You are a Data Fiduciary for your own staff and candidates, and usually a Data Processor for the client data your teams work on. Data of people outside India, handled under a contract with a foreign client, is mostly outside the Act, but security and responsibility for sub-contractors still apply.
The first four things to sort out
Notices at entry points.
Delete visitor data on schedule.
Check cab and guard vendor contracts.
Limit footage viewing.
A worked example: Night-shift cab rosters on a vendor app
Week 1Admin finds staff home addresses on the cab vendor's app.
Week 2The contract gets data terms.
Week 3Old trip data is deleted.
AfterAccess is limited to the transport desk.
Evidence kept: Contract; Deletion.
Transport vendors hold home addresses.
What others in the sector usually do. Night-shift cab data is an often-missed item.
Short answer: Yes, with notice, limits and a deletion period
All three are personal data. Put a clear notice where people are recorded, collect only what you need at reception, keep footage and registers for a set period, and protect biometric templates carefully. Do not keep copies of ID documents unless you must.
From your seat: Administration department. Admin runs the cameras and the reception desk. Notices, retention and viewing rights are yours to fix.
Their data is your responsibility when you decide why and how it is used, for example gate passes, attendance, biometrics and safety records. The agency holds payroll and personal files, so your contract with the agency must cover how it protects that data.
From your seat: Administration department. Guards, housekeeping and drivers are often agency staff. Their ID copies and gate records need care.
In IT and ITeS
Contractors and consultants placed through agencies need the same access rules as staff.
What the law says
Section 7(i) covers employment purposes. Section 8(1) and 8(2) make you responsible for processors such as manpower agencies working on your behalf. Section 7 · Section 8(1)–(2) · Section 8(5) · Rule 6
Steps
List what you hold about contract workers: ID copies, photos, biometrics, attendance, medical fitness.
Decide who is the Data Fiduciary for each item: you or the agency.
Put data terms in every manpower contract.
Give a short notice in the workers' language at the gate or induction.
Short answer: Yes, every vendor that touches personal data
You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.
From your seat: Administration department. Security, housekeeping, transport and CCTV vendors all touch personal data. Their contracts need data terms.
In IT and ITeS
Sub-contractors working on client data need the same terms you signed with the client.
Short answer: For the legal or business period, then erase
Keep data for as long as its purpose needs, or as long as a law requires, and then erase it. Every organisation must keep personal data and logs for at least one year under Rule 8(3). Write a retention schedule by record type, with the law or reason against each period.
From your seat: Administration department. Visitor registers, gate passes and paper files need a period and a shredding date.
In IT and ITeS
Candidates, employees, alumni, and client data at project end.
What the law says
Section 8(7) asks for erasure when the purpose is over, unless a law requires retention. Rule 8(3) sets a one-year minimum for personal data, traffic data and logs. Section 8(7) · Rule 8 · Section 8(5) · Rule 6
Steps
List the record types you hold.
Write the period for each, with the law, regulator rule or business reason.
Set a trigger for the period to start: end of relationship, date of transaction, exit date.
Automate deletion where you can; for paper, schedule shredding.
Keep a deletion log.
Evidence to keep
Retention schedule approved by Legal
Deletion log
Shredding or disposal certificates
Common mistakes
'Keep everything forever' because storage is cheap
Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report
Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.
From your seat: Administration department. A lost register or a stolen laptop is a breach. Call the DPO the same day.
In IT and ITeS
If client data is involved, the client contract sets your first deadline, often a few hours.
What the law says
Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6
Steps
Name one incident lead and a back-up, with phone numbers that work at night.
Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
Decide in advance who signs off each message.
Rehearse once a year with the people who would actually be called.
Evidence to keep
Incident plan with clocks
Rehearsal record
Incident log with times of each step
Common mistakes
Waiting to finish the investigation before telling anyone
Treating a wrong email or a lost laptop as 'not a breach'
Short answer: Yes, at every point where you collect data
A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.
From your seat: Administration department. Reception and gates are collection points. Put the short notice there.
In IT and ITeS
Your careers page, candidate portal, employee onboarding and website forms need notices. For client data, the client gives the notice.
What the law says
Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14
Steps
List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
Write one short notice per collection point, with the data items and purpose side by side.
Add how to withdraw consent, how to make a request and the DPO or contact person's details.
Offer the notice in English and in the languages your client customers actually use.
Keep each version with the date it went live.
Evidence to keep
Screenshots or copies of the notice at each collection point, with dates
Notice version history
Translations, where used
Common mistakes
Hiding the notice inside terms and conditions
One notice for everything, with no link between data items and purposes
Section 5 · Rule 3: Notice. Candidate portals, employee onboarding and your own website forms need notices. For client data, the client normally gives the notice.
Section 8(5) · Rule 6: Security safeguards. Remote access to client systems, laptops and ticketing tools need control, monitoring and one-year logs.
Section 8(1)–(2): Responsibility for vendors. You are usually the processor for client data and a fiduciary for your own staff. Your sub-contractors are your processors.
Other rules that sit alongside DPDP
Rule
What it says
What it means alongside DPDP
Source
CERT-In Directions, 28 April 2022
Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to NIC or NPL time servers. Data centres, VPS, cloud and VPN providers keep specified subscriber information for five years.
Breach handling must meet the six-hour CERT-In clock and the DPDP report to the Board. Subscriber records need DPDP-level protection.