You are a Data Fiduciary for your own staff and candidates, and usually a Data Processor for the client data your teams work on. Data of people outside India, handled under a contract with a foreign client, is mostly outside the Act, but security and responsibility for sub-contractors still apply.
The first four things to sort out
Standard positions.
Flow-down terms.
Offshore exemption tracking.
Incident notice times.
A worked example: A sub-contractor wants to use a cloud tool abroad
Day 1Legal checks the client contract.
Day 3Client approval is sought.
Week 2Approved with conditions.
AfterLogged.
Evidence kept: Approval.
Client approval before new locations.
What others in the sector usually do. Clause libraries speed up client negotiation.
Short answer: Mostly exempt for offshore data; security still applies
Mostly not. Section 17(1)(d) exempts processing of personal data of people outside India when you do it under a contract with a party outside India. Security safeguards and responsibility for your processors still apply. The exemption does not cover your Indian staff, Indian customers, or Indian data mixed into the same work.
Short answer: Client first, within contract hours; CERT-In in six hours
Tell the client first, within the time your contract sets, because the client is the fiduciary and must tell its own customers and the Board. Report to CERT-In within six hours if the incident is reportable. Give the client logs and facts quickly; do not contact the client's customers yourself unless the client asks.
What the law says
Section 8(6) puts the duty to tell people on the fiduciary. As processor, your contract decides your duty to the client. Section 8(6) · Rule 7 · Section 8(1)–(2)
Steps
Keep a list of client notice times.
Name who calls each client.
Prepare a client incident template.
File CERT-In if reportable.
Share logs and a written account.
Evidence to keep
Client notice list
Incident timeline
CERT-In record
Common mistakes
Waiting to finish the investigation before telling the client
Short answer: It depends on the use; most organisations need both
For every use of personal data you need one basis: consent, or one of the legitimate uses in Section 7, such as a legal duty, employment, a medical emergency, or data a person gave voluntarily for a specific purpose. Anything beyond what the person expects, such as marketing, profiling or sharing with partners, usually needs consent.
From your seat: Legal department. Record the legal basis for each purpose with the exact clause.
In IT and ITeS
Payroll and background checks are employment purposes. Newsletters to prospects need consent.
What the law says
Section 4 allows processing only with consent or for a legitimate use. Section 6 sets what valid consent looks like. Section 7 lists the uses that need no consent. Section 4 · Section 6 · Section 7
Steps
List each purpose for which you use personal data.
Against each purpose, write the basis: consent or the exact clause of Section 7.
Where the basis is consent, check that it was asked separately, with a clear action and no pre-ticked box.
Stop or re-paper any purpose with no basis.
Review the list whenever a new product, campaign or system starts.
Evidence to keep
Purpose and basis register
Consent records with date, version and channel
Legal sign-off on each legitimate use relied on
Common mistakes
Treating account terms as consent for marketing
Bundling several purposes in one tick-box
Relying on 'legitimate interest', which the Indian Act does not have
Short answer: Yes, every vendor that touches personal data
You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.
From your seat: Legal department. Keep a standard data-protection schedule and insist on it.
In IT and ITeS
Sub-contractors working on client data need the same terms you signed with the client.
You are a Data Fiduciary when you decide why and how personal data is used, as you do for your own staff and customers. You are a Data Processor when you handle data only on another organisation's instructions. Many organisations are both, for different data sets.
From your seat: Legal department. Decide the role for each data set and make contracts match.
In IT and ITeS
You are usually a processor for client data and a fiduciary for staff and candidates.
What the law says
Section 2(i) and 2(k) define the two roles. Section 8(1) puts the duties on the Data Fiduciary, which must use processors only under a valid contract. Section 8(1)–(2) · Section 17(1)(d)
Steps
List each data set you handle.
For each, ask: who decides the purpose?
Mark yourself as fiduciary or processor, and name the other party.
Check that contracts match the role.
Route requests about processor data to the fiduciary.
Evidence to keep
Role register by data set
Contracts matching the role
Common mistakes
Calling yourself a processor for data you use for your own purposes
Short answer: Yes, when the request is lawful and in writing
Check that the request is in writing, comes from the right authority and cites the legal power. Share only what is asked for, record what you sent and to whom, and keep the request on file. The Act allows processing to meet a legal duty, but it does not mean sharing everything on a phone call.
From your seat: Legal department. Check the legal power for every request and log what was shared.
What the law says
Section 7(d) and 7(e) allow processing to meet a legal duty to disclose to the State, or to comply with a judgment or order. Section 17(1)(c) exempts processing for preventing, detecting or investigating offences. Section 7 · Section 8(5) · Rule 6
Steps
Route every such request to Legal.
Check the authority, the legal power and the scope.
Share only what is asked, by a secure method.
Log the request, what was sent, by whom and when.
Tell the person, unless the law or the authority says you must not.
Short answer: Yes, unless a sector rule says otherwise
Under DPDP, yes, unless the government restricts a country, and none had been restricted when this page was last reviewed. A sector rule can be stricter, for example RBI's rule that payment system data must be stored only in India. Remote support access from abroad also counts as data going outside India.
From your seat: Legal department. Track sector localisation rules and add location clauses to contracts.
In IT and ITeS
Global HR and collaboration tools are often hosted abroad. Clients may restrict where their data goes.
What the law says
Section 16 allows transfers unless restricted, and keeps stricter sector laws in force. Rule 15 adds conditions on making data available to foreign states. Section 16 · Rule 15 · Section 8(1)–(2)
Steps
List where each system is hosted and where support teams log in from.
Check sector rules for localisation.
Put location and access terms in cloud and vendor contracts.
Keep the list current; new SaaS tools change it quietly.
Short answer: Check every channel; children often appear where you least expect
Anyone under 18 is a child under the Act. For a child's data you need verifiable consent from a parent or lawful guardian, and you must not track, behaviourally monitor or show targeted ads to children. Some classes and purposes are exempt under Rule 12 and the Fourth Schedule, for example healthcare to the extent needed to protect the child's health, and educational institutions for their educational work.
From your seat: Legal department. Record the Fourth Schedule reasoning for each purpose.
In IT and ITeS
Usually only if a client's service involves children, or in staff dependants' records.
What the law says
Section 9 sets the duties. Rule 10 explains how to verify the parent. Rule 12 and the Fourth Schedule list the exemptions. Section 9 · Rules 10, 12 · Section 6
Steps
Find where children's data enters: customers, dependants, interns, visitors, scholarships, app sign-ups.
Decide whether an exemption in the Fourth Schedule applies to that purpose.
Where none applies, add an age question and a parent-consent step.
Switch off tracking and targeted ads for under-18 users.
Record the decision for each channel.
Evidence to keep
Channel-by-channel note on children's data
Parent-consent records
Ad and tracking settings
Common mistakes
Assuming 'we are B2B, so no children'
Using the age 13 or 16 from foreign laws
Treating a tick-box from the child as parental consent
Section 6: Consent. Marketing to prospects and optional employee programmes need proper consent.
Section 7: Uses allowed without consent. Payroll, access control, background checks and security monitoring of staff are employment purposes.
Section 8(1)–(2): Responsibility for vendors. You are usually the processor for client data and a fiduciary for your own staff. Your sub-contractors are your processors.
Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to NIC or NPL time servers. Data centres, VPS, cloud and VPN providers keep specified subscriber information for five years.
Breach handling must meet the six-hour CERT-In clock and the DPDP report to the Board. Subscriber records need DPDP-level protection.