InfraVeritas360DPDPiq

DPDP Insights › IT, ITeS, BPO and GCC › Operations head

IT, ITeS, BPO and GCC

DPDP for the Operations head in IT and ITeS

Delivery floors, shared services and facilities handle data in tickets, screens and paper.

Open this seat in the interactive tool

What is different here

In BPO operations, floor rules matter: phones, paper, screen captures and who can listen to recordings.

The first four things to sort out

  1. Set clean-desk and phone rules on sensitive floors.
  2. Limit recording replay rights.
  3. Log and pass on any privacy request received by the floor.
  4. Report wrong sends at once.

A worked example: An agent writes a card number on paper

  1. Minute 5A supervisor sees the note during a floor walk.
  2. Minute 10The note is shredded and the client informed as the contract says.
  3. Day 1Recording pause for card details is checked.
  4. Week 1The floor moves to the clean-desk rule.

Evidence kept: Floor report; Client notice; Rule change.

Paper on the floor is a breach waiting to happen.

What others in the sector usually do. Contact centres with card data run 'clean rooms' with no phones or paper.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
IT services and consultingProduction data copied to laptops or test environments; Shared client credentials in team chats; Sub-contractors working under your client access
BPO and contact centreCard numbers spoken on recorded calls; Phones and paper on the floor; Outbound calls without consent checks for Indian customers
Global capability centreIndian customer data mixed into global data sets; Global HR systems hosted abroad; Intra-group agreements that predate DPDP
SaaS and software productsSupport staff browsing customer tenants; Analytics on customer data beyond the contract; Deletion that does not reach backups
Managed services, data centres and cloudPrivileged admin access across many clients; Subscriber records kept with no access limits; Backups of client systems held for years

8 guides for the Operations head, in full

How should our people access client systems?

Short answer: Named, logged and removed at roll-off

Through named accounts, from managed devices or controlled jump servers, with multi-factor sign-in and logging. Access should be removed the day someone rolls off. Client data should stay in client systems and not be copied to laptops, internal tickets or chat.

What the law says

Section 8(5) and Rule 6 apply to your safeguards even where you are the processor. Section 8(5) · Rule 6 · Section 8(1)–(2)

Steps
  1. No shared client credentials.
  2. MFA on all client access.
  3. Jump servers or VDI for sensitive clients.
  4. Roll-off removal the same day.
  5. Quarterly access review per client.
Evidence to keep
  • Access lists per client
  • Review records
  • Roll-off removal reports
Common mistakes
  • Shared logins in team chat
  • Copying production data to laptops
  • Access left after roll-off
Related questions

What should our privacy notice say, and where must people see it?

Short answer: Yes, at every point where you collect data

A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.

From your seat: Operations head. Your counters, forms and call scripts are where notices are actually seen. Check that each one shows the current version.
In IT and ITeS

Your careers page, candidate portal, employee onboarding and website forms need notices. For client data, the client gives the notice.

What the law says

Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14

Steps
  1. List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
  2. Write one short notice per collection point, with the data items and purpose side by side.
  3. Add how to withdraw consent, how to make a request and the DPO or contact person's details.
  4. Offer the notice in English and in the languages your client customers actually use.
  5. Keep each version with the date it went live.
Evidence to keep
  • Screenshots or copies of the notice at each collection point, with dates
  • Notice version history
  • Translations, where used
Common mistakes
  • Hiding the notice inside terms and conditions
  • One notice for everything, with no link between data items and purposes
  • Forgetting old data collected before the Act
Related questions

Someone asks what data we hold about them. What do we send?

Short answer: Yes, a clear summary, inside the published timeline

Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.

From your seat: Operations head. Front-line staff receive most requests. Teach them to log the request and pass it on the same day, not to answer it themselves.
In IT and ITeS

Requests about client data go to the client. Requests from staff and candidates come to you.

What the law says

Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14

Steps
  1. Log the request in one register the day it arrives.
  2. Verify identity using details you already hold.
  3. Search every system, including vendors' copies.
  4. Write a plain summary: what data, why it is used, who received it.
  5. Send it, and file the request, search notes and reply.
Evidence to keep
  • Request register
  • Search notes for each request
  • Copy of each reply with date
Common mistakes
  • Sending raw database dumps
  • Forgetting data held by vendors
  • No identity check before sending
Related questions

How do we handle a privacy complaint within 90 days?

Short answer: Reply within your published period, never beyond 90 days

Publish one clear way to complain, log every complaint, give it an owner and reply within the period you publish, never more than 90 days. People can go to the Data Protection Board only after using your process, so a good process keeps most matters with you.

From your seat: Operations head. Many complaints start as service complaints. Tag the ones about personal data so they enter the privacy log.
In IT and ITeS

Most complaints come from staff, ex-staff and candidates. Tag them.

What the law says

Section 8(10) requires a working grievance process. Rule 14(3) caps the reply time at 90 days. Section 13 says people must use your process before approaching the Board. Section 8(9)–(10) · Rules 9, 14 · Sections 11–14 · Rule 14 · Sections 18–26

Steps
  1. Publish one contact for privacy complaints on your website, app and notices.
  2. Log each complaint with the date, channel and a named owner.
  3. Acknowledge within a few days, and set an internal target well under 90 days.
  4. Find and fix the cause, not just the single case.
  5. Reply in writing and close the entry with the date.
Evidence to keep
  • Complaint register with dates
  • Replies sent
  • Monthly summary to management
Common mistakes
  • Mixing privacy complaints into general complaints with no tag
  • No owner, so nobody counts the days
  • Closing a complaint without fixing the cause
Related questions

Staff share personal data on WhatsApp and personal email. What do we do?

Short answer: Yes, this is a common breach; give staff a safer option

Sending personal data to the wrong chat or a personal account is one of the most common breaches. Banning messaging rarely works. Give staff an approved tool that is easy to use, set simple rules, and make it safe to report a wrong send at once.

From your seat: Operations head. Shift groups and vendor chats are where data leaks. Give supervisors an approved way to share lists and photos.
In IT and ITeS

Client credentials and customer screenshots in team chats are a common issue.

What the law says

Section 8(5) asks for reasonable safeguards. A wrong send is a breach under Section 2(u), and Section 8(6) applies. Section 8(5) · Rule 6 · Section 8(6) · Rule 7

Steps
  1. Ask teams how they actually share files and photos today.
  2. Provide an approved tool for that job.
  3. Set three simple rules: approved tool, no personal accounts, report wrong sends.
  4. Teach the rules with real examples from your own work.
  5. Treat a quick report as good behaviour, not a disciplinary case.
Evidence to keep
  • Approved-tool policy
  • Training record
  • Incident reports of wrong sends
Common mistakes
  • A ban with no alternative
  • Punishing people who report
  • Ignoring group chats with vendors
Related questions

What about CCTV, visitor registers and biometric attendance?

Short answer: Yes, with notice, limits and a deletion period

All three are personal data. Put a clear notice where people are recorded, collect only what you need at reception, keep footage and registers for a set period, and protect biometric templates carefully. Do not keep copies of ID documents unless you must.

From your seat: Operations head. Check notices at entrances and recording areas, and who on site can view footage.
In IT and ITeS

Offices, cafeterias and cab pick-up points.

What the law says

Section 5 needs notice. Section 8(5) needs safeguards. Section 8(7) needs erasure after the purpose. For staff, Section 7(i) can cover security and attendance. Section 5 · Rule 3 · Section 8(5) · Rule 6 · Section 8(7) · Rule 8 · Section 7

Steps
  1. Put notices at CCTV points and reception, in the local language.
  2. Ask visitors only for name, phone and whom they are meeting, unless security needs more.
  3. Set a period for footage and registers, then delete.
  4. Restrict who can view footage, and log viewing.
  5. Check the vendor contracts for CCTV, guards and attendance systems.
Evidence to keep
  • Notices in place
  • Retention settings on the recorder
  • Viewing log
Common mistakes
  • Photocopying visitor IDs as routine
  • Footage kept until the disk fills
  • Biometric systems with vendor default passwords
Related questions

What about call recordings and customer service screens?

Short answer: Yes, with notice, a retention period and masking

Call recordings, chat transcripts and agent screens hold a lot of personal data. Tell callers that calls are recorded and why, keep recordings for a set period, limit who can listen, and mask card numbers and passwords on screen and in recordings.

From your seat: Operations head. Call scripts need a recording notice, and agents need to know when to pause the recording.
In IT and ITeS

BPO call recordings must pause for card details and follow client retention rules.

What the law says

Section 5 needs notice, Section 8(5) needs safeguards, and Section 8(7) needs erasure after the purpose. Section 5 · Rule 3 · Section 8(5) · Rule 6 · Section 8(7) · Rule 8

Steps
  1. Play a short recording notice at the start of calls.
  2. Set a retention period by call type.
  3. Pause recording when card or other sensitive details are given.
  4. Limit replay rights to quality and complaint teams.
  5. Lock agent screens and stop phones on the floor if data is sensitive.
Evidence to keep
  • Recording notice script
  • Retention settings
  • Replay access list
Common mistakes
  • Recordings kept indefinitely
  • Card numbers in recordings
  • Open replay access for all supervisors
Related questions

Someone asks us to delete their data. Must we?

Short answer: Yes, unless a law requires you to keep it

You must erase data that you no longer need for the purpose it was collected for, unless a law requires you to keep it. Where a law does require it, keep the data, stop using it for anything else, and tell the person why it is being kept and until when.

From your seat: Operations head. Front-line teams need a simple answer for 'delete my data': log it, pass it on, and explain the timeline.
What the law says

Section 12 gives the right to correction and erasure. Section 8(7) allows retention only where a law requires it. Rule 8(3) asks every organisation to keep personal data and logs for at least one year first. Sections 11–14 · Rule 14 · Section 8(7) · Rule 8

Steps
  1. Log the request and verify identity.
  2. Check the retention schedule for each record type involved.
  3. Delete what has no legal reason to stay, including copies with vendors and in test systems.
  4. Mark what must stay, with the law and the end date.
  5. Reply in plain words: what was deleted, what is kept, why and until when.
Evidence to keep
  • Erasure log
  • Vendor deletion confirmations
  • Reply to the person
Common mistakes
  • Refusing every erasure request 'because of backups'
  • Deleting records a law requires
  • Not telling vendors
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for it, ites, bpo and gcc.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
CERT-In Directions, 28 April 2022Report specified cyber incidents within six hours. Keep ICT logs for 180 days within India. Sync clocks to NIC or NPL time servers. Data centres, VPS, cloud and VPN providers keep specified subscriber information for five years.Breach handling must meet the six-hour CERT-In clock and the DPDP report to the Board. Subscriber records need DPDP-level protection.CERT-In
DPDP Act, Section 17(1)(d)Processing of data of people outside India, under a contract with a party outside India, is exempt from most of the Act.Tag each data set by where the people live. The exemption does not cover Indian staff or Indian customers.MeitY
IT Act, Section 43A and SPDI Rules, 2011Reasonable security practices for sensitive personal data, until Section 43A is omitted on 13 May 2027.Your current ISO 27001 practices meet these today; DPDP Rule 6 takes over from May 2027.MeitY
TRAI Telecom Commercial Communications Customer Preference Regulations, 2018Commercial calls and SMS to Indian numbers must follow registration and preference rules.Outbound campaigns for Indian clients need both DPDP consent and TRAI compliance.TRAI
Labour Codes (in force from 21 November 2025)The four labour codes replaced older labour laws, including registers and records employers must keep.Set retention for staff records against the new codes and state rules.Ministry of Labour
Client contracts and foreign laws (for example GDPR for EU clients)Clients often bind you to their own country's law through contracts and standard clauses.These are contract duties, not Indian law, but you must meet them alongside DPDP.Contract
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.