GCCs face twin privacy compliance under DPDP Act and EU law

Indian Opinion DeskIndian Opinion DeskGovernance36 minutes ago4 Views

AI-generated illustration

India's 2,117 Global Capability Centres employing over two million professionals must comply with both the Digital Personal Data Protection Act, 2023, and the laws of the countries where the data originates, according…

India's 2,117 Global Capability Centres employing over two million professionals must comply with both the Digital Personal Data Protection Act, 2023, and the laws of the countries where the data originates, according to a legal analysis. Most GCCs process personal data on behalf of overseas parents or clients and have no direct relationship with the individuals concerned, creating overlapping obligations.

Illustration: GCCs face twin privacy compliance under DPDP Act and EU law

The DPDP Act applies to any digital personal data processed within India, regardless of whether the data subject is Indian. Data entering India from the EU, UK, or US is also governed by the originating jurisdiction's transfer rules, such as the GDPR's requirement for Standard Contractual Clauses. While India's blocklist model under Section 16 of the DPDP Act permits outbound transfers to most countries, the European Union does not recognise India as providing adequate protection.

The substantive provisions of the DPDP Act imposing obligations on data fiduciaries and processors become effective from May 13, 2027. GCCs that have mapped only their Indian obligations but not refreshed EU-side transfer mechanisms have solved only half the compliance problem.

Indian Opinion Analysis

The compliance burden on GCCs reflects a structural mismatch between India's blocklist approach and the EU's whitelist model for cross-border data transfers. A GCC processing German HR records in Bengaluru is simultaneously a data processor under the GDPR and a data fiduciary under the DPDP Act, with no single regulator overseeing both regimes. The practical consequence is legal uncertainty: the Ministry of Electronics and IT has not yet notified the restricted countries under Section 16, and the Data Protection Board has not adjudicated a single cross-border case. Until the DPDP Rules are tested in enforcement, GCCs must maintain separate lawful bases, breach notification protocols, and grievance mechanisms under each applicable law. The May 2027 deadline for substantive compliance gives little relief when EU transfer mechanisms need updating immediately.


Source: barandbench.com

This brief was synthesised by AI from the source linked above.

Ask their opinion on this story
They have read this article, our coverage, and the web.
AI simulations of historical figures. Responses are generated from the historical record, not authentic statements.

0 Votes: 0 Upvotes, 0 Downvotes (0 Points)

Share your opinion

Loading Next Post...
Search Trending
Ask their opinion
Loading

Signing-in 3 seconds...

Signing-up 3 seconds...

All fields are required.