
Introduction
Global Capability Centres (‘GCCs’) have moved well beyond their origins as cost-efficient offshore delivery units. Across technology, financial services, pharmaceuticals, retail, manufacturing and consulting, India-based GCCs now anchor product engineering, analytics, cybersecurity, finance and AI-led work for global enterprises. For foreign businesses, general counsel and investors evaluating or scaling a GCC, this shift carries an important legal consequence: the GCC model is not simply a corporate structuring or tax exercise. It is, equally, an employment, workforce-structuring and intellectual property risk-management exercise, and treating it otherwise can leave the global enterprise exposed well before any dispute or transaction brings the gap to light.
Indian Employment Law Applies in Full, Regardless of Workforce Profile
A common assumption among foreign businesses is that Indian employment law is primarily relevant to factories or unionised, blue-collar workforces. This does not hold for GCCs. Even a workforce composed entirely of engineers, analysts and technology specialists remains subject to a wide range of Central and State employment laws, spanning shops and establishments legislation, social security, labour welfare fund contributions, maternity benefits, sexual harassment prevention obligations, working hours and leave, wage-payment requirements and record-keeping.
This layer of compliance is also in transition. The four Labour Codes, covering wages, industrial relations, social security, and occupational safety, health and working conditions, came into force on 21 November 2025, with Central Rules notified in May 2026 and State-level implementation continuing in a phased manner. For GCCs, this means employment contracts, wage structures, payroll practices, working-hour policies, social security contributions and contractor arrangements all warrant reassessment against the Codes, rather than reliance on documentation carried over from other jurisdictions. Indian employment documentation generally needs to be localised for enforceability and practical administration, not merely translated from a global template.
Workforce Structuring: Employees, Contractors and BOT Arrangements
Most GCCs rely on a mix of direct employees, consultants, vendor personnel, secondees and outsourced service providers, and each category carries a different legal profile. The highest risk typically arises where personnel are formally employed by a contractor or vendor but are functionally controlled by the GCC, for instance where the GCC supervises day-to-day work, controls attendance, assigns tasks directly and integrates vendor personnel into its internal teams. In such situations, the arrangement may be examined to determine whether it reflects a genuine outsourcing relationship or a disguised employment relationship.
Build-operate-transfer (‘BOT’) structures warrant particular care. During the build phase, employees are typically hired by an Indian service provider with the intention that they later transition to the foreign company’s captive entity. Where this transition is not carefully documented, disputes can arise over continuity of service, accrued benefits, confidentiality, IP ownership and the allocation of liability between the vendor and the GCC. A preliminary legal review before choosing between direct hiring, outsourcing, a BOT structure, a professional employer organisation or a consultant model, together with vendor contracts that build in compliance obligations, indemnities and audit rights, can meaningfully reduce this exposure. Vendor and GCC employees are also best kept operationally distinct, through reporting lines, system access and HR processes, until any transfer is properly documented.
Restrictive Covenants Need an India-Specific Strategy
Foreign employers often look to protect their GCC investment through post-employment non-compete clauses. In India, however, such restrictions are generally not enforceable where they prevent an individual from pursuing their profession after employment ends. A more effective strategy centres on protections that are both enforceable and evidence-backed: confidentiality obligations, non-solicitation clauses, garden leave where appropriate, return-of-property requirements, invention assignment and data-access restrictions, supported operationally by role-based access controls, clean exit processes and repository logs.
For senior employees, product architects, AI engineers, cybersecurity personnel and finance or legal leadership in particular, a standard offer letter is unlikely to provide adequate protection. Employment contracts for such roles should be tailored to the individual’s access to sensitive information, and exit processes for employees with access to critical code, customer data or product strategy should not be delayed or treated as a formality.
IP Ownership Is Often the Central Legal Issue
Indian GCCs routinely generate software code, AI models, technical designs, databases, trade secrets and process improvements of real commercial value. Where ownership of this work product is not properly documented, the foreign parent may not hold a clean title chain to assets created in India, which in turn can affect both valuation and ownership at the point of a transaction or exit. Employment and consultancy agreements should clearly and presently assign relevant IP rights to the appropriate group entity, covering inventions, software, documentation, designs, databases and know-how, and should require employees and consultants to cooperate with patent filings and related documentation.
Work created by consultants and independent contractors carries a particular risk, since payment for work does not, on its own, transfer ownership of the resulting IP; a written assignment provision is essential. An internal IP register mapping key assets to their creators and underlying assignment documents, together with periodic review of open-source software usage, is a useful complement to the contractual protections.
Data Protection and AI Governance Add a Further Layer
GCCs typically process substantial volumes of personal data, spanning employees, customers, vendors and, in some cases, regulated data drawn from foreign markets. India’s data protection framework introduces obligations around notice, consent, the rights of individuals, security safeguards and breach response, and these obligations touch multiple GCC functions, including HR systems, background verification, workplace monitoring, internal investigations and cross-border data flows within the wider group.
The growing use of AI tools for coding, analytics, compliance review, recruitment and internal productivity adds a further dimension, raising questions around what data trains or tests a given AI system, whether employees are uploading confidential code or client data into external tools, who owns AI-assisted outputs, and whether adequate logs and audit trails are being maintained. These questions are best addressed through a documented AI-use policy rather than left to ad hoc practice.
AMLEGALS Remarks
Foreign businesses setting up or scaling a GCC in India would be well advised to treat employment structuring, restrictive covenants and IP ownership as core elements of the legal framework from the outset, rather than matters to be resolved once a dispute, audit or transaction brings a gap to light. This includes localising employment contracts and mapping compliance State by State, structuring vendor and BOT arrangements with clear documentation on transfer and continuity, and using enforceable protections such as confidentiality, non-solicitation and IP assignment in place of post-employment non-competes.
Equally, a defensible GCC framework should extend to POSH compliance, social security registrations, data protection notices, an AI-use and open-source policy, and a documented exit management protocol, reviewed periodically as the Labour Code’s State-level implementation and India’s data protection framework continue to develop.
For any queries or feedback, feel free to connect with Hiteashi.desai@amlegals.com
