Insights

Key Features of the GDPR

The EU's GDPR reshaped how organisations handle personal data — with strict obligations, powerful data-subject rights, and revenue-based fines. A clear rundown of its scope, the rights it grants, the duties it imposes, and why it reaches Indian businesses too.

Published 24 June 2019 · Updated 14 August 2026 · Reviewed by Selvam & Selvam

Since May 2018, the EU’s General Data Protection Regulation has transformed how organisations store, handle and process personal data — with strict duties, strong individual rights, and fines big enough that even Amazon and Facebook can’t ignore them. Here are its key features, and why they reach Indian businesses too.

Key definitions

  • Data subject — an identifiable natural person whose data is stored/processed.
  • Processing — any operation on personal data (automated or not): collection, recording, alteration, storage, retrieval, transmission, erasure, use.
  • Data controller — determines the means and purposes of processing.
  • Data processor — processes personal data on behalf of the controller.

Example: a marketing company surveys people (data subjects) and uses a third-party email platform to send promotions — the marketing company is the controller, the platform the processor.

Extraterritorial jurisdiction

The GDPR applies to processing by controllers/processors in the EU, and also to those outside the EU if they offer goods/services to EU residents or monitor behaviour in the EU. Non-EU businesses caught by it must appoint an EU representative — unless processing is occasional or excludes sensitive data.

Example: an Indian e-commerce site selling to EU citizens needs an EU representative; an Indian cloud provider serving only EU companies (legal persons, not data subjects) likely qualifies for an exemption.

Rights of data subjects

  • Express consent to store/process data, easily withdrawable; for minors under 16, parental consent.
  • Transparency — told whether, where and why their data is processed.
  • Right to be forgotten — request erasure or halting of processing, balanced against public interest.
  • Access — a free copy of processed data within one month.
  • Portability — data in a machine-readable format, transferable to another controller.
  • Breach notification — controllers must tell subjects within 72 hours of a risky breach.

Obligations on controllers/processors

  • Data-export limits — personal data can’t leave the EEA unless the destination is certified adequate or approved mechanisms (e.g. model clauses) are used — highly relevant to India.
  • Use-specific consent — data collected for one purpose can’t be reused (e.g. for marketing) without fresh consent.
  • Clear consent notices — stating the exact reason and retention period.
  • Accountability for processors — controllers remain liable even for a third-party breach.
  • Privacy by design and data minimisation — collect only what’s necessary.
  • Data Protection Impact Assessments for new projects or significant changes.
  • Detailed records of all processing activities.

Data Protection Officers

A controller/processor engaged in large-scale systematic monitoring, processing sensitive data, or handling criminal-record data must appoint a DPO — a data-protection expert (internal or external) who reports to top management, has the resources to act, and stays neutral (no conflicting duties).

Penalties

The headline change: revenue-based fines. Minor offences (poor records, missed 72-hour notifications, no DPIA) — up to €10 million or 2% of global revenue, whichever is higher. Serious breaches (e.g. processing without sufficient consent) — up to €20 million or 4% of global revenue.

The takeaways

  • The GDPR reaches beyond the EU — Indian businesses serving EU residents can be caught.
  • Data subjects hold strong rights — consent, erasure, access, portability, breach notice.
  • Controllers stay accountable — even for processor failures, with strict export limits.
  • Fines are revenue-based — up to 4% of global turnover, so compliance is non-negotiable.

Frequently asked questions

Does the GDPR apply to Indian businesses? It can — if they offer goods/services to EU residents or monitor behaviour in the EU, they fall within its extraterritorial scope and may need an EU representative.

What is the “right to be forgotten”? A data subject’s right to request erasure or cessation of processing of their personal data, balanced against the public interest in that data.

How quickly must a data breach be reported? Controllers must notify affected data subjects within 72 hours of becoming aware of a breach likely to risk individuals’ rights and freedoms.

What are the GDPR penalties? Up to €10 million or 2% of global revenue for minor offences, and up to €20 million or 4% for serious breaches — whichever is higher.

Useful official resources

Related reading