Why Legal and Compliance GCCs Are Expanding in India
In May 2025, the Bar Council of India notified amended rules that let registered foreign lawyers advise on cross-border matters and international arbitration from India, but bar them from practicing Indian law, appearing before Indian courts, or spending more than 60 days in any 12-month period in the country. Alongside India's Digital Personal Data Protection Act 2023 and its DPDP Rules 2025 (notified November 13, 2025), these rules define the regulatory envelope for the legal and compliance functions inside India's Global Capability Centers.
Global law firms, Fortune 500 in-house legal teams, and Big 4 advisory practices are building captive legal operations in India to handle contract management, regulatory monitoring, compliance reporting, litigation support, and data privacy operations at a fraction of onshore cost. This guide maps the regulatory terrain, staffing models, and compliance obligations for any foreign company building legal capability in India.
BCI Rules 2025: What Foreign Law Firms Can and Cannot Do in India
The Registration Framework
In May 2025, the Bar Council of India notified the amended Rules for Registration and Regulation of Foreign Lawyers and Foreign Law Firms in India. These rules fundamentally define the boundary between permitted and prohibited activities for any foreign legal entity operating in India, including GCCs with legal functions.
Key registration requirements under the 2025 rules:
- Mandatory BCI registration: Any foreign lawyer or firm providing legal services in India must register with the BCI
- Home-jurisdiction certification: A certificate or no-objection from the bar or regulatory authority of the lawyer's home jurisdiction, together with the declarations the BCI prescribes in the application form
- Pre-arrival disclosure: Foreign lawyers must disclose client identity, nature of work, and expected duration before entering India
- FIFO presence cap: Foreign lawyers are limited to 60 days in any 12-month period in India
- Reciprocity principle: Registration is only available to lawyers from jurisdictions that extend similar rights to Indian lawyers
Permitted Activities
Registered foreign lawyers and firms may:
- Advise on foreign law and international law in non-litigious matters
- Participate in international commercial arbitration involving foreign or international law
- Provide transactional advisory on cross-border deals governed by foreign law
- Support FDI transactions from the foreign law perspective
Prohibited Activities
The following activities are strictly prohibited for foreign legal professionals:
- Practicing Indian law in any form
- Appearing before Indian courts, tribunals, or quasi-judicial bodies
- Conveyancing of property, title investigation, or similar work under Indian law
- Drafting or filing documents for proceedings before Indian courts or authorities
- Unregistered collaborations, joint branding, or co-branded marketing with Indian law firms — the BCI has publicly cautioned Indian firms against such tie-ups
Non-compliance can trigger professional misconduct proceedings, leading to reprimand, suspension, or removal from the BCI register.

GCC Legal Functions: Where the Lines Are
What a Legal GCC Can Do (Without BCI Restrictions)
A GCC structured as a private limited company performing internal legal work for its parent company is not a "law firm" under BCI rules. This distinction is critical. A captive legal operations center can perform:
- Contract lifecycle management: Review, drafting, and negotiation of commercial contracts for the parent entity
- Compliance monitoring: Tracking regulatory changes across jurisdictions and flagging obligations
- Litigation support: Document review, e-discovery, case management, and legal research (not appearing before courts)
- Regulatory filings: Preparing and managing compliance filings for the parent group
- Data privacy operations: Managing GDPR, CCPA, and DPDP compliance workflows
- IP management: Patent and trademark portfolio management, freedom-to-operate analysis
- Corporate governance support: Board pack preparation, minutes drafting, entity management
The Gray Zone: Activities Requiring Careful Structuring
Certain activities require careful structuring to avoid BCI violations:
- Advising on Indian law: The GCC can research Indian law for internal purposes but cannot provide Indian legal advice to external third parties
- Client-facing work: If the GCC's parent is a law firm, work product flowing to external clients must not constitute practice of Indian law
- Indian regulatory advice: Internal compliance advice on Indian regulations is permissible; external advisory is not
DPDP Act 2023 and DPDP Rules 2025: Compliance Obligations
Legal and compliance GCCs process significant volumes of personal data, making the Digital Personal Data Protection Act 2023 and its implementing rules (notified November 13, 2025) directly applicable.
Key Compliance Requirements
- Consent management: Itemized notices must be provided to data principals. The registration process for Consent Managers becomes operational by November 2026.
- Data security: Reasonable security safeguards must be implemented, including encryption, access controls, and incident response procedures
- Breach notification: On becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal and give the Data Protection Board an initial description without delay, followed by the detailed particulars within 72 hours (or such longer period as the Board allows)
- Retention limits: Purpose-based retention timelines must be defined and enforced; data must be deleted when the purpose is fulfilled
- Cross-border transfers: Data transfers to jurisdictions not on the government's restricted list are permitted, but transfers to restricted countries are prohibited
- Children's data: Verifiable parental consent required for processing data of individuals under 18
Enhanced Obligations for Significant Data Fiduciaries
Large GCCs may qualify as Significant Data Fiduciaries (SDFs), triggering additional requirements:
- Annual Data Protection Impact Assessments (DPIAs)
- Mandatory annual audits by independent auditors
- Algorithmic fairness assessments
- Appointment of a Data Protection Officer (DPO) based in India
- Enhanced technical due diligence requirements
The full compliance timeline extends to May 2027, but GCCs should begin implementation immediately given the complexity of operationalizing consent management and breach reporting workflows. Penalties under the DPDP Act can reach INR 250 crore for serious violations. For GCC-specific data security guidance, see our DPDP Act compliance guide for GCCs.

Staffing a Legal and Compliance GCC
Team Structure
A legal and compliance GCC in India is normally built as a pyramid, from the widest layer up:
- Support: paralegals and contract reviewers — the widest layer, handling first-pass review and document management
- Junior: legal analysts and associates
- Mid-Level: legal counsel and managers, who own workstreams and quality
- Senior: senior legal counsel and senior managers
- Leadership: a single GCC legal head or Associate General Counsel
The ratios between those layers depend entirely on the mandate — a contract-review centre is far more bottom-heavy than an advisory team supporting a parent legal department — so size them against your own workload model rather than a published template. Compensation for each level moves quickly and varies by city and by whether you are competing with Indian law firms or with the Big 4. Benchmark it against a current salary survey at the time you build the budget rather than against a figure published in an article.
Hiring Strategy
India's law schools produce a large annual graduating cohort, and the constraint on a legal GCC is rarely raw supply — it is finding candidates who can work to an onshore standard on foreign-law-governed documents. For GCC hiring, prioritize:
- National Law University (NLU) graduates: The NLU network is the deepest single source of contract, IP and international law talent
- LLM holders with foreign law exposure: UK/US-educated Indian lawyers for cross-border work
- Compliance professionals: Certified professionals (CIA, CAMS, CFE) for regulatory compliance roles
- Technology-enabled lawyers: Candidates with experience in contract lifecycle management (CLM) tools, e-discovery platforms, and legal AI
Key cities for legal GCC talent include Bengaluru, Mumbai, Delhi NCR, Hyderabad, and Pune. See our GCC location selection guide for detailed city comparisons.
Retention Considerations
Attrition is the main operating risk in a legal GCC, and it concentrates in the analyst and paralegal layers where the work is most substitutable. Effective retention strategies include:
- ESOPs and RSUs on a multi-year vesting schedule
- International rotation programs to parent company offices
- Clear career progression from analyst to Associate General Counsel
- Market-competitive compensation benchmarked against Indian law firms and Big 4 advisory practices
Transfer Pricing for Legal GCCs
Legal GCCs typically operate on a cost-plus model for transfer pricing purposes. There is no statutory or safe-harbour markup for legal or legal-process services — the safe harbour rules cover other categories — so the markup has to come from a benchmarking study on comparable Indian companies. A markup adopted without a contemporaneous study will not survive a transfer pricing audit, whatever its level.
Key transfer pricing considerations:
- Benchmarking: Use the Transactional Net Margin Method (TNMM) with comparable Indian legal process outsourcing companies as benchmarks
- Documentation: Maintain contemporaneous transfer pricing documentation under sections 161 to 173 of the Income-tax Act, 2025 (sections 92 to 92F of the Income-tax Act, 1961)
- Form 48 (formerly Form 3CEB): The accountant's report under section 172 of the Income-tax Act, 2025 (section 92E of the Income-tax Act, 1961), due one month before the return — 31 October where the return is due 30 November
- Functional analysis: Clearly document whether the GCC is a low-risk service provider or a knowledge-based value creator, as this affects the appropriate markup

Technology Infrastructure for Legal GCCs
Core Technology Stack
A modern legal and compliance GCC requires investment in specialized technology platforms that enable efficient delivery of legal services across time zones. The technology infrastructure typically includes contract lifecycle management (CLM) platforms like Icertis, Ironclad, or Agiloft for end-to-end contract management; e-discovery tools such as Relativity, Nuix, or Logikcull for litigation support workflows; legal research databases including Westlaw, LexisNexis, and Manupatra for Indian law research; compliance management systems like Thomson Reuters CLEAR or Diligent for regulatory tracking; and matter management tools such as Legal Tracker or SimpleLegal for work allocation and reporting.
Licence cost is a material line item and should be budgeted separately from implementation and training, which usually run over a full quarter. Several global legal technology vendors publish India-specific pricing tiers below their US and European list prices — ask for them explicitly, because they are rarely offered unprompted.
AI and Automation Adoption
Legal GCCs in India are increasingly adopting AI-powered tools for contract review, due diligence, and compliance monitoring. Generative AI tools can handle first-pass contract review, clause extraction, and risk flagging at significantly lower cost per document than manual review. However, AI adoption in legal GCCs must be balanced against data security obligations under the DPDP Act, client confidentiality requirements, and the need for human oversight on all substantive legal conclusions. Establish clear AI governance policies covering approved tools, data handling protocols, and quality assurance workflows before deployment. See our GCC AI and automation guide for implementation strategies.
Employment Law Compliance
Legal GCCs must comply with both central and state-level employment laws:
- Prevention of Sexual Harassment (POSH) Act: Mandatory Internal Complaints Committee, annual POSH training, and filing of annual returns
- Equal Opportunity Policy: Required under the Rights of Persons with Disabilities Act, 2016
- Working hours: State-specific Shops and Establishments Acts govern working hours, overtime, and leave entitlements
- Termination procedures: Notice periods are set by the employment contract, subject to the statutory minimum in the applicable State Shops and Establishments Act
- EPF and ESI: Mandatory provident fund (12% employer contribution) and employee state insurance contributions
For the corporate and exchange-control side of standing the entity up, see our FEMA and RBI compliance services.

Entity Structure for a Legal GCC
Most legal GCCs in India are structured as wholly-owned subsidiaries (private limited companies) of the foreign parent. This structure provides the clearest separation between the GCC's internal operations and BCI-regulated activities. The subsidiary should be incorporated with a business object clause that describes IT-enabled services, business process services, or knowledge process services rather than "legal services" to avoid confusion with regulated legal practice. The GCC should register under the Shops and Establishments Act of the relevant state, obtain professional tax registration, and comply with all standard corporate compliance requirements including ROC filings, FEMA reporting, and tax obligations.
Some organizations explore the Build-Operate-Transfer (BOT) model where a third-party Indian legal services provider builds and operates the team initially, then transfers operations to the captive entity at a handover date fixed in the contract. This model reduces initial setup risk but introduces vendor dependency and potential IP leakage concerns during the transition period. For more on operating models, see our GCC operating models comparison.
Risk Management and Professional Liability
Legal GCCs face unique risk management challenges that differ from traditional IT or finance GCCs. Work product errors in contract review, compliance monitoring, or regulatory filing preparation can expose the parent organization to significant financial and legal liability. Implement the following risk management framework: establish mandatory peer review for all work product before delivery to the parent entity, maintain professional indemnity insurance covering errors and omissions in legal work product, create detailed standard operating procedures (SOPs) for each service line with escalation matrices for complex or ambiguous matters, conduct quarterly quality audits on sample work product across all service lines, and maintain comprehensive conflict-of-interest checking procedures, especially if the parent organization is a law firm serving multiple clients.
The professional indemnity insurance market for legal GCCs in India is still maturing, and pricing varies widely with the nature of the work and the claims history of the group. Engage a specialized insurance broker with experience in professional services to structure appropriate coverage, and confirm that the policy responds to work performed in India for an overseas parent.

Key Takeaways
- BCI boundary: A captive legal GCC performing internal work is not a "law firm" under BCI rules, but any client-facing legal advisory involving Indian law is prohibited without BCI registration.
- DPDP compliance: Start implementing consent management, breach notification (72-hour window), and data retention policies now. Full compliance required by May 2027, with penalties up to INR 250 crore.
- Staffing: Build a pyramid from paralegals and contract reviewers up to a GCC legal head, benchmark compensation against a current salary survey, and budget for meaningful attrition in the junior layers.
- Transfer pricing: Structure as a cost-plus service provider and derive the markup from a contemporaneous benchmarking study on Indian comparables — there is no safe-harbour rate for legal services. Document the functional analysis meticulously.
- Location: Bengaluru, Mumbai, and Delhi NCR offer the deepest legal talent pools; Hyderabad and Pune are the usual lower-cost alternatives.
Need help with GCC Operations? Our team handles it.
India Entry StrategyFrequently Asked Questions
Can a foreign law firm set up a GCC in India?
Yes, but with restrictions. A foreign law firm can establish a GCC for internal legal operations (contract review, compliance monitoring, e-discovery). However, providing Indian legal advice to external clients requires BCI registration, and activities are limited to foreign and international law under the 2025 amended rules.
What is the 60-day FIFO presence cap under BCI Rules 2025?
Under the 2025 BCI rules, registered foreign lawyers are limited to a cumulative presence of 60 days in any 12-month period in India. This is a fly-in/fly-out (FIFO) model. Permanent relocation to India for practicing foreign law is not permitted under these rules.
Does the DPDP Act apply to legal GCCs processing data for overseas clients?
Yes. The DPDP Act 2023 applies to processing of digital personal data within India, regardless of where the data principal is located. A legal GCC handling personal data of overseas individuals must comply with consent, security, and breach notification requirements.
What transfer pricing markup is appropriate for a legal GCC?
Legal GCCs typically operate on a cost-plus model, but there is no statutory or safe-harbour markup for legal or legal-process services. The markup must be derived from a benchmarking study — normally TNMM with Indian LPO comparables — and a low-risk contract review operation will benchmark lower than a knowledge-intensive advisory function.
How should I budget for staffing a legal GCC in India?
Total cost is driven by the shape of the pyramid — one legal head, a thin senior layer, and a broad base of analysts and paralegals — rather than by headcount alone. Build the budget from a current salary survey for each level in your chosen city, then add real estate, technology licences and employer social security contributions on top.
What are the penalties for DPDP Act non-compliance?
The DPDP Act 2023 authorizes penalties up to INR 250 crore for serious violations. Under the Schedule to the Act, failure to take reasonable security safeguards carries a penalty of up to INR 250 crore, and failure to give the Board or the affected Data Principal notice of a personal data breach carries up to INR 200 crore.