Short answer: Named, logged and removed at roll-off
Through named accounts, from managed devices or controlled jump servers, with multi-factor sign-in and logging. Access should be removed the day someone rolls off. Client data should stay in client systems and not be copied to laptops, internal tickets or chat.
Short answer: Yes, at every point where you collect data
A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.
From your seat: Operations head. Your counters, forms and call scripts are where notices are actually seen. Check that each one shows the current version.
In IT and ITeS
Your careers page, candidate portal, employee onboarding and website forms need notices. For client data, the client gives the notice.
What the law says
Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14
Steps
List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
Write one short notice per collection point, with the data items and purpose side by side.
Add how to withdraw consent, how to make a request and the DPO or contact person's details.
Offer the notice in English and in the languages your client customers actually use.
Keep each version with the date it went live.
Evidence to keep
Screenshots or copies of the notice at each collection point, with dates
Notice version history
Translations, where used
Common mistakes
Hiding the notice inside terms and conditions
One notice for everything, with no link between data items and purposes
Short answer: Yes, a clear summary, inside the published timeline
Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.
From your seat: Operations head. Front-line staff receive most requests. Teach them to log the request and pass it on the same day, not to answer it themselves.
In IT and ITeS
Requests about client data go to the client. Requests from staff and candidates come to you.
What the law says
Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14
Steps
Log the request in one register the day it arrives.
Verify identity using details you already hold.
Search every system, including vendors' copies.
Write a plain summary: what data, why it is used, who received it.
Send it, and file the request, search notes and reply.
Short answer: Reply within your published period, never beyond 90 days
Publish one clear way to complain, log every complaint, give it an owner and reply within the period you publish, never more than 90 days. People can go to the Data Protection Board only after using your process, so a good process keeps most matters with you.
From your seat: Operations head. Many complaints start as service complaints. Tag the ones about personal data so they enter the privacy log.
In IT and ITeS
Most complaints come from staff, ex-staff and candidates. Tag them.
Short answer: Yes, this is a common breach; give staff a safer option
Sending personal data to the wrong chat or a personal account is one of the most common breaches. Banning messaging rarely works. Give staff an approved tool that is easy to use, set simple rules, and make it safe to report a wrong send at once.
From your seat: Operations head. Shift groups and vendor chats are where data leaks. Give supervisors an approved way to share lists and photos.
In IT and ITeS
Client credentials and customer screenshots in team chats are a common issue.
Short answer: Yes, with notice, limits and a deletion period
All three are personal data. Put a clear notice where people are recorded, collect only what you need at reception, keep footage and registers for a set period, and protect biometric templates carefully. Do not keep copies of ID documents unless you must.
From your seat: Operations head. Check notices at entrances and recording areas, and who on site can view footage.
Short answer: Yes, with notice, a retention period and masking
Call recordings, chat transcripts and agent screens hold a lot of personal data. Tell callers that calls are recorded and why, keep recordings for a set period, limit who can listen, and mask card numbers and passwords on screen and in recordings.
From your seat: Operations head. Call scripts need a recording notice, and agents need to know when to pause the recording.
In IT and ITeS
BPO call recordings must pause for card details and follow client retention rules.
Short answer: Yes, unless a law requires you to keep it
You must erase data that you no longer need for the purpose it was collected for, unless a law requires you to keep it. Where a law does require it, keep the data, stop using it for anything else, and tell the person why it is being kept and until when.
From your seat: Operations head. Front-line teams need a simple answer for 'delete my data': log it, pass it on, and explain the timeline.
What the law says
Section 12 gives the right to correction and erasure. Section 8(7) allows retention only where a law requires it. Rule 8(3) asks every organisation to keep personal data and logs for at least one year first. Sections 11–14 · Rule 14 · Section 8(7) · Rule 8
Steps
Log the request and verify identity.
Check the retention schedule for each record type involved.
Delete what has no legal reason to stay, including copies with vendors and in test systems.
Mark what must stay, with the law and the end date.
Reply in plain words: what was deleted, what is kept, why and until when.
Evidence to keep
Erasure log
Vendor deletion confirmations
Reply to the person
Common mistakes
Refusing every erasure request 'because of backups'
Section 5 · Rule 3: Notice. Candidate portals, employee onboarding and your own website forms need notices. For client data, the client normally gives the notice.
Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to NIC or NPL time servers. Data centres, VPS, cloud and VPN providers keep specified subscriber information for five years.
Breach handling must meet the six-hour CERT-In clock and the DPDP report to the Board. Subscriber records need DPDP-level protection.