Readiness assessment
DPDP Implementation • Global Capability Centres

DPDP Implementation for Global Capability Centres in India

Classify India and global data flows, determine the GCC's role for each processing activity, reuse the privacy and security controls you already run, and identify what actually needs to change across people, systems and vendors.

Written for DPO / Privacy General Counsel CISO CIO GCC Head HR Risk

Practical implementation framework • Source-linked • Provider-neutral

Why this is different

One GCC. Several very different data realities.

A Global Capability Centre is not a single privacy problem. Inside one legal entity, personal data moves through populations, systems and contracts that each sit differently under the DPDP Act. Treating them as one programme is where most GCC efforts lose accuracy.

01

India workforce data

Employees, candidates, payroll, benefits, access provisioning, workplace monitoring and internal investigations. High volume, high sensitivity, and the population most clearly within India.

02

Global enterprise systems

Indian personal data commonly sits in platforms owned, configured or operated across several countries: global HRIS, identity, collaboration, service management and analytics.

03

Offshore workloads

The India centre may process personal data belonging to people outside India, for a foreign entity, under contract. Whether a specific carve-out is relevant depends on the facts, not the label.

04

Mixed organisational roles

For its own India operations the entity may decide purposes itself. For group work it may act on a parent's instructions. The same GCC can hold different roles for different activities.

The corporate label "GCC" does not answer the DPDP question. The processing activity does.

Classify before you comply

First determine what kind of data flow you are looking at.

The question is rarely "are we DPDP compliant?" It is a sequence of narrower questions, answered per data stream, that tell you which obligations attach and what has to change.

1Who is the Data Principal?
In IndiaOutside India
2Where and why is the data processed?
India operationGlobal operationForeign-parent or client contractMixed environment
3What role does the GCC play for this activity?
Data FiduciaryData ProcessorPotentially different roles by activity
4Are specific statutory provisions or exemptions relevant?
Section 7 legitimate usesSection 17 exemptionsRequires activity-specific assessment
5What actually needs implementation?
ControlsSystemsContractsProcessesGovernanceEvidence
Read this before you scope

Do not classify an entire global platform as "in scope" or "exempt" simply because one population or one processing activity appears to meet a particular condition. A single system often carries several streams that must be assessed separately.

Offshore processing

Why Section 17 needs activity-level analysis

Section 17(1) is a partial, purpose-specific exemption, not a blanket corporate carve-out. One of its listed purposes concerns processing personal data of Data Principals not within India under a contract with a person outside India. Whether it applies is a question of fact for each activity, and even where it does, the accountability duty under Section 8(1) and the security duty under Section 8(5) continue to apply.

Scenario A
India GCC processing Indian employees
Likely implication

Core workforce processing of people in India. Analyse under the normal applicable framework: notice, a lawful basis (consent or a Section 7 legitimate use), security, rights and retention.

Scenario B
Foreign customer data, foreign-parent or client contract
Potentially relevant

Processing personal data of people outside India for a foreign entity under contract may bring Section 17(1)(d) into consideration. This requires activity-specific assessment against the statutory conditions, not an assumption.

Scenario C
Global HR system holding Indian and foreign employees
Mixed data stream

The same platform carries both India and non-India populations. Do not treat the entire system identically. The India-resident records need their own analysis even if the tenant is shared.

Scenario D
Local purposes plus foreign-parent instructions
Potentially different roles

Where the entity decides some purposes itself and acts on a parent's instructions for others, it may hold different roles for different activities. Role should be resolved per activity.

What to verify before you conclude

  • Data Principal location
  • Contractual chain
  • Purpose of processing
  • Role for the activity
  • System and data segregation
  • Vendor relationships
  • The actual processing activity, not the entity type
Legal review point

Section 17 is written by processing purpose and, in parts, depends on government notification. Applicability in mixed or layered arrangements should be verified by qualified counsel against the current statutory text and any rules in force. Nothing here is legal advice, and no exemption should be assumed for an activity that has not been assessed.

Role mapping

Is the GCC a Data Fiduciary, a Data Processor, or both?

Role is not a property of the entity. It follows from who decides the purpose and the essential means of a given processing activity. The examples below are illustrative prompts for analysis, not universal legal answers.

ActivityWho decides purpose?Who controls essential means?Who selects vendors?Who faces the Data Principal?Possible role
Local recruitmentIndia entityIndia entityIndia entityIndia entityData Fiduciary
India payrollIndia entityIndia + vendorIndia entityIndia entityFiduciary; vendor a processor
Physical access & securityIndia entityIndia entityIndia entityIndia entityData Fiduciary
Employee benefitsSharedProviderGroup or IndiaIndia entityReview required
Global customer supportForeign clientForeign clientClientClientLikely Data Processor
Global HR shared servicesParentParentParentParent / localReview required
Group analyticsGroupGroupGroupRarely directReview required
Foreign-client processingClientClientClientClientLikely Data Processor
Local recruitment
Decides purposeIndia entity
Controls meansIndia entity
Possible roleData Fiduciary
India payroll
Decides purposeIndia entity
Controls meansIndia entity plus vendor
Possible roleFiduciary; vendor a processor
Global customer support
Decides purposeForeign client
Controls meansForeign client
Possible roleLikely Data Processor
Global HR shared services
Decides purposeParent
Controls meansParent
Possible roleReview required
Group analytics
Decides purposeGroup
Controls meansGroup
Possible roleReview required
Takeaway

Role mapping should be performed by processing activity, not by corporate entity label. A single GCC can be a Data Fiduciary for its own India workforce and a Data Processor for a foreign client in the same week.

Workforce data

Employee privacy is an operating lifecycle, not an HR notice.

Indian workforce data is usually the clearest population within India, and it moves through a long chain of systems and vendors. Implementation means the whole chain works, not that a policy exists.

Stage 01

Candidate

ATS / recruiter
Stage 02

Background check

Verification provider
Stage 03

Onboarding

HR + IT provisioning
Stage 04

HRIS

Global HR platform
Stage 05

Payroll & benefits

Payroll + benefit vendors
Stage 06

Access & security

IAM / badge / CCTV
Stage 07

Performance & learning

Talent + LMS
Stage 08

Travel & workplace tools

Collaboration / travel
Stage 09

Exit

HR + IT + security
Stage 10

Retention / erasure

Owners + processors
What the law says • Section 7(i)

Section 7 sets out certain legitimate uses that let a Data Fiduciary process personal data without fresh consent. It is a closed, listed set of situations, and one item concerns specified employment purposes. It is an alternative basis for particular purposes, not a general rule that workforce data never requires consent.

What this means operationally

Map each workforce processing purpose to its basis. Some may rely on the employment legitimate use; others may still need consent or a different basis, and all of them still require notice, security, rights handling and defensible retention. Where the basis is unclear for a purpose, that is a review item, not an assumption.

Global systems

Indian personal data rarely stays inside India HR.

A single employee record propagates across a stack that was designed globally. Each hop is a place where access, purpose, retention and a rights request have to be answerable.

India employee
India GCCLocal HR + IT
Global HRISSystem of record
Identity & collaborationSSO, directory, email, chat
Service management & securityTickets, logs, monitoring
Global analytics & group entitiesReporting, foreign affiliates
Processors & SaaSDownstream vendors

Ask this at every hop

  • Who owns this system?
  • Who has access, and from where?
  • What purpose is being served?
  • Which vendors are involved?
  • How long is the data retained?
  • Can a rights request be fulfilled here?
  • Can a deletion propagate downstream?
  • What evidence proves it was done?
Reuse what you have

Already GDPR, ISO 27001, ISO 27701 or SOC 2 mature? Don't restart from zero.

Many GCCs already operate inside mature global privacy, security and assurance environments. The implementation question is not "start again". It is: what can be reused, and what is the DPDP and India-specific delta?

Global privacy & security controls
DPDP mapping
Reusable controls

Inventories, vendor governance, access management, incident processes and assessment discipline often map across with adjustment.

India-specific gaps

DPDP roles, lawful basis, notice content, rights routing across global systems and defensible retention usually need targeted work.

Targeted remediation, tested, with evidence

GDPR

Reusable

Data inventory, rights machinery, vendor governance, assessment practice.

Review

DPDP's own legal structure and roles, and India-resident processing specifics. GDPR transfer mechanisms do not carry over.

ISO 27001

Reusable

Security governance, access control, supplier controls, incident response.

Review

Privacy purpose, notices, Data Principal rights, retention and role determination.

ISO 27701

Reusable

A privacy information management structure and control set.

Review

India-specific legal mapping and the actual DPDP data flows through your systems.

SOC 2

Reusable

Evidence discipline and a mature security control environment.

Review

It does not by itself answer DPDP role, purpose, notice or rights questions.

Keep this honest

No framework automatically equals DPDP compliance. Certification proves a control environment exists. It does not resolve who the Data Fiduciary is for a given activity, or whether an India-resident rights request can actually be fulfilled end to end.

Assess your GCC implementation needs
Rights operations

A Data Principal request may cross half the enterprise.

A single access, correction or erasure request rarely lives in one system. Fulfilling it means routing across owners and processors, acting, responding within time, and keeping proof.

1Request 2Verify identity 3Classify request 4Determine role & applicability 5Locate systems 6Route to owners 7Route to processors 8Fulfil 9Respond 10Preserve evidence
Likely owners HRITPrivacySecurityGlobal HRPayrollVendorForeign-parent team
The test

A web form is not a rights programme if the organisation cannot locate and action the underlying records across its global systems and processors. The intake is the easy part; the routing and the evidence are the implementation.

Retention & deletion

"Employee exited" does not mean "employee data disappeared."

One departure fans out into many systems. Each holds a copy, each has an owner, and each needs a decision that is actually executed, not just written down.

Employee exit
HRISPayrollEmail / collaborationIdentity & accessService managementSecurity logsShared drivesGlobal HRBenefitsBackground-check providerBackups
Retention ruleExceptionSystem ownerDeletion actionProcessor actionVerificationEvidence
What this means operationally

A retention schedule is a policy artefact. Implementation means making retention and erasure executable in each system and traceable to a record. Retention periods are not prescribed here; they should be set against your purposes and any sectoral or legal obligations, then written into the systems that hold the data.

Vendors & processors

Your GCC's privacy boundary extends into its vendor ecosystem.

Under Section 8, a Data Fiduciary remains responsible for processing carried out on its behalf and may engage a Data Processor only under a valid contract. The boundary of the programme is the boundary of the ecosystem, not the office.

Payroll
Recruitment
Background verification
Cloud infrastructure
India GCCAccountable Data Fiduciary for its own processing
SaaS platforms
Travel
Security vendors
Benefits & consultants
1Inventory 2Role 3Purpose 4Data 5Access 6Contract 7Security 8Retention 9Incident 10Offboarding 11Evidence
More than a contract review

Contract clauses matter, but they do not prove that access is scoped, that a rights request reaches the processor, or that offboarding actually removed the data. Vendor governance is an operating loop, not a signature.

Security & incident

Existing SOC processes are useful, but privacy obligations still need an operating layer.

A mature GCC already detects and responds to incidents. DPDP adds a personal-data lens on top of that capability, and the two need to run as one workflow.

Existing security capability

  • Detection
  • SOC
  • Incident response
  • Logging
  • Vendor escalation
  • Forensics

Privacy overlay

  • Personal-data impact
  • Role analysis
  • Processor coordination
  • Regulatory & legal review
  • Data Principal implications
  • Evidence preservation
One coordinated incident workflow Security handles containment; privacy handles obligations. They share the same timeline and the same evidence trail.
Legal review point

Reasonable security safeguards are a standing duty under Section 8(5), and breach handling is a Data Fiduciary obligation under Section 8. The precise content and timing of any notification obligation should be set against the current Act and the rules in force, and confirmed with counsel, rather than assumed from another regime.

AI, copilots & analytics

Personal data increasingly enters systems that were never designed as privacy workflows.

Assistants, copilots and analytics pipelines now sit on top of the same enterprise systems that hold workforce and customer data. They are processing activities like any other, and they need the same classification.

Employee / customer dataSource records
Enterprise systemsHRIS, CRM, knowledge, collaboration
Copilot / LLM / analyticsWhere personal data enters the model layer
Prompts, retrieval, outputs, logsNew copies and new surfaces
Global platform / external providerWhere the data may travel
Which AI tools receive personal data?
Which systems are connected to them?
Are prompts or files retained, and where?
Who determines the purpose?
Can outputs affect an employment or customer decision?
Can the data source be traced?
How would a correction or erasure propagate?
What do the provider contracts actually say?
Keep it proportionate

The DPDP Act does not prohibit AI. It means AI features that touch personal data are inventoried, given a purpose and a role, and brought inside the same rights, retention and evidence discipline as every other system.

The programme

What a GCC DPDP implementation actually contains

Eleven workstreams that move a GCC from policy to operation. Each starts from a real problem, inspects specific things, and leaves an operating outcome behind.

01

Data-stream classification

Populations and flows are treated as one.

Inspect

Data Principal location, purpose, contract, role per stream.

Outcome

A stream-level classification, not an entity-level guess.

02

Role mapping

Fiduciary vs processor is assumed, not decided.

Inspect

Who decides purpose and essential means per activity.

Outcome

A role register that stands up per activity.

03

Workforce privacy

Employee data spans a long lifecycle.

Inspect

Basis, notice, systems and vendors at each stage.

Outcome

An operating workforce data-flow, not just an HR notice.

04

Global-system mapping

Indian data moves through global platforms.

Inspect

Ownership, access, purpose and retention per system.

Outcome

A system inventory that answers rights and retention.

05

Notices & communications

Notice content and delivery are inconsistent.

Inspect

What is told, to whom, at which touchpoint.

Outcome

A notice matrix mapped to actual flows.

06

Rights operations

A request cannot be routed and actioned.

Inspect

Intake, routing, owners, processors, timelines.

Outcome

A working rights workflow with evidence.

07

Retention & deletion

Schedules exist but are not executed.

Inspect

Rules, exceptions, owners and downstream copies.

Outcome

Executable retention and erasure, verified.

08

Processor & vendor governance

The boundary extends into vendors.

Inspect

Inventory, role, contract, access, offboarding.

Outcome

A processor register and an operating loop.

09

Security & incident integration

Privacy sits outside the SOC workflow.

Inspect

Where the privacy overlay meets detection and IR.

Outcome

One coordinated incident workflow.

10

AI & analytics governance

Personal data enters the model layer unseen.

Inspect

Which tools, which data, which purpose, which contracts.

Outcome

An AI processing register inside the same discipline.

11

Governance, testing & evidence

Controls exist but are not proven.

Inspect

Ownership, tests, and the evidence each produces.

Outcome

A RACI and a readiness evidence base.

What good implementation leaves behind

Not just policies. Reviewable artefacts that show how the programme operates.

The output of implementation is a set of artefacts a reviewer, an auditor or the next DPO can actually inspect. The previews below are illustrative field structures, not templates.

Data-Stream Classification Matrix

Illustrative
PopulationIndia employees
SystemGlobal HRIS
PurposeWorkforce administration
RoleReview required
VendorYes
Section 17Not assumed
OwnerHR + Privacy

India / Global Processing Map

Illustrative
StreamGlobal support
Principal locationOutside India
ContractForeign client
AssessmentActivity-specific
Verified byLegal

Role-Mapping Register

Illustrative
ActivityIndia payroll
Decides purposeIndia entity
RoleData Fiduciary
ProcessorPayroll vendor

Workforce Data-Flow Map

Illustrative
StageOnboarding
SystemsHRIS, IAM, email
BasisPer purpose
RetentionLinked to owner

Global System Inventory

Illustrative
SystemIdentity provider
OwnerGlobal IT
AccessScoped, logged
Rights-readyIn progress

Processor / Vendor Register

Illustrative
VendorBackground check
RoleProcessor
ContractDPDP terms present
OffboardingDefined + tested

Notice Matrix

Illustrative
TouchpointCandidate apply
AudienceApplicants
ContentPurpose, rights
StatusLive

Rights Routing Workflow

Illustrative
RequestErasure
Systems hit7
OwnersHR, IT, Vendor
EvidenceRetained

Retention Matrix

Illustrative
RecordPayroll
RulePer obligation
OwnerFinance
ExecutableWiring

Deletion Playbook

Illustrative
TriggerExit
TargetsAll copies
Processor stepIncluded
VerificationRequired

DPDP Control Mapping

Illustrative
ExistingISO 27001
Maps toSecurity duty
GapNotice, rights
ActionTargeted

Incident Privacy Overlay

Illustrative
EventSuspected breach
PD impactAssessed
Processor coordTriggered
EvidencePreserved

AI Processing Register

Illustrative
ToolCopilot
DataEmployee content
PurposeDefined
ContractReviewed

Governance RACI

Illustrative
ControlRights handling
AccountableDPO
ResponsibleHR, IT
ConsultedLegal

Readiness Evidence Dashboard

Illustrative
Streams classifiedTracked
Roles resolvedTracked
Rights testedTracked
EvidenceRetained
Self-check

How far has your GCC moved from policy to implementation?

A quick read of where the work actually stands. This is a prompt for your own team, not a score.

We have classified India and foreign Data Principal data streams.
We understand where the India GCC acts as fiduciary versus processor.
We can trace Indian workforce data across global enterprise systems.
Existing GDPR, ISO or SOC 2 controls have been mapped against DPDP.
Key processors and vendors have been inventoried.
Rights requests can be routed and actioned across global systems.
Retention decisions are connected to actual system actions.
Employee exit triggers downstream data actions, including processors.
Privacy incidents integrate with the SOC and IR workflow.
AI tools that involve personal data are inventoried.
Control ownership is assigned and named.
Implementation evidence is retained and reviewable.
If several of these are unresolved, the next step is usually implementation scoping, not another generic privacy-policy review.
Assess your GCC implementation needs
Implementation assessment

Know what needs fixing before choosing who fixes it.

DPDPActIndia helps organisations understand and scope implementation requirements. Where specialist execution is required, relevant implementation capability may be considered based on factors such as your processing environment, systems, data flows, existing privacy and security maturity, technical remediation and sector context.

  • Processing environment
  • Global systems
  • Data flows
  • Privacy & security maturity
  • Technical remediation
  • Sector & regulatory context

The intake is shared across the DPDP implementation framework. Tell us it is a Global Capability Centre and describe the environment; scoping is provider-neutral.

FAQ

GCC and DPDP: common questions

Does the DPDP Act apply to a GCC in India?

Generally yes, where the GCC processes digital personal data in connection with activity in India. How it applies depends on the processing activity, the population involved and the role the GCC plays, which is why classification comes before compliance. Applicability in specific arrangements should be confirmed against the current Act.

Are GCCs always Data Processors?

No. A GCC is not automatically a Data Processor. For its own India operations it may decide purposes and act as a Data Fiduciary; for group or client work it may act on instructions and look more like a processor. The same entity can hold different roles for different activities, so role should be mapped per activity.

When can Section 17 matter for offshore processing?

Section 17(1) is a partial, purpose-specific exemption. One listed purpose concerns processing personal data of Data Principals not within India under a contract with a person outside India. Whether it applies is fact-specific and should be legally verified, and even where it applies, the Section 8(1) accountability and Section 8(5) security duties continue. It is not a blanket exemption for all offshore work.

Does GDPR compliance make a GCC DPDP compliant?

Not by itself. GDPR maturity gives you reusable inventories, rights machinery, vendor governance and assessment discipline. DPDP has its own legal structure, roles and requirements, and GDPR transfer mechanisms do not carry over. Treat GDPR as a strong starting point and map the India-specific delta.

Does ISO 27001 or SOC 2 cover DPDP?

They cover a security control environment and evidence discipline, which are genuinely reusable. They do not by themselves answer DPDP questions of role, purpose, notice, rights and retention. Those need a specific mapping exercise on top of the certification you already hold.

How should GCCs handle Indian employee data in global HR systems?

Map the workforce lifecycle across every system the data touches, identify the basis and notice for each purpose, and make rights and retention actually executable in those systems, including downstream processors. The presence of a global platform does not remove the India-resident analysis.

When should a GCC begin implementation?

Most substantive operational provisions are scheduled to commence on 13 May 2027. The reason to start earlier is not a deadline countdown; it is lead time. System discovery, role analysis, vendor remediation, workflow design and testing across global systems take time that a policy refresh does not.

Sources & references

Primary sources

Legal statements on this page are grounded in the primary text of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. Practical points are implementation interpretation, not legal advice.

  1. Digital Personal Data Protection Act, 2023 – Section 7 (certain legitimate uses), Section 8 (general obligations of Data Fiduciary, including the processor-contract duty at 8(2) and reasonable security safeguards at 8(5)), Section 16 (processing outside India) and Section 17 (exemptions). See our DPDP Act explorer.
  2. Digital Personal Data Protection Rules, 2025 – notified 13 November 2025; substantive operational provisions scheduled to commence 13 May 2027. See our Rules overview.
  3. Related concepts: Data Fiduciary, Data Processor, Data Principal, cross-border transfer, data retention and reasonable security safeguards.

What the law says is drawn from the enacted statute. What this means operationally and implementation consideration are our own framework and should be validated for your specific arrangements with qualified counsel. This page is not legal advice and DPDPActIndia is not a law firm, regulator or certification body.

Reviewed by the DPDPActIndia editorial team • Updated August 2026
DPDP implementation framework NBFC / digital lending Readiness assessment Industries