Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Governance, Risk & Compliance

GDPR compliance, built on knowing where the data is.

A GDPR compliance consultant in India is engaged for a reason that has little to do with Europe: an EU customer will not sign until the data processing agreement is in place and the security schedule survives review. GDPR reaches you because your customers are in scope, and their accountability flows down to you contractually.

Every GDPR programme has the same foundation and the same failure point. The foundation is knowing what personal data you hold, where it came from, why you have it, who you share it with, where it physically sits and how long you keep it. The failure point is that most organisations do not know, and no amount of policy writing substitutes for finding out.

We start with the mapping, establish lawful basis for each processing activity, build the rights and impact-assessment machinery, and get the transfer mechanisms right, which is where Indian service providers most often get caught. Where you want it certifiable, ISO 27701 is the management system; Indian obligations run in parallel under the DPDP Act.

Why you need it

01 / 06

Why GDPR reaches organisations in India.

01

It follows the data, not the office.

Article 3 applies the regulation to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour. An Indian company with EU users, or processing EU personal data for a client, is in scope regardless of where its servers are.

02

Your customers pass the obligation down.

Controllers are required by Article 28 to use only processors providing sufficient guarantees. That obligation reaches you as a data processing agreement, a security schedule, audit rights and sub-processor terms, and the deal does not close until you can sign them credibly.

03

Transfers out of the EU need a mechanism.

India has no adequacy decision, so transfers rely on Standard Contractual Clauses supported by a transfer impact assessment and appropriate supplementary measures. Getting this wrong is one of the more common and more expensive findings.

04

The penalties are structured to matter.

The regulation provides for administrative fines up to 4% of total worldwide annual turnover of the preceding financial year, or €20 million, whichever is higher, for the most serious infringements, with a lower tier for others. Commercially, losing the account usually arrives first.

Instrument

02 / 06

Where GDPR overlaps what you already do.

Toggle the regimes you are asked for. Most of the security half is shared; the privacy half is where the new work is.

What we deliver

03 / 06

What we deliver.

01

Data mapping and records of processing

A complete inventory of processing activities: categories of data and data subjects, purposes, lawful basis, recipients, transfers, retention and security measures. This is the Article 30 record and it is also the artefact everything else depends on.

02

Lawful basis and consent

Establishing and documenting the basis for each activity, legitimate interest assessments where that basis is relied upon, and consent mechanisms that meet the standard: freely given, specific, informed, unambiguous, and as easy to withdraw as to give.

03

Data protection impact assessments

A DPIA methodology with clear triggers, so assessments happen before a high-risk processing activity launches rather than after a regulator asks. Includes the first assessments for your highest-risk processing.

04

Data subject rights operations

Working procedures for access, rectification, erasure, restriction, portability and objection: identity verification, internal routing, the one-month response clock tracked, and responses evidenced.

05

International transfers

Transfer mapping, Standard Contractual Clauses in the correct modules, transfer impact assessments, and supplementary measures where the assessment requires them. Essential for any Indian entity processing EU personal data.

06

Processor obligations and documentation

Data processing agreements, sub-processor registers and flow-down terms, breach notification procedures meeting the 72-hour controller obligation, privacy notices, and the accountability documentation a customer audit will ask for.

How we run it

04 / 06

Six steps.

  1. 01

    Conduct a data audit

    Identifying and mapping all personal data collected, processed, stored and shared, across systems, spreadsheets, SaaS tools and suppliers. Interview-led, because the data flows that matter are rarely the documented ones.

    Weeks 1-4
  2. 02

    Implement data protection measures

    The Article 32 security measures appropriate to the risk (encryption, access control, pseudonymisation where useful, resilience and tested restoration) plus data minimisation and retention actually enforced.

    Months 1-3
  3. 03

    Update privacy policies and notices

    External privacy notices that meet the Article 13 and 14 transparency requirements in language people can read, and the internal policies that make them true.

    Month 2
  4. 04

    Establish consent mechanisms

    Where consent is the lawful basis: capture that meets the standard, granularity per purpose, a record of what was consented to and when, and withdrawal that is as easy as the original consent and actually propagates.

    Month 2-3
  5. 05

    Build data subject rights processes

    Request intake, identity verification, search across systems, redaction, response templates and deadline tracking, designed to be run by whoever is on duty rather than by the one person who understands it.

    Month 3
  6. 06

    Appoint a data protection officer if required

    Assessing whether Article 37 requires a DPO, and either appointing internally with the required independence or providing the role externally where that is more proportionate.

    Month 3-4

Key benefits

05 / 06

What changes after.

You know what you hold

A maintained record of processing activities, which is simultaneously the Article 30 obligation, the answer to most customer questionnaires, and the input to every other privacy decision.

EU contracts stop stalling

A data processing agreement, sub-processor register and transfer mechanism you can produce on request, rather than negotiate from scratch for each customer.

Rights requests have a process

Intake, verification, search and response on a tracked clock, so a subject access request is handled rather than escalated.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Regulation and guidance

  • GDPR (Regulation (EU) 2016/679)
  • EDPB guidelines
  • EU Standard Contractual Clauses (2021)

Privacy operations

  • Records of processing activities
  • DPIA methodology
  • Legitimate interest assessment template
  • Retention schedule

Rights and consent

  • Data subject request workflow
  • Consent and preference register
  • Identity verification procedure

Transfers

  • Transfer impact assessment
  • SCC module selection
  • Sub-processor register

Certifiable framework

  • ISO/IEC 27701
  • ISO/IEC 27001:2022

Included in this service

Data privacy governance

Also

Compliance with any single regime is a project. Governing privacy across several (GDPR, India's DPDP Act, CCPA and whatever arrives next) is an operating capability, and it is the only thing that scales for an organisation with users in more than one country.

We build the layer underneath the individual regimes: one data inventory that serves all of them, a privacy risk methodology and register, clear ownership of personal data by business function, retention and deletion enforced technically rather than by policy alone, privacy review built into product delivery rather than bolted on at launch, and vendor and sub-processor governance for everyone who touches the data.

Governed this way, a new regulation becomes a gap analysis against a known baseline rather than a fresh discovery exercise. That is the difference between a privacy function that absorbs each new law in weeks and one that runs a six-month programme every time a jurisdiction legislates.

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask about GDPR.

Does GDPR apply to us if we have no EU office?
It can. Article 3 extends the regulation to organisations established outside the EU where they offer goods or services to people in the EU or monitor their behaviour. Separately, and more commonly for Indian service providers, it reaches you contractually: your EU customer is a controller with Article 28 obligations, and it satisfies them by imposing equivalent terms on you. In practice the contract binds you well before the jurisdictional question does.
Do we need a data protection officer?
A DPO is mandatory under Article 37 where you are a public authority, where your core activities require regular and systematic monitoring of data subjects on a large scale, or where they involve large-scale processing of special category data. Many organisations fall outside those tests and still benefit from a designated privacy owner. Where a DPO is required, the role needs genuine independence and no conflicting duties, which is why an external appointment is often cleaner for a smaller organisation.
How do we transfer EU data to India lawfully?
India has no adequacy decision from the European Commission, so transfers rely on an Article 46 safeguard: in practice the 2021 Standard Contractual Clauses in the correct module for your relationship. Following Schrems II, the clauses alone are not sufficient: you also need a transfer impact assessment considering the destination's laws and practices, and supplementary technical or organisational measures where the assessment identifies a risk. This is where processors in India are most often found lacking.
What has to happen within 72 hours?
A controller must notify the relevant supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals. Where the risk is high, affected individuals must also be told without undue delay. If you are a processor, your obligation is to notify your controller without undue delay, and your contract almost certainly specifies a shorter window than 72 hours, so read it before you need it.
Is there a GDPR certification we can get?
Not one that certifies compliance with the regulation as a whole. Article 42 provides for approved certification mechanisms, and the available schemes are limited in scope. The practical route to demonstrable accountability is ISO 27701, which extends an ISO 27001:2022 management system into privacy and maps its controls to GDPR articles. It is not a legal certification of compliance, and it is the strongest available evidence that the machinery exists and operates.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.