GDPR

GDPR territorial scope and Article 32 security requirements explained

GDPR reaches companies that have never had an office in Europe. If you sell software to EU customers, the question is not whether it applies but which role you are in when it does.

  • Glossary
  • Compliance

The short answer

GDPR is the General Data Protection Regulation, the EU law governing how personal data is handled. It applies wherever the data subjects are in the EU, regardless of where the company processing that data sits. It is a legal obligation with a security component, not a certification you obtain, and there is no such thing as a GDPR certificate issued by a regulator.

Most of what a founder needs to resolve about GDPR comes down to five questions, and only two of them are technical.

Does GDPR apply to you

Article 3 sets the territorial scope, and it is deliberately wide. A company registered in Bengaluru with no European entity can still be squarely in scope.

Established in the EU An entity, branch or staff based in a member state Offering goods or services Selling to people in the EU, paid or free Monitoring behaviour Analytics, tracking or profiling of people in the EU Any one of the three is enough. Two of them require no European presence at all.

Controller or processor

This is the distinction that decides what you owe, and most B2B SaaS companies are in both roles at once without having written it down.

ControllerProcessor
Who it isThe party deciding why and how data is processedThe party processing it on the controller’s instructions
Typical SaaS exampleYour own marketing lists, employee records, prospect dataYour customer’s end-user data sitting in your product
Main dutiesLawful basis, notices, handling data subject requests, deciding retentionProcess only as instructed, secure the data, assist the controller, report incidents to them
Contract neededPuts the data processing agreement in placeSigns it, and is bound by it
Sub-processorsApproves themMust disclose them and pass obligations down

The processor role is what buyers audit

When an EU customer sends a data processing agreement and a security questionnaire, they are contracting with you as their processor. The questions are about your controls, your sub-processors and your breach reporting, not about your own marketing list. Companies that prepare for GDPR as a controller and then meet a processor review find they have documented the wrong half.

What GDPR requires technically

Article 32 covers security of processing. It names measures rather than prescribing products, and it asks that they be appropriate to the risk.

What Article 32 namesWhat it looks like in practice
Pseudonymisation and encryptionEncryption at rest and in transit, plus disk encryption on the endpoints data reaches
Confidentiality and integrityAccess control, least privilege, data loss prevention and logging
Availability and resilienceBackups, recovery objectives and evidence they have been tested
Ability to restore accessA restoration test with a date on it, not a documented intention
Regular testing and evaluationPenetration testing, vulnerability management and a risk assessment that gets revisited
Appropriate to the riskThe measures scale with the sensitivity and volume of what you hold

None of this is unfamiliar territory if you already run an ISMS. ISO 27001 and SOC 2 both cover most of Article 32, which is why they are the usual answer when an EU buyer asks how you satisfy it.

The 72 hour clock

A controller must notify its supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in risk. Where risk to individuals is high, the individuals must be told as well.

For a processor the obligation is different and tighter in practice: notify the controller without undue delay. Your customer cannot start their own 72 hour clock until you tell them, so a contractual window measured in hours is common in data processing agreements. That makes detection speed a commercial commitment, not just a security aspiration, and it is why incident response readiness gets sampled during vendor review.

GDPR and the DPDP Act

Indian companies increasingly answer to both. The concepts rhyme, the vocabulary does not.

GDPRDPDP Act
The individualData subjectData principal
The deciderControllerData fiduciary
The vendorProcessorData processor
Lawful basesSix, including legitimate interestsConsent and specified legitimate uses
Breach reporting72 hours to the supervisory authority, risk-basedNotification to the Board and affected principals
Security wordingAppropriate technical and organisational measuresReasonable security safeguards

The practical consequence is that one control set can serve both. The security measures overlap heavily. What differs is consent handling, notices and the legal paperwork sitting above them.

How Osto helps with GDPR

Osto covers the security half. Article 32 measures run as live controls, access, encryption, logging, testing and monitoring, and the compliance module maps them to GDPR alongside SOC 2, ISO 27001, DPDP and over 200 other frameworks from the same control set. Evidence comes out of the platform running the controls rather than from screenshots collected before a review.

The half a platform cannot do is worth stating plainly. Lawful basis, privacy notices, data processing agreements, records of processing, international transfer mechanisms, whether you need a data protection officer and how you handle data subject requests are legal and operational decisions. A control platform supports them with evidence. It does not make them for you, and anyone claiming a product delivers GDPR compliance on its own is overstating what a product can do.

Platform walkthrough

One control set, many frameworks

Article 32 measures running as live controls, mapped to GDPR, DPDP, SOC 2 and ISO 27001 at the same time. Evidence from the platform that enforces them. One owner, one dashboard.

Book a demo

200+ frameworks mapped · Evidence from live controls · One platform, everything

Frequently asked questions

Does GDPR apply to a company outside the EU?

Yes, if it offers goods or services to people in the EU or monitors their behaviour. No European entity or office is required. An Indian SaaS company with EU customers is typically in scope through the offering test.

Can you get GDPR certified?

No regulator issues a GDPR certificate. Certification schemes exist under Article 42 but adoption is limited. In practice EU buyers accept ISO 27001 or SOC 2 plus a signed data processing agreement as evidence of the security measures.

Are we a controller or a processor?

Most B2B SaaS companies are both. You are a processor for the customer data held in your product, and a controller for your own marketing, prospect and employee data. The obligations differ, so both need to be written down.

What is the 72 hour rule?

A controller must notify its supervisory authority within 72 hours of becoming aware of a personal data breach unless risk is unlikely. A processor must tell the controller without undue delay, which contracts often reduce to a fixed number of hours.

Does GDPR compliance cover the DPDP Act?

Partly. The security measures overlap substantially, so one control set can serve both. Consent handling, notices and terminology differ, and the DPDP Act has its own obligations that GDPR work does not automatically satisfy.