Where your data sits, and who can actually see it There is a question German manufacturers almost never ask us. Not because it doesn't matter, but because it sounds impolite: you develop in India. What happens to our data there?
Because it isn't asked, it isn't answered. It goes into the evaluation anyway, and helps decide the outcome without anyone having discussed it.
So we answer it unprompted. The answer starts with the part no vendor likes to lead with.
There is no adequacy decision for India
There is currently no general and no sectoral adequacy decision from the European Commission for India. Anyone telling you this is "covered" has either misunderstood the question or is not answering it.
Under Article 45 GDPR, personal data may flow freely to a third country where the Commission has found the level of protection adequate. No such finding exists for India.
Article 46 therefore applies. Every transfer of personal data from the EEA to India requires appropriate safeguards. In practice that means the Standard Contractual Clauses under Implementing Decision (EU) 2021/914, together with an assessment of whether those clauses are actually effective in the specific case — the transfer impact assessment required since Schrems II.
For the typical constellation — you are the controller, we are the processor — Module 2 normally applies. Where we then transfer personal data onward to a sub-processor in a third country, Module 3 normally applies. In the relevant modules the clauses also carry the requirements of Article 28 GDPR, so the transfer basis and the essential processing requirements can sit in a single set of contract documents.
None of this is a special case or a defect. It is the ordinary legal framework for working with any service provider outside the EEA without an adequacy decision. It cannot be negotiated away. It can be worked through cleanly.
Remote access is a transfer
"Your data sits in Frankfurt." Often true, and still not an answer — because it says nothing about who looks at it from where.
A transfer under Chapter V does not require data to be copied or moved. It is enough that someone in a third country can access it. A developer opening a session from Pune onto a server in Frankfurt is in principle to be treated as a third country transfer under Chapter V.
So "we host in Germany" is not on its own an argument. It is the first of two halves. The second is: and access from India is arranged so that it either reaches no personal data at all, or takes place under the agreed safeguards, logged and auditable.
If a vendor gives you the first half and turns vague on the second, you already have the real answer.
Hosting in Germany answers the question of location. It does not answer the question of access. The second is the one your data protection officer will ask.
Hosting in Germany answers the question of location. It does not answer the question of access. The second is the one your data protection officer will ask.


The questions your legal team will ask anyway
The transfer impact assessment is your obligation as controller, not ours. We cannot do it for you. We can make sure you don't have to fill it in with guesses.
Which categories of personal data reach the third country at all?
In manufacturing systems the honest answer is often: remarkably few. Bills of material, geometry, pricing logic and machine data are generally not personal data. Personal data appears at the edges — user accounts, handler references, contact names on quotations, timestamps. Naming those edges shortens the assessment considerably.
What access rights do authorities in the third country have?
This is where the assessment gets serious, and the part no vendor can replace with an assurance. What matters is the law and the actual practice in the third country, not the service provider's intentions. Your counsel will want to assess that; our job is to supply the information it needs, in full.
What supplementary measures apply where the clauses alone are not enough?
Technical measures can play a decisive role here — encryption, pseudonymisation, and above all the question of whether personal data needs to reach the third country at all. Contractual and organisational measures supplement them. Which combination is required depends on the specific transfer and on the assessment of the legal position in the third country.
The best way to handle a third country transfer is to avoid it
Working across borders does not require production data to cross the border with you. In most of our projects it doesn't.
Run on servers in Germany, or in your own data centre if you prefer. With on-premise operation the data never leaves your building at all.
A configurator can be built against invented customer names as well as real ones. Where possible we use synthetic test data. Where real data is needed for a specific test case, it is pseudonymised and reduced to what is necessary before provisioning. Pseudonymised data remains personal data — it lowers the risk, it does not end the assessment.
No blanket access for a development team. Named individuals, limited in time, for a documented reason, with a log. No uncontrolled local copies.
A list with name, location, purpose and the applicable data protection bases. Changes are announced in advance, not reported afterwards.
The less personal data reaches the third country, the shorter your assessment becomes. That is not a legal construction but a question of system architecture — and architecture is decided at the start, not at the end.
Documentation before you have to ask for it
Before the project starts we provide the documentation your assessment needs, without your having to ask for it: the processing agreement and Standard Contractual Clauses in the applicable module, the sub-processor list, a description of technical and organisational measures, the data location, a field list identifying the system's personal data fields, the deletion and retention concept, the access and role concept, and the information you need for your transfer impact assessment.
Separately from data protection, the continuity question: source code sits in escrow. If something happens to us, your systems keep running and somebody else can take them on.
And a reference. You speak to a European client who has already been through this process, before you commit.
Trust cannot be asserted. It can be made checkable — which is what this company is built around, because we cannot afford to assume it.
This article describes practice from a processor's perspective and is not legal advice. The data protection assessment of your specific case, in particular the transfer impact assessment, rests with you as controller and should be carried out with your data protection officer or counsel.

Photo by Andrew Kliatskyi on Unsplash.
Thirty minutes, one real enquiry.
Bring an actual customer enquiry and we will walk it from request to quote — including which fields it creates, which of them are personal data, and where they sit.

