Back to Sectors & Impact

Information Technology

DPDPA implications for IT companies, BPOs, and cloud service providers - data processor obligations, cross-border transfers, and multi-tenant security.

8 min read

Sector Overview

India's IT sector - encompassing IT services, BPO/KPO operations, cloud hosting providers, and software product companies - is one of the largest processors of personal data globally. Indian IT companies frequently act as data processors handling personal data on behalf of clients across jurisdictions, making DPDPA compliance a critical business imperative. The sector faces unique challenges including multi-tenant data processing environments, complex sub-processing chains, cross-border data flows inherent to global service delivery, and the dual role of being both a Data Fiduciary (for employee and direct customer data) and a Data Processor (for client data).

Key DPDPA Provisions for IT

Section 8(2) (Data Processor): While the DPDPA largely channels obligations through the Data Fiduciary, Section 8(5) (Security Safeguards) creates a direct legal standard that processors must meet. Under the 2025 Rules, processors are also explicitly named in the context of security audits and log maintenance. IT companies must therefore ensure both their contractual frameworks and their direct security posture align with the Act, as Data Fiduciaries will demand compliance commitments. Section 8(5) (Security Safeguards): IT companies must implement reasonable security safeguards whether acting as Fiduciary or Processor. Rule 6 mandates encryption, masking, tokenisation, access controls, and 1-year log retention - requirements directly relevant to IT infrastructure management. Section 16 (Cross-Border Transfer): IT companies with global delivery models must comply with cross-border transfer restrictions. The negative list approach under Section 16 and the Rule 15 committee mechanism will determine which jurisdictions are restricted. Section 8(6) (Breach Notification - Dual Clock): IT companies discovering breaches in client data must navigate two parallel timelines. Rule 7 of the DPDP Rules requires notification to the Board and affected individuals "without undue delay," with a detailed report within 72 hours. The 2022 CERT-In Directions (which remain in force) require cybersecurity incidents to be reported within 6 hours. An IT company may satisfy the DPDPA's 72-hour window but still be in violation of the IT Act / CERT-In's 6-hour window for the same incident, so processes must be designed to the shorter clock.

Compliance Considerations

1. Dual Role Management: IT companies must manage compliance as both Data Fiduciary (for their own employees, contractors, and direct customers) and Data Processor (for client data). Separate governance structures may be needed. 2. Contractual Frameworks: Review and update data processing agreements with clients to reflect DPDPA requirements. Include provisions for breach notification support, security safeguard standards, sub-processing restrictions, and cross-border transfer compliance. 3. Multi-Tenant Security: Cloud and SaaS providers must ensure data segregation across tenants, implement access controls preventing cross-tenant data access, and maintain separate processing logs per client. 4. Sub-Processing Chains: IT companies frequently engage sub-processors. The DPDPA requires the Data Fiduciary to ensure compliance across the processing chain, so IT companies must cascade obligations to their sub-processors. 5. Cross-Border Data Flows: Global delivery models involving offshore/nearshore teams require compliance with Section 16 transfer restrictions. IT companies should map data flows across jurisdictions and prepare for potential restrictions. 6. Employee Data: IT companies with large workforces must manage employee data processing under the legitimate uses framework while ensuring compliance with security and retention obligations.

Practical Compliance Checklist

*Note: This checklist is interpretive guidance derived from the DPDPA's general provisions (Sections 8, 16, Rules 6-7, 15). It should be validated by legal counsel for your specific organisational context.* • Identify and segregate Data Fiduciary vs. Data Processor roles across business lines • Update client contracts with DPDPA-aligned data processing clauses • Implement Rule 6 security safeguards across all data processing environments • Map cross-border data flows and assess exposure to potential transfer restrictions • Establish breach detection and notification procedures supporting client compliance • Cascade DPDPA obligations to sub-processors through contractual requirements • Implement granular access controls and processing logs in multi-tenant environments • Train delivery teams on data handling obligations under the DPDPA • Conduct DPIA for high-risk processing activities (if designated as SDF) • Prepare for client audit requirements related to DPDPA compliance

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.