GDPR reaches companies that have never had an office in Europe. If you sell software to EU customers, the question is not whether it applies but which role you are in when it does.
The short answer
GDPR is the General Data Protection Regulation, the EU law governing how personal data is handled. It applies wherever the data subjects are in the EU, regardless of where the company processing that data sits. It is a legal obligation with a security component, not a certification you obtain, and there is no such thing as a GDPR certificate issued by a regulator.
Most of what a founder needs to resolve about GDPR comes down to five questions, and only two of them are technical.
On this page
Does GDPR apply to you
Article 3 sets the territorial scope, and it is deliberately wide. A company registered in Bengaluru with no European entity can still be squarely in scope.
Controller or processor
This is the distinction that decides what you owe, and most B2B SaaS companies are in both roles at once without having written it down.
| Controller | Processor | |
|---|---|---|
| Who it is | The party deciding why and how data is processed | The party processing it on the controller’s instructions |
| Typical SaaS example | Your own marketing lists, employee records, prospect data | Your customer’s end-user data sitting in your product |
| Main duties | Lawful basis, notices, handling data subject requests, deciding retention | Process only as instructed, secure the data, assist the controller, report incidents to them |
| Contract needed | Puts the data processing agreement in place | Signs it, and is bound by it |
| Sub-processors | Approves them | Must disclose them and pass obligations down |
The processor role is what buyers audit
When an EU customer sends a data processing agreement and a security questionnaire, they are contracting with you as their processor. The questions are about your controls, your sub-processors and your breach reporting, not about your own marketing list. Companies that prepare for GDPR as a controller and then meet a processor review find they have documented the wrong half.
What GDPR requires technically
Article 32 covers security of processing. It names measures rather than prescribing products, and it asks that they be appropriate to the risk.
| What Article 32 names | What it looks like in practice |
|---|---|
| Pseudonymisation and encryption | Encryption at rest and in transit, plus disk encryption on the endpoints data reaches |
| Confidentiality and integrity | Access control, least privilege, data loss prevention and logging |
| Availability and resilience | Backups, recovery objectives and evidence they have been tested |
| Ability to restore access | A restoration test with a date on it, not a documented intention |
| Regular testing and evaluation | Penetration testing, vulnerability management and a risk assessment that gets revisited |
| Appropriate to the risk | The measures scale with the sensitivity and volume of what you hold |
None of this is unfamiliar territory if you already run an ISMS. ISO 27001 and SOC 2 both cover most of Article 32, which is why they are the usual answer when an EU buyer asks how you satisfy it.
The 72 hour clock
A controller must notify its supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in risk. Where risk to individuals is high, the individuals must be told as well.
For a processor the obligation is different and tighter in practice: notify the controller without undue delay. Your customer cannot start their own 72 hour clock until you tell them, so a contractual window measured in hours is common in data processing agreements. That makes detection speed a commercial commitment, not just a security aspiration, and it is why incident response readiness gets sampled during vendor review.
GDPR and the DPDP Act
Indian companies increasingly answer to both. The concepts rhyme, the vocabulary does not.
| GDPR | DPDP Act | |
|---|---|---|
| The individual | Data subject | Data principal |
| The decider | Controller | Data fiduciary |
| The vendor | Processor | Data processor |
| Lawful bases | Six, including legitimate interests | Consent and specified legitimate uses |
| Breach reporting | 72 hours to the supervisory authority, risk-based | Notification to the Board and affected principals |
| Security wording | Appropriate technical and organisational measures | Reasonable security safeguards |
The practical consequence is that one control set can serve both. The security measures overlap heavily. What differs is consent handling, notices and the legal paperwork sitting above them.
How Osto helps with GDPR
Osto covers the security half. Article 32 measures run as live controls, access, encryption, logging, testing and monitoring, and the compliance module maps them to GDPR alongside SOC 2, ISO 27001, DPDP and over 200 other frameworks from the same control set. Evidence comes out of the platform running the controls rather than from screenshots collected before a review.
The half a platform cannot do is worth stating plainly. Lawful basis, privacy notices, data processing agreements, records of processing, international transfer mechanisms, whether you need a data protection officer and how you handle data subject requests are legal and operational decisions. A control platform supports them with evidence. It does not make them for you, and anyone claiming a product delivers GDPR compliance on its own is overstating what a product can do.
Platform walkthrough
One control set, many frameworks
Article 32 measures running as live controls, mapped to GDPR, DPDP, SOC 2 and ISO 27001 at the same time. Evidence from the platform that enforces them. One owner, one dashboard.
Book a demo200+ frameworks mapped · Evidence from live controls · One platform, everything
Frequently asked questions
Does GDPR apply to a company outside the EU?
Yes, if it offers goods or services to people in the EU or monitors their behaviour. No European entity or office is required. An Indian SaaS company with EU customers is typically in scope through the offering test.
Can you get GDPR certified?
No regulator issues a GDPR certificate. Certification schemes exist under Article 42 but adoption is limited. In practice EU buyers accept ISO 27001 or SOC 2 plus a signed data processing agreement as evidence of the security measures.
Are we a controller or a processor?
Most B2B SaaS companies are both. You are a processor for the customer data held in your product, and a controller for your own marketing, prospect and employee data. The obligations differ, so both need to be written down.
What is the 72 hour rule?
A controller must notify its supervisory authority within 72 hours of becoming aware of a personal data breach unless risk is unlikely. A processor must tell the controller without undue delay, which contracts often reduce to a fixed number of hours.
Does GDPR compliance cover the DPDP Act?
Partly. The security measures overlap substantially, so one control set can serve both. Consent handling, notices and terminology differ, and the DPDP Act has its own obligations that GDPR work does not automatically satisfy.

