From consent architecture to breach notification, data retention to cross-border transfer rules — one team managing the complete data protection compliance lifecycle under India's DPDP Rules for your Global Capability Center.
Happy Clients
Satisfaction Rate
Support
Breach Notification Ready
Unresolved Data Gaps
India's data protection regime moved from theoretical to enforceable on 13 November 2025, when the Ministry of Electronics and Information Technology notified the final Digital Personal Data Protection Rules 2025 via Gazette G.S.R. 846(E), bringing the Digital Personal Data Protection Act, 2023 into force. For any GCC processing employee data, customer data, or data on behalf of its foreign parent, this is not a future obligation to plan around, the compliance clock is already running, and DPDP compliance services for GCC in India now mean active gap-closing, not a policy document sitting in a drawer.
Every GCC handling digital personal data of individuals in India falls under this framework, regulated by MeitY and enforced by the newly constituted Data Protection Board of India (DPB). DPDP compliance for Global Capability Centers hinges on three things: building a compliant consent and notice architecture, implementing the mandated security and breach-notification safeguards, and getting data retention and cross-border transfer practices aligned before the substantive deadline lands.
Security failures under the DPDP Rules can attract penalties of up to ₹250 crore, levied per violation. For a GCC processing HR data, payroll data, or operational data for a foreign parent, that exposure sits on the Indian entity regardless of where the parent is headquartered. Building a compliant posture before the May 2027 deadline is the most straightforward way to manage this exposure, and the 18-month window is shorter in practice than it looks on paper.
DPDP compliance for GCC entities operating in India spans six distinct filing and obligation categories under the Digital Personal Data Protection Act, covering consent management, data fiduciary registration, breach notification, and cross-border data transfer requirements.
| Sub-Category | Form / Requirement | Trigger / Deadline | Authority |
|---|---|---|---|
| Consent & Notice Architecture | Consent collection mechanisms, plain-language privacy notices, Consent Manager integration | Consent Manager provisions effective from 13 November 2026 | MeitY / Data Protection Board |
| Security Safeguards | Technical and organizational safeguards under Rule 6, including encryption, access controls, and audit trails | Full compliance due by 13 May 2027 | Data Protection Board |
| Breach Notification | Affected Data Principals notified within 72 hours of Board notification, including breach description and protective measures | Immediate upon breach detection | Data Protection Board |
| Data Retention & Erasure | Minimum 1-year retention of personal data and processing logs under Rule 8(3); sector-specific retention up to 3 years for high-volume entities under the Third Schedule | Ongoing from go-live | Data Protection Board |
| Significant Data Fiduciary (SDF) Obligations | Annual Data Protection Impact Assessments and independent compliance audits for designated SDFs | Annual, once SDF status is notified | Data Protection Board |
| Cross-Border Data Transfer | "Negative list" model — transfers permitted unless the Central Government explicitly restricts a country | Ongoing monitoring of restricted-country notifications | MeitY |
MeitY has staggered enforcement across three dates — 14 November 2025, 14 November 2026, and 14 May 2027, with the substantive provisions of the Act and Rules coming fully into force on 14 May 2027. That 18-month runway looks generous on paper, but organizations with GDPR implementation experience know that compliance programmes consume most of the available timeline once vendor contracts, technical builds, and staff training are factored in.
A few things worth flagging:
Data protection obligations vary based on how your entity is structured in India, with DPDP compliance requirements differing across Private Limited Companies, LLPs, Branch Offices, and Liaison Offices. The breakdown below outlines what applies to each structure.
| Requirement | Pvt Ltd (Subsidiary) | LLP | Branch Office | Liaison Office |
|---|---|---|---|---|
| Consent & Notice Architecture | Applicable | Applicable | Applicable | Applicable |
| Security Safeguards (Rule 6) | Applicable | Applicable | Applicable | Applicable |
| Breach Notification (72-hour) | Applicable | Applicable | Applicable | Applicable |
| Data Retention (1-year minimum) | Applicable | Applicable | Applicable | Applicable |
| SDF Obligations (DPIA, Audits) | Applicable if designated SDF | Applicable if designated SDF | Applicable if designated SDF | Rarely applicable given limited data processing |
| Cross-Border Transfer Monitoring | Applicable for parent-company data flows | Applicable | Applicable | Applicable |
DPDP & Data/Cyber is managed with a deliberate focus on building a defensible compliance position before the May 2027 deadline, not assembling documentation after an inspection notice. Companies that choose DPDP compliance services for GCC in India from Xpansa get a team actively mapping data flows and closing gaps, with compliance built as a defensible position. What this includes:
Inventorying personal data flows across HR systems, payroll, customer data, and parent-company transfers, benchmarked against DPDP Rule requirements.
Building compliant consent capture mechanisms and plain-language privacy notices ahead of the Consent Manager go-live.
Coordinating with IT/security teams on Rule 6 technical safeguards, access controls, and audit-trail retention.
Documented breach notification protocols built to the 72-hour Data Principal notification timeline.
Early evaluation of Significant Data Fiduciary exposure, so DPIA and independent audit obligations aren't a surprise.
DPDP compliance connects to Corporate & Secretarial (board-level data governance policy) and Labour Codes & Payroll (employee data handling), tracked under one accountable partner.
As a DPDP compliance partner working with GCC structures across entity types, Xpansa manages data protection as a connected obligation across HR, payroll, IT, and governance: updated as Rules and restricted-country notifications evolve.
Everything you need to know. Can't find the answer? Get in touch.
The DPDP Rules were notified on 13 November 2025, with an 18-month transition period for organizations to comply by 13 May 2027.
Security failures alone can attract penalties of up to ₹250 crore, and because penalties are levied per violation, a single breach can create cumulative exposure well beyond that figure.
No. Once the May 2027 deadline passes, all substantive obligations become immediately enforceable. Building compliance in advance is the most reliable way to ensure the entity is in a clean position from that date.
A minimum of one year from the date of processing, under Rule 8(3), with longer sector-specific periods of up to three years for certain high-volume entities under the Third Schedule.
The framework adopts a "negative list" approach, allowing personal data to be transferred outside India unless the Central Government explicitly restricts a country or territory via notification. This matters for any GCC routing data back to its foreign parent.
Yes. Employee data is also personal data under the Act, which means employee data protection compliance sits squarely within scope alongside any customer-facing data processing.
Data mapping, consent redesign, security safeguard alignment, and breach-response documentation require coordinated legal, IT, and HR input. A dedicated partner ensures these are built properly ahead of the May 2027 deadline, rather than assembled under time pressure.
Yes. Where the GCC processes personal data as a Data Processor on behalf of its foreign parent acting as a Data Fiduciary, obligations around security safeguards, breach notification, and data retention apply to the GCC directly, in addition to any contractual requirements from the parent.
11B 104-40 Queens Blvd,
Forest Hills 11375
New York, USA
No.7 Sriji Palace,
17, E.V.K Sampath Road,
Vepery, Chennai – 600 007
Xpansa is powered by IMC, so you get a startup's speed with a legacy firm's depth.
Copyright © Xpansa. All Rights Reserved.