skip to content

Under the GDPR, a contracted support desk in India views EU customer records hosted in the EU; is that a transfer, and what is needed?

level: middleimportance: must knowfreq 55%

answer

  1. access, not only copying
  2. who is the importer
  3. no adequacy for the destination
  4. pick the SCC module by role
  5. assess the local law too

basics

~20 s

Under the GDPR, making EU-hosted data viewable by a contractor in India is a transfer. Absent an adequacy decision, it needs Art. 46 safeguards, typically SCC Module Two with a Clause 14 assessment, plus notice to customers.

solid answer

~40 s

Chapter V is not about where the server sits. **EDPB guidance** treats personal data made accessible to a recipient in a third country, including by **remote access**, as a transfer. The GDPR itself does not define the term. An Indian support contractor acting on the EU company's instructions is a **processor**. Absent an adequacy decision for India, **Art. 46** requires safeguards, normally the Commission's 2021 SCCs in **Module Two (controller to processor)**, which also cover the Art. 28 processor terms. **Clause 14** requires a documented assessment of Indian laws and practices on public-authority access, with supplementary measures where needed. The privacy notice must mention the transfer and the safeguards under **Art. 13(1)(f)**.

go deeper

for a junior

Recall that access from a third country can be a transfer even when hosting stays in the EU, and that without adequacy, safeguards such as SCCs are needed.

for a middle

Identify exporter and importer roles, choose the SCC module that matches them, and explain what the Clause 14 assessment covers and who can ask to see it.

for a senior

Use data minimisation in the support tooling as a supplementary measure, and plan for sub-processors and a change in the destination's law under Clause 14(e).

for a principal

Weigh offshore support against the continuing Chapter V work: module contracts, assessments, sub-processor chains and notices, and decide where that overhead stops paying for itself.

## Why hosting in the EU does not end the question The GDPR does not define "transfer". **Art. 44** applies Chapter V to personal data *"undergoing processing or … intended for processing after transfer to a third country"*. Regulator guidance reads this functionally. The EDPB treats making personal data **accessible** to a recipient in a third country, for example through a screen or remote session, as a transfer, just as it treats sending a file. A support agent in India who opens an EU customer's record processes that personal data in India, on behalf of an EU controller. The rows never "moved", but the recipient is in a third country, so Chapter V applies. Where the data sits is still relevant to other questions, such as what an operator can reach. Those are architecture and residency questions. The legal trigger here is the **third-country recipient**. ## Step 1: identify exporter, importer and roles | Party | Role | Why | |---|---|---| | EU company | **controller**, data exporter | decides why and how customer data is processed | | Indian support contractor | **processor**, data importer | handles tickets on the company's instructions | If the desk were the company's own Indian **subsidiary**, it would still be a separate legal entity in a third country, so the same analysis applies. Intra-group BCRs become an option in that case. ## Step 2: find the Chapter V route 1. **Adequacy (Art. 45).** Is there a Commission adequacy decision for the destination? Absent one for India, move on. 2. **Appropriate safeguards (Art. 46).** For an outsourced desk the usual choice is the **standard contractual clauses** in Implementing Decision (EU) 2021/914, which are modular: | Module | Transfer | |---|---| | One | controller to controller | | **Two** | **controller to processor** | | Three | processor to processor | | Four | processor to controller | **Module Two** fits here. Under **Art. 1(2)** of the Decision, the clauses also set out the rights and obligations required by **Art. 28(3) and (4)** GDPR between controller and processor. One instrument covers both the transfer and the processor contract. 3. **Derogations (Art. 49)** do not fit a standing support operation. They apply only in the absence of adequacy or safeguards, and Recital 111 ties the contract derogations to *occasional* transfers. Daily ticket handling is not occasional, and SCCs are available. ## Step 3: the Clause 14 assessment Signing the SCCs is not the end. Under **Clause 14**, the parties warrant that they have *no reason to believe* that the destination's laws and practices, including public-authority access, prevent the importer from complying. To give that warranty they assess: - the **specific circumstances**: which fields agents see, how many agents, the transmission channel, onward transfers, the storage location; - the **laws and practices** of the destination relevant to those circumstances; - any **supplementary safeguards**, contractual, technical or organisational. The assessment is **documented and made available to the supervisory authority on request** (Clause 14(d)). The importer must tell the exporter if it becomes subject to laws that conflict with the clauses (Clause 14(e)). Technical design helps. If agents see only the fields a ticket needs, the processing in the third country shrinks, and so does what any access demand could reach. That feeds directly into the assessment. ## Step 4: tell the customers Under **Art. 13(1)(f)** (and Art. 14(1)(f) for data not obtained from the person), the controller's notice must state, where applicable, the intention to transfer to a third country, whether an adequacy decision exists, and for Art. 46 transfers a reference to the safeguards and how to obtain a copy. ## Common mistakes - "Data never leaves the EU, so no transfer." Remote access is enough. - Signing Module One because "they are a company too". Roles, not corporate form, decide the module. - Treating the signature as the whole job and skipping the Clause 14 assessment.

  • Under the 2021 SCCs, what if the Indian contractor hires a sub-processor in another country?
    The onward transfer is still governed by Chapter V (Art. 44). Under the Module Two clauses the contractor needs the exporter's general or specific authorisation, and a written contract giving the sub-processor the same data protection obligations. A footnote in the clauses says this can be met by the sub-processor acceding to the SCCs under the appropriate module.
  • Under the 2021 SCCs, may the parties edit the clauses to fit their support contract?
    Not the clauses themselves. Clause 2(a) says they provide appropriate safeguards only if not modified, except to select modules and fill in the Appendix. The parties may place them in a wider contract and add clauses or safeguards, as long as nothing contradicts the SCCs directly or indirectly or prejudices data subjects' rights.

saying these in an interview costs you the question

  • If the servers stay in the EU, no Chapter V transfer can occur.
  • A transfer only happens when files are downloaded to the other country.
  • An outsourced desk acting on instructions needs Module One, controller to controller.
  • Signing the SCCs alone completes the transfer compliance work.
  • Daily support access can run on an Art. 49 'necessary for a contract' derogation.