GDPR Standard Contractual Clauses for India-Based Processors

GDPR Standard Contractual Clauses for India-Based Processors

The GDPR standard contractual clauses run to eighteen clauses and four modules, and an India-based processor signs only two of those modules. Which of the two depends on a single question: whether the European client is the controller of the data, or is itself somebody else’s processor. Commission Implementing Decision (EU) 2021/914 fixed the text on 4 June 2021, and India holds no adequacy decision, so these clauses are the Article 46(2)(c) safeguard that makes the transfer lawful at all.



The clause text itself isn’t negotiable. Clause 2 permits modification only to select the applicable module or to add information to the Appendix, which leaves the real work in three annexes: who the parties are and what moves between them, what security the Indian side actually runs, and which sub-processors are approved.

Most Indian vendors meet the instrument as an attachment rather than as a law. It arrives from a procurement team, half-filled on the European side, with the annexes blank and a signature block at the bottom. And the blanks are where the liability gets decided.

Two documents do most of the interpretive work alongside the Decision itself: the European Data Protection Board’s Recommendations 01/2020 on supplementary measures, and the Commission’s own question-and-answer note of 25 May 2022.

Which GDPR standard contractual clauses apply to an Indian processor

The GDPR standard contractual clauses that apply to an Indian processor are Module Two or Module Three of the modular set adopted in 2021, combined with the general clauses that run whichever module is chosen. India is absent from the Commission’s adequacy list, which currently recognises sixteen countries and territories plus the European Patent Organisation, so Chapter V of the GDPR leaves a European exporter with an Article 46 safeguard or with nothing. The clauses are the ordinary choice because, unlike binding corporate rules or ad hoc clauses, they need no regulator approval before use. Set against the comparison between the DPDP Act and the GDPR, the structural point is that Indian law regulates export and European law regulates import, and the two don’t meet in the middle.

Module two and module three

Module Two covers a transfer from a controller to a processor, and Module Three a transfer from one processor to another. So which of them governs a given engagement? The distinction turns on what the European counterparty is, not on what the Indian firm is, since the Indian firm is the importer and the processor either way.

A European company that collected the data itself and hires an Indian team to work on it is the controller, so Module Two applies. A European agency that already processes for its own client and sub-contracts part of that work to India is a processor, so Module Three applies, and under Clause 8.1 of that module the instructions originate with the controller and reach the Indian side through the exporter. Module One (controller to controller) and Module Four (processor to controller) exist for different shapes entirely.

One consequence saves a document. The Commission’s question-and-answer note states that the requirements of Article 28 of the GDPR have been incorporated into Modules Two and Three, so parties using them don’t need a separate data processing agreement. But Indian vendors are still routinely asked to sign both, and the second usually contradicts the first. The choice then gets recorded in one line of Annex I.A (Role (controller/processor): processor), which has to agree with the module selected.

Annex I and the description of the transfer

Annex I carries three parts. Part A lists the parties with their contact details, the activities relevant to the transfer, a signature and date, and each side’s role. Part B describes the transfer. Part C identifies the competent supervisory authority.

In practice, though, Part B is the part procurement fills with a single line, and the part a supervisory authority would read first. The Decision asks for the categories of data subjects, the categories of personal data, any sensitive data and the restrictions applied to it, the frequency of the transfer, the nature and purposes of the processing, and the retention period or the criteria used to set one.

Part C follows Clause 13. Where the exporter is established in an EU Member State, that Member State’s authority is competent. Where the exporter sits outside the EU but inside Article 3(2) and has appointed a representative under Article 27(1), it is the authority in the representative’s Member State.

A retention line that survives review reads as a rule, not an intention: The period for which the personal data will be retained: for the duration of the services agreement and 90 days after termination, after which the data importer returns or deletes the data at the data exporter’s choice under Clause 16(d).

Annex II and the security measures

Annex II sets the security floor, and it binds. Clause 8.6(a) requires the importer to implement at least the measures specified in Annex II, and to run regular checks that they continue to provide an appropriate level of security. The same clause names encryption and pseudonymisation as measures to consider in particular, where the purpose of the processing can still be met that way.

The catch? The Decision’s explanatory note to Annex II says the measures must be described in specific, and not generic, terms. Its own example list runs from pseudonymisation and encryption through restoring availability after an incident, user authorisation, physical security and event logging, to data minimisation and limited retention.

Certification helps without substituting for the annex. Clause 8.9(c) says the exporter may take relevant certifications held by the importer into account when deciding on a review or an audit, which is a reason to hold ISO 27001 and not a reason to leave Annex II thin. Indian firms already receiving security annexes under the NIS2 Directive will recognise the format immediately.

Advertisement

Here’s what that actually looks like, in one line. Generic: Data is encrypted in transit and at rest. Specific: Personal data is encrypted in transit using TLS 1.3 and at rest using AES-256, with key management held in an access domain separate from the processing systems, and access logs retained for 12 months.

Annex III and the sub-processor list

Annex III is completed in one situation only: Modules Two and Three, where the parties chose specific prior authorisation under Clause 9(a), Option 1. Under that option the importer cannot sub-contract without the exporter’s prior specific written authorisation, requested a stated period in advance with the information the exporter needs. Sub-processors already authorised sit in Annex III, and both parties keep it current.

But Option 2 works on a different rhythm. General written authorisation lets the importer engage sub-processors from an agreed list, provided it informs the exporter in writing of any addition or replacement a stated period in advance, with enough information for the exporter to object. Either way, Clause 9(b) requires a written contract with the sub-processor providing, in substance, the same data protection obligations.

Worth flagging: this is where Indian vendors under-declare. The cloud hosting, the ticketing system and the contractor brought in for a three-week surge are all sub-processors, and a short engagement doesn’t stop one being one.

An Annex III entry names a role rather than a person: 1. Name: [cloud provider entity]. Address: [registered office]. Contact person’s name, position and contact details: Data Protection Contact, [email]. Description of processing: hosting and encrypted backup of the production database holding the transferred personal data, no provider access to plaintext except on documented support request.

What an India-based processor actually signs

Decision (EU) 2021/914
1 Pick the
module
Two of the four modules reach an Indian processor
Module Two
Controller to processor. The EU client collected the data itself. Instructions come from the client under Clause 8.1.
Module Three
Processor to processor. The EU client is somebody else’s processor, so the instructions originate with the controller and arrive through the exporter.
Both modules carry the Article 28 GDPR terms, so no separate data processing agreement is needed
2 Fill the
annexes
Three annexes, and this is the only negotiable part
Annex I
A parties, roles, signature. B data subjects, data categories, sensitive data, frequency, nature, purpose, retention. C competent supervisory authority under Clause 13.
Annex II
Technical and organisational measures. Must be specific, not generic. Clause 8.6(a) makes these the security floor the importer has to implement and re-check.
Annex III
Sub-processor list. Completed only under Clause 9(a) Option 1, specific prior authorisation. Option 2 runs off an agreed list with advance notice instead.
Clause 2 permits no other change: modify the clause text and it stops working as a transfer basis
3 Owe the
duties
Two standing obligations that outlast signature
Clause 14, transfer impact assessment
Warrant that local law does not prevent compliance, weighing the circumstances of the transfer, the destination country’s laws, and any added safeguards. Document it and hand it to the supervisory authority on request.
Clause 15, public authority access
Notify the exporter of any binding disclosure request, seek a waiver where notice is barred, report in aggregate, review the legality of the request and challenge it where there are reasonable grounds.
Clause 14 implements the Schrems II judgment, Case C-311/18, 16 July 2020
Not on the table
Clause 5: the clauses prevail over the master services agreement, before and after. Clause 8.9: the exporter may audit, including inspections at the importer’s premises. Clauses 17 and 18: EU Member State law governs, EU courts decide, and data subjects enforce directly as third-party beneficiaries under Clause 3.
SkillArbitrage

The transfer impact assessment under clause 14

Clause 14 is the assessment the Schrems II judgment produced. The Court of Justice decided Case C-311/18 on 16 July 2020, and under Clause 14(a) both parties now warrant that they have no reason to believe the laws and practices of the destination country prevent the importer from fulfilling its obligations.

Paragraph (b) names three elements the warranty has to be built on. The specific circumstances of the transfer, from the length of the processing chain and the transmission channels to the categories of data, the sector and the storage location. The laws and practices of the destination country relevant to those circumstances, including anything requiring disclosure to public authorities. And any safeguards added on top of the clauses.

But paragraph (c) puts the information-gathering on the importer, which is why the questionnaire lands in India rather than staying in Europe. Paragraph (d) requires the parties to document the assessment and make it available to the competent supervisory authority on request. Under paragraph (e) the importer must notify the exporter promptly if it comes to believe it has become subject to laws out of line with that warranty, and paragraph (f) then obliges the exporter to identify measures or suspend the transfer.

The EDPB’s Recommendations 01/2020, adopted on 18 June 2021, set out the six-step method most European exporters work through. Know your transfers, identify the transfer tools relied on, assess whether the Article 46 tool is effective in light of all circumstances of the transfer, adopt supplementary measures, take the procedural steps those measures require, and re-evaluate at appropriate intervals. Frankly, this gets overlooked on the Indian side, where the assessment is treated as the client’s homework rather than as a shared warranty.

Government access requests under clause 15

Clause 15 governs what happens when an authority in the destination country asks for the transferred data. Clause 15.1(a) requires the importer to notify the exporter, and where possible the data subject, promptly on receiving a legally binding disclosure request, naming the data requested, the requesting authority, the legal basis and the response provided. The same duty applies on becoming aware of direct access by public authorities.

Where local law prohibits notification, the clause doesn’t accept silence. Clause 15.1(b) requires documented best efforts to obtain a waiver. Clause 15.1(c) then requires periodic reporting in aggregate where permissible: the number of requests, the type of data, the requesting authorities, whether requests were challenged and how those challenges ended.

Clause 15.2 goes considerably further. The importer agrees to review the legality of each request, to challenge it where careful assessment gives reasonable grounds to consider it unlawful, to pursue appeals, and to seek interim measures suspending the request until a court rules on the merits. It also agrees to disclose only the minimum information permissible and to document its legal assessment, preserved under Clause 15.1(d) for the duration of the contract.

A notification obligation is easy to sign. A standing duty to litigate against one’s own government, on a promise made to a foreign counterparty, is a different proposition, and deserves reading before signature rather than after.

Working under the GDPR standard contractual clauses

Working under the GDPR standard contractual clauses changes three things inside an Indian company: what can be negotiated, what can be inspected, and which law decides a dispute.

So what is actually negotiable? Clause 2(a) fixes the text. The clauses provide the safeguards they claim to provide only where they are not modified, except to select the module or to add or update information in the Appendix. The Commission’s note is blunter still. Change the text beyond choosing modules, options, square brackets and annex content, and the result can no longer be used as a basis for transfers unless a national data protection authority approves it as ad hoc clauses under Article 46(3)(a). Bottom line: redlining the clause body is wasted effort. The negotiating room is in the scope recorded in Annex I.B, the measures listed in Annex II, and the notice periods written into Clause 9.

And Clause 5 decides what happens when the master services agreement says something different. The clauses prevail, over related agreements existing when they were signed and over ones entered into afterwards. A firm that negotiated a liability cap in its commercial contract has not capped the third-party beneficiary rights in Clause 3.

Audit rights run wider than most vendors expect. Under Clause 8.9(c) of Module Two the importer makes available all information necessary to demonstrate compliance and, at the exporter’s request, allows for and contributes to audits of the covered processing at reasonable intervals or where there are indications of non-compliance. Paragraph (d) lets the exporter conduct the audit itself or mandate an independent auditor, and says audits may include inspections at the importer’s premises or physical facilities on reasonable notice. Teams that already spend their quarters answering third-party risk assessments will find the questions familiar and the enforcement route new.

Two clocks attach after signature. Clause 8.6(c) requires notification of a personal data breach to the exporter without undue delay after the importer becomes aware of it, with a contact point, the nature of the breach and, where possible, the categories and approximate number of data subjects and records concerned. Clause 16 handles the larger failure: the importer informs the exporter if it is unable to comply for whatever reason, the exporter suspends transfers, and it may terminate where compliance is not restored within a reasonable time and in any event within one month of suspension. The competent supervisory authority is informed when that happens.

Fair warning: the jurisdiction point is the one Indian management tends to read last. Clause 17 puts the clauses under the law of an EU Member State whose law allows third-party beneficiary rights, and Clause 18 sends disputes to the courts of a Member State, with a data subject additionally able to bring proceedings where they habitually reside. The Indian signatory agrees to submit to that jurisdiction. Clause 3 makes data subjects enforceable third-party beneficiaries, so the counterparty on the other side of a claim is not necessarily the client.

What drives the pressure from the European side is a number. Article 83(5)(c) of the GDPR places infringements of the transfer rules in Articles 44 to 49 in the higher penalty band, up to 20 million euro or 4 per cent of total worldwide annual turnover, whichever is higher. That exposure sits with the exporter, and the Indian side’s own regulatory exposure runs on a separate track under the DPDP Act’s penalty provisions.

And one gap is worth knowing before signature. Article 1 of the Decision states that the clauses provide appropriate safeguards for transfers to an importer whose processing of the data is not subject to the GDPR, and the EDPB’s Guidelines 05/2021, adopted in final form on 24 February 2023, confirm that reading. A back-office processor working purely on a European controller’s documented instructions sits comfortably inside that description. An Indian company whose own processing is caught by Article 3(2), because it offers goods or services to people in the Union or monitors their behaviour, does not, and the Commission’s standard contractual clauses page still describes the additional set built for that scenario as in development.

FAQs

Does an India-based processor need to appoint an EU representative?

Article 27(1) of the GDPR requires a representative in the Union only where Article 3(2) applies, which means only where the Indian entity’s own processing offers goods or services to people in the Union or monitors their behaviour. A processor acting on a European controller’s documented instructions is generally outside that test. Clause 13 then routes supervision to the supervisory authority of the exporter’s own Member State rather than to anything the Indian side has to appoint.

Are the 2010 standard contractual clauses still valid if a client sends them?

Article 4 of Decision 2021/914 repealed Decisions 2001/497/EC and 2010/87/EU with effect from 27 September 2021, and the transition period for contracts concluded before that date ran only to 27 December 2022. Any agreement concluded after 27 September 2021 had to be based on the 2021 set. A European client circulating the older template is working from a stale precedent bank, and signing it provides no Article 46 safeguard at all.

What applies when the client is in the UK rather than the EU?

The UK runs its own instruments, and the ICO’s position is that the EU clauses are not valid on their own for a restricted transfer under the UK GDPR. A UK exporter uses either the International Data Transfer Agreement or the UK Addendum, which attaches to the EU clauses and makes them usable for UK transfers. Both were laid before Parliament on 2 February 2022, and a transfer risk assessment is required alongside either one.

How often must the transfer impact assessment be repeated?

Step 6 of the EDPB’s Recommendations 01/2020 asks exporters to re-evaluate at appropriate intervals rather than on a fixed calendar, so the cycle is set by the risk profile of the transfer. Clause 14(e) sets the event that forces a reassessment early. The importer has to notify the exporter promptly once it has reason to believe it has become subject to laws or practices out of line with the Clause 14(a) warranty, including after a change in the law or a disclosure request showing how that law works in practice.

References

Official guidance and regulations

  1. Commission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries. Official Journal of the European Union, 4 June 2021
  2. Regulation (EU) 2016/679 (General Data Protection Regulation). Official Journal of the European Union, 27 April 2016
  3. Adequacy decisions: data protection adequacy for non-EU countries. European Commission
  4. Standard Contractual Clauses (SCC). European Commission
  5. Questions and Answers for the two sets of Standard Contractual Clauses. European Commission, 25 May 2022
  6. What are standard data protection clauses (the UK IDTA and the Addendum)?. Information Commissioner’s Office

Guidance, opinions and case law

  1. Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data. European Data Protection Board, adopted 18 June 2021
  2. Guidelines 05/2021 on the interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR. European Data Protection Board, version 2.0 adopted 24 February 2023
  3. Judgment of the Court of Justice of 16 July 2020 in Case C-311/18 (Schrems II), ECLI:EU:C:2020:559

This article is for informational and educational purposes only and does not constitute professional, legal or compliance advice. Obligations under the GDPR depend on the specific facts of a transfer and on the terms of the contract signed. Consult a qualified professional before acting on any data protection or contractual decision.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *