Indian delivery centres serving UK and EU clients is an old model. What changed is that the data-protection questions are now asked by procurement in week one rather than by legal in month four — and a vague answer is a lost deal.
This is a practical account of what we had to put in place, in the order it mattered.
Establish who you are in the relationship
For most engineering engagements the client is the controller and you are the processor. That sounds like a technicality. It determines who owes what: the controller decides purposes and means, and the processor may only act on documented instructions. Get this wrong in the contract and you inherit obligations you cannot meet.
The transfer mechanism
India is not the subject of a UK or EU adequacy decision. Personal data reaching your Indian entity is a restricted transfer and needs a lawful mechanism:
- For UK controllers: the International Data Transfer Agreement, or the EU SCCs with the UK Addendum.
- For EU controllers: the Standard Contractual Clauses, module two or three depending on the chain.
- Either way: a documented Transfer Risk Assessment. Not optional, and the first thing a serious reviewer asks for.
The supplementary measures matter more than the paperwork. Encryption in transit and at rest, keys held in the client's region, access restricted to named individuals with logged justification, and a published policy for handling government access requests.
Residency as a product feature
The cleanest answer to a transfer question is not to make the transfer. We build so that production data can be pinned to an EU, UK or US region, with Indian engineers working against masked or synthetic datasets for everything except a narrow, logged break-glass path.
This is engineering work, not a policy statement. It has to be designed in — retrofitting residency into a system that assumed one region is close to a rewrite.
India's own regime
The Digital Personal Data Protection Act, 2023 now applies to your Indian operations independently of your client's obligations. Consent notices, purpose limitation, breach notification and data-principal rights all have Indian counterparts. Firms treating DPDP as a formality will find it becomes the binding constraint sooner than they expect.
What actually clears procurement fast
- A signed DPA ready to send, with the SCCs or IDTA already annexed — not 'we can look at yours'.
- A published sub-processor list with a notification commitment for changes.
- Article 30 records of processing that you can show, not describe.
- A named data protection contact who replies within one business day.
- A recent penetration test summary and a straight answer on certification status.
Every one of these is a document. Having them ready is the difference between clearing security review in two weeks and five months.
Working on this?
We run a paid two-week diagnostic that ends with an architecture record, a risk register and a costed plan — yours to keep either way.
Talk to an engineer