InfraVeritas360DPDPiq

DPDP Insights › Questions › Who should be able to see personal data in our systems?

Question

Who should be able to see personal data in our systems?

Short answer: Only those who need it, reviewed every quarter

Only people who need it for their job, and only the part they need. Use named accounts, give access by role, review it every quarter and remove it on the day someone leaves. Watch privileged accounts closely.

What the law says

Rule 6 names access control as a minimum safeguard, along with logs and monitoring that can detect misuse.

Steps

  1. Write a role matrix for each key system.
  2. Replace shared logins with named accounts.
  3. Use multi-factor sign-in for admin and remote access.
  4. Review access every quarter with each manager.
  5. Remove access on the last working day.

Evidence to keep

Common mistakes

How it plays out by sector

From each seat

What a good answer from management sounds like

“Access is by role, reviewed every quarter, and removed the day people leave. Shared logins are gone.” Effort and time: Medium to heavy · 8 to 16 weeks.

Related questions

Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.