Global Capability Centres (GCCs) have transitioned from mere back-office support to becoming strategic centers for innovation, including artificial intelligence (AI), product engineering, research and development (R&D), cybersecurity, and data analytics. India hosts the largest number of GCCs globally, with over 2,117 centers employing in excess of two million professionals. These centers are primarily located in cities such as Bengaluru, Hyderabad, Pune, Chennai, Gurugram, and Mumbai.
As such, the Digital Personal Data Protection Act, 2023 (DPDP Act), along with the Digital Personal Data Protection Rules, 2025 (DPDP Rules), holds significant relevance for this sector. Unlike many businesses that gather data directly from their customers, GCCs often process personal data on behalf of an overseas parent, affiliate, or client, generally without direct interaction with the individuals whose data they handle. Such data usually originates from multiple jurisdictions.
For GCCs operating in India, adherence to two distinct legal frameworks is essential: the DPDP Act, which governs personal data processed within India or in connection with goods or services offered to individuals in India, and the originating jurisdiction’s data protection laws, frequently the General Data Protection Regulation (GDPR), given that much of the data comes from the EU and UK.
Certain provisions of the DPDP Act have been in effect since November 13, 2025, but the significant obligations for Data Fiduciaries and Data Processors will commence on May 13, 2027.
Two Frameworks, Two Obligations
Many GCCs mistakenly believe that compliance with GDPR is solely the concern of their parent company’s privacy team. However, Section 3 of the DPDP Act applies to the processing of digital personal data within India, irrespective of whether the data pertains to Indian or foreign individuals. Therefore, if a GCC processes, for example, HR records of a German workforce or American cardholder data in India, such processing falls under the jurisdiction of the DPDP Act.
The Act also includes provisions for extraterritorial application, addressing data processed outside India if it relates to activities involving Indian consumers. Consequently, parties acting as Data Fiduciaries or Data Processors must comply with the DPDP Act’s requirements, including lawful processing bases, purpose limitations, security safeguards under Section 8(5), and the breach notification framework as outlined in Rule 6 of the DPDP Rules.
India’s Blocklist and the EU’s Adequacy Requirements
Section 16 of the DPDP Act, in conjunction with Rule 15 of the DPDP Rules, stipulates a blocklist model for data transfers. This means that personal data can be transferred from India to any country unless it is on a restricted list, which the Central government has yet to publish. Currently, outbound data transfer is largely unrestricted, subject to any specific conditions or restrictions imposed by the government.
Conversely, GDPR permits data transfers outside the EU only if the destination country provides adequate protection or if appropriate safeguards, such as Standard Contractual Clauses, are in place. This discrepancy between the DPDP Act and GDPR requires that each transfer of EU personal data into an Indian GCC is supported by a GDPR-compliant transfer mechanism, independent of DPDP requirements.
Rule 13(4) of the DPDP Rules also introduces data localization requirements for Significant Data Fiduciaries (SDFs), requiring GCCs to assess potential localization mandates where offshore parents may be deemed as SDFs.
Incident Response and Contractual Obligations
In the event of a data breach, the Data Protection Board of India (DPBI) requires notification within 72 hours under Rule 7 of the DPDP Rules. CERT-In mandates a separate 6-hour notification window under Section 70B(6) of the Information Technology Act, 2000. If EU data is implicated, GDPR’s own 72-hour notification requirement to the relevant EU supervisory authority also applies. GCCs must therefore prepare an incident response plan that adheres to the strictest notification timeline.
Unlike GDPR, which imposes direct obligations on data processors, the DPDP Act primarily assigns responsibilities to Data Fiduciaries. In most GCC structures, the offshore parent acts as the Data Fiduciary, while the Indian GCC is the Data Processor. Therefore, it is crucial that intra-group service agreements reflect and allocate DPDP obligations correctly between parties.
Looking Ahead
GCCs should be vigilant about the notification of SDFs under the DPDP Act. If an offshore parent is classified as an SDF, it must comply with additional obligations such as appointing a Data Protection Officer and conducting periodic data audits. Indian GCCs will likely play a critical role in fulfilling these requirements.
Additionally, while the DPDP’s restricted-country list is not yet announced, GCCs should not assume that the current gap will remain open indefinitely. Ultimately, GCCs must adopt a comprehensive approach to data flow, recognizing distinct legal requirements for each jurisdiction and ensuring compliance through integrated incident response and contractual frameworks.
Authors: Pratyush Kumar Singh, Partner, and Deepika Yadav, Principal Associate at TLH, Advocates & Solicitors.
Disclaimer: The opinions expressed in this article are those of the authors and do not necessarily reflect the views of Bar & Bench.
