DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

A Global Capability Centre (GCC) or captive centre in India is a Data Processor — and often a Data Fiduciary — under the DPDP Act 2023 for the Indian personal data it handles, even though it serves a foreign parent. The DPDP Act itself does not mandate broad data localisation: it uses a negative-list transfer model, so data can generally flow to the parent abroad unless the government restricts a country. However, sector-specific rules (such as RBI directions for payment data) and Significant Data Fiduciary obligations can require certain data to stay in or be mirrored in India. This checker assesses whether your GCC needs to localise, and what else applies.

GCC Data Localisation Guide (DPDP Act)

Running a captive centre or GCC in India for a global parent? Check whether you actually need to localise data in India under the DPDP Act — and what obligations really apply.

Check your GCC localisation obligations

GCC / captive centre DPDP obligations checklist

Does a GCC in India have to localise data under the DPDP Act?

This is one of the most common questions from Global Capability Centres and captive units, and the answer surprises many teams: the DPDP Act 2023 does not impose broad, economy-wide data localisation. It uses a negative-list transfer model under which personal data can generally be transferred outside India — including to a foreign parent — unless the Central Government notifies a specific country as restricted. So the mere fact that a GCC serves a parent abroad does not, by itself, require the data to stay in India under the DPDP Act.

Where localisation obligations do arise, they typically come from sector-specific regulators rather than the DPDP Act. The clearest example is RBI's requirement that certain payment-system data be stored in India, which applies to entities in the payments ecosystem regardless of the DPDP transfer rule. Insurance, telecom and some other sectors have their own data-residency expectations. So the practical question for a GCC is less whether DPDP forces localisation and more whether a sector regulator with jurisdiction over its data does.

What DPDP obligations does a GCC carry beyond localisation?

Localisation is often the wrong thing to worry about first. The more immediate question for a GCC is its role: if the captive centre decides any purposes of processing itself, it is a Data Fiduciary for that activity and carries the full set of fiduciary obligations — providing notice, ensuring a valid consent or legitimate-use basis, appointing a Grievance Officer, notifying breaches, and honouring Data Principal rights. If it acts purely on the parent's instructions, it is a Data Processor with narrower but still real obligations, principally around security and acting within the terms of a data processing agreement. Many GCCs are a mix of both across different workstreams.

A GCC's own Indian employees are also Data Principals whose HR data is Indian personal data, which brings notice, security and rights obligations regardless of where the parent sits. Niti Bharat helps GCCs and captive centres classify their processing correctly, put a DPDP-aligned agreement in place with the foreign parent, and confirm whether any sector localisation rule actually applies — turning an ambiguous localisation question into a clear, documented position before the expected May 2027 enforcement date.

Get the GCC DPDP localisation and obligations pack (free)

A practical PDF for captive centres: how to classify your fiduciary vs processor role, which data (if any) must stay in India, and a parent-GCC data processing agreement checklist.

Frequently Asked Questions

Does the DPDP Act require GCCs to store all data in India?+
No. The DPDP Act does not impose broad data localisation. It uses a negative-list transfer model, so data can generally flow to a foreign parent unless the government restricts the destination country. Localisation, where required, usually comes from sector regulators (like RBI for payment data), not the DPDP Act itself.
Is a GCC a Data Fiduciary or a Data Processor?+
It depends on the activity. If the GCC decides the purposes and means of processing, it is a Data Fiduciary for that activity. If it acts only on the parent's instructions, it is a Data Processor. Many GCCs are both across different workstreams and should classify each one.
What about the GCC's own employee data?+
A GCC's Indian employees are Data Principals under the DPDP Act, and their HR data is Indian personal data. The GCC owes them notice, security and rights-handling, and can generally share that data with the parent under the negative-list transfer model, subject to its DPA.
Do we need an agreement with our foreign parent?+
Yes. A DPDP-aligned data processing agreement between the GCC and the foreign parent is strongly advisable — it allocates security, breach-notification and processing responsibilities, which matters because the data fiduciary remains accountable for the data even after it leaves India.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
GenAI Consent & Data-Use CheckerGrievance Redressal Mechanism Under DPDP Act 2023Hospital Patient Consent Flow MapperDPDP Consent Validity CheckerSee all Reference & Checklists tools →📝 Does DPDP Apply to Foreign Companies India📝 Does DPDP Apply to My Company