InfraVeritas360DPDPiq

DPDP Insights › IT, ITeS, BPO and GCC › HR head

IT, ITeS, BPO and GCC

DPDP for the HR head in IT and ITeS

You hold the largest pool of personal data that is fully yours: employees, candidates and alumni.

Open this seat in the interactive tool

What is different here

IT companies hire in large numbers, run background checks through vendors, and keep alumni records. Candidate databases grow fast and are rarely cleaned.

The first four things to sort out

  1. Give candidates and employees a short notice.
  2. Set retention for unsuccessful candidates.
  3. Check background verification vendor contracts.
  4. Limit who can see salary and appraisal data.

A worked example: A candidate asks what you hold about her

  1. Day 1HR logs the request from the careers page.
  2. Day 3HR finds her CV, two interview notes and a background check report.
  3. Day 5She receives a summary and is asked whether she wants to stay in the talent pool.
  4. AfterCandidate records older than the set period are deleted.

Evidence kept: Request log; Summary sent; Deletion run.

Candidate data needs an expiry date.

What others in the sector usually do. Firms are adding an expiry date to candidate records and asking candidates before keeping them for future roles.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
IT services and consultingProduction data copied to laptops or test environments; Shared client credentials in team chats; Sub-contractors working under your client access
BPO and contact centreCard numbers spoken on recorded calls; Phones and paper on the floor; Outbound calls without consent checks for Indian customers
Global capability centreIndian customer data mixed into global data sets; Global HR systems hosted abroad; Intra-group agreements that predate DPDP
SaaS and software productsSupport staff browsing customer tenants; Analytics on customer data beyond the contract; Deletion that does not reach backups
Managed services, data centres and cloudPrivileged admin access across many clients; Subscriber records kept with no access limits; Backups of client systems held for years

8 guides for the HR head, in full

How long can we keep candidate data?

Short answer: For the hiring purpose, then delete unless the candidate agrees

Only as long as you need it for the hiring purpose. If you want to keep CVs for future roles, ask the candidate. Background check reports are sensitive and should have a short retention and limited access.

From your seat: HR head. Your largest data pile is usually candidates.
What the law says

Section 8(7) asks for erasure when the purpose is over. Section 6 needs consent for keeping data for future roles. Section 8(7) · Rule 8 · Section 6 · Section 5 · Rule 3

Steps
  1. Set a retention period for unsuccessful candidates.
  2. Ask consent for the talent pool.
  3. Limit access to background reports.
  4. Delete on schedule.
  5. Check job portal and recruiter vendor terms.
Evidence to keep
  • Retention setting in ATS
  • Talent pool consent
  • Deletion logs
Common mistakes
  • Keeping every CV forever
  • Recruiters with personal copies
  • Background reports in email
Related questions

Do we need consent for employee data?

Short answer: Not for employment purposes; yes for anything extra

Usually not for normal employment purposes. Section 7(i) lets you process employee data for employment, such as payroll, attendance, safety and preventing corporate espionage. Anything beyond that, such as wellness apps, photos for marketing or sharing with a bank for offers, needs consent.

From your seat: HR head. Write a one-page employee privacy notice and give it at joining. Keep consent separate for extras like wellness apps or photos.
In IT and ITeS

Large hiring volumes mean large records. Set retention by record type.

What the law says

Section 7(i) covers employment purposes and safeguarding the employer from loss or liability. Notice, security, retention and rights still apply to employees. Section 7 · Section 5 · Rule 3 · Section 8(7) · Rule 8 · Sections 11–14 · Rule 14

Steps
  1. List what you collect from staff and why.
  2. Mark which items are employment purposes and which are extra.
  3. Take consent for the extras, separately.
  4. Give staff a short employee privacy notice.
  5. Set retention for ex-employee records.
Evidence to keep
  • Employee data list with basis
  • Employee privacy notice
  • Consent for extras
Common mistakes
  • A blanket consent clause in the offer letter
  • Keeping candidate data forever
  • Sharing staff data with vendors without terms
Related questions

Are contract and agency workers our responsibility?

Short answer: Yes, for the data you decide about

Their data is your responsibility when you decide why and how it is used, for example gate passes, attendance, biometrics and safety records. The agency holds payroll and personal files, so your contract with the agency must cover how it protects that data.

From your seat: HR head. You decide what is collected at the gate and in induction. Make sure agency contracts cover the data agencies hold.
In IT and ITeS

Contractors and consultants placed through agencies need the same access rules as staff.

What the law says

Section 7(i) covers employment purposes. Section 8(1) and 8(2) make you responsible for processors such as manpower agencies working on your behalf. Section 7 · Section 8(1)–(2) · Section 8(5) · Rule 6

Steps
  1. List what you hold about contract workers: ID copies, photos, biometrics, attendance, medical fitness.
  2. Decide who is the Data Fiduciary for each item: you or the agency.
  3. Put data terms in every manpower contract.
  4. Give a short notice in the workers' language at the gate or induction.
  5. Delete gate and ID records on a schedule.
Evidence to keep
  • Contract-worker data list
  • Agency contracts with data terms
  • Notice at the gate
Common mistakes
  • Photocopies of Aadhaar kept in open files
  • No terms in the agency contract
  • Biometric data with no deletion date
Related questions

What about CCTV, visitor registers and biometric attendance?

Short answer: Yes, with notice, limits and a deletion period

All three are personal data. Put a clear notice where people are recorded, collect only what you need at reception, keep footage and registers for a set period, and protect biometric templates carefully. Do not keep copies of ID documents unless you must.

From your seat: HR head. Biometric attendance is the item to watch: who can see templates, how long they are kept, and what happens when someone leaves.
In IT and ITeS

Offices, cafeterias and cab pick-up points.

What the law says

Section 5 needs notice. Section 8(5) needs safeguards. Section 8(7) needs erasure after the purpose. For staff, Section 7(i) can cover security and attendance. Section 5 · Rule 3 · Section 8(5) · Rule 6 · Section 8(7) · Rule 8 · Section 7

Steps
  1. Put notices at CCTV points and reception, in the local language.
  2. Ask visitors only for name, phone and whom they are meeting, unless security needs more.
  3. Set a period for footage and registers, then delete.
  4. Restrict who can view footage, and log viewing.
  5. Check the vendor contracts for CCTV, guards and attendance systems.
Evidence to keep
  • Notices in place
  • Retention settings on the recorder
  • Viewing log
Common mistakes
  • Photocopying visitor IDs as routine
  • Footage kept until the disk fills
  • Biometric systems with vendor default passwords
Related questions

How long can we keep personal data?

Short answer: For the legal or business period, then erase

Keep data for as long as its purpose needs, or as long as a law requires, and then erase it. Every organisation must keep personal data and logs for at least one year under Rule 8(3). Write a retention schedule by record type, with the law or reason against each period.

From your seat: HR head. Ex-employee files are the usual pile-up. Set a period by record type, with labour-law minimums, and delete after it.
In IT and ITeS

Candidates, employees, alumni, and client data at project end.

What the law says

Section 8(7) asks for erasure when the purpose is over, unless a law requires retention. Rule 8(3) sets a one-year minimum for personal data, traffic data and logs. Section 8(7) · Rule 8 · Section 8(5) · Rule 6

Steps
  1. List the record types you hold.
  2. Write the period for each, with the law, regulator rule or business reason.
  3. Set a trigger for the period to start: end of relationship, date of transaction, exit date.
  4. Automate deletion where you can; for paper, schedule shredding.
  5. Keep a deletion log.
Evidence to keep
  • Retention schedule approved by Legal
  • Deletion log
  • Shredding or disposal certificates
Common mistakes
  • 'Keep everything forever' because storage is cheap
  • Deleting before the legal minimum
  • Forgetting email, shared drives and backups
Related questions

Who needs DPDP training, and what should it cover?

Short answer: Everyone who handles personal data, by role

Everyone who handles personal data needs short, practical training on what to do in their own job. Front-line staff need examples from their counter or desk. Managers need to know the clocks and their own duties. Management needs to know what to ask.

From your seat: HR head. HR runs the joining programme, so DPDP training fits naturally in the first month for every new joiner.
In IT and ITeS

Delivery teams need training on client access and data handling.

What the law says

Section 8(4) and 8(5) ask for appropriate technical and organisational measures. Training is part of showing those measures work. Section 8(5) · Rule 6

Steps
  1. Group staff by what they handle: front line, back office, IT, managers, management.
  2. Write three to five real scenarios for each group.
  3. Keep sessions short: 20 to 30 minutes.
  4. Test with a few questions, and record attendance.
  5. Repeat every year, and at joining.
Evidence to keep
  • Training plan by group
  • Attendance and test results
  • Scenario material
Common mistakes
  • One long legal lecture for all
  • Training once and never again
  • No record of attendance
Related questions

Staff share personal data on WhatsApp and personal email. What do we do?

Short answer: Yes, this is a common breach; give staff a safer option

Sending personal data to the wrong chat or a personal account is one of the most common breaches. Banning messaging rarely works. Give staff an approved tool that is easy to use, set simple rules, and make it safe to report a wrong send at once.

From your seat: HR head. Teams share CVs, salary sheets and ID copies on chat. Give recruiters and payroll an approved way to share.
In IT and ITeS

Client credentials and customer screenshots in team chats are a common issue.

What the law says

Section 8(5) asks for reasonable safeguards. A wrong send is a breach under Section 2(u), and Section 8(6) applies. Section 8(5) · Rule 6 · Section 8(6) · Rule 7

Steps
  1. Ask teams how they actually share files and photos today.
  2. Provide an approved tool for that job.
  3. Set three simple rules: approved tool, no personal accounts, report wrong sends.
  4. Teach the rules with real examples from your own work.
  5. Treat a quick report as good behaviour, not a disciplinary case.
Evidence to keep
  • Approved-tool policy
  • Training record
  • Incident reports of wrong sends
Common mistakes
  • A ban with no alternative
  • Punishing people who report
  • Ignoring group chats with vendors
Related questions

Something has gone wrong. What happens in the first 72 hours?

Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report

Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.

From your seat: HR head. A leaked salary sheet or ID folder is a breach. Make sure HR knows to call the DPO at once.
In IT and ITeS

If client data is involved, the client contract sets your first deadline, often a few hours.

What the law says

Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6

Steps
  1. Name one incident lead and a back-up, with phone numbers that work at night.
  2. Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
  3. Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
  4. Decide in advance who signs off each message.
  5. Rehearse once a year with the people who would actually be called.
Evidence to keep
  • Incident plan with clocks
  • Rehearsal record
  • Incident log with times of each step
Common mistakes
  • Waiting to finish the investigation before telling anyone
  • Treating a wrong email or a lost laptop as 'not a breach'
  • Only IT knowing the plan
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for it, ites, bpo and gcc.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
CERT-In Directions, 28 April 2022Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to NIC or NPL time servers. Data centres, VPS, cloud and VPN providers keep specified subscriber information for five years.Breach handling must meet the six-hour CERT-In clock and the DPDP report to the Board. Subscriber records need DPDP-level protection.CERT-In
DPDP Act, Section 17(1)(d)Processing of data of people outside India, under a contract with a party outside India, is exempt from most of the Act.Tag each data set by where the people live. The exemption does not cover Indian staff or Indian customers.MeitY
IT Act, Section 43A and SPDI Rules, 2011Reasonable security practices for sensitive personal data, until Section 43A is omitted on 13 May 2027.Your current ISO 27001 practices meet these today; DPDP Rule 6 takes over from May 2027.MeitY
TRAI Telecom Commercial Communications Customer Preference Regulations, 2018Commercial calls and SMS to Indian numbers must follow registration and preference rules.Outbound campaigns for Indian clients need both DPDP consent and TRAI compliance.TRAI
Labour Codes (in force from 21 November 2025)The four labour codes replaced older labour laws, including registers and records employers must keep.Set retention for staff records against the new codes and state rules.Ministry of Labour
Client contracts and foreign laws (for example GDPR for EU clients)Clients often bind you to their own country's law through contracts and standard clauses.These are contract duties, not Indian law, but you must meet them alongside DPDP.Contract
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.