IT companies hire in large numbers, run background checks through vendors, and keep alumni records. Candidate databases grow fast and are rarely cleaned.
The first four things to sort out
Give candidates and employees a short notice.
Set retention for unsuccessful candidates.
Check background verification vendor contracts.
Limit who can see salary and appraisal data.
A worked example: A candidate asks what you hold about her
Day 1HR logs the request from the careers page.
Day 3HR finds her CV, two interview notes and a background check report.
Day 5She receives a summary and is asked whether she wants to stay in the talent pool.
AfterCandidate records older than the set period are deleted.
Short answer: For the hiring purpose, then delete unless the candidate agrees
Only as long as you need it for the hiring purpose. If you want to keep CVs for future roles, ask the candidate. Background check reports are sensitive and should have a short retention and limited access.
From your seat: HR head. Your largest data pile is usually candidates.
Short answer: Not for employment purposes; yes for anything extra
Usually not for normal employment purposes. Section 7(i) lets you process employee data for employment, such as payroll, attendance, safety and preventing corporate espionage. Anything beyond that, such as wellness apps, photos for marketing or sharing with a bank for offers, needs consent.
From your seat: HR head. Write a one-page employee privacy notice and give it at joining. Keep consent separate for extras like wellness apps or photos.
In IT and ITeS
Large hiring volumes mean large records. Set retention by record type.
Their data is your responsibility when you decide why and how it is used, for example gate passes, attendance, biometrics and safety records. The agency holds payroll and personal files, so your contract with the agency must cover how it protects that data.
From your seat: HR head. You decide what is collected at the gate and in induction. Make sure agency contracts cover the data agencies hold.
In IT and ITeS
Contractors and consultants placed through agencies need the same access rules as staff.
What the law says
Section 7(i) covers employment purposes. Section 8(1) and 8(2) make you responsible for processors such as manpower agencies working on your behalf. Section 7 · Section 8(1)–(2) · Section 8(5) · Rule 6
Steps
List what you hold about contract workers: ID copies, photos, biometrics, attendance, medical fitness.
Decide who is the Data Fiduciary for each item: you or the agency.
Put data terms in every manpower contract.
Give a short notice in the workers' language at the gate or induction.
Short answer: Yes, with notice, limits and a deletion period
All three are personal data. Put a clear notice where people are recorded, collect only what you need at reception, keep footage and registers for a set period, and protect biometric templates carefully. Do not keep copies of ID documents unless you must.
From your seat: HR head. Biometric attendance is the item to watch: who can see templates, how long they are kept, and what happens when someone leaves.
Short answer: For the legal or business period, then erase
Keep data for as long as its purpose needs, or as long as a law requires, and then erase it. Every organisation must keep personal data and logs for at least one year under Rule 8(3). Write a retention schedule by record type, with the law or reason against each period.
From your seat: HR head. Ex-employee files are the usual pile-up. Set a period by record type, with labour-law minimums, and delete after it.
In IT and ITeS
Candidates, employees, alumni, and client data at project end.
What the law says
Section 8(7) asks for erasure when the purpose is over, unless a law requires retention. Rule 8(3) sets a one-year minimum for personal data, traffic data and logs. Section 8(7) · Rule 8 · Section 8(5) · Rule 6
Steps
List the record types you hold.
Write the period for each, with the law, regulator rule or business reason.
Set a trigger for the period to start: end of relationship, date of transaction, exit date.
Automate deletion where you can; for paper, schedule shredding.
Keep a deletion log.
Evidence to keep
Retention schedule approved by Legal
Deletion log
Shredding or disposal certificates
Common mistakes
'Keep everything forever' because storage is cheap
Short answer: Everyone who handles personal data, by role
Everyone who handles personal data needs short, practical training on what to do in their own job. Front-line staff need examples from their counter or desk. Managers need to know the clocks and their own duties. Management needs to know what to ask.
From your seat: HR head. HR runs the joining programme, so DPDP training fits naturally in the first month for every new joiner.
In IT and ITeS
Delivery teams need training on client access and data handling.
What the law says
Section 8(4) and 8(5) ask for appropriate technical and organisational measures. Training is part of showing those measures work. Section 8(5) · Rule 6
Steps
Group staff by what they handle: front line, back office, IT, managers, management.
Write three to five real scenarios for each group.
Short answer: Yes, this is a common breach; give staff a safer option
Sending personal data to the wrong chat or a personal account is one of the most common breaches. Banning messaging rarely works. Give staff an approved tool that is easy to use, set simple rules, and make it safe to report a wrong send at once.
From your seat: HR head. Teams share CVs, salary sheets and ID copies on chat. Give recruiters and payroll an approved way to share.
In IT and ITeS
Client credentials and customer screenshots in team chats are a common issue.
Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report
Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.
From your seat: HR head. A leaked salary sheet or ID folder is a breach. Make sure HR knows to call the DPO at once.
In IT and ITeS
If client data is involved, the client contract sets your first deadline, often a few hours.
What the law says
Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6
Steps
Name one incident lead and a back-up, with phone numbers that work at night.
Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
Decide in advance who signs off each message.
Rehearse once a year with the people who would actually be called.
Evidence to keep
Incident plan with clocks
Rehearsal record
Incident log with times of each step
Common mistakes
Waiting to finish the investigation before telling anyone
Treating a wrong email or a lost laptop as 'not a breach'
Section 7: Uses allowed without consent. Payroll, access control, background checks and security monitoring of staff are employment purposes.
Section 5 · Rule 3: Notice. Candidate portals, employee onboarding and your own website forms need notices. For client data, the client normally gives the notice.
Section 8(5) · Rule 6: Security safeguards. Remote access to client systems, laptops and ticketing tools need control, monitoring and one-year logs.
Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to NIC or NPL time servers. Data centres, VPS, cloud and VPN providers keep specified subscriber information for five years.
Breach handling must meet the six-hour CERT-In clock and the DPDP report to the Board. Subscriber records need DPDP-level protection.