Cyber Defence
Cyber Security

What is GDPR? A Simple Guide for Businesses (2026)

What is GDPR? A plain-English 2026 guide for businesses: core principles, individual rights, who must comply, penalties, and how GDPR compares with India's DPDP Act 2023, plus a practical compliance checklist.

What is GDPR? A Simple Guide for Businesses (2026)
Amit Kumar
Amit KumarEthical Hacker & Founder
8 min read

Short answer: GDPR (General Data Protection Regulation) is the European Union's data-privacy law that took effect in May 2018. It gives individuals control over their personal data and forces any business that handles EU residents' data to protect it, get consent, and report breaches, with fines up to EUR 20 million or 4% of global turnover.

What is GDPR in Simple Terms?

The General Data Protection Regulation is a single, EU-wide law that governs how organisations collect, store, use and share the personal data of people in the European Union and the European Economic Area (EEA). Personal data means anything that can identify a living person: name, email, phone number, IP address, location, cookies, health records, and more.

GDPR replaced a patchwork of older national laws with one strict standard. Its core idea is simple: personal data belongs to the individual, not the company. Businesses are only temporary custodians and must handle that data lawfully, fairly and transparently.

Who Must Comply With GDPR?

Many Indian and global businesses wrongly assume GDPR only applies to European companies. It does not. GDPR applies to you if:

  • You are based in the EU/EEA and process personal data.
  • You are based anywhere in the world but offer goods or services to people in the EU (a paid product or even a free app).
  • You monitor the behaviour of people in the EU (analytics, tracking, ad targeting).

This "extra-territorial" reach means a software company in Hisar, a SaaS startup in Bengaluru, or an e-commerce store in Delhi that ships to Germany all fall under GDPR. If you have even one EU customer whose data you store, you are in scope.

The 7 Core Principles of GDPR

Every processing activity must respect these principles, which regulators use as the yardstick during investigations:

  • Lawfulness, fairness and transparency - have a valid legal basis and be open about it.
  • Purpose limitation - collect data only for a specific, stated reason.
  • Data minimisation - collect only what you actually need.
  • Accuracy - keep data correct and up to date.
  • Storage limitation - do not keep data longer than necessary.
  • Integrity and confidentiality - secure data with encryption, access control and testing.
  • Accountability - be able to prove you follow all of the above.

Key Rights GDPR Gives to Individuals

GDPR grants eight enforceable rights to "data subjects." Your business must be able to honour these within one month of a request:

  • Right to be informed about how data is used.
  • Right of access (a copy of their data).
  • Right to rectification of wrong data.
  • Right to erasure (the "right to be forgotten").
  • Right to restrict processing.
  • Right to data portability.
  • Right to object to processing, including marketing.
  • Rights around automated decision-making and profiling.

GDPR vs India's DPDP Act 2023: A Comparison

India passed its own privacy law, the Digital Personal Data Protection (DPDP) Act, in August 2023. If you run an Indian business, you likely need to comply with both. They share DNA but differ in important ways.

AspectGDPR (EU)DPDP Act 2023 (India)
EffectiveMay 2018Passed 2023; rules being phased in
ScopeEU residents' data, worldwide reachDigital personal data of people in India
Legal basesSix (consent, contract, legitimate interest, etc.)Mainly consent plus "legitimate uses"
TerminologyController / Processor / Data SubjectData Fiduciary / Data Processor / Data Principal
Breach noticeWithin 72 hours to the regulatorTo the Data Protection Board and affected users
Maximum penaltyEUR 20M or 4% of global turnoverUp to INR 250 crore per instance
RegulatorNational Data Protection AuthoritiesData Protection Board of India
Children's dataConsent needed under 16 (varies)Verifiable parental consent under 18

The practical takeaway: a strong GDPR programme gives you most of what DPDP demands, but DPDP has stricter rules around children and relies more heavily on explicit consent. Businesses serving both markets should build one unified privacy framework.

What Happens if You Ignore GDPR?

Fines are tiered. Lower-level violations can cost up to EUR 10 million or 2% of annual global turnover, while serious breaches of core principles reach EUR 20 million or 4% - whichever is higher. Beyond fines, non-compliance brings reputational damage, loss of EU customers, and civil claims. Regulators have already issued penalties running into hundreds of millions of euros against major tech firms.

Common GDPR Mistakes Businesses Make

  • Pre-ticked consent boxes (consent must be a clear, opt-in action).
  • Vague privacy policies no one can understand.
  • Keeping data "just in case" with no retention limit.
  • No process to handle access or deletion requests.
  • Sharing data with vendors that have no data-processing agreement.
  • Weak security - unencrypted databases, shared passwords, no testing.

A Practical GDPR Compliance Checklist

  • Map your data: know what you collect, where it lives and who can access it.
  • Identify a lawful basis for each processing activity.
  • Rewrite your privacy notice in plain language.
  • Fix your consent flows - opt-in, granular, easy to withdraw.
  • Sign data-processing agreements with every vendor.
  • Build a breach-response plan that meets the 72-hour deadline.
  • Appoint a Data Protection Officer if required.
  • Run regular security testing such as VAPT to prove "integrity and confidentiality."

That last point matters most in practice. Regulators repeatedly cite "inadequate technical measures" when they fine companies after a breach. Penetration testing and security audits are how you show you took security seriously.

The Six Lawful Bases for Processing Data

Under GDPR you cannot process personal data just because you want to. You must have one of six lawful bases, chosen before you start, and record which one applies:

  • Consent - the person has given clear, opt-in permission for a specific purpose.
  • Contract - processing is necessary to deliver a contract, such as shipping an order.
  • Legal obligation - a law requires you to process the data, for example tax records.
  • Vital interests - processing protects someone's life.
  • Public task - processing is needed for an official function.
  • Legitimate interests - a genuine business need that does not override the person's rights.

Marketing teams often lean on consent, while operations teams rely on contract or legitimate interests. Choosing the wrong basis, or switching bases midway, is a frequent cause of complaints and fines.

Data Transfers Outside the EU

GDPR restricts sending personal data to countries without "adequate" protection. For Indian businesses this matters: to receive EU data legally you typically need safeguards such as Standard Contractual Clauses (SCCs) in your contracts. Simply storing EU customer data on Indian servers without these safeguards can itself be a violation, so build compliant contracts with your EU clients from day one.

How Cyber Defence Helps With Privacy Compliance

Cyber Defence is an ISO-certified, GeM-registered cyber security institute and VAPT provider based in Hisar, Haryana, founded by Amit Kumar (CEH, CRTA). We help Indian businesses meet the technical-security expectations of both GDPR and the DPDP Act through vulnerability assessment and penetration testing (VAPT) and full security audits that produce the evidence auditors want to see.

We also train the people who run these programmes. Our cyber security course costs INR 15,000 and runs 3-4 months, while our advanced ethical hacking course (INR 60,000, 6 months) is available through our VAPT training track. Businesses across Haryana work with our Hisar cyber security team for hands-on compliance support. To understand how testing maps directly to Indian law, read our guide on VAPT for DPDP Act compliance.

FAQ

Does GDPR apply to Indian companies?

Yes. If your Indian business offers goods or services to people in the EU, or tracks their online behaviour, GDPR applies regardless of where your company is located. Even a single EU customer whose data you store can bring you into scope.

What is the difference between a data controller and a data processor?

A controller decides why and how personal data is processed, while a processor handles data on the controller's behalf. For example, an online store is the controller and its cloud email provider is a processor. Both have legal obligations under GDPR.

How quickly must a data breach be reported under GDPR?

You must notify the relevant supervisory authority within 72 hours of becoming aware of a breach that risks people's rights and freedoms. If the risk is high, affected individuals must also be told without undue delay.

Is GDPR consent the same as DPDP consent?

They are similar but not identical. Both require clear, informed, opt-in consent, but the DPDP Act relies more heavily on consent as a legal basis and applies stricter rules to children's data, requiring verifiable parental consent for anyone under 18.

How can VAPT help with GDPR compliance?

GDPR requires "appropriate technical and organisational measures" to secure data. Vulnerability assessment and penetration testing prove you actively find and fix security flaws, which is exactly the evidence regulators look for after a breach. It supports the integrity and confidentiality principle.

Do small businesses need to comply with GDPR?

Yes. GDPR has no small-business exemption based on size. However, some record-keeping obligations are lighter for organisations under 250 employees, provided processing is occasional and low-risk. The core principles still apply to everyone.

Need help meeting GDPR or DPDP security requirements in India? Talk to the Cyber Defence team in Hisar, led by Amit Kumar (CEH, CRTA), for VAPT, security audits and privacy-focused training. Call +91-75175-72000 today.

Talk to a Cyber Defence Expert

Get a free consultation on cybersecurity, training and certifications. Our team responds within 10 minutes during business hours.