A Global Capability Centre (GCC) or captive centre in India is a Data Processor — and often a Data Fiduciary — under the DPDP Act 2023 for the Indian personal data it handles, even though it serves a foreign parent. The DPDP Act itself does not mandate broad data localisation: it uses a negative-list transfer model, so data can generally flow to the parent abroad unless the government restricts a country. However, sector-specific rules (such as RBI directions for payment data) and Significant Data Fiduciary obligations can require certain data to stay in or be mirrored in India. This checker assesses whether your GCC needs to localise, and what else applies.
Running a captive centre or GCC in India for a global parent? Check whether you actually need to localise data in India under the DPDP Act — and what obligations really apply.
This is one of the most common questions from Global Capability Centres and captive units, and the answer surprises many teams: the DPDP Act 2023 does not impose broad, economy-wide data localisation. It uses a negative-list transfer model under which personal data can generally be transferred outside India — including to a foreign parent — unless the Central Government notifies a specific country as restricted. So the mere fact that a GCC serves a parent abroad does not, by itself, require the data to stay in India under the DPDP Act.
Where localisation obligations do arise, they typically come from sector-specific regulators rather than the DPDP Act. The clearest example is RBI's requirement that certain payment-system data be stored in India, which applies to entities in the payments ecosystem regardless of the DPDP transfer rule. Insurance, telecom and some other sectors have their own data-residency expectations. So the practical question for a GCC is less whether DPDP forces localisation and more whether a sector regulator with jurisdiction over its data does.
Localisation is often the wrong thing to worry about first. The more immediate question for a GCC is its role: if the captive centre decides any purposes of processing itself, it is a Data Fiduciary for that activity and carries the full set of fiduciary obligations — providing notice, ensuring a valid consent or legitimate-use basis, appointing a Grievance Officer, notifying breaches, and honouring Data Principal rights. If it acts purely on the parent's instructions, it is a Data Processor with narrower but still real obligations, principally around security and acting within the terms of a data processing agreement. Many GCCs are a mix of both across different workstreams.
A GCC's own Indian employees are also Data Principals whose HR data is Indian personal data, which brings notice, security and rights obligations regardless of where the parent sits. Niti Bharat helps GCCs and captive centres classify their processing correctly, put a DPDP-aligned agreement in place with the foreign parent, and confirm whether any sector localisation rule actually applies — turning an ambiguous localisation question into a clear, documented position before the expected May 2027 enforcement date.
A practical PDF for captive centres: how to classify your fiduciary vs processor role, which data (if any) must stay in India, and a parent-GCC data processing agreement checklist.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.