Quick Answer
Indian companies serving EU customers must comply with two separate laws at once. The DPDP Act (India’s Digital Personal Data Protection Act, 2023) governs data leaving India. The GDPR governs personal data of EU residents regardless of where your company sits. Neither substitutes for the other. India has no GDPR adequacy decision, so EU-to-India transfers require Standard Contractual Clauses.
An Indian SaaS company signs an EU client and assumes DPDP compliance covers it. It does not. The DPDP Act and the GDPR are two distinct legal regimes with two distinct triggers. One governs how personal data leaves India. The other reaches Indian companies the moment they process the personal data of EU residents. A company serving customers in both markets answers to both simultaneously.
This guide maps where the two regimes align, where they diverge, and what an Indian technology or BPO company must build to satisfy both at once. It covers the DPDP Act’s approved-countries mechanism under Phase III, GDPR adequacy and Standard Contractual Clauses, the dual-compliance obligation for companies serving EU customers, a side-by-side comparison table, and the data processing agreement structure that satisfies both laws in a single document.
What Is the DPDP Act's Approach to Cross-Border Transfers: The Approved Countries List
The DPDP Act, 2023 takes a negative-list approach to cross-border transfers. Data fiduciaries may transfer personal data outside India to any country except those the Central Government restricts by notification. The approved-countries framework sits within Phase III of the Act’s phased rollout, expected around May 2027.
The framework is not yet finalized. Until the Central Government notifies the restricted-countries list and the Phase III rules take effect, cross-border transfers proceed under the general obligation in the DPDP Act: reasonable security safeguards. A data fiduciary transferring personal data abroad today must apply reasonable security safeguards to protect that data the same baseline obligation that applies to any processing under the Act.
Two points matter for planning:
- The default is permissive. Unlike the GDPR, the DPDP Act does not require a specific transfer mechanism before data can leave India. Transfer is allowed unless the destination country is restricted.
- Phase III will change the analysis. Once the approved-countries framework takes effect, transfers to restricted countries stop, and companies routing data through those jurisdictions must reroute or restructure. Build your data flows now with that shift in mind.
For the full sequence of DPDP obligations and enforcement dates, see our DPDP compliance timeline guide.
Do GDPR Adequacy and Standard Contractual Clauses Still Apply to India
Yes. The GDPR governs the direction the DPDP Act does not personal data moving from the EU into India. And the GDPR’s transfer rules apply in full, because India does not have a GDPR adequacy decision.
An adequacy decision is a formal determination by the European Commission that a non-EU country provides data protection equivalent to the GDPR. Countries with adequacy Japan, the UK, and others receive EU personal data without additional safeguards. India is not on that list. The DPDP Act, 2023 may support a future adequacy application, but no decision exists today.
The consequence is direct. Any transfer of EU residents’ personal data to an Indian company requires a valid GDPR transfer mechanism. For nearly all Indian companies, that mechanism is Standard Contractual Clauses (SCCs) the European Commission’s pre-approved contract terms that both parties sign to legally bind the data importer to GDPR-level protection.
- SCCs are mandatory for EU-to-India transfers. Without SCCs (or another Article 46 safeguard), an EU company cannot lawfully send personal data to an Indian vendor.
- A transfer impact assessment often accompanies SCCs. Following the Schrems II ruling, EU exporters must assess whether the importing country’s laws undermine the SCCs’ protections, and add supplementary measures if they do.
How Do Indian Companies Serving EU Customers Achieve Dual Compliance
GDPR Article 3 extends the regulation’s reach beyond EU borders. An Indian company with no office, server, or employee in the EU still falls under the GDPR if it does either of two things: offers goods or services to individuals in the EU, or monitors the behavior of individuals in the EU.
This extraterritorial reach is the single most misunderstood point for Indian companies. Physical presence is irrelevant. A Chennai SaaS provider with EU subscribers, a Hyderabad BPO processing EU customer records, or a Bangalore analytics firm tracking EU website visitors all fall under GDPR Article 3 regardless of where their servers or staff sit.
That means a company serving EU customers carries two obligations at once:
- DPDP Act obligations on personal data it processes as an Indian data fiduciary consent, notice, security safeguards, and data principal rights under Indian law.
- GDPR obligations on the personal data of EU residents lawful basis, data subject rights, breach notification within 72 hours, and a valid transfer mechanism for data moving between the EU and India.
The two sets of obligations overlap on principles both require consent, security, and respect for individual rights but diverge on specifics such as breach-notification timelines, penalty ceilings, and the mechanics of cross-border transfer. Meeting one does not meet the other. A dual-compliance program maps each obligation to both laws and satisfies the stricter standard where they differ.
Key Differences Between the DPDP Act and the GDPR
The two regimes share a foundation but differ on the specifics that determine compliance cost and risk. This table sets the material differences side by side.
Factor | DPDP Act, 2023 (India) | GDPR (EU) |
Territorial scope | Processing of digital personal data within India, and processing outside India connected to offering goods or services in India | Processing by EU-established entities, plus non-EU entities offering goods/services to or monitoring EU residents (Article 3) |
Cross-border transfer rule | Permissive by default transfer allowed except to restricted countries (approved-countries list under Phase III, ~May 2027) | Restrictive by default transfer to non-adequate countries requires SCCs or another Article 46 safeguard |
Adequacy of India | N/A | No adequacy decision; SCCs required for EU-to-India transfers |
Legal basis for processing | Consent, plus certain legitimate uses | Six lawful bases including consent, contract, and legitimate interests |
Breach notification | Notify the Data Protection Board and affected individuals (manner and timing set by rules) | Notify supervisory authority within 72 hours of awareness |
Maximum penalty | Up to ₹250 crore per instance | Up to €20 million or 4% of global annual turnover, whichever is higher |
Key roles | Data Fiduciary, Data Processor, Data Principal | Controller, Processor, Data Subject |
Data subject rights | Access, correction, erasure, grievance redressal, nomination | Access, rectification, erasure, portability, restriction, objection |
Read the table as a checklist. Where the two columns diverge, your program must satisfy the stricter requirement; the 72-hour GDPR breach window, for example, is tighter than the DPDP timeline, so a dual-compliant company builds to 72 hours.
How Should a Data Processing Agreement Cover Both DPDP and GDPR
A data processing agreement (DPA) is the contract between a data fiduciary/controller and a data processor that governs how the processor handles personal data. When your vendors sit across borders, an Indian company using a US cloud provider, or an EU client using your Indian BPO service the DPA is the document that carries compliance across the transfer.
Build one DPA that satisfies both laws rather than maintaining two. A single instrument that meets the stricter standard on each point covers both regimes and removes the risk of conflicting terms. The DPA should include:
- Scope and roles. Name each party’s role under both laws data fiduciary/controller and data processor under the DPDP Act, controller and processor under the GDPR.
- Processing instructions. Restrict the processor to processing only on the documented instructions of the controller/fiduciary.
- Security safeguards. Require reasonable security safeguards (DPDP) and appropriate technical and organizational measures (GDPR Article 32).
- Sub-processor terms. Require prior authorization for sub-processors and flow-down of equivalent obligations.
- Cross-border transfer mechanism. Incorporate SCCs where EU personal data moves to India, and account for the Phase III approved-countries framework for data leaving India.
- Breach notification. Bind the processor to notify the controller fast enough to meet the GDPR’s 72-hour supervisory-authority deadline.
- Audit and deletion. Grant audit rights and require return or deletion of personal data at the end of the engagement.
For clause-level drafting of SaaS agreements and DPAs that carry both DPDP and GDPR terms, see our SaaS agreement and DPA drafting guide.
Build One Compliance Program for Both Regimes with Altacit Global
Indian technology and BPO companies serving EU customers cannot treat DPDP and GDPR as one obligation but they can meet both with one unified program. Altacit Global advises Indian companies on dual DPDP/GDPR compliance, DPA drafting, SCC implementation, and cross-border transfer mechanisms. From our offices in Bangalore, Hyderabad, and Chennai, contact Altacit Global at info@altacit.com.
Frequently Asked Questions: Cross-Border Data Transfer India
Q1: Does the GDPR apply to an Indian company with no physical presence in the EU?
Yes. GDPR Article 3 applies to any company that offers goods or services to individuals in the EU or monitors their behavior, regardless of where the company is established. An Indian SaaS provider with EU subscribers, or a BPO processing EU customer data, falls under the GDPR even with no EU office, server, or employee. Physical presence is not the test the target and activity are.
Q1: Is India considered a GDPR-adequate country?
No. India does not have a GDPR adequacy decision from the European Commission. Because of this, EU companies cannot freely transfer EU residents’ personal data to Indian companies. They must use Standard Contractual Clauses (SCCs) or another Article 46 safeguard, and typically a transfer impact assessment, to make the transfer lawful. The DPDP Act, 2023 may support a future adequacy application, but no decision exists today.
Q1: If a company is DPDP compliant, is it automatically GDPR compliant?
No. DPDP compliance and GDPR compliance are separate. The two laws share principles of consent, security, individual rights but differ on specifics such as lawful bases, the 72-hour breach-notification window, penalty ceilings, and transfer mechanisms. A DPDP-compliant Indian company serving EU customers must separately meet GDPR obligations, including a valid EU-to-India transfer mechanism. Meeting one law does not satisfy the other.



