DPDP Compliance Decoded: Sectoral Nuances and Regulatory Expectations

Part II: Global Capability Centers at A Crossroads: Harmonizing the DPDP Act, 2023 with Global Data Flows
In furtherance to our article titled “DPDP Act: The New Privacy Playbook for BFSI”, in our second article of the series, we seek to examine the impact of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) on Global Capability Centers (“GCCs”) established in India. GCCs represent the intersection of increased global data flows and operations while optimizing innovation. The emergence of these legal structures, which act as an extension to their parent companies, has led to increased investment in India. As foreign parent companies increasingly establish GCCs in India, they face growing regulatory pressure from the Indian Government’s efforts to control digital personal data.
The newly enacted DPDP Act aims to enhance and alter the regulatory framework on protection of data by placing onus on the Data Fiduciary. For GCCs with offshore parent entities, the DPDP Act introduces new compliance challenges in data processing methods, cross-border data transfers, and corporate accountability. This analysis examines the structure of GCCs, their role in the data processing ecosystem, and legal mechanics of the DPDP Act applying to these entities.
Demographics and Statistics of GCCs operating in India
According to Nasscom’s GCC Landscape Report, India hosts an estimated 2,117 GCCs which employ over 2.36 million science, technology, engineering, and mathematics professionals and generate approximately $98.4 billion USD in annual revenue. Trends also indicate this number will multiply and by 2030 this ecosystem will include 2700 or more GCCs. This is evidenced by the fact that GCCs account for a 40% share of country’s commercial office space leasing over the last decade.
Below is the data for GCCs established in India which process various kinds of Inbound and Outbound data: 1

Illustration 1: Diagram Representing number of GCCs establised in India by companies located outside India.
(Source: Nasscom and Zinnov GCC Landscape Report 2026)
- What are GCCs and what is the role played by them?
A GCC is a captive offshore entity which is owned and operated by a parent company aiming to provide and deliver strategic business functions and operations. Unlike third-party business processing outsourcing (‘BPO’) firms, a GCC operates as an extended arm of the parent company which retains absolute control over the GCCs operations, technological capabilities and governance mechanisms Establishing a GCC in India involves navigating a complex set of laws including corporate compliance, foreign direct investment norms, taxation laws, and going forward GCCs will also need to navigate the newly introduced data protection laws.
GCCs in India can be established in three following manners: –
- Build-operate-transfer: A local partner firstly builds and operates the GCC for a certain period, thereafter, the local partner transfers full legal ownership to the parent entity.
- Managed GCC: The GCC is managed under service agreements by a third party without transferring ownership.
- Wholly owned captive GCC: The GCC is a wholly owned subsidiary and operated by the parent entity.
Structurally, these GCCs are integrated with their parent companies. This integration affects their classification under data protection laws from third party data processors. Accordingly, they are classified as Data Processors acting on the instructions of their parent company, the Data Fiduciary.
- Cross-border data transfer regime under the Digital Personal Data Protection Act, 2023 and its applicability to the operations of GCCs.
The DPDP Act has a foreseeable impact on every single GCC whose core model relies on uninterrupted cross-border data transfers. As the DPDP Act does not provide any regulations regarding the treatment of inbound data, outbound data transfers are governed by Section 16 of DPDP Act. Section 16 of the DPDP Act creates a framework which is permissive unless expressly restricted. Accordingly, personal data processed in India can be freely transferred to parent entities of GCCs located in other countries. However, the DPDP Act allows the Central Government to restrict the transfer of personal data for processing outside the territory of India by way of notification. As on date of this article, no such notification has been issued by the Central Government.
Further, going forward GCCs may be designated as a Significant Data Fiduciary (“SDF”) in terms of Section 10 of the DPDP Act owing to the nature and the volume of data they would process. Accordingly, pursuant to such designation, GCCs will be required to, inter alia, appoint a Data Protection Officer or conduct periodic audits and comply with the additional obligations provided under Section 10(2) of the DPDP Act or any such rules or regulations as prescribed.
On a comparative note, outbound data transfers are governed in a more restrictive way globally:
The EU GDPR transfer framework: Article 45 of the European Union’s (“EU”) GDPR regulates transfers of personal data from the EU to third countries. It permits such transfers without additional safeguards only where the destination country is recognized by the EU as providing an adequate level of data protection akin to the GDPR. The European Commission recognizes only 16 countries whose laws are considered somewhat adequate to the GDPR. As India does not appear in the list of the 16 approved countries any transfer from EU to India is subject to Article 46 of the GDPR. Article 46 allows transfer to such unapproved countries subject to strict implementation of appropriate safeguards in terms of Standard Contractual Clauses (“SCCs”) embedded in the Data Processing Agreement (“DPA”) between the parent entity and the data processor. 2
For GCCs operating in India and having an EU parent, this raises concerns and costs on both sides. The EU parent entity would need to ensure at all times that the SCCs are implemented. Moreover, due to the recent Schrems II ruling, parent entities in EU now also require conducting a Transfer Impact Assessment (“TIA”) before incorporating an SCC clause. 3 The TIA requires the EU entity to map and evaluate whether the DPDP Act undermines the protections which are aimed to be afforded by the SCC. As a result of these SCCs, it may be the case that such GCCs would now be subject to additional contractual compliance obligations over and above the DPDA obligations under Section 8.
Singapore Personal Data Protection Act Framework: Section 26 of Singapore’s Personal Data Protection Act, 2012 4 (“PDPA”) imposes a transfer limitation over of personal data outside Singapore. Under the PDPA, transfer of personal data to an entity located outside Singapore is only allowed if the receiving country has laws which provide a standard of protection to personal data comparable to PDPA.
Because India’s domestic legal framework may not offer comparable protection to the PDPA, a Singapore parent entity cannot freely transfer data to an Indian GCC. Instead, it might legally execute the transfer by potentially relying on ‘legally enforceable obligations’ alternative found in standard contracts, to force the Indian GCC to maintain a level of protection equal to the PDPA as required by Regulation 11 of Singapore PDPA Regulations 2021.5 Consequently, Indian GCCs handling Singaporean personal data are subjected to rigorous PDPA-comparable contractual compliance measures over and above their reasonable obligations to protect DPDP Act duties under Section 8.
California Consumer Privacy Act Framework: The California Consumer Privacy Act (“CCPA”) does not impose geographical restrictions or adequacy requirements on the transfer of personal data out of the state or country. However, structural compliance is still mandated through clauses in vendor/service contracts. Under the California Civil Code, a US parent company transferring data to an Indian GCC must execute a written agreement establishing the GCC as a “service provider”.6 This contract shall mandate that the GCC will process personal data solely on behalf of the American business and explicitly prohibit the GCC from selling, sharing, or retaining the personal information for any purpose outside the direct business relationship under the contract.
While a Transfer Impact Assessment like the EU is not required, the GCC is obligated to adhere to these contractual limitations. In case, the GCC does not adhere, the flow of data would be classified as a “sale” of data, triggering consumer opt-out rights and compliance violations under the CCPA.
Nonetheless, GCCs established by foreign parent entities still require compliance with respect to the reasonable protection standards as per Section 8(5) of the DPDP Act in relation to personal data of foreign nationals and compliance with the entire DPDP Act in regard to the personal data collected for people within the territory of India who are employed by the GCC.
- Our Thoughts
To adapt themselves to the changing environment, GCCs set up in India should adopt a sensible approach to compliance and take action instead of waiting for the regulators to step in. As foundational step GCCs need to ensure that cross-border data transfers comply with Indian regulations alongside global standards like the EU, PDPA, and CCPA. GCCs also need to undertake an internal stock of matters regarding their stance on the DPDP Act and formulate procedures and internal hierarchies which would allow them to deal with the requirements of the Act efficiently. Furthermore, because large GCCs process substantial volumes of sensitive data, they are highly likely to be designated as Significant Data Fiduciaries. Consequently, these organizations must take proactive measures to ensure compliance, which includes preparing for statutory audits and appointing a resident Data Protection Officer in India.
Extending the Conversation: Webinar on DPDP Act
In a webinar held on 29 July 2026, Acuity Law, in association with Legal 500, explored the practical impact of the DPDP Act and shared sector-specific insights to help organisations navigate the new framework with confidence.
Contributors & Disclaimer
Authors: Souvik Ganguly and Srividya M S
For any queries or further engagement on the matters discussed in this paper, please reach out to Acuity Law at [email protected].
The information contained in this document is not legal advice or legal opinion. The contents recorded in the said document are for informational purposes only and should not be used for commercial purposes. Acuity Law LLP disclaims all liability to any person for any loss or damage caused by errors or omissions, whether arising from negligence, accident, or any other causes.
- Nasscom and Zinnov, Nasscom-Zinnov GCC Landscape Report 2026: The GCC Value Orbit – From Delivery Engine to Enterprise Nerve Centre (2026) can be accessed at < https://zinnov.com/centers-of-excellence/zinnov-nasscom-india-gcc-landscape-2026-report/> ↩︎
- European Commission, ‘Standard Contractual Clauses (SCC)’ (European Commission, 4 June 2021) https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en accessed 22 September 2026. ↩︎
- Case C-362/14 Maximillian Schrems v Data Protection Commissioner [2015] ECLI:EU:C:2015:650 ↩︎
- Singapore Personal Data Protection Act (2012) ↩︎
- Singapore Personal Data Protection Regulations (2021) ↩︎
- California Civil Code, California Consumer Privacy Act of 2018, Division 3 Part 4 Title 1.81.5 (b) ↩︎



