Rättskällor med officiella primärkällor

Utskrivet ·

Hoppa till innehåll
Hoppa till svaret

Do Indian IT services firms need GDPR compliance without an EU office?

Yes. The GDPR applies by reference to whose data is processed and where the individuals are, not to where the processor sits. An Indian IT services firm, BPO or global capability centre processing EU personal data is a processor with direct obligations under Article 28 and Article 32, and the data reaching India is a Chapter V transfer that needs its own legal basis.

What has to be done

  • Establish your role per processing activity: processor for customer data, controller for your own account and telemetry data, and paper each one correctly.
  • Sign a data processing agreement that meets Article 28, including the sub-processor list, the audit right and the assistance duties.
  • Handle the transfer separately from the contract: Standard Contractual Clauses plus a transfer impact assessment for the India leg.

Citations

Full requirement

Source and version

Read date
2026-08-26
Address
/in/questions/it-services-gdpr-no-eu-office

Continue

Nästa steg

Vill ni använda registret i eget arbete finns tre vägar in.

Börja med din uppgift