SupportCentral Enterprise

DPDP compliance

The Digital Personal Data Protection Act, 2023 applies to almost every Indian IT and HR team, because almost every one of them holds employee personal data. Here is what it asks of you, and how a service desk helps or hurts.

Last updated: · Applies to SupportCentral Enterprise, operated by Support IT Ventures.

We build software; we are not your lawyers. This page is a practical orientation written for an IT manager who has been handed a compliance action item. Take advice before you rely on it.

Why your helpdesk is in scope

A service desk accumulates personal data almost by accident: names and personal email addresses in ticket bodies, phone numbers for verification, manager relationships, exit dates, and attachments people paste in without thinking. Most organisations underestimate how much of it is sitting in their support mailbox.

Under the Act your organisation is the Data Fiduciary for that data. Your vendor is a Data Processor acting on your instructions. The obligations land on you, which is why the choice of vendor matters.

What the Act asks of you

  • Process personal data for a lawful purpose, with notice and — where required — consent.
  • Give a clear notice in plain language about what you collect and why.
  • Keep data accurate and complete where it will be used to make a decision about someone.
  • Apply reasonable security safeguards.
  • Report a personal data breach to the Data Protection Board and to affected individuals.
  • Erase personal data when the purpose is served, unless the law requires you to keep it.
  • Answer data-principal requests: access, correction, completion, erasure and nomination.
  • Publish a Grievance Officer's contact details and actually answer them.

How this product helps

  • Purpose limitation: a ticket carries a category and a retention period rather than living forever in a mailbox nobody prunes.
  • Access and correction: an employee record is one screen, so an access or correction request is minutes rather than an afternoon of searching.
  • Erasure: records can be deleted with an audit trail proving it happened.
  • Security safeguards: role-based access, per-organisation isolation, encrypted secrets and an append-only audit log — concrete answers to a questionnaire.
  • Breach readiness: the audit log tells you who accessed what and when, which is the first question you will be asked.
  • Residency: the data stays in India, so there is no transfer to justify.

Where a helpdesk can make things worse

Uncontrolled attachments, permanent retention, and letting everyone see everything are the three that cause real problems. Configure roles so requesters see only their own records, set a retention period you can defend, and train your agents not to paste identity documents into a ticket body when a secure field would do.

The Act expects a clear notice in plain language, itemised by purpose, available in English and the Eighth Schedule languages on request. For a service desk the notice that matters is the one to your own employees: what the desk records when they raise a request, how long it is kept, who inside the company can see it, and how to ask for a correction.

Most organisations already have an employee privacy notice and have never updated it to mention the helpdesk. That is the gap worth closing first, and it costs nothing but an afternoon.

Consent is not always the right basis. Much of what a service desk does is necessary for the employment relationship or for a legitimate use the Act recognises. Decide the basis per purpose rather than collecting a blanket consent that will not hold up.

Retention is where most desks fail

A shared mailbox keeps everything forever, which is the opposite of what the Act asks. Decide how long a resolved ticket needs to exist — a year is common, some regulated functions need longer — write it down, and configure it. Being able to show a retention rule and evidence that it runs is worth more than a policy document nobody implemented.

Significant Data Fiduciaries

The Act lets the government designate some organisations as Significant Data Fiduciaries, with extra duties including a Data Protection Officer based in India, an independent data auditor and periodic impact assessments. Whether that applies to you depends on volume and sensitivity, not on your software — but if it does apply, your vendor needs to be able to support an audit, which is why we publish our controls rather than summarising them as "enterprise-grade".

Penalties, and why this is worth an afternoon

The Act provides for substantial financial penalties, with the largest attaching to a failure to take reasonable security safeguards. The point is not the headline number; it is that "reasonable safeguards" is assessed against what you could plainly have done. Role-based access, a retention rule and an audit trail are all things a service desk can give you in an afternoon, and all things that are awkward to explain the absence of.

A practical starting checklist

  • Write down what personal data your desk holds and why.
  • Publish an employee-facing notice, separate from your customer privacy policy.
  • Appoint and publish a Grievance Officer with a real inbox someone reads.
  • Set retention periods per record type, and turn them on.
  • Restrict who can see employee records, and check it by signing in as a requester.
  • Get a signed DPA from every vendor that touches the data — ours is on this site.
  • Run a breach drill once: who is called, who decides, who notifies, and by when.

Something here unclear or unfair? Tell us at support@supportcentral.in. We would rather fix the wording than argue about it later. See also Terms, Privacy and Grievance redressal.