If you run an Indian IT-services firm, BPO, GCC or clinical research organisation, you are not buying GDPR software to comply with a regulator. You are buying it to pass European client due diligence. The questionnaire arrives, the SCCs arrive with it, and somebody has forty-eight hours to produce a processor record, a sub-processor list, a transfer impact assessment and evidence that your security measures are what the annex says they are. That is the actual requirement, and it is a different requirement from the one a European controller has.
The short answer: choose a platform that produces a genuine Art. 30(2) processor record structured per client, holds your DPA and SCC repository with module and annex versions, runs a sub-processor authorisation and notification workflow, and exports audit evidence with timestamps. Legiscope (EU-based, built by data protection lawyers, strong on records and documentation automation) covers this without an enterprise implementation. OneTrust and TrustArc sit at the top of the market. Securiti and BigID solve discovery rather than documentation. Sprinto, Vanta and Drata handle the security-certification half of the same questionnaire and will not produce a processor record.
The Processor Record Is the Whole Problem
Most GDPR tooling is built for controllers. It models the organisation’s own processing activities: one company, one register, purposes and bases owned internally. That structure is wrong for a services firm.
Art. 30(2) requires a processor to maintain a record containing, for each controller on whose behalf it acts: the name and contact details of that controller, of the controller’s representative and DPO, and of the processor’s own; the categories of processing carried out on behalf of each controller; transfers to a third country or international organisation, identified, with documentation of the safeguards where the transfer relies on the second subparagraph of Art. 49(1); and a general description of the technical and organisational security measures under Art. 32(1).
Read that again: per controller. A firm with 120 European clients does not have one record — it has 120 record segments, each of which a different client may demand in isolation, and none of which should disclose another client’s engagement. Very few platforms model this natively. Most force you to create one “processing activity” per client and hope, which breaks as soon as two clients share an application or a delivery centre. Our Art. 30 field guide sets out the required fields and the ROPA guide covers maintenance; ROPA software for Art. 30 compares the tools specifically on this capability.
Ask any vendor to demonstrate exporting a client-scoped Art. 30(2) extract with the rest of the register redacted. It is the single best qualifying question in the category, and it eliminates most of the field.
What Else the Tool Has to Carry
The DPA and SCC repository. Which client is on Module 2 and which on Module 3, which annexes are current, which negotiated deviations exist, which breach SLA applies, which audit rights were granted and when they were last exercised. Most firms discover during their first serious audit that the executed versions live in three different mailboxes. The underlying obligations are set out in our Art. 28 page and the data processing agreement guide.
Sub-processor management. Art. 28(2) requires prior specific or general written authorisation before engaging a sub-processor, with notice of intended changes and an opportunity to object; Art. 28(4) requires the same obligations to be flowed down by contract and leaves you fully liable for the sub-processor’s performance. Operationally that means a live sub-processor register with locations, a per-client notice workflow with each client’s agreed notice period, executed flow-down agreements, and an SCC module for every onward transfer to a third country. Adding an offshore support vendor without triggering that workflow is the most common cause of a client escalation.
Transfer register with the assessment attached. India holds no EU adequacy decision, so every EEA-to-India flow needs an Art. 46 safeguard and a documented clause 14 assessment. The register has to state, per flow, the mechanism, the module, the assessment version and the supplementary measures applied. See India-EU data transfers for the substance and the transfer impact assessment guide for the method.
A breach workflow with three clocks. Art. 33(2) requires notification to the controller without undue delay — and your contract almost certainly says 24 or 48 hours, because your client has 72 from its own awareness. The CERT-In directions of 28 April 2022 require reporting specified cyber incidents to CERT-In within six hours. And once the DPDP Act’s substantive rules commence, s. 8(6) and Rule 7 add intimation to the Data Protection Board and to affected Data Principals. Three recipients, three deadlines, one incident. Our breach playbook covers running them together.
The audit evidence pack. ISO 27001 with the Statement of Applicability, ISO 27701 if you have it — increasingly what European clients actually ask for — SOC 2 Type II, penetration test reports, access reviews, training completion records, background-check policy, and the Art. 32 measures written as measures rather than adjectives. The tool should hold these as versioned, dated artefacts linked to the processing activities they cover, so that “show me your evidence” is an export rather than a project.
Art. 27 tracking, if you also sell your own product. Art. 27 applies to processors as well as controllers where Art. 3(2) is triggered, so an Indian firm with its own EU-facing SaaS alongside its services business needs a representative and needs it named in the privacy notice. See Art. 27 and the practical guide to choosing an EU representative.
Criteria Table
| Criterion | Why it matters for an Indian services firm | Minimum bar |
|---|---|---|
| Art. 30(2) processor record | The document clients demand | Per-controller structure, client-scoped export |
| DPA and SCC repository | Module and annex tracking across clients | Versioned, searchable, deviation notes |
| Sub-processor workflow | Art. 28(2) notice and objection rights | Register, per-client notice periods, flow-down tracking |
| Transfer register | No adequacy for India | Mechanism, module and TIA per flow |
| Multi-clock breach workflow | Client SLA, CERT-In, DPDP | Configurable timers and recipients |
| Evidence management | Client audits under Art. 28(3)(h) | Versioned artefacts linked to activities |
| DPIA support | Art. 28(3)(f) assistance duty | Editable templates, exportable to clients |
| EU hosting option | Asked in every EU questionnaire | EU data centres, documented |
The Market
Legiscope — EU-hosted GDPR automation built by data protection lawyers. Strong on generating and maintaining records and legal-grade documentation without a consulting engagement, which is the right shape for a services firm that needs client-facing artefacts rather than an internal governance programme. Weaker fit if your requirement is scanning a petabyte estate for personal data.
OneTrust — broadest module catalogue on the market and the tool your largest clients probably use. Implementations run months and typically need certified consultants; annual cost commonly USD 30,000-100,000+. Rational above roughly 1,000 employees with a dedicated privacy team. See our Legiscope vs OneTrust comparison.
TrustArc — strong assessment and accountability frameworks, useful if you want control mapping across the GDPR, the DPDP Act and ISO 27701 in one place. US hosting is a friction point in European procurement. TrustArc alternatives covers the comparison set.
Securiti and BigID — discovery and classification first. Genuinely valuable if your problem is that client data has spread across environments and you cannot say where it is. Expensive if your problem is documentation.
Sprinto, Vanta and Drata — security compliance automation for SOC 2, ISO 27001 and increasingly ISO 27701. Sprinto is India-founded and priced for the Indian mid-market. These earn their place in the evidence pack and are not privacy platforms: they will not produce an Art. 30(2) record or a defensible DPIA. Buy both, not one.
Consent platforms — Didomi, Osano and the CMP category. Relevant only if you run EU-facing web properties of your own, and never a substitute for the record and the transfer file.
What It Costs
| Segment | Typical annual software budget | Typical stack |
|---|---|---|
| Small services firm (<50) | INR 2.5 - 8 lakh (EUR 2,500 - 8,500) | Privacy platform, security tool |
| Mid-size (50-500) | INR 8 - 30 lakh (EUR 8,500 - 32,000) | Platform, security tool, DSAR automation |
| Large (500-5,000) | INR 30 lakh - 1 crore (EUR 32,000 - 105,000) | Enterprise suite, discovery, integrations |
| Enterprise or GCC (5,000+) | INR 1 crore+ (EUR 105,000+) | Full suite, discovery, BCR programme |
Onboarding fees of USD 2,000-15,000 are standard on enterprise suites, and per-module or per-seat pricing escalates quickly once legal and delivery teams both need access. Our EU software pricing benchmark gives comparable figures for the platforms named above.
The honest comparison is not against doing nothing; it is against the deal you lose. A stalled enterprise contract while procurement waits for a transfer file costs more than any of the numbers above, and a client-side fine that lands on your indemnity costs considerably more than that. The manual ROPA cost analysis quantifies the internal effort you displace.
Which Should You Choose?
- Services firm, 50-500 staff, 10-60 European clients: an EU-hosted privacy platform for the record, DPA repository and transfer register, plus a security-compliance tool for ISO 27001 and SOC 2. That combination answers roughly 90% of a European client questionnaire.
- Clinical research or health data: prioritise DPIA support and evidence management above everything else. Your clients’ processing is Art. 9 special-category data, their DPIA is effectively mandatory under Art. 35(3)(b), and Art. 28(3)(f) obliges you to assist with it. Expect on-site vendor qualification audits.
- GCC or captive inside a European group: you may be better served by joining the parent’s instance and negotiating a country layer for CERT-In and DPDP, and by evaluating Binding Corporate Rules for intra-group transfers instead of maintaining hundreds of SCC sets.
- Product SaaS selling to EU customers: you are a controller for your own users and a processor for your customers’ data. You need both records, plus an Art. 27 representative. Start from GDPR for Indian companies to establish which hat applies where.
- Under 50 people, first EU client: do not buy an enterprise suite. Build the Art. 30(2) record and the DPA repository in a light platform and add capability as client count grows. The startup guide covers the minimum viable programme.
FAQ
Does DPDP Act tooling cover the GDPR?
No. The DPDP Act has no Art. 30(2) processor record, no special-category regime, no portability or objection rights and no SCC instrument, and its substantive rules commence in May 2027. A DPDP-native tool will not produce what a European client asks for. The differences are set out in DPDP Act 2023 vs GDPR.
Our clients accept our ISO 27001 certificate. Do we still need this?
Certification evidences security measures under Art. 32. It is not an Art. 30(2) record, not an Art. 46 transfer safeguard, and not a DPIA. Clients accept it as one component of a file and then ask for the rest — usually at the point where the contract is otherwise ready to sign.
Should the platform be hosted in the EU?
It is not a legal requirement, but your compliance tool holds a register of your clients’ processing, which is itself personal data in places. A US-hosted privacy platform means answering a Chapter V question about your own compliance tooling, which is an unhelpful conversation to have mid-audit.
How do we handle 100 clients without 100 spreadsheets?
Model the record as a matrix: processing activities and systems on one axis, controllers on the other, so that a shared platform serving forty clients is described once and mapped forty times. Then generate per-client extracts. A tool that cannot do this will not scale past your first twenty European accounts.
How long does this take to stand up?
Six to ten weeks for a firm with a defined client list and cooperative delivery leads: inventory, record structure, DPA repository, transfer register, sub-processor workflow, evidence pack. The constraint is almost never the software — it is getting delivery managers to describe accurately what data they touch.
Conclusion
For an Indian company, GDPR software earns its cost by turning a due-diligence request into an export. The capabilities that matter are narrow and specific: an Art. 30(2) record structured per controller, a DPA and SCC repository that knows which module governs which client, a sub-processor workflow that respects each client’s notice rights, a transfer register that reflects the fact that India has no adequacy decision, and versioned evidence linked to the activities it supports. Start with the processor record. If a vendor cannot demonstrate a client-scoped Art. 30(2) export on your own data, nothing else in the demo matters.
See Legiscope in action
AI-powered GDPR compliance that saves 340+ hours/year. Trusted by compliance professionals across Europe.
Request a demo



