Skip to content
AnithraSolutions
Compliance · 11 min

Shipping software to UK and EU clients from an Indian delivery centre

Data residency, transfer mechanisms, sub-processor disclosure and the contract clauses that decide whether procurement clears you in two weeks or five months.

Published 30 April 2026By the Anithra Solutions engineering team

Indian delivery centres serving UK and EU clients is an old model. What changed is that the data-protection questions are now asked by procurement in week one rather than by legal in month four — and a vague answer is a lost deal.

This is a practical account of what we had to put in place, in the order it mattered.

Establish who you are in the relationship

For most engineering engagements the client is the controller and you are the processor. That sounds like a technicality. It determines who owes what: the controller decides purposes and means, and the processor may only act on documented instructions. Get this wrong in the contract and you inherit obligations you cannot meet.

The transfer mechanism

India is not the subject of a UK or EU adequacy decision. Personal data reaching your Indian entity is a restricted transfer and needs a lawful mechanism:

  • For UK controllers: the International Data Transfer Agreement, or the EU SCCs with the UK Addendum.
  • For EU controllers: the Standard Contractual Clauses, module two or three depending on the chain.
  • Either way: a documented Transfer Risk Assessment. Not optional, and the first thing a serious reviewer asks for.

The supplementary measures matter more than the paperwork. Encryption in transit and at rest, keys held in the client's region, access restricted to named individuals with logged justification, and a published policy for handling government access requests.

Residency as a product feature

The cleanest answer to a transfer question is not to make the transfer. We build so that production data can be pinned to an EU, UK or US region, with Indian engineers working against masked or synthetic datasets for everything except a narrow, logged break-glass path.

This is engineering work, not a policy statement. It has to be designed in — retrofitting residency into a system that assumed one region is close to a rewrite.

India's own regime

The Digital Personal Data Protection Act, 2023 now applies to your Indian operations independently of your client's obligations. Consent notices, purpose limitation, breach notification and data-principal rights all have Indian counterparts. Firms treating DPDP as a formality will find it becomes the binding constraint sooner than they expect.

What actually clears procurement fast

  • A signed DPA ready to send, with the SCCs or IDTA already annexed — not 'we can look at yours'.
  • A published sub-processor list with a notification commitment for changes.
  • Article 30 records of processing that you can show, not describe.
  • A named data protection contact who replies within one business day.
  • A recent penetration test summary and a straight answer on certification status.

Every one of these is a document. Having them ready is the difference between clearing security review in two weeks and five months.

Working on this?

We run a paid two-week diagnostic that ends with an architecture record, a risk register and a costed plan — yours to keep either way.

Talk to an engineer

Let's find out whether we're a fit.

Thirty minutes with an engineer who has shipped this before — not a salesperson reading a deck. You leave with a straight answer about scope, cost and timeline, whether or not you work with us.

Prefer email? sales@anithrasolutions.com · We reply within one business day