InfraVeritas360DPDPiq

DPDP Insights › IT, ITeS, BPO and GCC › Director

IT, ITeS, BPO and GCC

DPDP for the Director in IT and ITeS

Your clients trust the company with their data. That trust is what you are really overseeing.

Open this seat in the interactive tool

What is different here

One incident in one client's systems can affect renewals across many accounts. Directors should look at incident readiness and sub-contractor control.

The first four things to sort out

  1. Ask how client data is separated and protected.
  2. Ask how fast clients are told about incidents.
  3. Ask whether sub-contractors sign the same terms.
  4. Ask for evidence, not only certifications.

A worked example: The board reviews client data risk

  1. BeforeDirectors receive the list of top clients by data sensitivity and their incident notice terms.
  2. MeetingA director asks how many sub-contractors have client access. The answer is 12, all under flow-down terms.
  3. Good answerA named owner, drill results and a sub-contractor list with dates.
  4. AfterClient data risk becomes a standing item.

Evidence kept: Board note; Minutes.

Directors should ask about sub-contractors by number.

What others in the sector usually do. Boards are asking to see access reviews and incident drills rather than relying on certificates alone.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
IT services and consultingProduction data copied to laptops or test environments; Shared client credentials in team chats; Sub-contractors working under your client access
BPO and contact centreCard numbers spoken on recorded calls; Phones and paper on the floor; Outbound calls without consent checks for Indian customers
Global capability centreIndian customer data mixed into global data sets; Global HR systems hosted abroad; Intra-group agreements that predate DPDP
SaaS and software productsSupport staff browsing customer tenants; Analytics on customer data beyond the contract; Deletion that does not reach backups
Managed services, data centres and cloudPrivileged admin access across many clients; Subscriber records kept with no access limits; Backups of client systems held for years

What a good answer from management sounds like

Question to askA good answer sounds likeEffort and time
A client's data is involved in an incident. Who tells whom?“We know each client's notice time, and in our last drill the client was told within two hours.”Light · 3 to 4 weeks
Does DPDP apply to data of foreign clients' customers?“Every project is tagged. Mixed projects follow full DPDP for the Indian data, and security is the same everywhere.”Light · 2 to 4 weeks
Are we a Data Fiduciary or a Data Processor?“We know, for each data set, whether we decide or act for someone else, and our contracts say so.”Light · 2 to 4 weeks
What should the board of directors ask management about DPDP?“DPDP is a standing quarterly item. Management brings a short note with names, numbers and evidence.”Light · one agenda item every quarter
Do we need a DPO?“We have named an accountable person with a deputy, published the contact, and that person reports to management every month.”Light · 2 to 4 weeks
Something has gone wrong. What happens in the first 72 hours?“We have one plan that meets every clock. It was rehearsed this year, and the next rehearsal date is fixed.”Medium · 4 to 8 weeks, then a yearly drill
What must a vendor contract say about personal data?“Our top vendors have data terms with a short incident-notice time, and we review them every year.”Medium · 8 to 16 weeks for the top vendors
Could we be a Significant Data Fiduciary?“We have estimated our exposure. If we are notified, we can appoint a DPO and an auditor within weeks, because the groundwork is done.”Medium if you are a likely candidate
How much effort and time will it take to be ready by 13 May 2027?“We have a dated plan with named owners. Each month we see evidence, not just colours, and we expect to finish before March 2027.”Programme · six to nine months

9 guides for the Director, in full

A client's data is involved in an incident. Who tells whom?

Short answer: Client first, within contract hours; CERT-In in six hours

Tell the client first, within the time your contract sets, because the client is the fiduciary and must tell its own customers and the Board. Report to CERT-In within six hours if the incident is reportable. Give the client logs and facts quickly; do not contact the client's customers yourself unless the client asks.

From your seat: Director. Ask for the fastest and slowest client notice in the last drill.
What the law says

Section 8(6) puts the duty to tell people on the fiduciary. As processor, your contract decides your duty to the client. Section 8(6) · Rule 7 · Section 8(1)–(2)

What a good answer from management sounds like: “We know each client's notice time, and in our last drill the client was told within two hours.”
Effort and time: Light · 3 to 4 weeks.
Steps
  1. Keep a list of client notice times.
  2. Name who calls each client.
  3. Prepare a client incident template.
  4. File CERT-In if reportable.
  5. Share logs and a written account.
Evidence to keep
  • Client notice list
  • Incident timeline
  • CERT-In record
Common mistakes
  • Waiting to finish the investigation before telling the client
  • Contacting the client's customers directly
  • Missing the CERT-In clock
Related questions

Does DPDP apply to data of foreign clients' customers?

Short answer: Mostly exempt for offshore data; security still applies

Mostly not. Section 17(1)(d) exempts processing of personal data of people outside India when you do it under a contract with a party outside India. Security safeguards and responsibility for your processors still apply. The exemption does not cover your Indian staff, Indian customers, or Indian data mixed into the same work.

What the law says

Section 17(1)(d) sets the exemption. Section 8(5) and 8(1) still apply. Section 17(1)(d) · Section 8(5) · Rule 6 · Section 8(1)–(2)

What a good answer from management sounds like: “Every project is tagged. Mixed projects follow full DPDP for the Indian data, and security is the same everywhere.”
Effort and time: Light · 2 to 4 weeks.
Steps
  1. Tag each project by where the people live.
  2. Find mixed projects with Indian data.
  3. Keep security controls the same for all.
  4. Record which contracts rely on the exemption.
  5. Review when projects change.
Evidence to keep
  • Project tagging
  • Contract list
Common mistakes
  • Assuming all client work is exempt
  • Lower security for exempt data
  • Missing Indian data in global data sets
Related questions

Are we a Data Fiduciary or a Data Processor?

Short answer: Often both, for different data

You are a Data Fiduciary when you decide why and how personal data is used, as you do for your own staff and customers. You are a Data Processor when you handle data only on another organisation's instructions. Many organisations are both, for different data sets.

In IT and ITeS

You are usually a processor for client data and a fiduciary for staff and candidates.

What the law says

Section 2(i) and 2(k) define the two roles. Section 8(1) puts the duties on the Data Fiduciary, which must use processors only under a valid contract. Section 8(1)–(2) · Section 17(1)(d)

What a good answer from management sounds like: “We know, for each data set, whether we decide or act for someone else, and our contracts say so.”
Effort and time: Light · 2 to 4 weeks.
Steps
  1. List each data set you handle.
  2. For each, ask: who decides the purpose?
  3. Mark yourself as fiduciary or processor, and name the other party.
  4. Check that contracts match the role.
  5. Route requests about processor data to the fiduciary.
Evidence to keep
  • Role register by data set
  • Contracts matching the role
Common mistakes
  • Calling yourself a processor for data you use for your own purposes
  • No contract when you act as processor
  • Answering requests that belong to your client
Related questions

What should the board of directors ask management about DPDP?

Short answer: Five plain questions, asked every quarter

Directors do not need technical detail. They need to know who is accountable, how the organisation would handle a breach, which outside parties hold data, and whether the plan to May 2027 is on track with evidence.

From your seat: Director. Ask the five questions every quarter, and record the answers in the minutes. The answers will improve when management knows the questions are coming.
In IT and ITeS

Ask about client incident terms and sub-contractor numbers.

What the law says

The Act places duties on the Data Fiduciary, the organisation itself. Directors oversee whether management has put those duties into practice. Section 8(1)–(2) · Section 8(6) · Rule 7 · Section 10 · Rule 13

What a good answer from management sounds like: “DPDP is a standing quarterly item. Management brings a short note with names, numbers and evidence.”
Effort and time: Light · one agenda item every quarter.
Steps
  1. Ask who is accountable for personal data, by name.
  2. Ask when the breach plan was last rehearsed and what was learnt.
  3. Ask for the list of vendors holding the most personal data.
  4. Ask how many requests and complaints came in, and how fast they were answered.
  5. Ask for the plan to May 2027 with evidence, not colours.
Evidence to keep
  • Quarterly note to the board
  • Minutes showing the questions asked
  • Management responses
Common mistakes
  • Discussing DPDP once and then never again
  • Accepting 'IT is handling it'
  • No date for the breach rehearsal
Related questions

Do we need a DPO?

Short answer: Not required by law unless notified as an SDF, but name one person

Only a Significant Data Fiduciary must appoint a DPO, based in India. Every other organisation must publish the contact of a person who can answer questions about personal data. In practice, most organisations of any size name one accountable person anyway, because someone has to own requests, complaints and breaches.

From your seat: Director. Ask who the accountable person is, what authority they have, and when they last reported to the board or a committee.
In IT and ITeS

Large IT firms with big staff and candidate data are not automatically SDFs, but clients expect a named DPO.

What the law says

Section 8(9) and Rule 9 require a published contact person for every Data Fiduciary. Section 10 requires a DPO in India for Significant Data Fiduciaries. Section 8(9)–(10) · Rules 9, 14 · Section 10 · Rule 13

What a good answer from management sounds like: “We have named an accountable person with a deputy, published the contact, and that person reports to management every month.”
Effort and time: Light · 2 to 4 weeks.
Steps
  1. Name one accountable person, with a deputy.
  2. Publish the contact on your website, app and notices.
  3. Give the role time, a budget line and a route to management.
  4. Set a short monthly report: requests, complaints, incidents, actions.
  5. Review the role if you are notified as an SDF.
Evidence to keep
  • Appointment letter
  • Published contact
  • Monthly report
Common mistakes
  • Giving the job to IT as a side task
  • A contact email nobody reads
  • No authority to make changes
Related questions

Something has gone wrong. What happens in the first 72 hours?

Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report

Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.

From your seat: Director. Ask when the plan was last rehearsed, who took part, and what went wrong in the drill. A drill with no findings was probably too easy.
In IT and ITeS

If client data is involved, the client contract sets your first deadline, often a few hours.

What the law says

Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6

What a good answer from management sounds like: “We have one plan that meets every clock. It was rehearsed this year, and the next rehearsal date is fixed.”
Effort and time: Medium · 4 to 8 weeks, then a yearly drill.
Steps
  1. Name one incident lead and a back-up, with phone numbers that work at night.
  2. Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
  3. Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
  4. Decide in advance who signs off each message.
  5. Rehearse once a year with the people who would actually be called.
Evidence to keep
  • Incident plan with clocks
  • Rehearsal record
  • Incident log with times of each step
Common mistakes
  • Waiting to finish the investigation before telling anyone
  • Treating a wrong email or a lost laptop as 'not a breach'
  • Only IT knowing the plan
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: Director. Ask which three vendors hold the most personal data, and when their contracts were last reviewed.
In IT and ITeS

Sub-contractors working on client data need the same terms you signed with the client.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

What a good answer from management sounds like: “Our top vendors have data terms with a short incident-notice time, and we review them every year.”
Effort and time: Medium · 8 to 16 weeks for the top vendors.
Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Could we be a Significant Data Fiduciary?

Short answer: Only by notification; none notified yet

Only the government can notify an organisation or a class of organisations as a Significant Data Fiduciary, based on the volume and sensitivity of data and the risk to people or the State. None had been notified when this page was last reviewed. Large holders of sensitive data should plan as if it could happen.

From your seat: Director. Ask whether management has assessed the chance of notification. Large or sensitive data holders should have a view.
In IT and ITeS

Notification is more likely for consumer platforms than for IT services, but large SaaS players should watch.

What the law says

Section 10 and Rule 13 set the extra duties: a DPO in India, an independent data auditor, a yearly Data Protection Impact Assessment and audit, and checks on algorithms. Rule 13(4) allows the government to restrict some data from leaving India. Section 10 · Rule 13 · Section 16 · Rule 15

What a good answer from management sounds like: “We have estimated our exposure. If we are notified, we can appoint a DPO and an auditor within weeks, because the groundwork is done.”
Effort and time: Medium if you are a likely candidate.
Steps
  1. Estimate how many people's data you hold and how sensitive it is.
  2. Note any public or security role your data plays.
  3. If you are a likely candidate, run a trial impact assessment this year.
  4. Identify an auditor you could appoint.
  5. Watch MeitY notifications.
Evidence to keep
  • Volume and sensitivity note
  • Trial impact assessment
  • Board note
Common mistakes
  • Assuming 'not notified' means 'never'
  • Waiting for notification to start
  • Thinking only tech companies will be notified
Related questions

How much effort and time will it take to be ready by 13 May 2027?

Short answer: Six to nine months of steady work for most

For most organisations it is a programme of six to nine months, not a single project. The heavy parts are the data inventory, vendor contracts, access control and the request process. Notices, the contact person and training are lighter. Starting now leaves time to fix what you find.

From your seat: Director. Ask for evidence against the plan, such as signed contracts, rehearsal reports and request logs, not just status colours.
In IT and ITeS

Staff data work is quick; client contract alignment takes longer.

What the law says

Most duties under the DPDP Rules start on 13 May 2027. Section 8(5) · Rule 6 · Section 8(1)–(2) · Sections 11–14 · Rule 14

What a good answer from management sounds like: “We have a dated plan with named owners. Each month we see evidence, not just colours, and we expect to finish before March 2027.”
Effort and time: Programme · six to nine months.
Steps
  1. Month 1: name the owner, set a budget line, start the inventory.
  2. Months 2 to 3: notices, consent records, contact person, request register.
  3. Months 3 to 6: vendor contracts, access control, logs, retention schedule.
  4. Months 6 to 8: breach rehearsal, training, internal review.
  5. Month 9: management review with evidence.
Evidence to keep
  • Programme plan with owners
  • Monthly status with evidence
  • Management minutes
Common mistakes
  • Leaving it to the last quarter
  • Buying a tool before knowing the gaps
  • Status colours with no evidence behind them
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for it, ites, bpo and gcc.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
CERT-In Directions, 28 April 2022Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to NIC or NPL time servers. Data centres, VPS, cloud and VPN providers keep specified subscriber information for five years.Breach handling must meet the six-hour CERT-In clock and the DPDP report to the Board. Subscriber records need DPDP-level protection.CERT-In
DPDP Act, Section 17(1)(d)Processing of data of people outside India, under a contract with a party outside India, is exempt from most of the Act.Tag each data set by where the people live. The exemption does not cover Indian staff or Indian customers.MeitY
IT Act, Section 43A and SPDI Rules, 2011Reasonable security practices for sensitive personal data, until Section 43A is omitted on 13 May 2027.Your current ISO 27001 practices meet these today; DPDP Rule 6 takes over from May 2027.MeitY
TRAI Telecom Commercial Communications Customer Preference Regulations, 2018Commercial calls and SMS to Indian numbers must follow registration and preference rules.Outbound campaigns for Indian clients need both DPDP consent and TRAI compliance.TRAI
Labour Codes (in force from 21 November 2025)The four labour codes replaced older labour laws, including registers and records employers must keep.Set retention for staff records against the new codes and state rules.Ministry of Labour
Client contracts and foreign laws (for example GDPR for EU clients)Clients often bind you to their own country's law through contracts and standard clauses.These are contract duties, not Indian law, but you must meet them alongside DPDP.Contract
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.