InfraVeritas360DPDPiq

DPDP Insights › IT, ITeS, BPO and GCC › Practical examples

IT, ITeS, BPO and GCC

Practical examples for IT and ITeS

Five documents most organisations in this sector need before 13 May 2027.

Examples to adapt, not legal advice. Replace the text in square brackets with your own details.

EXAMPLE · NOT LEGAL ADVICE

Notice wording: Candidate application (careers page)

We collect your name, contact details, CV, education, work history and, if you are shortlisted, details for a background check. We use them to assess you for the role you applied for and to contact you about it.

We keep your details for [6] months after the role closes. If you tick the box below, we will keep them for [12] more months to consider you for other roles. You can withdraw this any time.

You can ask what we hold, ask for correction or deletion, or complain to [contact]. You may also approach the Data Protection Board of India.

EXAMPLE

Request and complaint log

RefDateRequesterData setFiduciaryActionDueStatus
RQ-20112-11-2026CandidateATSUsSummarywithin published periodReplied day 5
RQ-20213-11-2026Client customerClient CRMClientForwarded to clientper contractClient instructed deletion
RQ-20315-11-2026Ex-employeeHRMS, payrollUsSummary and erasure checkwithin published periodStatutory records kept
EXAMPLE · NOT LEGAL ADVICE

Retention schedule

RecordKeep forWhy
Unsuccessful candidates6 months, or longer with consentHiring purpose
Background check reportsShort period after joining decisionSensitive; purpose over
Employee filesEmployment plus the period labour and tax laws requireLabour Codes, tax
Client dataAs the client contract says; delete at project endProcessor duty
Access and activity logsAt least 1 year; ICT logs 180 days in IndiaDPDP Rules; CERT-In
EXAMPLE · NOT LEGAL ADVICE

Vendor data clause

The Sub-contractor shall process Client Personal Data only on documented instructions of the Company, which reflect the Client's instructions, and for no other purpose. It shall not engage another sub-contractor without prior written approval, shall give access only to named individuals, and shall keep reasonable security safeguards including multi-factor sign-in and logging. It shall notify the Company of any personal data breach within [4] hours of becoming aware. On roll-off or termination it shall delete all Client Personal Data from its systems and devices within 7 days and confirm in writing.

EXAMPLE · NOT LEGAL ADVICE

Breach notice to affected people

Dear [Client], at [time] on [date] we found that a laptop used by our team on your project was stolen. The device was encrypted and has been wiped remotely. We found that a file containing about [number] of your customer records had been saved on it. We have reported the incident to CERT-In. Our log extract and timeline are attached. Please tell us if you need anything for your own notices to affected people and to the Data Protection Board. Contact: [name, phone].

Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.