Rättskällor med officiella primärkällor

Utskrivet ·

Hoppa till innehåll
Hoppa till svaret

Indian software and SaaS handling EU data

What EU requirements apply to Indian SaaS and software companies selling into the EU?

Answer

Selling software into the EU pulls in four separate regimes at once: the GDPR as a processor or controller, the Chapter V transfer rules for the data that lands in India, the Cyber Resilience Act where software is placed on the market as a product, and the accessibility requirements for consumer-facing services. Add the AI Act on top where the product embeds a model.

What has to be done

  • Establish your role per processing activity: processor for customer data, controller for your own account and telemetry data, and paper each one correctly.
  • Sign a data processing agreement that meets Article 28, including the sub-processor list, the audit right and the assistance duties.
  • Handle the transfer separately from the contract: Standard Contractual Clauses plus a transfer impact assessment for the India leg.
  • Meet the security requirements: breach notification within 72 hours to the customer's authority route, and the CRA vulnerability handling duties where software ships as a product.
  • Check the accessibility requirements for e-commerce, banking and consumer services; they apply to the interface, not only to the back end.

Citations

Related questions

Related requirements

Source and version

Sector
SaaS, software products, IT services
Read date
2026-08-26
Register version
in-export-v1.0.0
Address
/in/export/software-eu-data

Nästa steg

Vill ni använda registret i eget arbete finns tre vägar in.

Börja med din uppgift