Regulation · EU
Standard Contractual Clauses and the transfer impact assessment
This is the inbound direction — personal data coming from Europe to you. For an Indian firm serving European customers the transfer mechanism is a schedule in the contract, and a questionnaire you will be asked to answer accurately.
Facts checked — 2026-09-11
What does a transfer impact assessment ask?
Transfers of personal data out of the EEA are restricted. Without an adequacy decision for India, they typically rely on Standard Contractual Clauses, accompanied by an assessment of whether the law and practice in the destination country undermine the protection those clauses promise. Note the direction of the presumption: under the GDPR a transfer is prohibited until something permits it, which is the reverse of India’s own rule for data leaving.
Practically, your customer sends you a questionnaire. The useful thing is to answer it precisely: where the data physically sits, which of your staff can access it and from where, under what legal circumstances a third party could compel disclosure, and what technical measures — encryption, key custody, access controls, pseudonymisation — reduce that exposure.
Answer it once, accurately, and keep the answers. The same questions arrive from every European customer, and the firms that answer precisely move through procurement noticeably faster than the ones improvising each time.
The bottom line
Prepare the answers once and reuse them. And keep the two directions straight — the rules governing data coming to you from Europe are not the rules governing data leaving India.
Related services
ISO/IEC 27701 — Privacy Information Management
Turn privacy from a policy document into a management system, with the records a regulator or an enterprise buyer will ask to see.
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
Related insights
Regulation · India
Is the DPDP Act in force? What applies today, and the deadline that matters
The Act is law today and its obligations bite on 13 May 2027. Penalties reach ₹250 crore, and the work that takes longest is the work nobody has started.
Regulation · EU
Does the GDPR apply to an Indian company? Scope, roles and the EU representative question
Most Indian firms are caught through a contract rather than by a regulator — and most do not need the EU representative they are being sold.
Regulation
Breach notification: the clock starts before you know what happened
Both regimes start counting when you become aware — and India’s rules have no risk threshold for telling the people affected.