GCCs at the crossroads: Navigating DPDP and overlapping cross-border privacy regimes

Indian GCCs must treat cross-border data flows as two legal “legs” — complying with the DPDP Act for processing in India while separately meeting originating-jurisdiction laws like the GDPR.
Pratyush Kumar Singh, Deepika Yadav
Pratyush Kumar Singh, Deepika Yadav
Published on
5 min read
Listen to this article

Global Capability Centres (“GCCs”) have evolved from back-office support operations into strategic hubs for artificial intelligence (AI), product engineering, research and development (R&D), cybersecurity, and data analytics. India is now the world’s largest GCC destination, with around 2,117 centres employing more than two million professionals, concentrated in Bengaluru, Hyderabad, Pune, Chennai, Gurugram, and Mumbai.

That scale is what makes the Digital Personal Data Protection Act, 2023 (“DPDP Act”) read with the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”) a live issue for this sector. Most privacy discussions assume a business that collects data directly from its own customers. A GCC rarely does. It processes personal data on behalf of an overseas parent, affiliate, or client, often with no direct relationship to the individuals concerned, and that data usually comes from several jurisdictions at once. Having said that, a GCC in India must satisfy two distinct compliance obligations simultaneously: firstly, the DPDP Act, which governs what happens to the personal data processed within the territory of India and personal data processed outside India, if it is in connection with the offering of goods or services to individuals within India, and, secondly, the law of wherever the data came from, i.e. most often the General Data Protection Regulation (“GDPR”), given how much of this data originates in the EU and UK.

Certain provisions of the DPDP Act came into force on November 13, 2025, while the substantive provisions imposing obligations on Data Fiduciaries and Data Processors will become effective from May 13, 2027.

Two legs, two laws

Many GCCs assume this is not really their problem, that EU data is a GDPR question, or that the parent company’s privacy team already has it covered.

Section 3 of the DPDP Act says otherwise. It applies to the processing of digital personal data within India, and draws no line between Indian and foreign individuals. Accordingly, if a GCC processes the HR records of a German workforce or the transaction data of American cardholders in India, such processing will be governed by the DPDP Act the moment it takes place in India. The Act also contains an extraterritorial limb which applies to processing of digital personal data outside India where such processing is in connection with any activity related to the offering of goods or services to Data Principals within India, a dimension relevant to GCCs with hybrid functions that engage directly with Indian consumers.

Once the DPDP Act applies, whichever party is acting as Data Fiduciary or Data Processor must meet its requirements, including a lawful basis for processing, purpose limitation, reasonable security safeguards under Section 8(5) and Rule 6 of the DPDP Rules compliances with respect to the breach notification framework and grievance redressal obligations.

In short, this splits the compliance question into two legs, moving personal data out of Germany or the US and into India is governed by the exporting jurisdiction’s law and what happens to it once it is in India is a separate matter governed by the DPDP Act.

Why India’s blocklist doesn’t solve the EU problem

Section 16 of the DPDP Act, read with Rule 15 of the DPDP Rules, works on a blocklist model, i.e., any personal data can leave India for any country except those the Central government later names as restricted. No such list exists yet, so outbound transfer is effectively unrestricted for now, aside from a separate condition or restriction on sharing of personal data with foreign states or their agencies as may be prescribed by the Central government. That is the mirror image of the GDPR, which permits transfers of personal data outside the European Union only where the destination country has been recognised by the European Union as providing an adequate level of protection or where appropriate safeguards, such as Standard Contractual Clauses or Binding Corporate Rules, have been implemented as per Articles 46 and 47 of GDPR.

That mismatch matters in practice. Every transfer of EU personal data into an Indian GCC still needs its own GDPR transfer mechanism, entirely independent of whatever the DPDP Act requires for the onward Indian leg. A GCC that has mapped its DPDP obligations but never refreshed its EU-side Standard Contractual Clauses has only solved half the problem. The same check applies to whatever other law governs the data's origin, such as UK GDPR, US state privacy statutes, Singapore's PDPA, or any other regime the source jurisdiction falls under, so each one needs to be verified on its own terms, rather than assumed to be covered just because the GDPR or DPDP box has been ticked.

Further, Rule 13(4) of DPDP Rules imposes a data localisation requirement on Significant Data Fiduciary (“SDF”), restricting the transfer of such personal and traffic data outside India as specified by the Central government. GCCs should therefore assess potential localisation requirements where their offshore parents may be classified as SDFs.

One incident, two clocks - sometimes three

A breach affecting a GCC’s system can trigger the Data Protection Board of India (DPBI) 72-hour notification duty under the Rule 7 of DPDP Rules, and separately CERT-In’s 6-hour reporting window issued under Section 70B(6) of the Information Technology Act, 2000, both running from the moment the organisation becomes aware. If the affected data originated in the EU, the same incident may also trigger the GDPR’s own 72-hour notice to the relevant EU supervisory authority under Article 33 of GDPR, a different 72 hours, against a different threshold, to a different regulator, in a different format. A GCC’s incident response plan needs to run on the shortest of these clocks, with a clear decision-tree for which regulators to notify and in what order, rather than waiting on instructions from a head office five time zones away.

The contract is doing all the work

Unlike the GDPR, the DPDP Act places almost no direct statutory duties on a data processor. Under Section 2(k), a processor processes on behalf of a Data Fiduciary, and the DPDP Act’s real obligations, such as notice, purpose limitation, security safeguards, breach reporting sit with the Data Fiduciary. In most GCC structures, the offshore parent is the Data Fiduciary, while the Indian GCC acts as the Data Processor. Since the Data Fiduciary may not have a presence in India, the intra-group services agreement plays a key role in allocating and implementing the DPDP obligations between the parties.

Many GCCs rely on Data Processing Agreements (“DPAs”) that have been drafted primarily to comply with the GDPR. While these agreements generally address controller instructions and cross-border data transfer requirements, they may not adequately deal with certain obligations under the DPDP Act, such as compliance with the prescribed security safeguards, breach reporting requirements, or the handling of grievances where the Data Fiduciary has no presence in India. Accordingly, GCCs should review their existing DPAs to ensure that they also address the specific requirements of the DPDP Act and the DPDP Rules.

Going forward

Two things are worth watching. GCCs should closely monitor the notification of SDFs under the DPDP Act. Where an offshore parent is classified as an SDF, it will be required to comply with additional obligations under the Act, including the appointment of a Data Protection Officer, periodic data audits, and other enhanced compliance requirements. Although these obligations are imposed on the Data Fiduciary, Indian GCCs that undertake the processing activities will likely play a significant role in supporting the implementation and ongoing compliance with such requirements.

And while the Section 16 read with Rule 15 restricted-country list remains unnotified, GCCs whose parents sit in jurisdictions that could plausibly be flagged should not assume that the gap stays open indefinitely.

All of these developments lead to the same foundational discipline: Treat every data flow as at least two legs, determine which law governs each leg and on what clock, and build one integrated incident response and contracting framework around the tighter of the two sets of obligations, rather than running separate compliance programmes that each assume the other has it covered.

About the authors: Pratyush Kumar Singh is a Partner and Deepika Yadav is a Principal Associate at TLH, Advocates & Solicitors.

Disclaimer: The opinions expressed in this article are those of the author(s). The opinions presented do not necessarily reflect the views of Bar & Bench.

If you would like your Deals, Columns, Press Releases to be published on Bar & Bench, please fill in the form available here.

Bar and Bench - Indian Legal news
www.barandbench.com