For considerable time, many multinational enterprises have considered their Indian Global Capability Centres (“GCCs”) as an extension of the parent company in terms of data protection. Essentially, the overseas parent was considered as the controller of personal data and the Indian GCC was considered as a processor acting on the instructions of the parent. As such, many organisations entered into intra-group Data Processing Agreements (“DPAs”) on this controller-processor basis.
The Digital Personal Data Protection Act, 2023 (“DPDP Act”) questions the assumption that this characterisation will always hold true. The Act recognizes the distinction between a Data Fiduciary and a Data Processor, but places emphasis on who decides the purpose and the means by which personal data will be processed. As GCCs evolve from operational support centres to strategic business hubs, organisations should question whether the traditional processor-only model is actually reflective of operational reality.
The DPDP Act adopts a functional approach
The DPDP Act defines Data Fiduciary as any person who, alone or in conjunction with others, determines the purpose and means of processing personal data. By contrast, a Data Processor processes personal data for a Data Fiduciary.[1]
The distinction is significant because the Act imposes primary statutory responsibility on the Data Fiduciary. Section 8 expressly provides that a Data Fiduciary remains responsible for complying with the Act, irrespective of any agreement to the contrary or the involvement of a Data Processor. It also permits a Data Fiduciary to engage a Data Processor only under a valid contract.[2]
Thus, the legal status of an entity cannot be derived merely from contractual language. The intra-group DPA is of course still important, but so is the practical division of decision-making powers within the corporate group.
Modern GCCs often do more than execute instructions
The traditional outsourcing model was based on the premise that it was the overseas parent that determined why and how personal data would be processed, with the captive centre simply following instructions. Today’s GCCs often function quite differently.
Many Indian centres develop internal technology solutions, manage enterprise-wide HR systems, implement cyber security controls, design AI-based analytical tools, conduct fraud monitoring and support compliance across multiple jurisdictions. These activities may involve decisions about how personal data is collected, retained, organised or used.
This does not necessarily mean that all GCCs will automatically become Data Fiduciaries under the DPDP Act. However, the processor-only characterisation requires further examination when a GCC participates in the determination of the purposes or means of processing, either alone or jointly with the parent company.[3]
The DPDP Act deliberately uses functional definitions, not labels based only on the corporate structure. Organisations should therefore regularly review whether contractual arrangements still reflect actual business operations.
Why the 2024 intra-group DPA may not be enough
Many multinational groups have updated their intra-group DPAs in anticipation of India’s new privacy framework. These contracts are still valid as Section 8 mandates a valid contract when a Data Processor processes personal data on behalf of a Data Fiduciary.[4]
Nevertheless, a DPA cannot alter the statutory allocation of responsibility if the underlying operational model has changed.[5]
For instance, if an Indian GCC independently determines retention periods for employee data, designs automated decision-making tools, establishes processing workflows or exercises meaningful discretion over the manner in which personal data is processed, regulators may look into whether those functions go beyond the role of a processor acting solely on another entity’s instructions.
This is not a conclusion forced by the DPDP Act. Rather, it is consistent with the more general principle that statutory definitions are to be understood in relation to the facts of processing, rather than the language of contracts alone.
Governance implications for multinational groups
Re-evaluating the function of a GCC is not just an academic exercise. This has real implications for governance, accountability and risk management. Organisations should consider whether governance documents, privacy policies, reporting structures and internal decision-making accurately reflect those responsibilities in cases where a GCC has a role in functions that affect the purposes or means of processing.[6]
It is equally important to document which entity makes key decisions related to data collection, processing, storage, security and deletion. Well-maintained governance records can assist organisations in evidencing compliance if questioned about the allocation of responsibilities under the DPDP framework. Multinationals should also ensure that privacy responsibilities are not informally spread across business units without proper oversight. As the GCCs grow in global operations, governance structures should be evolving to reflect operational realities.
Looking beyond contractual labels
The DPDP Act is based on the principle of accountability. It is intended to regulate the substance of processing of personal data, not the terminology used by organisations. For multinational groups this means that an intra-group DPA should not be viewed as the end of the compliance journey. Rather, it needs to fit into a wider governance framework that reflects how decisions about personal data are made in practice. The key question is not, therefore, whether a GCC has been described as a Data Processor in the past. The more pertinent question is whether the organization’s daily work is consistent with that description.
As Indian GCCs move up the value chain from execution centres to strategic business partners the answer might increasingly depend on operational reality and not historical assumptions. Organisations should now review their governance arrangements to ensure their legal documentation, internal accountability and business practices are aligned with the DPDP Act.[7]
[1] Digital Personal Data Protection Act, No. 22 of 2023, S 2(i), (k).
[2] Id. S 8(1)(2).
[3] Id. S 2(i), (k).
[4] Id. S 8(2).
[5] Id. S 8(1)
[6] Id. S3,S8
[7] Press Information Bureau, Government of India, DPDP Rules, 2025 Notified: A Citizen-Centric Framework for Privacy Protection and Responsible Data Use (Nov. 17, 2025).




