Home / GDPR & Data Protection

GDPR & Data Protection at Kawach Technology

How we handle personal data on software projects for UK and European clients: NDAs, a Data Processing Agreement on request, Standard Contractual Clauses where needed, EU-region hosting, access control, encryption and support for your own compliance decisions.

  • DPA and SCCs on request
  • AWS / Azure EU regions
  • UK GDPR supported
  • IP transfers to you
Last updated October 2026

Our approach to data protection, in short

  • Contracts: NDA before detailed discussions; we can sign a Data Processing Agreement and use Standard Contractual Clauses where your legal team requires them.
  • Hosting: production data can stay in AWS or Azure EU (or UK) regions, with team access limited to what each task needs.
  • Engineering: encryption, role-based access, data minimisation and separate environments built in from the start.
  • Honest limits: we are not a law firm and claim no GDPR or ISO certification; final compliance sign-off is your counsel's decision.

Can an Indian software company work in a GDPR-compliant way?

Yes. GDPR does not prevent you from using a development partner in India, but it does require the right safeguards. Because India has no EU adequacy decision, the usual approach is a Data Processing Agreement plus Standard Contractual Clauses, backed by EU-region hosting, access control, encryption and data minimisation. You remain the controller and make the final decision.

Many projects need far less personal data than expected. Developers can usually work with anonymised or synthetic test data, and production data can stay in an EU region. Designing this way from the start reduces both risk and paperwork. For the wider picture, see our guide to outsourcing software development to India.

On Your Project

How We Handle Personal Data on Your Project

The contractual and technical measures we put in place, agreed with you before development starts.

NDA FirstWe sign an NDA before any detailed project discussion, before you share plans, data or business logic.
Data Processing AgreementWhere we process personal data for you, we can sign a DPA covering the Article 28 terms your legal team requires.
Standard Contractual ClausesWhere a transfer to India needs a safeguard, we can use SCCs, or for UK clients the IDTA or UK Addendum.
EU-Region HostingInfrastructure on AWS or Microsoft Azure regions in the EU or UK, so production data stays where your policies require.
Access ControlRole-based, least-privilege access; production access only where a task needs it, and removed when it ends.
EncryptionEncryption in transit and at rest, with secrets kept out of source code.
Data MinimisationCollect only what the product needs, and use anonymised or synthetic data in development and testing.
Breach Notification SupportWe notify you without undue delay and share what we know, so you can meet your own reporting obligations.
IP AssignmentOwnership of custom source code and work product transfers to you on full payment.

Is India an adequate country under GDPR, and what are SCCs?

No. At the time of writing, the European Commission has not adopted an adequacy decision for India, so it is treated as a third country. Standard Contractual Clauses are Commission-approved contract terms that allow personal data to be transferred to a third country with appropriate safeguards, normally alongside a transfer risk assessment and supporting technical measures.

India's own Digital Personal Data Protection Act, 2023 applies to processing in India, but it does not replace your obligations under GDPR.

Do you need a Data Processing Agreement with an offshore developer?

Usually, yes. If the developer will access or process personal data on your behalf, such as production databases, user records or support logs, GDPR Article 28 requires a written contract with specific terms, commonly called a Data Processing Agreement. If the team only ever works with anonymised or synthetic data, your counsel may decide one is not needed.

How do you handle UK GDPR?

UK GDPR mirrors the EU rules closely but has its own transfer tools. For UK clients, transfers to India typically use the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and data can be hosted in a UK cloud region. We work with whichever mechanism your legal team chooses.

UK-based? See our software development page for UK businesses.

Have data protection requirements for your project?

Send us your DPA template or questionnaire and we will go through it with you.

Who Does What

Your Responsibilities and Ours

In most projects you are the data controller and we act as a processor. A typical split looks like this.

AreaYou (controller)Kawach Technology (processor)
Lawful basis and privacy noticesDecide the lawful basis and inform usersBuild consent, notice and preference features you specify
ContractsChoose the DPA and transfer mechanismSign the DPA and SCCs / IDTA where your legal team requires them
HostingChoose the region and own the cloud accountBuild and deploy in AWS or Azure EU / UK regions
SecuritySet security requirements and approve accessApply access control, encryption and secure development practices
Data subject requestsRespond to usersBuild export, correction and deletion features; assist on request
BreachesAssess and notify the authority and users where requiredNotify you without undue delay and share what we know
Final compliance sign-offYour counselProvide documentation to support the assessment

Are you ready for the EU AI Act?

The EU AI Act entered into force in 2024 and its obligations apply in phases, depending on the risk level of an AI system and whether you are its provider or deployer. If your product uses AI, we help document data sources, model behaviour, human oversight and logging, so your counsel can assess which obligations apply.

This is a general readiness note, not legal advice. Timelines and guidance continue to evolve, so check the current position with your counsel.

Does the European Accessibility Act apply to your website or app?

It may. The European Accessibility Act has applied since 28 June 2025 to many consumer-facing digital products and services sold in the EU, such as e-commerce and banking services, with exemptions for microenterprises. We can build new software to WCAG 2.1 AA as a design target, which is the usual technical reference.

We do not offer accessibility audits or certification; whether the Act applies to your business is a question for your counsel.

An honest note on compliance: Kawach Technology is a software development company, not a law firm, and this page is not legal advice. We don't claim GDPR, ISO 27001 or SOC 2 certification, and we do not sign a DPA or SCCs by default: we agree them per project where your legal team requires them. We build software with privacy and security in mind and support your assessment, but final compliance sign-off is always your counsel's decision.
Common Questions

GDPR & Data Protection: Frequently Asked Questions

Can an Indian software company be GDPR compliant?

An Indian company can process EU personal data in a way that supports your GDPR compliance. Because India has no EU adequacy decision, the transfer needs safeguards, usually a Data Processing Agreement plus Standard Contractual Clauses, backed by access control, encryption and data minimisation. As controller, you and your counsel make the final compliance decision.

Do I need a Data Processing Agreement with an offshore developer?

If the developer will process personal data on your behalf, for example by accessing a production database or user records, GDPR Article 28 requires a written contract with specific terms, usually called a Data Processing Agreement. If the team only ever works with anonymised or synthetic data, one may not be needed. We can sign a DPA on request.

Is India an adequate country under GDPR? What are SCCs?

No. At the time of writing, the European Commission has not adopted an adequacy decision for India. Standard Contractual Clauses are model contract terms approved by the Commission that let you transfer personal data to a third country with appropriate safeguards. They are normally combined with a transfer risk assessment and supporting technical measures.

Do you sign Standard Contractual Clauses?

Yes, where your legal team requires them. We can sign a Data Processing Agreement and use Standard Contractual Clauses, or for UK clients the UK International Data Transfer Agreement or UK Addendum, as part of the contract. They are agreed per project rather than signed by default.

Can our data be hosted in the EU?

Yes. We can build and deploy on AWS or Microsoft Azure regions inside the EU, or in the UK, so production data is stored in the region your policies require. Access by our team can then be limited to what each task needs, which reduces the personal data that leaves the EU.

Are you GDPR certified or ISO 27001 certified?

We don't claim any certification on this site. There is no general GDPR certificate that a supplier can hold for all work. We work to the contractual and technical measures described on this page, can share details of the specific controls your project needs, and support your own compliance assessment.

What happens if there is a personal data breach?

As processor, we notify you without undue delay after becoming aware of a breach affecting your data, and share what we know so you can assess it and, where required, notify the supervisory authority within the 72 hours GDPR allows controllers. Notification terms are set out in the Data Processing Agreement.

Does the EU AI Act apply to the software you build?

It can. The EU AI Act applies in phases and places obligations based on the risk level of an AI system and your role as provider or deployer. If your product uses AI, we help document data sources, model behaviour and human oversight so your counsel can assess which obligations apply.

Does the European Accessibility Act apply to my website or app?

It may. The European Accessibility Act has applied since 28 June 2025 to many consumer-facing digital products and services in the EU, including e-commerce and banking services, with exemptions for microenterprises. We can build new software to WCAG 2.1 AA as a design target; whether the Act applies to you is a question for your counsel.

Have a Software Project in Mind?

Tell us what you're building, what you're trying to improve, or where your current software is falling short.

We usually respond within 24 business hours · NDA available before detailed discussion · contact@kawachtech.com