InfraVeritas360DPDPiq

DPDP Insights › IT, ITeS, BPO and GCC › Legal department

IT, ITeS, BPO and GCC

DPDP for the Legal department in IT and ITeS

Legal holds client and sub-contractor contracts.

Open this seat in the interactive tool

What is different here

You are a Data Fiduciary for your own staff and candidates, and usually a Data Processor for the client data your teams work on. Data of people outside India, handled under a contract with a foreign client, is mostly outside the Act, but security and responsibility for sub-contractors still apply.

The first four things to sort out

  1. Standard positions.
  2. Flow-down terms.
  3. Offshore exemption tracking.
  4. Incident notice times.

A worked example: A sub-contractor wants to use a cloud tool abroad

  1. Day 1Legal checks the client contract.
  2. Day 3Client approval is sought.
  3. Week 2Approved with conditions.
  4. AfterLogged.

Evidence kept: Approval.

Client approval before new locations.

What others in the sector usually do. Clause libraries speed up client negotiation.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
IT services and consultingProduction data copied to laptops or test environments; Shared client credentials in team chats; Sub-contractors working under your client access
BPO and contact centreCard numbers spoken on recorded calls; Phones and paper on the floor; Outbound calls without consent checks for Indian customers
Global capability centreIndian customer data mixed into global data sets; Global HR systems hosted abroad; Intra-group agreements that predate DPDP
SaaS and software productsSupport staff browsing customer tenants; Analytics on customer data beyond the contract; Deletion that does not reach backups
Managed services, data centres and cloudPrivileged admin access across many clients; Subscriber records kept with no access limits; Backups of client systems held for years

8 guides for the Legal department, in full

Does DPDP apply to data of foreign clients' customers?

Short answer: Mostly exempt for offshore data; security still applies

Mostly not. Section 17(1)(d) exempts processing of personal data of people outside India when you do it under a contract with a party outside India. Security safeguards and responsibility for your processors still apply. The exemption does not cover your Indian staff, Indian customers, or Indian data mixed into the same work.

What the law says

Section 17(1)(d) sets the exemption. Section 8(5) and 8(1) still apply. Section 17(1)(d) · Section 8(5) · Rule 6 · Section 8(1)–(2)

Steps
  1. Tag each project by where the people live.
  2. Find mixed projects with Indian data.
  3. Keep security controls the same for all.
  4. Record which contracts rely on the exemption.
  5. Review when projects change.
Evidence to keep
  • Project tagging
  • Contract list
Common mistakes
  • Assuming all client work is exempt
  • Lower security for exempt data
  • Missing Indian data in global data sets
Related questions

A client's data is involved in an incident. Who tells whom?

Short answer: Client first, within contract hours; CERT-In in six hours

Tell the client first, within the time your contract sets, because the client is the fiduciary and must tell its own customers and the Board. Report to CERT-In within six hours if the incident is reportable. Give the client logs and facts quickly; do not contact the client's customers yourself unless the client asks.

What the law says

Section 8(6) puts the duty to tell people on the fiduciary. As processor, your contract decides your duty to the client. Section 8(6) · Rule 7 · Section 8(1)–(2)

Steps
  1. Keep a list of client notice times.
  2. Name who calls each client.
  3. Prepare a client incident template.
  4. File CERT-In if reportable.
  5. Share logs and a written account.
Evidence to keep
  • Client notice list
  • Incident timeline
  • CERT-In record
Common mistakes
  • Waiting to finish the investigation before telling the client
  • Contacting the client's customers directly
  • Missing the CERT-In clock
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: Legal department. Keep a standard data-protection schedule and insist on it.
In IT and ITeS

Sub-contractors working on client data need the same terms you signed with the client.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Are we a Data Fiduciary or a Data Processor?

Short answer: Often both, for different data

You are a Data Fiduciary when you decide why and how personal data is used, as you do for your own staff and customers. You are a Data Processor when you handle data only on another organisation's instructions. Many organisations are both, for different data sets.

From your seat: Legal department. Decide the role for each data set and make contracts match.
In IT and ITeS

You are usually a processor for client data and a fiduciary for staff and candidates.

What the law says

Section 2(i) and 2(k) define the two roles. Section 8(1) puts the duties on the Data Fiduciary, which must use processors only under a valid contract. Section 8(1)–(2) · Section 17(1)(d)

Steps
  1. List each data set you handle.
  2. For each, ask: who decides the purpose?
  3. Mark yourself as fiduciary or processor, and name the other party.
  4. Check that contracts match the role.
  5. Route requests about processor data to the fiduciary.
Evidence to keep
  • Role register by data set
  • Contracts matching the role
Common mistakes
  • Calling yourself a processor for data you use for your own purposes
  • No contract when you act as processor
  • Answering requests that belong to your client
Related questions

Police, a court or a regulator asks for someone's data. What do we do?

Short answer: Yes, when the request is lawful and in writing

Check that the request is in writing, comes from the right authority and cites the legal power. Share only what is asked for, record what you sent and to whom, and keep the request on file. The Act allows processing to meet a legal duty, but it does not mean sharing everything on a phone call.

From your seat: Legal department. Check the legal power for every request and log what was shared.
What the law says

Section 7(d) and 7(e) allow processing to meet a legal duty to disclose to the State, or to comply with a judgment or order. Section 17(1)(c) exempts processing for preventing, detecting or investigating offences. Section 7 · Section 8(5) · Rule 6

Steps
  1. Route every such request to Legal.
  2. Check the authority, the legal power and the scope.
  3. Share only what is asked, by a secure method.
  4. Log the request, what was sent, by whom and when.
  5. Tell the person, unless the law or the authority says you must not.
Evidence to keep
  • Authority request log
  • Copies of requests
  • Record of what was sent
Common mistakes
  • Sharing on a phone call
  • Sending whole files when a few lines were asked
  • No log
Related questions

Can personal data be stored or accessed outside India?

Short answer: Yes, unless a sector rule says otherwise

Under DPDP, yes, unless the government restricts a country, and none had been restricted when this page was last reviewed. A sector rule can be stricter, for example RBI's rule that payment system data must be stored only in India. Remote support access from abroad also counts as data going outside India.

From your seat: Legal department. Track sector localisation rules and add location clauses to contracts.
In IT and ITeS

Global HR and collaboration tools are often hosted abroad. Clients may restrict where their data goes.

What the law says

Section 16 allows transfers unless restricted, and keeps stricter sector laws in force. Rule 15 adds conditions on making data available to foreign states. Section 16 · Rule 15 · Section 8(1)–(2)

Steps
  1. List where each system is hosted and where support teams log in from.
  2. Check sector rules for localisation.
  3. Put location and access terms in cloud and vendor contracts.
  4. Keep the list current; new SaaS tools change it quietly.
  5. Tell people in your notice if data goes abroad.
Evidence to keep
  • Hosting and access-location list
  • Contract clauses
  • Sector rule check
Common mistakes
  • Forgetting email, CRM and helpdesk SaaS
  • Ignoring overseas support logins
  • Assuming 'Indian vendor' means 'data in India'
Related questions

Do we process children's data, and what changes if we do?

Short answer: Check every channel; children often appear where you least expect

Anyone under 18 is a child under the Act. For a child's data you need verifiable consent from a parent or lawful guardian, and you must not track, behaviourally monitor or show targeted ads to children. Some classes and purposes are exempt under Rule 12 and the Fourth Schedule, for example healthcare to the extent needed to protect the child's health, and educational institutions for their educational work.

From your seat: Legal department. Record the Fourth Schedule reasoning for each purpose.
In IT and ITeS

Usually only if a client's service involves children, or in staff dependants' records.

What the law says

Section 9 sets the duties. Rule 10 explains how to verify the parent. Rule 12 and the Fourth Schedule list the exemptions. Section 9 · Rules 10, 12 · Section 6

Steps
  1. Find where children's data enters: customers, dependants, interns, visitors, scholarships, app sign-ups.
  2. Decide whether an exemption in the Fourth Schedule applies to that purpose.
  3. Where none applies, add an age question and a parent-consent step.
  4. Switch off tracking and targeted ads for under-18 users.
  5. Record the decision for each channel.
Evidence to keep
  • Channel-by-channel note on children's data
  • Parent-consent records
  • Ad and tracking settings
Common mistakes
  • Assuming 'we are B2B, so no children'
  • Using the age 13 or 16 from foreign laws
  • Treating a tick-box from the child as parental consent
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for it, ites, bpo and gcc.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
CERT-In Directions, 28 April 2022Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to NIC or NPL time servers. Data centres, VPS, cloud and VPN providers keep specified subscriber information for five years.Breach handling must meet the six-hour CERT-In clock and the DPDP report to the Board. Subscriber records need DPDP-level protection.CERT-In
DPDP Act, Section 17(1)(d)Processing of data of people outside India, under a contract with a party outside India, is exempt from most of the Act.Tag each data set by where the people live. The exemption does not cover Indian staff or Indian customers.MeitY
IT Act, Section 43A and SPDI Rules, 2011Reasonable security practices for sensitive personal data, until Section 43A is omitted on 13 May 2027.Your current ISO 27001 practices meet these today; DPDP Rule 6 takes over from May 2027.MeitY
TRAI Telecom Commercial Communications Customer Preference Regulations, 2018Commercial calls and SMS to Indian numbers must follow registration and preference rules.Outbound campaigns for Indian clients need both DPDP consent and TRAI compliance.TRAI
Labour Codes (in force from 21 November 2025)The four labour codes replaced older labour laws, including registers and records employers must keep.Set retention for staff records against the new codes and state rules.Ministry of Labour
Client contracts and foreign laws (for example GDPR for EU clients)Clients often bind you to their own country's law through contracts and standard clauses.These are contract duties, not Indian law, but you must meet them alongside DPDP.Contract
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.