GDPR Article 28: Indian Offshore Processor Duties

GDPR Article 28 establishes the contractual and operational obligations that apply when a data controller engages a data processor to process personal data on its behalf. For Indian offshore development centres working with European Union (EU) clients, these obligations commonly cover data processing agreements, documented instructions, confidentiality, security measures, sub-processor authorisation, breach notification, audit rights and the return or deletion of personal data.
An Indian IT company does not automatically fall under every GDPR requirement simply because it provides services to an EU customer. However, when it processes personal data on behalf of an organisation subject to the General Data Protection Regulation (GDPR), the processing arrangement may bring it within the Regulation's scope. The exact obligations depend on the parties' roles, the nature of the processing and the circumstances described in GDPR Article 3.
For Indian offshore development centres, Article 28 is particularly relevant to software development, application maintenance, cloud operations, business process outsourcing, managed IT services and other engagements involving EU customer, employee or end-user information. EU clients typically examine contractual commitments, security controls, access management, sub-processor arrangements and evidence of compliance before and during an outsourcing relationship.
Strengthen Data Protection Practices With GDPR Compliance. Demonstrate Your Commitment to Privacy With INTERCERT.
What Is GDPR Article 28 and Why It Applies to Indian Offshore Development Centres?
GDPR Article 28 governs the relationship between data controllers and data processors. It requires controllers to use processors that provide sufficient guarantees of appropriate technical and organisational measures and establishes mandatory contractual terms for processing personal data on the controller's behalf.
For an Indian offshore development centre, Article 28 becomes relevant when its services involve handling personal data under the instructions of an EU client. For example, a software development company may access customer profiles, employee records, application logs containing identifiable information or production databases while delivering contracted services.
The location of the processor in India does not, by itself, determine whether GDPR applies. The controller's obligations, the processor's activities and the territorial scope of the Regulation must be considered together. Where GDPR applies to the processing arrangement, the parties must address the applicable processor requirements and any separate international data transfer obligations.
Article 28 in the Controller-Processor Relationship
A data controller determines the purposes and essential means of processing personal data, while a data processor processes that information on the controller's behalf. These roles depend on the actual activities and decision-making arrangements, not simply on the labels used in a contract.
For example, an EU e-commerce company may engage an Indian software development centre to maintain its customer management platform. If the Indian provider accesses customer information solely to perform contracted services under the EU company's instructions, it will generally act as a processor for that activity.
The EU client remains responsible for its controller obligations, while the Indian processor must comply with the processor obligations applicable under GDPR. If the Indian company independently determines the purposes and means of a particular processing activity, it may qualify as a controller for that activity instead. Different activities within the same commercial relationship can therefore have different roles.
Why EU Clients Apply Article 28 to Indian Service Providers
EU organisations remain accountable for selecting processors that offer sufficient guarantees concerning data protection and information security. Article 28 also requires a binding contract or other qualifying legal act that establishes the processor's obligations.
As a result, EU clients commonly review Indian vendors before granting access to personal data. Their checks may cover access permissions, confidentiality commitments, security incident procedures, encryption, retention practices, business continuity, subcontracting arrangements and the ability to demonstrate compliance.
These checks are relevant to commercial risk as well as regulatory obligations. An offshore provider that cannot demonstrate how it protects personal data may face delayed onboarding, additional contractual conditions, restricted system access or the loss of a proposed engagement.
When an Indian Offshore Development Centre Is a Processor
An Indian offshore development centre will generally act as a processor when it handles personal data on behalf of a client and under that client's instructions.
Common examples include developing or maintaining applications that contain personal data, hosting customer databases, processing employee information through outsourced systems, providing technical administration for client platforms and analysing personal data under an agreed service arrangement.
The classification must be determined for each relevant activity. An offshore provider that processes its own employee payroll information or manages its own customer relationships may act as a controller for those activities, even if it acts as a processor for an EU client's data.
GDPR Data Processor Obligations for Indian Offshore Development Centres
GDPR Article 28(3) sets out the principal contractual obligations for processors, while Article 28(4) addresses the appointment of other processors. Article 32 establishes security obligations for both controllers and processors, and Article 33(2) requires a processor to notify the controller of a personal data breach without undue delay after becoming aware of it.
Indian offshore development centres must translate these requirements into contractual commitments, access controls, operational procedures and verifiable records.
Processing Only on Documented Instructions
Under Article 28(3)(a), a processor must process personal data only on documented instructions from the controller, including instructions concerning transfers to a third country or an international organisation, unless applicable Union or Member State law requires otherwise. In that situation, the processor must inform the controller of the legal requirement before processing, unless the law prohibits such disclosure on important grounds of public interest.
For Indian IT companies, documented instructions may be established through a data processing agreement, service contract, approved technical specifications, authorised change requests or written operational instructions.
The provider should ensure that access to personal data is limited to authorised activities and that material changes to processing purposes are not made independently. If an instruction appears to infringe GDPR or other applicable data protection provisions, Article 28(3)(h) requires the processor to inform the controller.
Confidentiality Commitments for Personnel
Article 28(3)(b) requires the processor to ensure that persons authorised to process personal data are committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
For offshore development centres, this can involve employment confidentiality clauses, non-disclosure agreements, role-based access permissions and procedures governing employee access to client systems. Personnel should receive instructions appropriate to their responsibilities and understand the restrictions applicable to the personal data they handle.
Confidentiality obligations should also address access by temporary staff and other authorised personnel. Access should be removed when a person's role ends or no longer requires access to the relevant information.
Security of Processing Measures
Article 28(3)(c) requires the processor to take the measures required under Article 32. The appropriate measures depend on the risks presented by the processing, the state of the art, the costs of implementation and the nature, scope, context and purposes of processing.
Relevant controls can include encryption, pseudonymisation where appropriate, access management, multi-factor authentication, logging, vulnerability management, secure software development practices, backup arrangements and procedures for restoring availability after an incident.
For an Indian development centre, the necessary controls depend on the information being processed and the access granted by the EU client. A provider handling sensitive personal data or production systems may face different risk considerations from a provider working exclusively with synthetic test data.
The objective is not to apply an identical security checklist to every engagement. It is to maintain measures appropriate to the actual processing risks and the contractual requirements.
Data Subject Rights Handling
Article 28(3)(e) requires the processor to take appropriate technical and organisational measures, insofar as possible, to assist the controller in fulfilling its obligation to respond to requests to exercise data subject rights.
Depending on the service, these rights may include access, rectification, erasure, restriction of processing, data portability and objection. The applicability of individual rights depends on the relevant GDPR provisions and circumstances.
An Indian offshore provider may need to locate records, retrieve relevant information, correct inaccurate data, delete specified records or restrict processing when instructed by the controller. The processor should establish a clear process for identifying such requests, referring them to the controller and completing authorised technical actions within agreed timelines.
The processor does not automatically become responsible for independently deciding every request. Its role is to perform the contractual and statutory duties applicable to its processing activities while enabling the controller to meet its own obligations.
Breach Notification to the Controller
Under Article 33(2), a processor must notify the controller of a personal data breach without undue delay after becoming aware of it. Article 28(3)(f) also requires the processor to assist the controller in ensuring compliance with the relevant obligations under Articles 32 to 36, taking into account the nature of processing and the information available to the processor.
A data processing agreement should therefore establish a practical incident notification process. It can specify a contractual reporting deadline, escalation contacts, the information to be shared and the procedure for providing updates as the investigation develops.
For Indian offshore development centres, incidents may involve unauthorised database access, exposed cloud storage, compromised credentials, malicious code, lost devices or unintended disclosure of customer information. The provider should assess whether an incident constitutes a personal data breach under GDPR and notify the controller without undue delay when the Article 33(2) requirement applies.
The GDPR does not establish a universal 72-hour deadline for processors to notify controllers. The 72-hour rule in Article 33(1) applies to a controller's notification to the supervisory authority, where required. Contracts may set shorter deadlines for processors to enable controllers to meet their own obligations.
Deletion or Return of Data at Contract End
Article 28(3)(g) requires the processor, at the controller's choice, to delete or return all personal data after the end of the processing services and delete existing copies, unless Union or Member State law requires storage.
Offshore service contracts should specify how data is returned, how deletion is verified, how backups are treated and how any legally required retention is handled. The arrangement should also address personal data held in development environments, support tickets, exports, logs and other locations where copies may exist.
The provider should not retain personal data indefinitely simply because it was previously necessary for service delivery. Any continuing retention must be consistent with the applicable legal requirements and contractual terms.
Making Information Available for Audits
Article 28(3)(h) requires the processor to make available to the controller all information necessary to demonstrate compliance with Article 28 and to allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
For Indian offshore development centres, evidence may include security policies, access records, incident reports, sub-processor registers, training records, risk-related information, relevant independent audit reports and certification records where available.
Contracts can define how audits are scheduled, how confidential information is protected, how remote inspections are performed and how findings are addressed. These arrangements should not remove the controller's rights under Article 28(3)(h).
GDPR Data Processing Agreement Requirements for Indian IT Firms
A data processing agreement (DPA) is a core contractual requirement when a controller engages a processor for processing personal data covered by Article 28. Article 28(3) specifies the matters that the contract or other qualifying legal act must address.
For Indian IT firms, a DPA should reflect the actual services, data flows, security responsibilities, access arrangements and subcontracting structure. A generic agreement that does not accurately describe the processing may leave important responsibilities unclear.
Mandatory Clauses Under Article 28(3)
The DPA must set out the subject matter and duration of processing, its nature and purpose, the types of personal data, the categories of data subjects, and the controller's obligations and rights.
It must also establish the processor's obligations concerning documented instructions, confidentiality, security, sub-processors, data subject rights, assistance with compliance, deletion or return of personal data, and the provision of information and audit rights.
The agreement should reflect the practical division of responsibilities between the EU client and the Indian provider. For example, it should clarify who authorises access, how incidents are escalated, which party communicates with data subjects and how evidence is provided during audits.
Article 28 does not prescribe one universal DPA template for every industry. The terms must meet the applicable legal requirements and be appropriate to the processing arrangement.
Subject Matter, Duration, Nature and Purpose of Processing
The agreement should describe what the provider does with personal data and for how long. It should identify the relevant services, processing activities and purposes, rather than relying only on a broad statement that the provider will deliver IT services.
For example, a DPA for application maintenance may cover access to customer accounts, troubleshooting, database administration and the testing of software features. The duration should correspond to the relevant processing arrangement, including any agreed period for returning or deleting information after service termination.
Clear descriptions help both parties determine whether actual processing remains within the agreed scope.
Types of Personal Data and Categories of Data Subjects
The DPA must identify the types of personal data and categories of data subjects involved. Depending on the engagement, these may include names, business contact details, account identifiers, transaction records, employee information or technical logs that identify individuals.
Categories of data subjects might include the EU client's customers, employees, suppliers or platform users. Where special categories of personal data under Article 9 or information relating to criminal convictions and offences under Article 10 are involved, the arrangement requires particular attention to the applicable legal conditions and security risks.
An accurate data inventory enables the parties to establish appropriate access restrictions, retention rules and security measures.
GDPR Article 28 Contractual Obligations for Indian Processors
Contractual terms determine how the statutory processor requirements operate in an offshore engagement. Indian service providers should ensure that the DPA and the main service agreement establish clear responsibilities for instructions, subcontracting, audits, security incidents and liability.
Instruction-Based Processing Clauses
The agreement should establish how the controller issues documented instructions and how the processor identifies authorised changes. It should also address the process for raising concerns when an instruction appears inconsistent with applicable data protection law.
A clearly defined instruction process reduces the risk of employees using client data for unrelated testing, analytics or product development without an appropriate legal basis and authorisation.
Sub-Processor Authorisation and Flow-Down Terms
Article 28(2) requires a processor to obtain the controller's prior specific or general written authorisation before engaging another processor. Where general written authorisation applies, the processor must inform the controller of intended changes involving the addition or replacement of sub-processors, giving the controller an opportunity to object.
Under Article 28(4), the processor must impose the same data protection obligations as those set out in the controller-processor contract on the sub-processor through a contract or other qualifying legal act, particularly sufficient guarantees concerning appropriate technical and organisational measures.
If a sub-processor fails to fulfil its data protection obligations, the initial processor remains fully liable to the controller for the sub-processor's performance of those obligations under Article 28(4).
For Indian offshore development centres, sub-processors may include cloud hosting providers, outsourced support teams, monitoring vendors or specialist technology providers. The provider should maintain an accurate record of relevant sub-processors, their processing activities, locations and authorisation status.
Audit and Inspection Rights Clauses
The DPA should reflect the controller's rights to obtain necessary compliance information and conduct or commission audits and inspections. Practical arrangements can define notice periods, access procedures, audit frequency and safeguards for other customers' confidential information.
Independent audit reports and recognised certifications can contribute to the evidence available to a controller. However, they do not automatically replace the controller's rights under Article 28(3)(h), and their relevance depends on the scope and currency of the evidence.
Liability and Accountability Terms
The contract should distinguish the parties' responsibilities for processing, security incidents, regulatory cooperation, subcontracting and contractual breaches. It should also specify relevant notification procedures, cooperation obligations and any agreed allocation of commercial risk.
Contractual provisions cannot simply remove statutory responsibilities imposed by GDPR. Article 82 establishes rules concerning liability and compensation, including circumstances in which controllers and processors may be liable for damage caused by infringements. A processor is subject to the specific conditions in Article 82(2), including where it fails to comply with obligations directed specifically at processors or acts outside or contrary to lawful controller instructions.
The actual liability of each party depends on the facts, the applicable provisions and the circumstances of the infringement.
GDPR Processor Requirements for EU Clients Outsourcing to India
EU controllers must select processors that provide sufficient guarantees of appropriate technical and organisational measures. Article 28(1) establishes this requirement, while Article 28(3) sets out the contractual framework governing the relationship.
For EU clients outsourcing to India, vendor evaluation commonly examines the provider's security practices, organisational controls, processing locations, sub-processors, incident handling and ability to demonstrate compliance with contractual commitments.
Processor Due Diligence Expectations of EU Controllers
Before granting access to personal data, an EU client may evaluate the Indian provider's information security programme, personnel confidentiality arrangements, identity and access management, data retention practices and incident response capabilities.
The level of scrutiny should reflect the processing risk. A provider with privileged access to production databases or large volumes of customer information may face more extensive checks than a provider with access only to anonymised or synthetic data.
The controller must determine whether the processor offers sufficient guarantees for the proposed processing rather than relying exclusively on the provider's size, reputation or contractual assurances.
Sufficient Guarantees Under Article 28(1)
Sufficient guarantees involve more than signing a DPA. The controller must consider whether the provider has appropriate technical and organisational measures and can demonstrate the ability to meet the obligations relevant to the processing arrangement.
Evidence may include current security policies, access control records, vulnerability management information, incident response procedures, employee confidentiality commitments and independent assurance reports. The exact evidence required depends on the nature of the service and the associated risks.
A certification can provide useful evidence of a defined management system or control framework, but it should be evaluated alongside the actual scope of services and processing activities.
Vendor Questionnaires and Evidence Requests
EU clients may use vendor questionnaires to understand how Indian service providers manage personal data. Questions commonly address data locations, access permissions, encryption, security incidents, employee access, retention, deletion and sub-processor arrangements.
The provider should respond accurately and consistently with its actual practices. Supporting records should be current, relevant to the service in question and consistent with contractual commitments.
Where a requested control does not apply, the provider should explain the reason and identify any relevant alternative measures rather than claiming that a control exists when it does not.
Ongoing Monitoring of the Indian Processor
Controller oversight does not end when the contract is signed. Depending on the risk and contractual arrangements, ongoing monitoring may include periodic reviews of security evidence, changes to sub-processors, incident reports, material changes to processing and the renewal of relevant assurance certificates.
Indian providers should ensure that their documented practices remain consistent with the services being delivered. Changes to hosting locations, access models, third-party providers or processing purposes may require contractual review and further authorisation.
Cross-Border Transfer Requirements for Indian Processors
GDPR Article 28 addresses the controller-processor relationship, but it does not, by itself, establish a lawful basis for transferring personal data from the EU to India. International transfers must be evaluated separately under Chapter V of GDPR.
For offshore development centres, the relevant questions include who transfers the data, which organisations receive it, where remote access takes place, whether onward transfers occur and which transfer mechanism applies.
Transfers from the EU to India Under GDPR
Where an EU organisation transfers personal data to a separate Indian entity, the parties must assess the applicable Chapter V requirements. India does not benefit from a general EU adequacy decision that would permit unrestricted transfers on the basis of adequacy.
Depending on the circumstances, a transfer may rely on appropriate safeguards under Article 46, subject to the applicable requirements. Article 49 provides specific derogations for certain situations, but these are not a general substitute for an appropriate transfer framework for routine, ongoing outsourcing.
The analysis should consider the actual data flow and the legal relationship between the exporter and importer.
Standard Contractual Clauses Alongside Article 28 Terms
The European Commission's Standard Contractual Clauses (SCCs) can provide an appropriate transfer mechanism where the relevant conditions are met. The 2021 SCCs include modular clauses for different controller-processor relationships and transfers to third countries.
An EU controller and an Indian processor may use the relevant controller-to-processor module, depending on their roles and the circumstances. The parties must select the correct module, complete the applicable annexes and meet the requirements associated with the chosen clauses.
The SCCs and the Article 28 DPA address related but distinct matters. The parties should ensure that the transfer mechanism and the processing contract are consistent and collectively address the applicable legal requirements.
Onward Transfers and Sub-Processors in India
An Indian processor may engage another provider or transfer personal data to an additional location as part of its service delivery. These arrangements require both contractual scrutiny under Article 28 and a separate assessment of any applicable international transfer requirements.
The processor should maintain visibility into its sub-processors, processing locations and relevant data flows. Where SCCs apply, the parties must also comply with the applicable requirements concerning onward transfers and any relevant transfer restrictions.
A change in hosting region or the addition of a third-party service can affect the original transfer arrangement. Such changes should be evaluated before personal data is moved or made accessible through the new arrangement.
GDPR Article 28 Compliance for Indian Service Providers
GDPR Article 28 compliance for Indian service providers depends on the combination of appropriate contractual terms, operational controls and evidence demonstrating that the provider meets its obligations. A signed DPA alone does not establish that processing practices comply with the agreement.
Indian offshore development centres should be able to explain what personal data they handle, why they handle it, who can access it, which third parties are involved, how incidents are reported and how data is returned or deleted when services end.
Evidence EU Clients Expect from Indian Processors
The evidence requested will vary according to the services and the risks involved. Common examples include a current DPA, a processing activity inventory, an approved sub-processor list, information security policies, access management records, confidentiality commitments, incident response procedures and relevant audit or certification reports.
The provider should also be able to demonstrate how it fulfils data subject requests, manages deletion, restricts processing to documented instructions and responds to client audit requests.
Evidence should reflect actual operations. An outdated policy or certificate that does not cover the relevant service may be insufficient to demonstrate that the current arrangement meets the client's requirements.
Technical and Organisational Measures Under Article 32
Article 32 requires controllers and processors to implement security measures appropriate to the risk. It identifies relevant considerations and examples, including pseudonymisation and encryption, ongoing confidentiality, integrity, availability and resilience, timely restoration of availability and access to personal data, and regular testing and evaluation of security measures.
For Indian IT providers, these measures may include multi-factor authentication, least-privilege access, network segmentation, secure development controls, vulnerability testing, monitoring, backup validation and incident response exercises.
The controls should be proportionate to the data and systems involved. For example, access to production databases containing customer information may require stronger restrictions, monitoring and approval procedures than access to a development environment populated with synthetic data.
The provider should also evaluate whether the controls remain effective as its systems, threats and service arrangements change.
Records of Processing Activities for Processors
Article 30(2) requires processors and, where applicable, their representatives to maintain a record of all categories of processing activities carried out on behalf of each controller. The record must contain the information specified in that provision, including the relevant categories of processing, transfers to third countries or international organisations where applicable, and a general description of technical and organisational security measures.
The limited exemption in Article 30(5) applies only where its conditions are met. Among other things, it generally does not apply to organisations with fewer than 250 employees where the processing they carry out is likely to result in a risk to individuals' rights and freedoms, is not occasional, or includes special categories of data or personal data relating to criminal convictions and offences.
Because offshore development work may involve regular processing of client information, Indian providers should determine whether they fall within the exemption rather than assuming that company size removes the record-keeping requirement.
Records should accurately reflect the provider's processing activities and be updated when material changes occur.
Role of ISO/IEC 27001 and ISO/IEC 27701 as Assurance Evidence
ISO/IEC 27001 specifies requirements for an information security management system (ISMS). It provides a structured framework for managing information security risks and establishing, operating, monitoring and continually improving an information security management system within a defined scope.
ISO/IEC 27701 specifies requirements and provides guidance for a privacy information management system. It can be relevant to organisations seeking a structured approach to managing privacy-related responsibilities as controllers and processors, subject to the applicable edition and certification scope.
For Indian offshore development centres, independently verified certification can provide EU clients with evidence that a defined management system has been assessed against the relevant standard. The certificate's scope, validity, covered locations and applicable services should be examined to determine its relevance to a particular outsourcing arrangement.
Neither ISO/IEC 27001 nor ISO/IEC 27701 certification automatically proves compliance with every requirement of GDPR Article 28. GDPR compliance depends on the applicable legal obligations, contractual arrangements and actual processing practices.
Independent Certification and Third-Party Assurance for EU Clients
Independent certification can provide evidence of a defined management system and contribute to vendor assurance reviews. For Indian IT companies serving EU customers, relevant certification may demonstrate that specified information security or privacy management processes have undergone an independent assessment.
The value of certification depends on the standard, the certification scope, the organisation and locations covered, and the controls relevant to the client's services. EU clients may still request additional evidence concerning DPAs, transfer mechanisms, sub-processors, incident notification and data deletion.
INTERCERT provides independent certification and assurance services, including services relevant to information security and privacy management systems. Indian offshore development centres can explore the applicable certification scope and assessment requirements to determine which assurance options are relevant to their operations.
Common Article 28 Gaps Found in Indian Offshore Development Centres
Article 28-related weaknesses often arise when contractual commitments do not match actual service delivery. Gaps can affect the provider's ability to demonstrate compliance, satisfy client requirements and maintain consistent data protection practices.
Incomplete or Outdated Data Processing Agreements
A DPA may omit important processing details, use an outdated sub-processor list or fail to reflect changes in service delivery. An agreement may also describe broad IT services without clearly identifying the data, processing purposes, retention arrangements or responsibilities of each party.
Indian providers should review agreements when services, data categories, hosting locations or subcontracting arrangements change. Contractual terms should remain aligned with actual processing activities.
Uncontrolled Sub-Processor Use
A provider may introduce a new cloud service, monitoring tool or external support provider without following the authorisation process specified in the DPA. This can create contractual and regulatory concerns, particularly where the new provider receives personal data or can access it remotely.
A maintained sub-processor register, a defined approval process and periodic review of third-party access can reduce this risk. Any international transfers involving the new provider must also be evaluated separately.
Weak Breach Notification Timelines
Contracts that do not establish a clear incident escalation process can delay communication between the Indian provider and the EU controller. The absence of defined responsibilities may also make it difficult to gather the information needed to assess the incident.
The processor's legal obligation is to notify the controller without undue delay after becoming aware of a personal data breach. Contractual notification deadlines should be designed to enable timely escalation and should not be treated as permission to delay notification until a deadline expires.
Inadequate Evidence During Client Audits
An organisation may have policies and procedures but be unable to demonstrate that they are followed. Examples include missing access review records, incomplete processing inventories, expired certification, inconsistent sub-processor lists or insufficient evidence of deletion.
Maintaining accurate, current and relevant records makes it easier to demonstrate how the provider meets contractual and applicable statutory requirements. Evidence should correspond to the actual scope of the engagement and the processing risks.
Consequences of Article 28 Non-Compliance for Processors and EU Clients
Non-compliance with Article 28 can expose Indian offshore development centres and EU clients to contractual, operational and regulatory consequences. The specific impact depends on the nature of the failure, the parties' roles, the applicable GDPR provisions and the circumstances of the processing.
Processor Liability and Regulatory Exposure
Under Article 82, a processor may be liable for damage caused by processing where it has failed to comply with obligations specifically directed at processors or has acted outside or contrary to lawful controller instructions. The provision also sets out conditions under which controllers and processors may be liable for the same damage.
GDPR administrative fines are not automatic for every contractual failure. Article 83 establishes the framework for administrative fines, with the applicable level depending on the infringed provision and the circumstances of the case. Other corrective measures may also be available to supervisory authorities under Article 58.
Indian providers should not assume that operating outside the EU removes all potential exposure. The Regulation's territorial scope, the processing arrangement and the applicable enforcement circumstances must be considered.
Contractual and Commercial Impact on Offshore Engagements
A failure to meet Article 28 obligations may lead to additional contractual conditions, restricted access to client systems, remediation requirements, suspension of data processing or termination of a service agreement where the relevant contract permits it.
For Indian IT firms, the commercial consequences may extend to vendor onboarding, renewal discussions and future procurement decisions. EU clients often require evidence that providers can maintain the agreed security and privacy controls throughout the engagement.
Consistent contractual compliance and credible assurance evidence can therefore be important to maintaining business relationships with EU customers.
Reinforce GDPR Compliance and Data Privacy Practices. Build Trust in Personal Data Protection With INTERCERT.
Article 28 Compliance Checklist for Indian Offshore Development Centres
Indian offshore development centres can use the following checklist to review whether their processing arrangements address the principal requirements of GDPR Article 28. The checklist is a practical review tool and does not, by itself, establish legal compliance.
- Confirm whether the Indian entity acts as a controller or processor for each relevant processing activity.
- Verify that GDPR applies to the processing arrangement and identify the applicable territorial and legal requirements.
- Maintain a written DPA or other qualifying legal act that meets Article 28(3).
- Specify the processing subject matter, duration, nature, purpose, data categories and categories of data subjects.
- Establish a documented process for receiving, recording and following controller instructions.
- Ensure authorised personnel are bound by confidentiality obligations.
- Maintain security measures appropriate to the risks under Article 32.
- Define procedures for referring and responding to data subject rights requests.
- Establish an incident escalation process that enables notification to the controller without undue delay after awareness of a personal data breach.
- Define the controller's choice and the process for returning or deleting personal data at the end of services, subject to applicable legal retention requirements.
- Obtain the required prior written authorisation before engaging sub-processors and follow the applicable change notification and objection process.
- Ensure sub-processor contracts impose the required data protection obligations.
- Maintain relevant processing records under Article 30 where required.
- Provide information needed to demonstrate compliance and preserve applicable audit and inspection rights.
- Assess international transfers separately under GDPR Chapter V and use an appropriate transfer mechanism where required.
- Maintain current evidence of security controls, contractual compliance and relevant independent assurance.
- Review changes to services, data categories, access permissions, hosting arrangements and sub-processors.
- Confirm that certification claims accurately reflect the applicable standard, scope, locations and validity.
The checklist should be adapted to the provider's services, data flows, contractual commitments and risk profile. Where legal interpretation is required, the parties should obtain advice from a suitably qualified data protection professional.