The Complete Compliance Checklist for BPOs and Global Capability Centres

A compliance checklist for Indian BPOs and Global Capability Centres covering OSP registration, labour law, POSH, night shifts and data protection.

ComplianceCheck Team·Published 15 July 2026

BPOs and Global Capability Centres (GCCs) in India run large, often round-the-clock workforces handling sensitive client and customer data, which puts them at the intersection of labour law, workplace safety and data protection compliance. This checklist covers the areas that matter most.

Key facts at a glance

  • BPOs handling certain telecom-linked traffic may still need to confirm Other Service Provider (OSP) registration status with the Department of Telecommunications.
  • EPF is mandatory once a company has 20 or more employees, on wages up to Rs 15,000/month.
  • ESI is mandatory once a company has 10 or more employees, on wages up to Rs 21,000/month, and coverage has expanded to more IT/BPO categories.
  • A POSH Internal Committee is mandatory once a company has 10 or more employees, including remote and hybrid teams.
  • Most states require additional safeguards for women working night shifts, such as transport and security.
  • DPDP Act substantive obligations become enforceable from 13 May 2027, applying to any personal data processed within India regardless of client location.
  • The four Labour Codes came into force nationally on 21 November 2025, with state-level rules still being notified.

OSP registration and telecom-linked compliance

BPOs handling voice or data traffic historically needed Other Service Provider (OSP) registration from the Department of Telecommunications, particularly for international call centres. Recent years have seen significant relaxation of these requirements, including removal of many reporting and infrastructure conditions. Companies should confirm current applicability with DoT for their specific service model rather than assume either full exemption or full applicability by default.

Shops and Establishments and Special Economic Zone status

Most BPO and GCC offices register under the state Shops and Establishments Act, which governs working hours, leave, holidays and record-keeping. GCCs and BPOs operating out of SEZ units follow an additional layer of compliance under SEZ rules, including specific reporting to the Development Commissioner, alongside the standard state-level registration.

Labour law compliance for round-the-clock operations

BPOs and GCCs frequently run multiple shifts, including overnight, which brings additional labour compliance considerations beyond the standard thresholds.

RequirementThresholdNotes
Shops and Establishments registrationFrom first employee, state-specificGoverns shift hours and leave
EPF20+ employeesRs 15,000/month wage ceiling
ESI10+ employeesRs 21,000/month wage ceiling, expanded IT/BPO coverage in several states
POSH Internal Committee10+ employeesApplies to remote and hybrid staff too
Night shift safeguards for womenState-specificTransport, security, consent requirements

POSH for hybrid and remote-heavy workforces

Because much of the BPO/GCC workforce operates in hybrid or fully remote arrangements, the Internal Committee and POSH policy need to explicitly cover virtual harassment scenarios (video calls, chat platforms) in addition to physical workplace incidents. The Supreme Court's push for district-wise POSH audits and mandatory ICC registration on the government's SHe-Box portal applies to these companies the same way it applies to traditional offices.

Data protection for client and customer data

BPOs and GCCs process large volumes of personal data on behalf of clients, often across borders. Under the DPDP Act 2023, the Data Protection Board is already operational, the Consent Manager framework becomes operational 13 November 2026, and full substantive obligations around notice, consent, security safeguards and breach reporting become enforceable 13 May 2027. Penalties for failing to implement reasonable security safeguards can reach up to Rs 250 crore per instance. For companies processing data for overseas clients, this is a domestic Indian obligation that sits alongside whatever data protection terms exist in the client contract, not a substitute for them.

Labour Codes transition

The four Labour Codes (Wages, Industrial Relations, Social Security, OSH) came into force nationally on 21 November 2025. Because labour is a concurrent subject, each state must notify its own rules before the Codes are fully operational there, and most states had not fully notified as of mid-2026. BPOs operating across multiple states should track each state's specific status for provisions like overtime, working hours and social security definitions rather than assuming uniform national applicability yet.

If you are not sure where your BPO or GCC stands on labour and statutory compliance, ComplianceCheck's statutory compliance assessment gives you a clear picture in a few minutes.

Sources

  • Department of Telecommunications — dot.gov.in
  • Ministry of Labour and Employment — labour.gov.in
  • EPFO — epfindia.gov.in
  • ESIC — esic.gov.in
  • MeitY / Data Protection Board — meity.gov.in
  • Respective state labour department

This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.

Frequently Asked Questions

Do BPOs still need Other Service Provider (OSP) registration in India?
The Department of Telecommunications significantly relaxed OSP registration requirements in recent years, but companies handling certain telecom-linked or international voice traffic should confirm current applicability with DoT before assuming it no longer applies.
At how many employees does ESI become mandatory for a BPO?
ESI becomes mandatory once a BPO or GCC has 10 or more employees, and coverage has been extended in several states to IT and commercial office categories that were previously often excluded in practice.
Are night shift women employees subject to special rules in BPOs?
Yes, most states require additional safeguards for women working night shifts, such as transport, security and written consent, under state-specific shops and establishments or factory rules.
Does a Global Capability Centre need a separate compliance framework from a BPO?
No, GCCs and BPOs both fall under the same core Indian labour, tax and data protection frameworks; the difference is usually in entity structure (branch office versus subsidiary) rather than a separate compliance regime.
Is POSH compliance mandatory for a GCC with mostly remote employees?
Yes, the POSH Act applies regardless of work arrangement once headcount crosses 10 employees, and companies with hybrid or remote staff still need a functioning Internal Committee and a documented policy covering virtual interactions.
Does DPDP apply to a BPO processing data for an overseas client?
Yes, DPDP applies to processing of personal data within India regardless of where the end client is based, so BPOs processing personal data on behalf of foreign principals need to build DPDP compliance into their operations.

Check your status

Statutory Health Check

A 12-question health check of PF, ESI, Professional Tax, Gratuity and Bonus compliance for Indian employers.

Start free assessment →Free during beta · no subscription
Share:LinkedInXWhatsApp