How we handle personal data on software projects for UK and European clients: NDAs, a Data Processing Agreement on request, Standard Contractual Clauses where needed, EU-region hosting, access control, encryption and support for your own compliance decisions.
Yes. GDPR does not prevent you from using a development partner in India, but it does require the right safeguards. Because India has no EU adequacy decision, the usual approach is a Data Processing Agreement plus Standard Contractual Clauses, backed by EU-region hosting, access control, encryption and data minimisation. You remain the controller and make the final decision.
Many projects need far less personal data than expected. Developers can usually work with anonymised or synthetic test data, and production data can stay in an EU region. Designing this way from the start reduces both risk and paperwork. For the wider picture, see our guide to outsourcing software development to India.
The contractual and technical measures we put in place, agreed with you before development starts.
No. At the time of writing, the European Commission has not adopted an adequacy decision for India, so it is treated as a third country. Standard Contractual Clauses are Commission-approved contract terms that allow personal data to be transferred to a third country with appropriate safeguards, normally alongside a transfer risk assessment and supporting technical measures.
India's own Digital Personal Data Protection Act, 2023 applies to processing in India, but it does not replace your obligations under GDPR.
Usually, yes. If the developer will access or process personal data on your behalf, such as production databases, user records or support logs, GDPR Article 28 requires a written contract with specific terms, commonly called a Data Processing Agreement. If the team only ever works with anonymised or synthetic data, your counsel may decide one is not needed.
UK GDPR mirrors the EU rules closely but has its own transfer tools. For UK clients, transfers to India typically use the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and data can be hosted in a UK cloud region. We work with whichever mechanism your legal team chooses.
UK-based? See our software development page for UK businesses.
Send us your DPA template or questionnaire and we will go through it with you.
In most projects you are the data controller and we act as a processor. A typical split looks like this.
| Area | You (controller) | Kawach Technology (processor) |
|---|---|---|
| Lawful basis and privacy notices | Decide the lawful basis and inform users | Build consent, notice and preference features you specify |
| Contracts | Choose the DPA and transfer mechanism | Sign the DPA and SCCs / IDTA where your legal team requires them |
| Hosting | Choose the region and own the cloud account | Build and deploy in AWS or Azure EU / UK regions |
| Security | Set security requirements and approve access | Apply access control, encryption and secure development practices |
| Data subject requests | Respond to users | Build export, correction and deletion features; assist on request |
| Breaches | Assess and notify the authority and users where required | Notify you without undue delay and share what we know |
| Final compliance sign-off | Your counsel | Provide documentation to support the assessment |
The EU AI Act entered into force in 2024 and its obligations apply in phases, depending on the risk level of an AI system and whether you are its provider or deployer. If your product uses AI, we help document data sources, model behaviour, human oversight and logging, so your counsel can assess which obligations apply.
This is a general readiness note, not legal advice. Timelines and guidance continue to evolve, so check the current position with your counsel.
It may. The European Accessibility Act has applied since 28 June 2025 to many consumer-facing digital products and services sold in the EU, such as e-commerce and banking services, with exemptions for microenterprises. We can build new software to WCAG 2.1 AA as a design target, which is the usual technical reference.
We do not offer accessibility audits or certification; whether the Act applies to your business is a question for your counsel.
Related reading, or talk to us directly:
An Indian company can process EU personal data in a way that supports your GDPR compliance. Because India has no EU adequacy decision, the transfer needs safeguards, usually a Data Processing Agreement plus Standard Contractual Clauses, backed by access control, encryption and data minimisation. As controller, you and your counsel make the final compliance decision.
If the developer will process personal data on your behalf, for example by accessing a production database or user records, GDPR Article 28 requires a written contract with specific terms, usually called a Data Processing Agreement. If the team only ever works with anonymised or synthetic data, one may not be needed. We can sign a DPA on request.
No. At the time of writing, the European Commission has not adopted an adequacy decision for India. Standard Contractual Clauses are model contract terms approved by the Commission that let you transfer personal data to a third country with appropriate safeguards. They are normally combined with a transfer risk assessment and supporting technical measures.
Yes, where your legal team requires them. We can sign a Data Processing Agreement and use Standard Contractual Clauses, or for UK clients the UK International Data Transfer Agreement or UK Addendum, as part of the contract. They are agreed per project rather than signed by default.
Yes. We can build and deploy on AWS or Microsoft Azure regions inside the EU, or in the UK, so production data is stored in the region your policies require. Access by our team can then be limited to what each task needs, which reduces the personal data that leaves the EU.
We don't claim any certification on this site. There is no general GDPR certificate that a supplier can hold for all work. We work to the contractual and technical measures described on this page, can share details of the specific controls your project needs, and support your own compliance assessment.
As processor, we notify you without undue delay after becoming aware of a breach affecting your data, and share what we know so you can assess it and, where required, notify the supervisory authority within the 72 hours GDPR allows controllers. Notification terms are set out in the Data Processing Agreement.
It can. The EU AI Act applies in phases and places obligations based on the risk level of an AI system and your role as provider or deployer. If your product uses AI, we help document data sources, model behaviour and human oversight so your counsel can assess which obligations apply.
It may. The European Accessibility Act has applied since 28 June 2025 to many consumer-facing digital products and services in the EU, including e-commerce and banking services, with exemptions for microenterprises. We can build new software to WCAG 2.1 AA as a design target; whether the Act applies to you is a question for your counsel.
Tell us what you're building, what you're trying to improve, or where your current software is falling short.