InfraVeritas360DPDPiq

DPDP Insights › Questions › How should our people access client systems?

Question · IT, ITeS, BPO and GCC

How should our people access client systems?

Short answer: Named, logged and removed at roll-off

Through named accounts, from managed devices or controlled jump servers, with multi-factor sign-in and logging. Access should be removed the day someone rolls off. Client data should stay in client systems and not be copied to laptops, internal tickets or chat.

What the law says

Section 8(5) and Rule 6 apply to your safeguards even where you are the processor.

Steps

  1. No shared client credentials.
  2. MFA on all client access.
  3. Jump servers or VDI for sensitive clients.
  4. Roll-off removal the same day.
  5. Quarterly access review per client.

Evidence to keep

Common mistakes

From each seat

What a good answer from management sounds like

“All client access is named, logged and removed the day people roll off. Quarterly reviews show zero stale accounts.” Effort and time: Medium · 6 to 12 weeks.

Related questions

Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.