Every UK law firm or business that works with an offshore team in India eventually asks the same question: “Can we lawfully send them our client data?” The answer is yes, provided you do it properly. But the rules changed in 2026, and many firms are still using processes designed for the pre-2026 regime.
This guide explains how a UK GDPR transfer to India works after the Data (Use and Access) Act 2025: what counts as a restricted transfer, which transfer mechanisms to use, how the new data protection test works, and how India’s own data protection law applies on the other side. Halverton & Co. advises on Indian law only; take advice from a UK data protection solicitor on the UK GDPR points.
Is sending data to India a restricted transfer?
Under UK GDPR, personal data can only be transferred outside the UK in limited circumstances. There’s no UK adequacy regulation covering India, so a UK GDPR transfer to India usually needs another safeguard. The ICO’s updated guidance on international transfers, published on 15 January 2026, sets out a three-step test for identifying a restricted transfer.
The three questions are whether UK GDPR applies to the processing of the data being transferred, whether your organisation is initiating the transfer to an organisation outside the UK, and whether the transfer is to a separate legal entity from the exporter. If you engage an independent offshore provider in India, the answer to all three will usually be yes.
For law firms, the question arises constantly: research tasks may involve client names, document review involves personal data in emails and contracts, and due diligence involves employee information. In practice, almost any meaningful offshore legal support will involve a UK GDPR transfer to India; see our guides to paralegal support for solicitors and what the SRA expects. Remote access counts. The ICO’s own example describes a UK business contracting with an IT support company in India whose staff access UK-held personal data through a VPN, and treats that as a restricted transfer occurring at the moment the data becomes accessible. Keeping data on UK servers doesn’t avoid the rules if an Indian team can see it.
What changed in 2026: the data protection test
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and most of its data protection changes, including the new international transfers regime, came into force on 5 February 2026.
The headline change is a new “data protection test”. The old standard of “essentially equivalent” protection has been replaced by a requirement that protection in the destination is “not materially lower” than under UK law. The DUAA also codifies the requirement to carry out a transfer risk assessment where you rely on appropriate safeguards, which must be done “reasonably and proportionately”.
Existing transfer arrangements put in place before commencement remain effective if they continue to comply with the law as it stood when signed, but new transfers after commencement must be assessed against the new test. If you’re starting a new offshore relationship with an Indian provider in 2026, the new test applies.
The mechanics: IDTA, UK Addendum and transfer risk assessment
For most UK GDPR transfers to India, the transfer mechanism will be the ICO’s International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK Addendum. Both are standard data protection clauses that can be used as appropriate safeguards under Article 46 of UK GDPR. The ICO has said organisations should continue using the current IDTA while updates are developed.
Alongside the transfer agreement, you’ll need the usual Article 28 data processing terms where the Indian provider acts as your processor, and a documented transfer risk assessment considering the type of data, the purpose, the security measures, and the legal environment in India, including government access to data.
Document your reasoning. If the ICO or a client ever asks, a short written assessment explaining why the UK GDPR transfer to India meets the data protection test, with the contract, security measures and access controls attached, is far more persuasive than an unsigned template. Practical safeguards strengthen the assessment: keeping data in your own UK-hosted systems and granting controlled remote access, encryption in transit and at rest, role-based access, logging, data minimisation and pseudonymisation where possible, and contractual rights to audit and to require deletion.
| Step | What to do |
|---|---|
| Identify the transfer | Apply the ICO three-step test; remote access from India counts |
| Choose a mechanism | IDTA, or EU SCCs with the UK Addendum (no UK adequacy regulation covers India) |
| Add processing terms | Article 28 terms where the Indian provider is your processor |
| Assess | Documented transfer risk assessment against the “not materially lower” test |
| Secure | Own systems, encryption, role-based access, logging, minimisation, audit and deletion rights |
How India’s own law applies on the other side
When you assess the legal environment in India, India’s Digital Personal Data Protection Act, 2023 is relevant. Importantly, Section 17(1)(d) of the Act exempts the processing in India of personal data of people outside India where it’s carried out under a contract with a person outside India. That means most of the DPDP Act’s obligations don’t apply to your UK clients’ data processed by an Indian provider, though the duty to protect it with reasonable security safeguards continues to apply. See our guides to India’s DPDP Act for UK businesses and Indian AI teams and US client data.
Other Indian laws also apply to the provider. CERT-In’s 2022 directions require organisations in India to report specified cyber incidents within six hours and to keep system logs for 180 days; see our guide to the CERT-In 6-hour rule. The Information Technology Act, 2000 penalises unauthorised access and data theft, and Indian courts will enforce the confidentiality obligations in your contract.
For your transfer risk assessment, this combination, contractual protections under the IDTA, the provider’s statutory security duties in India, and practical access controls, is usually the foundation for concluding that the data protection test is met for routine legal support work.
A UK GDPR transfer checklist, remedies and quick answers
Before starting a UK GDPR transfer to India, confirm whether each data flow is a restricted transfer, select the IDTA or the EU SCCs with the UK Addendum, complete and document the transfer risk assessment, put Article 28 processing terms in place, update your privacy notices and records of processing, and check client engagement terms for any restrictions on offshore processing.
If an incident occurs, the provider should notify you quickly; you’ll then need to assess whether to notify the ICO within 72 hours and whether to inform affected individuals and clients. The DUAA also aligned PECR fines with UK GDPR, with a maximum of £17.5 million or 4% of global turnover, so the stakes for getting data handling wrong remain high. UK GDPR content should be reviewed by a UK data protection solicitor before you act on it.
Quick answers
Can UK firms send personal data to India?
Yes, using a transfer mechanism such as the IDTA or the EU SCCs with the UK Addendum, plus a transfer risk assessment, because India has no UK adequacy regulation.
Is remote access from India a restricted transfer?
Yes. The ICO treats access by an Indian provider’s staff to UK-held data, for example over a VPN, as a restricted transfer.
Does India’s DPDP Act apply to UK clients’ data processed in India?
Mostly not, because of the Section 17(1)(d) exemption, but the provider must still keep the data secure.
Related reading: offshore data processing for UK client data.
Final word
Halverton & Co. is an Indian law firm that advises on Indian law, including the Indian side of data transfers, DPDP compliance and data processing contracts for UK clients. We practise in Jharkhand, Maharashtra and before the Supreme Court of India, and we work alongside your UK solicitors, who advise on English law. Halverton & Co.: Where tech needs law! If you have a question about Indian law, write to us at office@halvertonandco.com, or get in touch.
This article reflects developments reported up to early October 2026. It is for general information only, is not legal advice, and does not create a solicitor-client relationship. Halverton & Co. is an Indian law firm, is not authorised or regulated by the Solicitors Regulation Authority, and does not advise on English law.
Related practice area
Technology & AI Law
Contracts, data protection and AI policies for products that handle other people’s data.
View the practice area



