Insights

India and the GDPR: Adequacy, Compliance and Cost

India has no adequacy decision from the European Commission, so transfers to Indian entities need safeguards — standard contractual clauses, pseudonymisation, DPOs. For the IT sector, that made GDPR compliance a commercial requirement rather than a legal one.

Published 21 June 2019 · Updated 14 August 2026 · Reviewed by Selvam & Selvam

The GDPR’s most consequential feature for India is a decision the European Commission has never made: India is not on the adequacy list. Every data transfer to an Indian entity therefore needs a safeguard attached to it, which is why GDPR compliance became a commercial necessity for the IT sector long before Indian law required anything similar.

The transfer restriction

Under the GDPR, personal data cannot be exported outside the European Economic Area unless the destination jurisdiction has been certified by the European Commission as having adequate protection, or specific export mechanisms are in place.

Only a handful of countries have adequacy decisions, and India is not among them.

The impact is hard to quantify but almost certainly adverse. The EU is the world’s largest single market and the second largest market for the Indian IT sector after the US. Restrictions on data transfer affect that industry’s performance, or at minimum make Indian providers less attractive to international customers than providers in adequate jurisdictions.

What that means in practice

Absent adequacy, European companies must ensure transfers to Indian entities carry appropriate safeguards. The Commission has approved standard contractual clauses for commercial contracts, and industry bodies have drawn up codes of conduct for categories of controllers and processors.

Given the penalties for non-compliance, European counterparties are likely to insist on stringent GDPR-compliant standards from Indian partners. For Indian companies that means:

Clear, explicit, purpose-specific consent. Terms of use must comply, or the heavy penalties follow.

Structural safeguards. Data minimisation, transparency, and breach reporting mechanisms.

Pseudonymisation. Processing personal data so it can no longer be attributed to a specific data subject without additional information. Pseudonymised data attracts more relaxed standards under the GDPR — for instance, it does not require a fresh instance of consent to be used for a purpose different from the one for which it was collected. Indian organisations benefit from having proper pseudonymisation systems in place to stay competitive in the global ecosystem.

Data Protection Officers. Many Indian entities appointed DPOs early. Beyond the mandate, it signals a commitment to compliance.

All of which raises compliance costs, potentially substantially for smaller organisations and startups.

The counterintuitive finding

Despite those costs, a 2019 Cisco report ranked India sixth globally for GDPR compliance — out of eighteen countries surveyed, but a notable position given India is outside the EU. Unsurprising, perhaps, given how important the EU market is to India’s IT and manufacturing sectors.

More interesting were the benefits organisations reported from compliance: faster sales turnaround, fewer data breaches and less system downtime, and significantly lower costs when breaches did occur.

More data would be needed to establish causation, but the pattern suggests strong privacy protocols had become a customer consideration — meaning companies with robust protections held a competitive advantage rather than merely a compliance burden. That reframing is the useful part: privacy investment reads as a cost until customers start selecting for it.

Home-grown legislation

Perhaps the GDPR’s most significant Indian impact was not corporate but civic. Following the GDPR’s announcement in 2016 and the Supreme Court’s 2017 decision holding privacy a fundamental right, a draft Personal Data Protection Bill was formulated in 2018, showing strong GDPR influence in both the rights conferred and the obligations imposed — with distinctive additions including criminal penalties and a fiduciary relationship between data principals and those processing their data.

What followed: the Bill was withdrawn in 2022, and the Digital Personal Data Protection Act, 2023 was enacted in its place — retaining the fiduciary terminology while dropping the criminal penalties, the sensitive data category and the localisation mandate.

The prediction made here has largely held: the structural changes brought by GDPR compliance are increasingly a natural cost of doing business rather than an EU-specific overhead, because Indian law now requires much of the same. India still has no adequacy decision, so the transfer analysis above continues to apply.

The takeaways

  • India has no adequacy decision — transfers need standard contractual clauses or equivalent safeguards.
  • European counterparties will impose GDPR standards by contract regardless of Indian law.
  • Pseudonymisation attracts relaxed treatment and is worth building in.
  • Compliance correlated with commercial benefits — faster sales, fewer breaches.

Frequently asked questions

Does India have an EU adequacy decision? No — India is not on the European Commission’s adequacy list, so transfers require standard contractual clauses or other approved safeguards.

What do European clients expect from Indian vendors? GDPR-compliant consent mechanisms, data minimisation and breach reporting, pseudonymisation where appropriate, and often a designated Data Protection Officer.

What is pseudonymisation? Processing personal data so it can no longer be attributed to a specific individual without additional information — attracting more relaxed treatment under the GDPR.

Does Indian law now impose similar obligations? Broadly yes — the Digital Personal Data Protection Act, 2023 draws on the GDPR, though it differs on sensitive data, localisation and penalties.

Useful official resources

Related reading