
India's 2,117 Global Capability Centres employing over two million professionals must comply with both the Digital Personal Data Protection Act, 2023, and the laws of the countries where the data originates, according…
India's 2,117 Global Capability Centres employing over two million professionals must comply with both the Digital Personal Data Protection Act, 2023, and the laws of the countries where the data originates, according to a legal analysis. Most GCCs process personal data on behalf of overseas parents or clients and have no direct relationship with the individuals concerned, creating overlapping obligations.

The DPDP Act applies to any digital personal data processed within India, regardless of whether the data subject is Indian. Data entering India from the EU, UK, or US is also governed by the originating jurisdiction's transfer rules, such as the GDPR's requirement for Standard Contractual Clauses. While India's blocklist model under Section 16 of the DPDP Act permits outbound transfers to most countries, the European Union does not recognise India as providing adequate protection.
The substantive provisions of the DPDP Act imposing obligations on data fiduciaries and processors become effective from May 13, 2027. GCCs that have mapped only their Indian obligations but not refreshed EU-side transfer mechanisms have solved only half the compliance problem.
The compliance burden on GCCs reflects a structural mismatch between India's blocklist approach and the EU's whitelist model for cross-border data transfers. A GCC processing German HR records in Bengaluru is simultaneously a data processor under the GDPR and a data fiduciary under the DPDP Act, with no single regulator overseeing both regimes. The practical consequence is legal uncertainty: the Ministry of Electronics and IT has not yet notified the restricted countries under Section 16, and the Data Protection Board has not adjudicated a single cross-border case. Until the DPDP Rules are tested in enforcement, GCCs must maintain separate lawful bases, breach notification protocols, and grievance mechanisms under each applicable law. The May 2027 deadline for substantive compliance gives little relief when EU transfer mechanisms need updating immediately.
Source: barandbench.com
This brief was synthesised by AI from the source linked above.