GDPR
What is GDPR?
GDPR stands for the General Data Protection Regulation, a European Union law controlling how personal data gets collected, stored, and moved. It applies to anyone processing the personal data of people in the EU, regardless of where the company processing that data is headquartered. A US company with a single EU client, or an EU employee working remotely, can fall under GDPR without ever opening an office there.
For companies building international teams, GDPR shows up in a place people don't always expect: employee records. Salaries, bank details, performance reviews, medical leave notes, all of it counts as personal data under GDPR, and moving it between countries triggers specific legal obligations.
Why GDPR matters when you're hiring in India
Say your company is based in Germany and you're building an engineering team in India through an Employer of Record. Your employees' data still needs to move somewhere: into payroll systems, benefits platforms, sometimes back to your own HR tools at headquarters. Every one of those transfers is a GDPR event.
The regulation requires that data moving outside the EU either goes to a country with recognized adequate protection, or travels under a specific legal safeguard like Standard Contractual Clauses. Skip that step and you're exposed to fines that scale with global revenue, not just local revenue.
kaam.work builds GDPR compliance into how employee data moves between your systems and ours from the start, so this isn't something you have to solve on your own mid-project.
What GDPR actually requires day to day
Three things come up constantly once a company starts operating under GDPR. First, you need a documented legal basis for every piece of personal data you're collecting, not just a vague "we need it for HR." Second, individuals retain rights over their own data even after they've handed it over, including the right to see what you're holding and, in some cases, ask you to delete it. Third, a data breach involving personal data has to be reported to regulators within 72 hours of discovery, which is a tighter window than most companies expect until they've lived through it.
Frequently asked questions
- Does GDPR apply to my Indian employees if my company is US-based?
- GDPR applies based on whose data you're processing, not where your company sits. If none of your employees or customers are in the EU, GDPR likely doesn't apply. If any are, it can.
- What happens if we transfer employee data without GDPR safeguards in place?
- Fines under GDPR can reach into the tens of millions of euros or a percentage of global annual revenue, whichever is higher. Regulators have shown they'll enforce this against companies of all sizes.
- Is Standard Contractual Clauses the only way to transfer data legally under GDPR?
- No. SCCs are the most common mechanism, but adequacy decisions and certain certification schemes can also satisfy GDPR's transfer requirements depending on the destination country.
- Do I need a GDPR compliance officer to hire internationally?
- Not necessarily, though larger-scale processing often triggers a legal requirement for a Data Protection Officer. Smaller teams typically handle GDPR through their EOR partner and legal counsel instead.