What EU requirements apply to Indian SaaS companies selling services in the EU?
Four regimes apply together: the GDPR for the processing, Chapter V for the data that lands in India, the Cyber Resilience Act where software is placed on the market as a product, and the accessibility requirements for consumer-facing services. The AI Act joins them where the product embeds a model.
What has to be done
- Establish your role per processing activity: processor for customer data, controller for your own account and telemetry data, and paper each one correctly.
- Sign a data processing agreement that meets Article 28, including the sub-processor list, the audit right and the assistance duties.
- Handle the transfer separately from the contract: Standard Contractual Clauses plus a transfer impact assessment for the India leg.
Citations
Full requirement
Source and version
- Read date
- 2026-08-26
- Address
- /in/questions/saas-eu-requirements
Continue
Nästa steg
Vill ni använda registret i eget arbete finns tre vägar in.
Börja med din uppgift
Advokat, tvist
Hitta stöd i avgörande
Sök i vägledande domar, se vad som vunnit laga kraft och följ ändringar i rättsläget.
Bolagsjurist, transaktion
Kartlägg regelverket i affären
Gå från tema till rättsakt och vidare till artikeln som bär kravet.
Compliance
Bedöm risken i en behandling
Riskklassning per rättsområde, med källorna bakom varje poäng.