India to EU: legal questions answered with their citations
The answer to each question is in the first paragraph, and each one links to the requirement node that carries the article reference. The answers come from EU articles we have read, not from a second-hand summary.
Register
- Questions
- 38
- Read date
- 2026-08-26
- Version
- in-questions-v1.0.0
Start here
- Indian companies exporting to the EU — what requirements apply?
Three layers apply at once, and they are assessed separately. First, an economic operator established in the EU must take responsibility for the product or the data processing. Second, the product or service must meet the substantive Union legislation for its category, which is normally several acts rather than one. Third, sector rules on carbon, deforestation, chemicals or due diligence apply on top, and they are contractual as well as regulatory because the EU buyer is under the same duty.
- India to EU export compliance — where do we start?
Start by naming the role you occupy in the transaction, because every obligation follows from the role rather than from the place of registration. Manufacturer, provider, exporter or platform each carry a different set. Then list every act that touches the product or service, appoint the EU-side entity each act requires, and only after that build the documentation. Companies that start with documentation end up rebuilding it.
- Do Indian IT services firms need GDPR compliance without an EU office?
Yes. The GDPR applies by reference to whose data is processed and where the individuals are, not to where the processor sits. An Indian IT services firm, BPO or global capability centre processing EU personal data is a processor with direct obligations under Article 28 and Article 32, and the data reaching India is a Chapter V transfer that needs its own legal basis.
All questions
- Do Indian companies need an EU authorised representative to export to the EU?
Yes, and usually more than one. The product side requires a responsible person established in the Union, the data side requires a GDPR representative, and AI providers require an authorised representative under the AI Act. These are three separate obligations and one appointment does not satisfy the others.
- Do Indian SaaS companies need an EU representative?
Yes, where the company has no establishment in the Union and offers services to people in the EU or monitors their behaviour. The GDPR representative must be appointed in writing in a Member State where the affected individuals are, and the identity and contact details must appear in the privacy notice.
- How do you transfer personal data between India and the EU under GDPR Chapter V?
India has no adequacy decision, so the transfer runs on the appropriate safeguards in Article 46, which in practice means the Commission's Standard Contractual Clauses plus a transfer impact assessment describing Indian government access powers and the supplementary measures you apply.
- Can the EU Standard Contractual Clauses be modified?
No. The Commission's text may not be altered. You select the module that matches the real roles and complete the annexes; changing the clauses themselves removes the legal effect they were adopted to give.
- Does complying with the DPDP Act mean we comply with the GDPR?
No. The structures overlap but the obligations are separate. The DPDP Act rests on consent and legitimate uses, while the GDPR has six legal bases, portability and objection rights, and mandatory impact assessments for high-risk processing. Each has to be discharged on its own terms.
- What EU requirements apply to Indian SaaS companies selling services in the EU?
Four regimes apply together: the GDPR for the processing, Chapter V for the data that lands in India, the Cyber Resilience Act where software is placed on the market as a product, and the accessibility requirements for consumer-facing services. The AI Act joins them where the product embeds a model.
- What EU requirements apply to Indian software companies handling EU data?
Establish the role for each processing activity, sign a data processing agreement that meets Article 28, secure the processing to Article 32, and handle the India leg of the transfer separately with Standard Contractual Clauses and a transfer impact assessment. Breach notification runs on a 72-hour clock.
- Must Indian AI models comply with the EU AI Act to be sold in the EU?
Yes. The party placing the system on the EU market is the provider, even where all development and training happened in India. Obligations follow the risk class, and a provider without an EU establishment must appoint an authorised representative in writing.
- How does the EU AI Act affect Indian generative AI and foundation models?
A general-purpose model carries its own duties: technical documentation, information for downstream providers, a Union copyright policy and a sufficiently detailed public summary of the training content. Models with systemic risk add evaluation, adversarial testing, incident reporting and cybersecurity duties.
- Do general-purpose AI providers have to disclose their training data in the EU?
A sufficiently detailed summary of the training content must be published, following the AI Office template, together with a policy for complying with Union copyright law including the reservation of rights for text and data mining. The full dataset does not have to be published.
- What CE requirements apply to Indian electronics manufacturers exporting to the EU?
CE is a manufacturer's own declaration, not a certificate. Identify every applicable act, which for electronics is normally product safety, electromagnetic compatibility, radio equipment and low voltage together, compile the technical documentation and keep it for ten years, and sign the declaration of conformity listing each act and standard relied on.
- Is a BIS or ISI certificate accepted as CE marking in the EU?
No. BIS is a third-party registration scheme and CE is a self-declaration by the manufacturer against Union legislation. Test reports can often be reused, but the declaration, the technical documentation and the EU responsible person have to be built separately.
- How do Indian companies meet the EU General Product Safety Regulation?
Appoint the EU responsible person and put the name and address on the product, carry out an internal risk analysis, keep the technical documentation for ten years, put traceability elements on the article, supply instructions in the language of the Member State of sale, and report accidents through the Safety Business Gateway.
- Must Indian companies have a responsible person in the EU under GPSR?
Yes. Since December 2024 no consumer product may be placed on the EU market unless an economic operator established in the Union takes responsibility for it, and that operator's name and address must appear on the product, the packaging or the accompanying document.
- What documents are required to export machinery from India to the EU?
The technical file, the EU declaration of conformity, the instructions for use and assembly in the language of the destination Member State, and the CE marking. For the higher-risk categories listed in the Machinery Regulation a notified body must be involved before placing on the market.
- How do Indian manufacturers meet the EU Cyber Resilience Act?
Design to the essential cybersecurity requirements, ship secure by default with no universal factory passwords, maintain a vulnerability handling process and a software bill of materials for the whole support period, provide free security updates, and report actively exploited vulnerabilities to ENISA within twenty-four hours.
- Do the CERT-In directions cover the EU Cyber Resilience Act?
No. CERT-In regulates the operator, with a six-hour incident report and 180-day log retention in India. The Cyber Resilience Act regulates the product, with secure design, vulnerability handling and a 24-hour report to ENISA. Both chains have to be in place before an incident, not after.
- What CBAM requirements apply to Indian steel and cement exporters?
Embedded emissions must be reported by the EU declarant, and the data can only come from the Indian installation. An exporter that cannot supply installation-level figures is priced at default values, which are conservative and therefore more expensive for the buyer.
- Can a carbon price already paid in India be deducted under CBAM?
Yes, where the payment is verifiable and declared on the EU side. Keep the payment evidence and pass it to the declarant with the emissions data; an unevidenced claim is not deductible.
- How does the EU Deforestation Regulation affect Indian suppliers?
Rubber, leather, coffee, timber, soya and their derived products need a due diligence statement with the geolocation of the plot of production. Traceability to the trader or the aggregator is not sufficient, and the statement's reference number is required before customs clearance.
- Does the EU Deforestation Regulation require plot coordinates?
Yes. The coordinates of the plots of land where the commodity was produced, with the production period, are part of the due diligence statement. Small holdings need coordinates too; simplified due diligence relieves the EU operator, not the traceability.
- How does the EU CSDDD affect Indian subcontractors?
The statutory duty sits with the large EU company and travels down the contract chain. In practice the Indian supplier faces a code of conduct, an audit right including unannounced audits, human rights and environmental questionnaires, remediation deadlines and an obligation to pass the same terms to its own suppliers.
- Why do EU customers demand on-site audits of Indian suppliers?
Because the audit right is how the EU customer discharges its own due diligence duty. It is a legal requirement passed down by contract, not a commercial expression of distrust, and refusing it puts the customer in breach rather than merely inconvenienced.
- What does the EU Batteries Regulation require of Indian battery manufacturers?
A carbon footprint declaration per functional unit, documented recycled content of cobalt, lead, lithium and nickel, a third-party verified raw materials due diligence policy, a producer responsibility representative in each Member State, and from February 2027 a digital battery passport.
- How do Indian companies meet EU ecodesign requirements?
Identify the product group and the delegated act that governs it, design against durability, reparability, spare parts availability and recycled content, prepare the digital product passport data set, and register the model in EPREL where energy labelling applies.
- What EU requirements apply to Indian medical device manufacturers?
Classify the device, engage a notified body for everything above class I non-sterile, appoint an EU authorised representative under Article 11, operate a quality management system and post-market surveillance, compile the clinical evaluation, and register in EUDAMED with a unique device identifier.
- Does a CDSCO licence allow a device to be sold in the EU?
No. The Indian classes A to D do not map one to one onto the EU classes, and the EU route requires notified body involvement, an authorised representative, EUDAMED registration and clinical evidence that stands without leaning on equivalence.
- How does the EU Data Act apply to Indian IoT manufacturers?
The user of a connected product has a right to access the data it generates and to have it shared with a third party. That makes access a design obligation: readily available data must be accessible free of charge in a structured, commonly used format, and the contract must state what is available.
- What EU requirements apply to Indian e-commerce platforms under the DSA and DMA?
Appoint an EU legal representative, publish points of contact, run a notice and action mechanism with a statement of reasons for every restriction, and verify trader identity before listing. The DMA only applies to designated gatekeepers, which no Indian marketplace currently is.
- Why do EU marketplaces ask Indian sellers to verify their business details?
Because the Digital Services Act requires the platform to obtain and keep the trader's identity, address, payment account and a compliance self-certification, and to stop displaying products from traders that have not been verified.
- How does REACH apply to Indian chemical exporters?
A non-EU manufacturer cannot register itself. Substances above one tonne a year are registered either by the EU importer or by an only representative established in the Union appointed by the Indian manufacturer, which is the route that keeps the registration under your own control.
- What EU requirements apply to Indian textile and apparel exporters?
Fibre composition labelling in the language of the Member State of sale, REACH screening of dyes and finishing chemicals before production, an EU responsible person with traceability elements on the article under GPSR, and preparation for the ecodesign delegated act with the digital product passport.
- What EU requirements apply to Indian food exporters?
Traceability one step back and one step forward, HACCP-based controls, maximum residue levels and contaminant limits that are in several cases stricter than the Indian ones, entry through a designated border control post with the correct certificate, and labelling in the language of the Member State of sale.
- Is FSSAI compliance enough to export food to the EU?
No. FSSAI licensing says nothing about EU maximum residue levels or aflatoxin limits, which is where spice, rice, groundnut and sesame consignments are most often stopped. Rejections are published in the Union alert system, which is where the commercial damage occurs.
- What does the EU require of Indian pharmaceutical manufacturers?
A marketing authorisation held by an applicant established in the Union, a site inspected against EU GMP, batch release by a qualified person in the EU, pharmacovigilance with a qualified person resident in the Union, and the falsified medicines safety features on the pack.
Continue
Nästa steg
Vill ni använda registret i eget arbete finns tre vägar in.
Börja med din uppgift
Advokat, tvist
Hitta stöd i avgörande
Sök i vägledande domar, se vad som vunnit laga kraft och följ ändringar i rättsläget.
Bolagsjurist, transaktion
Kartlägg regelverket i affären
Gå från tema till rättsakt och vidare till artikeln som bär kravet.
Compliance
Bedöm risken i en behandling
Riskklassning per rättsområde, med källorna bakom varje poäng.