it
GDPR is the law every other data regime borrows from, and for good reason. It is broad, it is strict, and it reaches any company anywhere that handles the personal data of people in the EU. If you sell to European customers, GDPR readiness is not optional.
Here is the trap for scaling companies. The EU has been adding to the stack: NIS2 for security obligations, DORA for financial entities, the AI Act, and the Cyber Resilience Act. These frameworks overlap but do not merge. A single cloud vendor relationship can trigger a GDPR data processing agreement, a NIS2 supplier assessment, and AI Act due diligence at once.
The UAE: PDPL, plus the free-zone regimes
The UAE runs a slightly unusual setup, and missing it is a classic founder error. There is a federal data protection law, the PDPL, that covers most of the country, and then two major financial free zones, the DIFC and ADGM, that run their own separate data protection regimes. Which one applies depends on where and how you operate.
Two practical notes for founders eyeing the Gulf. The PDPL does not force every company to appoint a Data Protection Officer the way GDPR sometimes does, but high-risk or large-scale processing changes that calculation. And if you operate inside a free zone, you follow that zone’s rules, not only the federal law.
APAC: not one market, but a dozen rulebooks
“APAC compliance” is largely a myth. There is no single Asia-Pacific data law. There is a patchwork of national regimes ranging from light-touch to stricter-than-GDPR, and selling across the region means meeting several at once.
| Market | Law | Character |
|---|---|---|
| Singapore | PDPA | Clear, business-friendly, well-established |
| Japan | APPI | Extraterritorial reach, regular updates |
| Australia | Privacy Act | Reform underway, tightening obligations |
The certifications that travel: SOC 2 and ISO 27001
Here is the leverage point. The laws above differ on detail, but they all want the same underlying thing: proof that you protect data with real controls. Two globally recognised certifications are how you package that proof for buyers and regulators.
Neither certificate makes you automatically compliant with GDPR, DPDP, or PDPL. What they do is give you one well-run security programme whose evidence maps onto most of what those laws ask for. Do the security once, and reuse it everywhere.
The founder’s real problem: doing this once, not five times
Read back over this guide and the pattern is obvious. Five regions, one underlying job: deploy real security, then prove it in whatever format the buyer or regulator wants. The hard way is to bolt a separate compliance tool onto a patchwork of point products and stitch the evidence together by hand, per framework, per region.
| What you need | Osto | Compliance-only tools | Point-tool patchwork |
|---|---|---|---|
| Framework coverage | 200+ incl. SOC 2, ISO 27001, DPDP, GDPR, HIPAA, CCPA | Common frameworks | Depends on the tools |
| Actual security controls | Deployed by Osto’s own platform | Evidence collection only | Spread across vendors |
| Web, cloud, endpoint, VAPT | One platform | Not included | Separate tools |
| Evidence source | Straight from Osto’s modules | Integrations you maintain | Manual, tool by tool |
| SOC 2 timeline | About 115 days end-to-end | Varies | Often longer |
Do the security once. Prove it everywhere.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Deploy the controls global data laws expect on one platform, and map the same posture to SOC 2, ISO 27001, DPDP, GDPR, and 200+ frameworks, with evidence collected in one place. No security team required.
Frequently asked questions
Do foreign data laws apply to my startup?
Very likely, yes. GDPR, India’s DPDP Act, Japan’s APPI, and Singapore’s PDPA all have extraterritorial reach. If you handle the personal data of people in those places while offering them goods or services, their law applies even if your company is based elsewhere.
Which framework should a startup tackle first?
Follow your customers. If your pipeline is US and global enterprise, SOC 2 usually unblocks the most revenue fastest. If you sell into Europe, GDPR readiness and often ISO 27001 come first. If you are an Indian company handling local data, DPDP is your baseline.
Does SOC 2 or ISO 27001 make me GDPR or DPDP compliant?
Not automatically. These certifications prove your security controls work, and their evidence maps onto much of what the laws require, but each law has specific obligations, such as consent and breach notification, that you address directly. The security work, however, is largely shared.
What is the DPDP Act penalty?
India’s DPDP Act allows penalties of up to ₹250 crore for failing to maintain reasonable security safeguards. The DPDP Rules, notified in November 2025, set the operational requirements and a phased enforcement calendar.
How do I avoid rebuilding compliance for every region?
Build one strong security programme and map its evidence to each framework, rather than starting over per region. A platform that runs the controls and collects the evidence lets a lean team cover many frameworks from a single posture.

