Do Indian IT services firms need GDPR compliance without an EU office?
Yes. The GDPR applies by reference to whose data is processed and where the individuals are, not to where the processor sits. An Indian IT services firm, BPO or global capability centre processing EU personal data is a processor with direct obligations under Article 28 and Article 32, and the data reaching India is a Chapter V transfer that needs its own legal basis.
What has to be done
- Establish your role per processing activity: processor for customer data, controller for your own account and telemetry data, and paper each one correctly.
- Sign a data processing agreement that meets Article 28, including the sub-processor list, the audit right and the assistance duties.
- Handle the transfer separately from the contract: Standard Contractual Clauses plus a transfer impact assessment for the India leg.
Citations
Full requirement
Source and version
- Read date
- 2026-08-26
- Address
- /in/questions/it-services-gdpr-no-eu-office
Continue
Nästa steg
Vill ni använda registret i eget arbete finns tre vägar in.
Börja med din uppgift
Advokat, tvist
Hitta stöd i avgörande
Sök i vägledande domar, se vad som vunnit laga kraft och följ ändringar i rättsläget.
Bolagsjurist, transaktion
Kartlägg regelverket i affären
Gå från tema till rättsakt och vidare till artikeln som bär kravet.
Compliance
Bedöm risken i en behandling
Riskklassning per rättsområde, med källorna bakom varje poäng.