How do you transfer personal data between India and the EU under GDPR Chapter V?
India has no adequacy decision, so the transfer runs on the appropriate safeguards in Article 46, which in practice means the Commission's Standard Contractual Clauses plus a transfer impact assessment describing Indian government access powers and the supplementary measures you apply.
What has to be done
- Sign the Commission's Standard Contractual Clauses and select the module that matches the real roles: controller to processor for most IT services and BPO work, controller to controller where the Indian entity decides purposes of its own.
- Complete a transfer impact assessment covering Indian government access powers, including the Information Technology Act section 69 interception route and the Telecommunications Act, and record what you concluded.
- Document supplementary measures concretely: encryption in transit and at rest, keys held in the EU, field minimisation, pseudonymisation of production data used in development, and a documented process for handling government access requests.
Citations
- GDPR Article 44: general principle for transfers
- GDPR Article 45: transfers on an adequacy decision
- GDPR Article 46: transfers subject to appropriate safeguards
- GDPR Article 47: binding corporate rules
- GDPR Article 48: transfers not authorised by Union law
- GDPR Article 49: derogations for specific situations
- GDPR Article 28: processor obligations
Full requirement
Source and version
- Read date
- 2026-08-26
- Address
- /in/questions/transfer-data-india-to-eu
Continue
Nästa steg
Vill ni använda registret i eget arbete finns tre vägar in.
Börja med din uppgift
Advokat, tvist
Hitta stöd i avgörande
Sök i vägledande domar, se vad som vunnit laga kraft och följ ändringar i rättsläget.
Bolagsjurist, transaktion
Kartlägg regelverket i affären
Gå från tema till rättsakt och vidare till artikeln som bär kravet.
Compliance
Bedöm risken i en behandling
Riskklassning per rättsområde, med källorna bakom varje poäng.