Encryption helps, but client data on laptops is the real gap.
What others in the sector usually do. Client contracts now often ask to be told of an incident within hours, because the client's own clock starts when you tell them.
Short answer: Named, logged and removed at roll-off
Through named accounts, from managed devices or controlled jump servers, with multi-factor sign-in and logging. Access should be removed the day someone rolls off. Client data should stay in client systems and not be copied to laptops, internal tickets or chat.
From your seat: CISO / Security head. This is where most IT-sector incidents start.
Short answer: Client first, within contract hours; CERT-In in six hours
Tell the client first, within the time your contract sets, because the client is the fiduciary and must tell its own customers and the Board. Report to CERT-In within six hours if the incident is reportable. Give the client logs and facts quickly; do not contact the client's customers yourself unless the client asks.
From your seat: CISO / Security head. Start both clocks: client and CERT-In.
What the law says
Section 8(6) puts the duty to tell people on the fiduciary. As processor, your contract decides your duty to the client. Section 8(6) · Rule 7 · Section 8(1)–(2)
Steps
Keep a list of client notice times.
Name who calls each client.
Prepare a client incident template.
File CERT-In if reportable.
Share logs and a written account.
Evidence to keep
Client notice list
Incident timeline
CERT-In record
Common mistakes
Waiting to finish the investigation before telling the client
Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report
Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.
From your seat: CISO / Security head. You start the six-hour CERT-In clock and feed the DPO what is needed for the people and Board messages. Keep the timeline evidence: who saw what, and when.
In IT and ITeS
If client data is involved, the client contract sets your first deadline, often a few hours.
What the law says
Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6
Steps
Name one incident lead and a back-up, with phone numbers that work at night.
Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
Decide in advance who signs off each message.
Rehearse once a year with the people who would actually be called.
Evidence to keep
Incident plan with clocks
Rehearsal record
Incident log with times of each step
Common mistakes
Waiting to finish the investigation before telling anyone
Treating a wrong email or a lost laptop as 'not a breach'
Short answer: At least one year; 180 days of ICT logs in India
Keep logs that show who accessed personal data and what they did, for at least one year under the DPDP Rules. CERT-In separately asks for ICT system logs to be kept for 180 days within India. Logs must be protected so nobody can quietly change them.
From your seat: CISO / Security head. Check retention on every log source against one year, and make sure ICT logs stay in India for 180 days. Logs that can be edited by the admins they record are weak evidence.
In IT and ITeS
Keep logs of access to client systems, as well as your own systems.
What the law says
Rule 6 lists logs and monitoring as a minimum safeguard. Rule 8(3) asks for logs to be kept for at least one year. The CERT-In Directions of 2022 ask for 180 days of ICT logs kept within India. Section 8(5) · Rule 6 · Section 8(7) · Rule 8
Steps
List systems holding personal data and what each logs today.
Turn on access logging where it is missing.
Send logs to one protected store, with at least one year of retention.
Keep a copy of ICT logs in India for at least 180 days.
Short answer: Only those who need it, reviewed every quarter
Only people who need it for their job, and only the part they need. Use named accounts, give access by role, review it every quarter and remove it on the day someone leaves. Watch privileged accounts closely.
From your seat: CISO / Security head. Prioritise privileged and remote access. One review of admin accounts across core systems usually finds the biggest gaps.
In IT and ITeS
Your own HRMS and payroll, as well as client systems.
What the law says
Rule 6 names access control as a minimum safeguard, along with logs and monitoring that can detect misuse. Section 8(5) · Rule 6
Steps
Write a role matrix for each key system.
Replace shared logins with named accounts.
Use multi-factor sign-in for admin and remote access.
Short answer: Yes, through a written backup-expiry rule
Deletion should reach every copy you control. For backups, the usual practice is to let deleted records expire with the normal backup cycle, never restore them into live use, and write this down. Test and training copies should use masked data.
From your seat: CISO / Security head. Test a full restore, not a file restore. Then check that backup retention does not quietly keep deleted records for years.
In IT and ITeS
Client backups held by managed service teams must follow client retention.
What the law says
Section 8(7) asks for erasure. Rule 6 asks for backups for continuity. The two meet in a backup retention rule that is short enough and written down. Section 8(7) · Rule 8 · Section 8(5) · Rule 6
Steps
List where copies live: backups, replicas, test, analytics, laptops, vendors.
Set backup retention to match the retention schedule.
Write a rule: deleted records are not restored into live systems.
Mask personal data in test and training copies.
Get deletion confirmations from vendors.
Evidence to keep
Backup retention settings
Written backup-expiry rule
Masking procedure for test data
Common mistakes
Ten-year backups for convenience
Live copies in test
Restoring old backups and bringing deleted records back
Short answer: Yes, every vendor that touches personal data
You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.
From your seat: CISO / Security head. Set the technical schedule: incident notice in hours, logging, MFA, sub-contractor approval. Ask for evidence once a year.
In IT and ITeS
Sub-contractors working on client data need the same terms you signed with the client.
Short answer: Yes, unless a sector rule says otherwise
Under DPDP, yes, unless the government restricts a country, and none had been restricted when this page was last reviewed. A sector rule can be stricter, for example RBI's rule that payment system data must be stored only in India. Remote support access from abroad also counts as data going outside India.
From your seat: CISO / Security head. Look at where admins and support staff log in from, not only where servers sit. Overseas support access is a transfer.
In IT and ITeS
Global HR and collaboration tools are often hosted abroad. Clients may restrict where their data goes.
What the law says
Section 16 allows transfers unless restricted, and keeps stricter sector laws in force. Rule 15 adds conditions on making data available to foreign states. Section 16 · Rule 15 · Section 8(1)–(2)
Steps
List where each system is hosted and where support teams log in from.
Check sector rules for localisation.
Put location and access terms in cloud and vendor contracts.
Keep the list current; new SaaS tools change it quietly.
Short answer: Yes, this is a common breach; give staff a safer option
Sending personal data to the wrong chat or a personal account is one of the most common breaches. Banning messaging rarely works. Give staff an approved tool that is easy to use, set simple rules, and make it safe to report a wrong send at once.
From your seat: CISO / Security head. Your tooling can help: data-loss rules on email, an approved file-share, mobile device controls. Pair it with a reporting route that people trust.
In IT and ITeS
Client credentials and customer screenshots in team chats are a common issue.
Short answer: They cover security, not the whole Act
They help a great deal with the security part. ISO/IEC 27001 and NIST CSF 2.0 are good evidence of reasonable security safeguards. They do not cover notice, consent, rights, complaints or children's data. ISO/IEC 27701 adds privacy controls, but no certificate replaces the Act.
From your seat: CISO / Security head. Use the control map below. Most of Rule 6 is already in your ISO or NIST work; the job is to collect the evidence in one place.
In IT and ITeS
ISO/IEC 27001 is common in the sector; ISO/IEC 27701 adds privacy controls clients ask for.
What the law says
Section 8(5) and Rule 6 ask for reasonable security safeguards. A recognised standard is strong evidence of that duty, and only of that duty. Section 8(5) · Rule 6
Steps
Map your current controls to Rule 6.
Add the DPDP-only items: notice, consent, rights, complaints, children, retention.
Use the same evidence for audits and for DPDP.
Include privacy in the scope of your next internal audit.
Consider ISO/IEC 27701 if clients ask for it.
Evidence to keep
Control map
Audit reports
Gap list for DPDP-only items
Common mistakes
Treating a certificate as DPDP compliance
Scope that leaves out the systems with the most personal data
Section 8(5) · Rule 6: Security safeguards. Remote access to client systems, laptops and ticketing tools need control, monitoring and one-year logs.
Section 8(6) · Rule 7: Telling people about a breach. Clients' contracts often require notice within hours, because their own clock starts when you tell them.
Section 8(1)–(2): Responsibility for vendors. You are usually the processor for client data and a fiduciary for your own staff. Your sub-contractors are your processors.
Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to NIC or NPL time servers. Data centres, VPS, cloud and VPN providers keep specified subscriber information for five years.
Breach handling must meet the six-hour CERT-In clock and the DPDP report to the Board. Subscriber records need DPDP-level protection.