Insights

An Introduction to the GDPR

The GDPR applies wherever EU residents' data is processed, regardless of where the processing happens — which is why it reached Indian businesses that had never operated in Europe. Scope, consent, access rights, and penalties reaching 4% of global revenue.

Published 24 June 2019 · Updated 14 August 2026 · Reviewed by Selvam & Selvam

The GDPR’s defining feature is that geography stopped mattering. It applies to the data of EU residents wherever that data is processed — which is how a regulation made in Brussels became a compliance problem for businesses in Chennai.

The context

Discussion of privacy intensified alongside the rise of social media, improved surveillance and monitoring, and the treatment of user data as a commodity. Entire industries grew on harvesting, selling and trading it. Advertisers build profiles by aggregating search history, browsing habits and media consumption to target individuals — and there have been allegations of user data being used to build profiles and influence people during elections.

In that context governments worldwide brought forward data protection legislation. In India, the Supreme Court held privacy to be a fundamental right, and the draft Personal Data Protection Bill, 2018 followed. (That Bill was later withdrawn; the Digital Personal Data Protection Act, 2023 now governs.)

The most important privacy law in effect remains the EU’s General Data Protection Regulation, notified in 2016 with a two-year implementation window, in force from 25 May 2018.

Who it applies to

The GDPR applies to any entity conducting business in the EU, and any entity that collects, stores or processes data of EU citizens or residents — including non-citizens physically in the EU. So it also reaches:

  • non-EU companies employing EU citizens, regardless of location; and
  • non-EU companies handling EU residents’ data — even a single EU user of a company’s products or services brings the GDPR into play.

In a world where services are not restricted by physical borders, an Indian business that is not careful can find itself in breach of a regulation it never considered applicable.

What it covers

  • Personal data — anything identifying an individual: a name, date of birth, physical address, even an IP address or pseudonym.
  • Sensitive personal data — protected characteristics including racial information, religious beliefs, sexual orientation, political affiliation, genetic information and trade union membership.

The key features

1. Scope. Its predecessor, the Data Protection Directive of 1995, was drafted when under 5% of the global population had internet access and cross-continental data transfer was closer to science fiction — and was correspondingly ambiguous about its reach. The GDPR makes clear that geography is not a consideration. Given the EU is the world’s largest single market, companies are reluctant to breach its rules and risk access.

2. Express consent. Entities must obtain express permission to collect, process or store personal data, clearly define the purpose, and treat consent as use-specific — data given to access research cannot be repurposed for targeted advertising. The model is opt-in, not opt-out. Collecting beyond the scope of the consent is barred, and users must be able to withdraw consent easily and at any time.

3. Access and erasure. Users are entitled to know what data is collected, how it is processed and used, and who has access. On request, the organisation must provide a copy free of charge, and correct inaccurate information. The right to be forgotten empowers users to demand erasure, and in some circumstances to require that third parties can no longer process it.

4. Structural requirements. The GDPR requires organisations to change how data is collected, stored and processed — including mandating Data Protection Officers with specific employment protections for organisations meeting certain criteria, documented storage arrangements and safeguards, and provision for data audits.

5. Penalties. For smaller or first-time breaches, up to €10 million or 2% of global revenue, whichever is higher. For serious or repeated breaches, €20 million or 4% of global revenue. For large multinationals, non-compliance can run into billions.

Those penalties are why the GDPR matters to Indian entities. An Indian business in breach that later seeks a presence in the EU faces financial and reputational consequences that are difficult to absorb — which is why many aligned their data handling with the GDPR without any immediate European operations.

Why it still matters here

The GDPR changed how organisations handle data globally, and its influence runs through the legislation that followed — including India’s own. Anyone comparing the two frameworks should note where the DPDP Act, 2023 diverges: it has no separate sensitive data category, no general localisation mandate, an adjudicatory Board rather than a supervisory authority, and penalties on a fixed schedule rather than a percentage of turnover.

The takeaways

  • Geography is irrelevant — the GDPR follows EU residents’ data anywhere.
  • Consent must be express, purpose-specific and withdrawable.
  • Access, correction and erasure are enforceable user rights.
  • Penalties reach 4% of global revenue — the reason compliance moved quickly.

Frequently asked questions

Does the GDPR apply to Indian companies? Yes, where they process the data of EU citizens or residents, or employ EU citizens — regardless of where the processing takes place.

What is the difference between personal and sensitive personal data? Personal data identifies an individual; sensitive personal data covers protected characteristics such as race, religion, sexual orientation, political affiliation, genetic data and trade union membership.

What are the GDPR penalties? Up to €10 million or 2% of global revenue for lesser breaches, and €20 million or 4% of global revenue for serious ones, whichever is higher.

Does India’s law mirror the GDPR? It draws on it but diverges — the DPDP Act, 2023 has no sensitive data category, no general localisation requirement, and penalties on a fixed schedule.

Useful official resources

Related reading