DPDP Insights › IT, ITeS, BPO and GCC › Practical examples
Five documents most organisations in this sector need before 13 May 2027.
Examples to adapt, not legal advice. Replace the text in square brackets with your own details.
We collect your name, contact details, CV, education, work history and, if you are shortlisted, details for a background check. We use them to assess you for the role you applied for and to contact you about it.
We keep your details for [6] months after the role closes. If you tick the box below, we will keep them for [12] more months to consider you for other roles. You can withdraw this any time.
You can ask what we hold, ask for correction or deletion, or complain to [contact]. You may also approach the Data Protection Board of India.
| Ref | Date | Requester | Data set | Fiduciary | Action | Due | Status |
|---|---|---|---|---|---|---|---|
| RQ-201 | 12-11-2026 | Candidate | ATS | Us | Summary | within published period | Replied day 5 |
| RQ-202 | 13-11-2026 | Client customer | Client CRM | Client | Forwarded to client | per contract | Client instructed deletion |
| RQ-203 | 15-11-2026 | Ex-employee | HRMS, payroll | Us | Summary and erasure check | within published period | Statutory records kept |
| Record | Keep for | Why |
|---|---|---|
| Unsuccessful candidates | 6 months, or longer with consent | Hiring purpose |
| Background check reports | Short period after joining decision | Sensitive; purpose over |
| Employee files | Employment plus the period labour and tax laws require | Labour Codes, tax |
| Client data | As the client contract says; delete at project end | Processor duty |
| Access and activity logs | At least 1 year; ICT logs 180 days in India | DPDP Rules; CERT-In |
The Sub-contractor shall process Client Personal Data only on documented instructions of the Company, which reflect the Client's instructions, and for no other purpose. It shall not engage another sub-contractor without prior written approval, shall give access only to named individuals, and shall keep reasonable security safeguards including multi-factor sign-in and logging. It shall notify the Company of any personal data breach within [4] hours of becoming aware. On roll-off or termination it shall delete all Client Personal Data from its systems and devices within 7 days and confirm in writing.
Dear [Client], at [time] on [date] we found that a laptop used by our team on your project was stolen. The device was encrypted and has been wiped remotely. We found that a file containing about [number] of your customer records had been saved on it. We have reported the incident to CERT-In. Our log extract and timeline are attached. Please tell us if you need anything for your own notices to affected people and to the Data Protection Board. Contact: [name, phone].