Inge Kristian Brodersen
Partner
Oslo
by Inge Kristian Brodersen and Akash Karmakar
Published:
An interview between Inge Kristian Brodersen, Partner in the technology department in Schjødt and Akash Karmakar, Senior Partner and Practice Head of the Technology Laws and Strategic Transactions Group at Panag, Babu & Sarangi.
For European businesses operating globally, transferring personal data outside the European Economic Area (EEA) has always been challenging. In the landmark Schrems II ruling of the Court of Justice of the European Union (CJEU) in July 2020, the CJEU confirmed the personal data transferred from EEA must continue to be accorded an equivalent level of protection, irrespective of the destination jurisdiction, and exporters are required to assess and verify, on a case-by-case basis, whether the laws or practices of the destination jurisdiction impinges or undermines the effectiveness of the relevant transfer safeguards.
India has been of particular interest and concern in this context, since it hosts a significant outsourcing and technology services industry, and companies, particularly from the United States and Europe, rely heavily on Indian data processors for IT services, business process outsourcing, back-office operations, and increasingly for automation, albeit with a human in the loop.
Yet, for several decades, this reliance has existed against a backdrop of legal uncertainty from a European perspective. Until 2023, India lacked a comprehensive personal data protection law, making it difficult for European data exporters to assess the level of protection afforded to personal data transferred there. Instead, a patchwork of legislation continues to govern personal data in India. While India has recently enacted the Digital Personal Data Protection Act, 2023 (DPDPA), the DPDPA is intentionally a concept-based legislation that is in a state of partial implementation, with phased implementation bringing the entirety of the law into force by May 12, 2027.
Once fully enforced, the DPDPA will mark a significant consolidation and streamlining of India’s privacy landscape, in a manner that’s broadly reminiscent of the GDPR. For European businesses, the immediate question is whether the DPDPA imposes additional compliance obligations in connection with transferring personal data to India, and whether the ‘essential equivalence’ test under the GDPR would be satisfied.
Following the Schrems II ruling, the European Data Protection Board (EDPB) issued recommendations[1] setting out a structured, six-step roadmap for assessing international data transfers, commonly referred to as a Transfer Impact Assessment (TIA). In essence, where the European Commission has not recognised a country as providing an adequate level of protection under Article 45 of the GDPR, exporters must rely on alternative transfer mechanisms set out under Article 46 of the GDPR, with the most common mechanism being the Standard Contractual Clauses (SCCs), and carry out a further assessment of whether such a mechanism works effectively in practice.
The most critical step in this six-step roadmap is determining whether anything in the destination country’s law and/or practices may impinge on the effectiveness of the safeguards of the transfer tool being relied upon, in the context of the specific transfer. In other words, the assessment is not limited to the law on paper; it also extends to how the system operates in practice, particularly in relation to access by public authorities.
In practical terms, this TIA requires the exporter to consider questions such as: Can public authorities in the destination country access the transferred data? Are such access powers proportionate and subject to effective oversight? Do data subjects have meaningful redress mechanisms? It also involves considering broader indicators, such as the existence of a comprehensive data protection framework, an independent supervisory authority, and adherence to international instruments that recognise data protection safeguards. The obligations or powers resulting from laws and practices will be considered to impinge on the commitments of Article 46 of the GDPR transfer mechanisms if they do not respect the essence of the fundamental rights and freedoms of the EU Charter, or exceed what is necessary and proportionate in a democratic society to safeguard important objectives.
Where problematic legislation or practices are identified, the exporter must identify and adopt supplementary measures, whether technical, contractual, or organisational, to bring the level of protection up to the EU standard of “essential equivalence”. If no effective supplementary measure can be found, the transfer must be suspended or terminated.
India does not currently hold an EU adequacy decision. Accordingly, for transfers to India, the introduction of the DPDPA, combined with its implementing rules and ongoing institutional developments, may change the factual basis on which European exporters should build their country risk assessments. The law introduces a statutory framework governing data processing, individual rights, and obligations on data fiduciaries. Whether and to what extent this brings India closer to meeting the " EU’s standard of “essential equivalence” is the kind of question that legal practitioners on the ground in India are well placed to address.
[1] EDPB.link
Schjødt recently had the opportunity to speak with Akash Karmakar, Senior Partner and Practice Head of the Technology Laws and Strategic Transactions Group at Panag, Babu & Sarangi, one of India's leading sector-specialist law firms with a strong practice in data protection and technology laws. We asked Akash to share his perspective on India's evolving data protection framework and what it means for European businesses transferring personal data to India.
Q1: India's Digital Personal Data Protection Act was enacted in 2023. For a European lawyer or business that has not followed this closely, can you give a brief overview of what the Act introduces and where things stand today in terms of implementation?
The DPDPA was notified as law in 2023 after it was promulgated into legislation by both houses of Parliament and had received the President’s assent. But here’s the important caveat that often gets lost in the headlines: the DPDPA has not yet become fully operational. In terms of its scope of applicability, the DPDPA regulates the processing of digital personal data, meaning data is either collected digitally or collected offline and subsequently digitised. The definition of personal data tracks closely with the GDPR: “any data about an individual who is identifiable by, or in relation to such data.” The consent standard is also familiar territory for European lawyers – it requires consent to be free, specific, informed, unconditional, and unambiguous, and signified through a clear affirmative action.
So, on paper, the alignment with European standards is quite deliberate. What I think European businesses will find particularly interesting is that the DPDPA doesn’t perfectly map to the GDPR and has distinct rights and additional circumstantial obligations that are unique to India. Beyond the expected rights of access, correction, and erasure, the DPDPA creates a right of grievance redressal and a right to nominate a representative to exercise the data subject’s rights in the event of death or incapacity.
That said, we are very much in a transitional phase. The law exists on the statute books, but its implementation architecture remains incomplete. I’d caution European businesses against treating the DPDPA as fully operational until the Data Protection Board of India begins issuing enforcement guidance.
Q2: Under the GDPR and the EDPB's recommendations on supplementary measures, European exporters must carry out a country risk assessment, i.e., a Transfer Impact Assessment, before relying on Standard Contractual Clauses for transfers to countries outside the EEA. A key part of that assessment is evaluating whether the law and practice in the destination country meets the EU's standard of "essential equivalence" in terms of data protection. In your view, does the DPDPA move India meaningfully closer to that standard, and in which respects do gaps remain?
Yes, the DPDPA does move India meaningfully closer to the GDPR’s standards of essential equivalence, at least at the level of legislative design. The fundamental elements of a consent-based framework, data subject rights, and conditional extraterritorial reach are all modeled on GDPR principles.
The DPDPA applies not just to processing within India but also to processing outside India, where it relates to offering goods or services to Indian data subjects. Conceptually, it mirrors the GDPR’s extraterritorial application and signals the direction in which India is heading.
But I’d be doing European exporters a disservice if I didn’t flag that there are several gaps, and that drawing too close a parallel would risk forcing a false equivalence. Current Indian privacy laws, including the DPDPA as it is enacted, are silent on several rights that European data subjects take for granted under Chapter III of the GDPR. There’s no right to restrict processing, no right to data portability, no right to object, and no explicit provisions dealing with automated decision-making and profiling. These are likely to be addressed in the subordinate rules, FAQS, or clarificatory guidance issued by the Government of India, but until those rules are framed and notified, this is a tangible gap that any diligent TIA should acknowledge.
One point that often gets overlooked is that the existing rules governing the processing of sensitive personal data and information under the Information Technology Act, 2000 (IT Act), which remain operative pending the full enforcement of the DPDPA, mirror many GDPR principles, and mandate security practices aligned with IS/ISO/IEC 27001 for the protection of sensitive personal information. However, these rules only apply to data collected from persons residing in India. As a result, their limited protective reach doesn’t extend to European data subjects whose data is transferred here. This is a material distinction for TIA purposes.
On the positive side, the DPDPA’s exemptions for State access of personal data are relatively narrowly circumscribed and are limited to sovereignty, security, friendly relations with foreign states, and public order. Given that it is still an ambivalent threshold, I think there’s a reasonable basis to argue that the DPDPA would not unduly prejudice a data exporter’s ability to comply with SCCs. But a “reasonable basis” is not a “settled position,” and it remains subject to interpretative latitude. European exporters need to be conscious of that distinction.
Q3: One of the most sensitive issues for European exporters assessing country risk is the question of government access to data — that is, whether public authorities in the third country have powers to access personal data in a manner that goes beyond what would be permissible under EU law. How does Indian law address this, and are there limitations on government access that a European data exporter should be aware of?
This is probably the issue that keeps European DPOs up at night, and rightly so. Let me walk through the framework, because it’s more structured than many European lawyers assume. Under the IT Act, specified government authorities, such as the Intelligence Bureau, Narcotics Control Bureau, CBI, and the National Investigation Agency, among others, can intercept, monitor, or decrypt information stored in or transmitted through computer resources. However, this should not be interpreted as a blank cheque, because every such interception requires prior approval by way of a written order from a competent authority. The grounds are defined but remain open to broad interpretation: sovereignty and integrity of India, defense, security of the state, friendly relations with foreign states, public order, or the prevention or investigation of specified offenses. In emergency situations, agencies can act first and ratify later, within a stipulated timeframe, but the ratification requirement is mandatory. There are also built-in sunset provisions that I think European exporters should find reassuring. Interception directions are valid for only 60 days, renewable, but capped at 180 days total. Records must be destroyed within 2 months of the interception ending, and government agencies themselves must purge their records every 6 months unless needed for ongoing functions. These are concrete temporal safeguards, not vague promises.
Under the erstwhile Criminal Procedure Code (replaced by the Bharatiya Nagarik Suraksha Sanhita, 2023), courts can issue search warrants, but any interception orders must pass the proportionality test laid down by the Supreme Court in Justice K.S. Puttaswamy v. Union of India, which has been nicknamed the ‘Privacy Judgment’. This is a four-pronged test asking whether the interference is: sanctioned by law, necessary in a democratic society for a legitimate aim, proportionate, and guarded by procedural safeguards against abuse. European lawyers will recognize the conceptual DNA of this test; it’s not dissimilar to the proportionality analysis under EU fundamental rights law.
Now, here’s where I think candour is important. Review committees do oversee the lawfulness of interception requests, and they can set aside non-compliant directions and order the destruction of intercepted data. But these committees comprise members of the executive branch, which means that the same branch that authorizes or carries out interception also plays a role in reviewing it. So, there is a legitimate question about whether this oversight is truly independent in the sense that Schrems II contemplates. The Indian government has publicly clarified that no agency has blanket permission to intercept data, and all activities follow statutory procedures. That’s encouraging, but the structural independence question remains the unaddressed elephant in the room for any TIA.
Q4: The EDPB's recommendations indicate that effective redress for data subjects is an important element of the country risk assessment. Under Indian law, what options does an individual — including a European data subject whose data has been transferred to India — have to seek redress if their data is misused or unlawfully processed?
This is actually one of the stronger aspects of the Indian framework, and it’s a point that often doesn’t get sufficient attention in European assessments. The fundamental right to privacy under Article 21 of the Constitution applies to all persons, not just Indian citizens. That essentially means that foreign nationals, including European data subjects, have the right to seek judicial protection before Indian courts. This is not a theoretical proposition but a settled position of constitutional law. Practically, an individual can challenge disproportionate government access to their data before Indian courts, invoking the proportionality test from the Privacy Judgment. The Supreme Court has been quite clear that the right to privacy can only be restricted by a law stipulating a procedure that is fair, just, and reasonable.
Indian courts have even recognized the privacy-protective remedies, including the right of foreign citizens to be forgotten, and orders directing the removal or destruction of evidence collected in breach of procedural safeguards. This right is currently a hypothetical concept with isolated judicial precedent that is still evolving. The DPDPA will materially strengthen the redress picture considerably, once it becomes fully operational. The right of grievance redressal will become a statutory right, and the Data Protection Board will serve as the adjudicatory body. But let me reiterate: as it stands today, several specific GDPR rights, including the right to restrict processing, data portability, the right to object, and protection from automated decision-making, simply aren’t available under Indian law. We expect the DPDPA and its implementing rules to fill these gaps, but European exporters need to factor that into their assessments today, whilst the uncertainty continues.
Q5: When advising Indian data processors who work with European clients, what are the most common compliance gaps you see in practice? And conversely, what do you think European data exporters most often overlook or misunderstand when assessing data transfers to India?
On the Indian side, with processors, the most common dissonance in practice that I see is treating SCCs as a mere contractual formality or a ‘rubber stamp’ rather than a substantive compliance framework. There can be a real disconnect between the commitments made in the SCCs, whether it relates to data subject rights, sub-processing chains, breach notification, government access, transparency, and what’s actually happening operationally.
Put simply, mere lip service to such standards without actual adoption does not materially satisfy the requirements of the GDPR. Security standards are another area. The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules) require reasonable security practices that are aligned with IS/ISO/IEC 27001 for sensitive personal information, but the rigor of implementation varies significantly across the industry. Some organizations treat it as a genuine security baseline; others treat it as a little more than certification to hang on a wall. From the European lens, the biggest mistake I see is the assumption that the absence of a comprehensive data protection law in India prior to the DPDPA meant there were no safeguards or legislative protections whatsoever. That’s simply not accurate. The IT Act and its SPDI Rules have been in place for years and mirror many GDPR principles. More importantly, the constitutional right to privacy, as interpreted by the Supreme Court in the Privacy Judgment, provides a foundational framework that predates the DPDPA entirely. Conversely, European exporters sometimes overlook a critical nuance: the existing SPDI Rules apply only to data collected from persons residing in India. Their protective reach doesn’t extend to European data subjects whose data is transferred to India. This distinction is absolutely critical when you’re conducting a TIA, and getting it wrong can lead to an assessment that’s either overly optimistic or unnecessarily pessimistic.
Q6: The EDPB recommends that data exporters re-evaluate their country risk assessments at appropriate intervals, particularly when significant legal or practical developments occur. Given that the DPDPA's implementing rules and the establishment of the Data Protection Board of India are still in progress, how would you advise European exporters to monitor developments in India on an ongoing basis? Are there specific signals or milestones they should watch for?
I’d advise treating the TIA as an evolving exercise, not something that’s locked down and filed away after the initial assessment. The Indian framework is still in active evolution, and the factual basis of your TIA could change materially in a relatively short period.
There are three specific milestones to watch. First, the phased commencement of the DPDPA’s substantive provisions, particularly those expected to take full effect on May 12, 2027. Second, the Data Protection Board of India being operational in practice, with the capacity and independence to adjudicate matters effectively. Third, how the new rules are interpreted, applied, and supplemented through official guidance, notifications, and early enforcement decisions. Beyond these legislative milestones, I’d also keep an eye on judicial developments, particularly decisions of the Supreme Court or High Courts that further interpret the scope of the proportionality test from the Privacy Judgment. Any changes to the composition or functioning of the review committees overseeing government interception could also materially alter the country risk assessment. My practical recommendation would be to engage Indian counsel who can flag material developments as they occur rather than relying on periodic reviews. In a landscape developing this quickly, annual check-ins may not be sufficient.
Q7: Looking ahead, how do you see the relationship between India's data protection framework and the EU's GDPR evolving? Is there a realistic prospect of India obtaining an adequacy decision from the European Commission, and do you have any thoughts on what would need to happen for that to become achievable?
The trajectory is clearly one of convergence, and I suspect that is by design, not as an inadvertent position that’s become the default position. The DPDPA is quite deliberately modelled on GDPR principles, and the Privacy Judgment’s proportionality test has conceptual parallels with the EU fundamental rights jurisprudence. India has consciously moved towards European equivalent standards with a view to aligning its framework with the global gold standard. As for an adequacy decision, I think it’s a realistic prospect over the longer term, particularly given the depth of Europe’s commercial reliance on Indian service providers, but several factors would need to align before that becomes achievable.
The DPDPA needs to be fully operational, and the Data Protection Board of India needs to demonstrate independence and effectiveness, not just exist on paper. The gaps in data subject rights, particularly data portability, the right to object, and automated decision-making protections, need to be addressed more comprehensively. Perhaps most importantly from a Schrems II perspective, the question of independent oversight of government surveillance needs to be addressed. The review committees currently comprise members of the executive branch, which raises the obvious question about structural independence. For an adequacy decision, the European
Commission would need to be satisfied about this point, and I don’t think it can be sidestepped.
That said, it is a settled position of Indian law that government interference with fundamental rights must be limited to what is strictly necessary, and that effective legal protection against such interference exists. On balance, I’m cautiously optimistic about an adequacy decision becoming a reality owing to the EU-India free trade agreement, the increasing collaboration between Europe and India, and the steady implementation and institutional development of India’s data protection laws. If there is one point I would emphasize, it is that a TIA should never be approached as a box-ticking exercise or with a predetermined conclusion in mind. No exporter should commence the assessment by assuming either that India is clearly compliant or that it is clearly deficient. The assessment has to be honest, fact-sensitive, and case-by-case. That is really the central lesson from Schrems II and the EDPB’s recommendations.
And the reason for that is quite simple: no two transfers are ever exactly the same. The nature of the data, the sector involved, the identity of the processor, the technical and organizational safeguards in place, the likelihood of government access, and the practical availability of redress can all vary significantly from one case to another. Even across sectors, the risk analysis may look very different. A transfer in the healthcare or financial services space, for example, may raise very different concerns from a transfer involving routine back-office support or limited operational data.
That is also why it is important not to freeze the analysis at a single point in time. TIAs need to remain dynamic. Legal frameworks evolve, implementing rules are clarified, institutions begin to function in practice, courts interpret rights more fully, and enforcement patterns start to emerge. In India, in particular, this is especially relevant because the framework is still developing. The DPDPA has clearly moved the conversation forward and signals a serious effort to align with global privacy standards, but the practical significance of that shift will depend on how the regime is implemented, interpreted, and enforced over time.
So, for European exporters, India should neither be written off nor waved through without a careful evaluation. The better approach is to assess each transfer on its own facts, keep the position under review, and remain attentive to legal and sector-specific developments as they unfold. In that sense, a good TIA is not really a one-time document; it is an ongoing process to inform and calibrate risk assessment.
This article was produced by Schjødt in collaboration with Panag Babu Sarangi. It is intended as a general overview and does not constitute legal advice. Businesses considering data transfers to India should seek tailored legal advice in light of their specific circumstances.
Akash Karmakar is a Senior Partner and Practice Head of the Technology Laws and Strategic Transactions Group at Panag, Babu & Sarangi.
Partner
Oslo
Partner
Oslo
Partner
Oslo
Partner
Oslo
Partner
Oslo
Partner
Oslo
Partner
Stavanger
Partner
Stavanger
Partner
Oslo
Associate
Stockholm
Managing Associate - Qualified as EEA lawyer
Oslo
Senior Lawyer
Oslo
Senior Associate
Oslo
Senior Associate
Stockholm
Associate
Stockholm
Associate
Oslo
Associate
Oslo