Cyphertree Cyphertree

GDPR compliance when hiring in India

India is a third country under GDPR. This guide walks a European DPO through the transfer mechanism, roles, rights, and breach timelines that keep the hire lawful.

Updated

India is a third country. That sets the frame.

The European Commission has issued no adequacy decision for India. For a data protection officer, that single fact decides the shape of the file. Employing someone in India means personal data moves from the EEA to a country GDPR treats as a third country, so the hire lives under Chapter V, the rules on transfers. Get Chapter V right and the rest of the employment relationship sits on solid ground.

This guide is written for the legal or DPO reader who already knows GDPR and wants the India-specific detail: the transfer mechanism, the two sets of law in play, who holds which role, and where the timelines differ.

The transfer mechanism: EU Standard Contractual Clauses

With no adequacy decision, the lawful route for EEA-to-India transfers is the European Commission's Standard Contractual Clauses, Implementing Decision (EU) 2021/914. For an EU company hiring through an Employer of Record, the applicable set is Module Two, Controller to Processor. The European client determines the purposes and means of processing employee data; the Indian EOR processes on documented instructions.

The SCCs are incorporated by reference into the Data Processing Agreement, and where the DPA and the clauses conflict, the SCCs prevail. Two documents complete the Chapter V file:

  • A Transfer Impact Assessment that evaluates Indian law and the safeguards applied to the data.
  • Supplementary measures that back the clauses in practice: encryption in transit and at rest, access controls, and audit logging.

These are the substance a supervisory authority looks for behind the signed clauses, and they are the reason a transfer holds up under scrutiny.

The Indian side: the DPDP Act 2023

India now has its own baseline. The Digital Personal Data Protection Act, 2023 gives the Indian employee, the Data Principal, defined rights and gives the EOR obligations as a data processor. Under the DPDP Act, transfers to countries not on the Indian government's restricted list are permitted, so the flow runs in both directions. Data retention for payroll, PF, ESI, and tax records follows Indian statutory periods, and those periods sit inside the DPA so the retention picture stays predictable for the controller.

Controller and processor roles

The role split is the load-bearing part of the arrangement, so it pays to state it plainly:

  • The European company is the controller under GDPR, and the data fiduciary under the DPDP Act. It decides why and how employee data is processed.
  • The EOR is the processor under GDPR, and the data processor under the DPDP Act. It processes payroll, tax, onboarding, performance, and recruitment data on the controller's documented instructions, for those purposes alone.
  • The Indian employee is the data subject, the Data Principal, whose data is protected across both regimes.

Each processing activity rests on a defined GDPR lawful basis. Payroll and tax computation run on Art. 6(1)(c), a legal obligation. Employee lifecycle management and electronic signatures run on Art. 6(1)(b), contract. AI candidate ranking in the ATS runs on Art. 6(1)(a), consent, and stays consent-gated. The full mapping is set out in the DPA.

Data subject rights, in practice

The Indian employee holds the GDPR rights the DPO knows well: access (Art. 15), rectification (Art. 16), erasure (Art. 17), portability (Art. 20), and restriction (Art. 18). The DPDP Act gives parallel rights on the Indian side, together with a grievance route. Because the EOR acts as processor, it assists the controller in answering these requests inside committed response windows, and forwards any request it receives directly to the controller rather than acting alone. The controller keeps the decision; the processor supplies the data and the assist.

Two breach clocks, kept separate

This is where files most often blur two obligations that stay distinct. Keep the clocks apart:

  • Processor to controller, 24 hours. Under the DPA, the EOR notifies the controller without undue delay and no later than 24 hours after becoming aware of a personal data breach, with the nature of the breach, the categories and approximate number of data subjects affected, likely consequences, and remedial measures.
  • Controller to supervisory authority, 72 hours. The 72-hour deadline in GDPR Art. 33 runs to the supervisory authority and is the controller's obligation, not the processor's. The EOR assists that filing and assists Art. 34 notice to affected data subjects where required.

Separately, under Section 8(6) of the DPDP Act, the EOR notifies the Data Protection Board of India without delay of a breach affecting Data Principals in India. Three distinct duties, three distinct recipients.

A note on verification

Cyphertree holds no SOC 2 or ISO 27001 certification, and this guide claims none. The posture here rests on the binding contract and on measures a controller can inspect: the SCCs and DPA, a documented Transfer Impact Assessment, encryption in transit and at rest, PostgreSQL Row-Level Security for tenant isolation, and audit logging of PII operations. Audit rights in the DPA let the controller, or an independent auditor, verify the arrangement once a year. The value for a DPO is a file that stands on documents open to inspection, not on a badge.

For the technical and organisational measures behind these commitments, see security. For the binding terms, roles, and breach obligations in full, see the Data Processing Agreement.

BUILT QUIETLY IN PUNE · SHIPPING ACROSS EUROPE

See it work with your team.

20-minute demo with the founder. No slides, no pitch deck. We’ll set up a real employee live and you’ll watch payroll run on your numbers.