Skip to content
GDPR / THIRD-COUNTRY TRANSFER

Is it GDPR-compliant for a team in India to work in our systems?

It can be, and the mechanism is well established — but it depends on facts about your data that only you know, so this page explains what to check rather than declaring you compliant.

Last manually reviewed:

So is access from India actually lawful?

Yes, with the right safeguards in place — and the first thing to establish is whether a transfer happens at all. Neither India nor the United Arab Emirates has an EU adequacy decision [2], so where personal data is accessed from either country, the transfer needs safeguards under Art. 46 GDPR alongside the processing agreement under Art. 28 [1].

  • Remote access from India to systems holding personal data counts as a transfer, even when no file is copied [3].
  • No adequacy decision covers India or the UAE, so the transfer runs on Art. 46 safeguards.
  • A data processing agreement accompanies the engagement, and the transfer mechanism for your engagement is set out in it.
  • If your own policy or your customers forbid processing outside the EU, offshore access is the wrong answer — not a thing to paper over.

How the pieces fit

Three questions in order. Most reviews go wrong by starting at the third.

Is personal data involved at all?

Plenty of engagements touch none — infrastructure work, greenfield builds, systems holding only company data. Where that is genuinely the case, the transfer question narrows sharply. Establish it first rather than assuming either way.

Who is controller and who processes?

You remain the controller of your data. The processing that happens on your behalf is governed by the data processing agreement, which is the document your data protection officer should be reading, not this page.

What safeguards the transfer

With no adequacy decision for India or the UAE, transfers rest on the Art. 46 route, which in practice means standard contractual clauses [4] plus the technical and organisational measures around them [5]. Ask us for the wording that applies to your engagement.

What this means for your review

The parts your data protection officer will want settled before anything starts.

Scope the data before the engagement

Which systems the team needs, and whether those systems hold personal data, decides most of the analysis. It is much cheaper to scope it now than to restrict access after someone has it.

Limit access by design

Least privilege, pseudonymised or synthetic data in non-production environments, and no standing access to production where it is not needed. These reduce the transfer question rather than answering it after the fact.

Check your own commitments

Your customer contracts may impose residency terms stricter than the GDPR itself. Those bind you regardless of what safeguards we can offer, so read them before the kick-off.

Document the assessment

Whatever conclusion you reach, write down why. A transfer that was thought through and recorded is a very different position from one nobody examined.

What we hand over for the review

  • The data processing agreement for the engagement, including the transfer mechanism it relies on.
  • A description of the access model: which systems, which environments, and what controls sit around them.
  • A call with your data protection officer, early enough that scope can still change if the answer requires it.

Follow-up Questions

Is remote access a transfer if nothing is downloaded?

Yes. Making personal data available to someone in a third country is a transfer whether or not a copy is made [3], which is why access-only arrangements still need the same safeguards. This is the point most internal reviews get wrong.

Can the team work only on non-production data?

Often, and it is worth designing for. Pseudonymised or synthetic data in development and test environments removes a great deal of the question. Where production access is genuinely needed, scope it narrowly and time-box it rather than granting it by default.

Our customers require EU-only processing. What then?

Then offshore access to that data does not work, and we will tell you so. There may still be parts of your estate where an offshore team fits — infrastructure, tooling, systems with no personal data — but we are not going to argue you past a commitment you have already made to your own customers.

Does the Dubai entity change the analysis?

It adds a second third country rather than removing one: the UAE has no adequacy decision either. Your contract sits with the Dubai entity while the work happens in India, so both need to be covered, and the data processing agreement is where that is set out.

Do you have a DPA ready, or do we send ours?

We have one, and we are also fine working from yours if your legal team prefers its own paper. Either way, agree it before access is granted rather than alongside the first sprint.

Sources

All sources retrieved and checked against the cited passages on 6 August 2026.

  1. [1] Regulation (EU) 2016/679 (GDPR), Art. 28 and Art. 44 et seq. — official text, EUR-Lex — https://eur-lex.europa.eu/eli/reg/2016/679/oj Art. 44 sentence 1: any transfer to a third country “shall take place only if … the conditions laid down in this Chapter are complied with”; Art. 46(1): appropriate safeguards; Art. 28: processing on behalf of a controller.
  2. [2] European Commission — adequacy decisions for third countries (neither India nor the UAE is on the list) — https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en Lists the recognised third countries; neither India nor the UAE is on the list (checked 6 August 2026).
  3. [3] EDPB Guidelines 05/2021 on the interplay of Art. 3 and Chapter V GDPR — remote access from a third country qualifies as a transfer. Version 2.0, adopted 14 February 2023, European Data Protection Board (PDF) — https://www.edpb.europa.eu/system/files/documents/2023-02/edpb_guidelines_05-2021_interplay_between_the_application_of_art3-chapter_v_of_the_gdpr_v2_en_0.pdf Para. 16 (p. 8): “remote access from a third country (even if it takes place only by means of displaying personal data on a screen, for example in support situations, troubleshooting or for administration purposes) … is also considered to be a transfer”, provided the three criteria of para. 9 (p. 7) are met.
  4. [4] Commission Implementing Decision (EU) 2021/914 — standard contractual clauses for third-country transfers. EUR-Lex — https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj Art. 1(1): the clauses in the Annex “are considered to provide appropriate safeguards within the meaning of Article 46(1) and (2)(c)” of the GDPR for transfers to importers not subject to it.
  5. [5] CJEU, judgment of 16 July 2020, C-311/18 (Schrems II), ECLI:EU:C:2020:559 — full text, EUR-Lex — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311 Summary, not a verbatim quote: the ruling invalidated the Privacy Shield adequacy decision and holds that SCC-based transfers require a level of protection essentially equivalent to that in the EU, with supplementary measures where needed.

This page describes how our engagements are set up and how we understand the rules to apply to that setup. It is general information, not legal advice — have your own data protection adviser review your specific situation before you rely on it.

Bring your data protection officer in early

Scope, access model and the processing agreement are all easier to settle before an engagement than to renegotiate during one.

We value your privacy

We use cookies to understand how the site is used and to improve it. You decide: accept all, or continue with only the technically necessary ones. Privacy Policy