How Do EU Companies Stay GDPR and DPDPA Compliant Using EOR?
- Saransh Garg

- 3 days ago
- 7 min read

Since India's Digital Personal Data Protection Rules came into force, hiring engineers through an Indian employer of record is no longer just an HR decision, it's a data protection decision too. GDPR fines can reach €20 million or 4% of global annual turnover. DPDPA fines can reach ₹250 crore per instance. When a European company hires through an EOR in India, both laws apply to the same employment record at the same time. Staying GDPR and DPDPA compliant using EOR hiring means understanding exactly where these two laws overlap, where they conflict, and who is responsible for what.
Why GDPR and DPDPA Now Apply to the Same India Hire
Every EU company hiring in India manages two layers of data. The first is the employment data of the person they hire: payroll, tax records, ID documents. The second is the client, product, or customer data that person touches once they start working. GDPR governs the second layer the moment an EU company decides why that data is processed, which is almost always the case even when an EOR is the legal employer on paper. DPDPA governs the same data the moment it sits on a server, laptop, or SaaS tool located in India, no matter which country owns the company using it.
This overlap catches out fast-growing companies most often in fintech, healthtech, and SaaS, where an offshore engineer isn't just writing code but touching production systems containing EU customer information. An EOR handles Indian employment law compliance. It does not automatically take on GDPR accountability, which stays with whichever company decides how the data is used.
GDPR and DPDPA Compliant Using EOR: What Actually Changes in Your Contract
Under GDPR, the EU company is usually the data controller because it decides what data is processed and why. The EOR, and the Indian engineer reporting into a European team, function as a processor or sub processor. This means the EU company stays liable for GDPR even though it doesn't directly employ the person handling the data.
Under DPDPA, the Indian EOR entity is typically the Data Fiduciary for local employment records such as payroll, PF, and ESI filings, while the EU client can be a separate Data Fiduciary for the product or customer data the engineer accesses. Cross border transfer into India is allowed by default under DPDPA, unlike GDPR's stricter adequacy model, but the Indian government can restrict transfers to specific countries through notification.
This is also where contract hiring and full time hiring start to matter for compliance planning, not just cost. A contract hire through an EOR usually has a shorter, more clearly scoped data access period, which makes it easier to define exactly what GDPR and DPDPA obligations apply and for how long. A full time hire under the same EOR structure needs longer term data governance built into the contract from day one, since the access relationship is expected to continue indefinitely rather than end at a project boundary.
Contract Hiring or Full Time Hiring: Which Keeps You More Compliant?
Neither model is automatically safer. What matters is how clearly the data access is scoped. Contract hiring works well for short, well defined projects, such as a three month data migration or a specific product build, because the Data Processing Agreement can name exact start and end dates, exact systems accessed, and exact deletion timelines once the contract closes.
Full time hiring suits ongoing product or platform work, where the engineer needs continuous access to systems over years, not months. Here, the DPA needs to account for role changes, expanding access rights over time, and periodic re-consent as responsibilities grow. Companies at AnjuSmriti Global typically recommend full time EOR hiring once a role moves from project based to core platform ownership, because that shift usually means the person's data access will only grow, not shrink.
GDPR vs DPDPA Compliance Checklist for EU Companies Hiring in India
This is the table our clients use directly during their internal compliance reviews.
Compliance Area | GDPR Requirement | DPDPA Requirement |
Legal basis | Consent, contract, or legitimate interest | Consent or defined legitimate uses |
Breach notification | 72 hours to the supervisory authority | Without delay to the Data Protection Board of India |
Cross border transfer | Adequacy decision or Standard Contractual Clauses | Allowed by default unless a country is restricted |
Data rights | Access, rectification, erasure, portability | Access, correction, erasure, grievance via Consent Manager |
DPO requirement | Mandatory above certain processing thresholds | Not mandatory for most private Data Fiduciaries |
Penalty ceiling | €20 million or 4% of global turnover | ₹250 crore per instance |
The line most HR teams miss is the DPO row. If your company already has a Data Protection Officer, confirm in writing whether their mandate covers the Indian EOR relationship, or whether that responsibility sits with your recruitment partner instead.
How AI, Cloud, and Distributed Hiring Trends Are Changing Compliance Requirements
More EU companies are now building AI, cloud, and platform engineering pods in India rather than single contractor roles, and that shift changes the compliance picture. AI teams often work with training data that includes real customer records, which pushes GDPR obligations further into the technical workflow than a typical backend hire would. Cloud infrastructure teams increasingly manage systems that span EU and Indian regions at once, which means DPDPA and GDPR can apply to the same server environment simultaneously.
We're also seeing more EU companies set up formal Global Capability Centers (GCC) in India instead of one off hires, partly because a GCC structure allows for a single, centralized compliance framework rather than negotiating a new DPA for every hire.
How to Stay GDPR and DPDPA Compliant Using EOR: A Practical Process
Our onboarding sequence for every EU India EOR placement follows four steps. First, legal basis mapping before any candidate is shared with the client. Second, Data Processing Agreement drafting in parallel with candidate shortlisting. Third, a compliance specific technical screen for the candidate, alongside their skills interview. Fourth, a joint onboarding session where the EOR's compliance lead, the client's HR contact, and the client's DPO, where one exists, walk through the data access map before day one.
This typically adds five to seven working days to a standard hire. Clients consistently tell us it's worth it after their first internal audit, because retrofitting compliance into an existing hire is far more expensive than building it in from the start. For companies also managing salary and statutory filings across two countries, this usually connects directly to payroll outsourcing, since payroll data is one of the first things a DPDPA audit will check.
What Compliant EOR Hiring Actually Costs
A mid level backend engineer in Bengaluru with four to six years of experience typically costs €2,800 to €3,400 a month all in, including salary, employer contributions, and EOR fee. A senior engineer with seven to ten years runs €3,800 to €4,800. A lead or architect level hire with prior GDPR governed project experience runs €5,200 to €6,500. Adding a proper compliance layer, meaning dual DPA drafting and a joint onboarding review, typically adds €800 to €1,500 as a one time cost, plus a small ongoing uplift on the EOR fee for continuous DPDPA monitoring.
Compared to opening an Indian subsidiary, which usually costs €15,000 to €25,000 in legal and registration fees before a single employee is hired, EOR hiring with proper GDPR and DPDPA compliant structuring still comes out significantly cheaper in year one, even after accounting for the compliance work.
Getting GDPR and DPDPA compliant using EOR hiring right isn't a one time contract review. It's an ongoing process that has to track two regulators moving on different timelines, especially as more companies shift from single contract hires to full scale AI and cloud teams in India.
If you're structuring your first India hire and want a second review of your DPA before signing, book a compliance walkthrough with our team.
Interesting Reads:
FAQs
1.What is the difference between GDPR and DPDPA for EU companies hiring in India?
GDPR governs any personal data an EU company decides to process, regardless of where it's stored, and carries fines up to 4% of global turnover. DPDPA governs personal data processed on infrastructure located in India, with penalties up to ₹250 crore per instance. An EU company hiring through an Indian EOR usually needs to satisfy both at once, since the same employee touches data covered by each law.
2.Is an EOR responsible for GDPR compliance when hiring engineers in India?
Not automatically. The EOR typically acts as a data processor handling Indian employment law and payroll, while the EU company usually remains the GDPR data controller responsible for how customer or product data is used. Many HR teams assume the EOR absorbs this risk entirely, which is incorrect unless it's explicitly written into the Data Processing Agreement between both parties.
3.Do Indian data protection laws apply to EU company data processed in India?
Yes. DPDPA applies to personal data processed digitally within India regardless of which country owns the company involved. If an EU company's data touches a server, laptop, or SaaS tool located in India through an EOR hire, DPDPA obligations apply alongside any GDPR requirements the EU company already carries for that same data.
4.How does DPDPA affect cross border data transfer for EU businesses?
DPDPA allows cross border data transfer by default, unlike GDPR's stricter adequacy decision model, but the Indian government can restrict transfers to specific countries through official notification. EU companies still need Standard Contractual Clauses on the GDPR side to legally move EU personal data into India, even though DPDPA itself doesn't block the transfer.
5.Can EU companies hire contract employees in India without breaching GDPR?
Yes, as long as the contract clearly scopes what data the contractor accesses and for how long. Contract hiring often makes GDPR compliance easier than full time hiring because the Data Processing Agreement can specify exact start dates, end dates, and data deletion timelines tied to the project, rather than open ended access that continues indefinitely.
6.What happens if an EOR hire causes a data breach?
Both GDPR and DPDPA breach notification duties can apply simultaneously. GDPR requires notification to the relevant supervisory authority within 72 hours where feasible, while DPDPA requires notification to the Data Protection Board of India without delay. Companies that build a single incident response plan covering both timelines avoid missing either deadline during an actual breach.
7.Do EU companies need a Data Protection Officer for India hiring?
Only if they meet GDPR's threshold for large scale processing or systematic monitoring, which most companies hiring one or two engineers through an EOR don't reach. Smaller EU companies can assign GDPR oversight to an existing compliance or legal lead instead, but should still name a specific accountable person in the contract rather than leaving responsibility undefined.
8.Is EOR hiring more compliant than opening a subsidiary in India?
It depends on execution rather than the structure itself. An EOR with a properly layered Data Processing Agreement and a dedicated DPDPA compliance process is generally lower risk than a rushed subsidiary setup with no local data governance experience. An EOR chosen purely for lower cost, without a compliance process built in, can actually increase risk instead of reducing it.
.png)
Comments