Data transfers from the EU to India
How does an Indian company lawfully receive personal data from the EU under GDPR Chapter V?
Answer
The European Commission has not issued an adequacy decision for India, so personal data cannot be sent from the EU to India on that basis. The route available is the appropriate safeguards in Chapter V, which in practice means the Commission's Standard Contractual Clauses backed by a transfer impact assessment. This applies to Indian IT services firms, BPOs, GCCs and SaaS vendors alike, whether or not they have an EU office.
What has to be done
- Sign the Commission's Standard Contractual Clauses and select the module that matches the real roles: controller to processor for most IT services and BPO work, controller to controller where the Indian entity decides purposes of its own.
- Complete a transfer impact assessment covering Indian government access powers, including the Information Technology Act section 69 interception route and the Telecommunications Act, and record what you concluded.
- Document supplementary measures concretely: encryption in transit and at rest, keys held in the EU, field minimisation, pseudonymisation of production data used in development, and a documented process for handling government access requests.
- Record the transfer in the record of processing activities and name India as the recipient country in the privacy notice.
- Map the Indian side in parallel: the Digital Personal Data Protection Act 2023 imposes its own obligations on the same processing, and satisfying one does not satisfy the other.
Citations
- GDPR Article 44: general principle for transfersArticle nodeOfficial text
- GDPR Article 45: transfers on an adequacy decisionArticle nodeOfficial text
- GDPR Article 46: transfers subject to appropriate safeguardsArticle nodeOfficial text
- GDPR Article 47: binding corporate rulesArticle nodeOfficial text
- GDPR Article 48: transfers not authorised by Union lawArticle nodeOfficial text
- GDPR Article 49: derogations for specific situationsArticle nodeOfficial text
- GDPR Article 28: processor obligationsArticle nodeOfficial text
Related questions
Related requirements
China corridor
The same requirement is published for Chinese exporters in simplified Chinese: 个人信息出境:GDPR 第五章
Source and version
- Sector
- IT services, SaaS, BPO, GCC
- Read date
- 2026-08-26
- Register version
- in-export-v1.0.0
- Address
- /in/export/gdpr-chapter-v
Nästa steg
Vill ni använda registret i eget arbete finns tre vägar in.
Börja med din uppgift
Advokat, tvist
Hitta stöd i avgörande
Sök i vägledande domar, se vad som vunnit laga kraft och följ ändringar i rättsläget.
Bolagsjurist, transaktion
Kartlägg regelverket i affären
Gå från tema till rättsakt och vidare till artikeln som bär kravet.
Compliance
Bedöm risken i en behandling
Riskklassning per rättsområde, med källorna bakom varje poäng.