What the DPDP Act 2023 means for your helpdesk
Almost every Indian IT and HR team is in scope, because almost every one holds employee personal data. What the Act actually asks, and the three places a helpdesk quietly makes things worse.
The Digital Personal Data Protection Act, 2023 applies to organisations processing digital personal data in India. If you run an IT or HR service desk, you are processing it — probably more of it than you think.
Why your service desk is in scope
A desk accumulates personal data almost by accident. Names and personal email addresses in ticket bodies. Phone numbers captured for verification. Manager relationships. Exit dates. Attachments people paste in without thinking — a photograph of an ID card to prove who they are, a payslip attached to a query about it.
Most organisations badly underestimate how much of this is sitting in a shared mailbox that nobody has ever pruned. The first useful exercise is not buying anything: it is searching your existing support mailbox for the word "Aadhaar" and seeing what comes back.
Who is responsible for what
Your organisation is the Data Fiduciary for the personal data in your desk. Your software vendor is a Data Processor acting on your instructions. The obligations land on you, which is exactly why the choice of vendor matters — you cannot delegate the duty, only the processing.
That is also why a vendor who cannot tell you where the data is stored, who else can reach it, or how to get it all back out is a problem for you rather than for them.
What the Act asks of you
- Process personal data for a lawful purpose, with notice and — where required — consent.
- Give a clear notice in plain language about what you collect and why.
- Keep data accurate where it will be used to make a decision about someone.
- Apply reasonable security safeguards.
- Report a personal data breach to the Data Protection Board and to affected individuals.
- Erase personal data when the purpose is served, unless the law requires you to keep it.
- Answer data-principal requests: access, correction, completion, erasure and nomination.
- Publish a Grievance Officer's contact details — and actually answer them.
The notice most companies have not written
Most organisations have a customer-facing privacy policy and have never updated it to mention the helpdesk. The notice that matters here is the one to your own employees: what the desk records when they raise a request, how long it is kept, who inside the company can see it, and how to ask for a correction.
That gap costs an afternoon to close and is the most common finding in any first review.
Three places a helpdesk makes things worse
Adopting a tool does not automatically improve your position. Three specific defaults hurt:
- Permanent retention. A shared mailbox keeps everything forever, which is the opposite of what the Act asks. Decide how long a resolved ticket needs to exist, write it down, and configure it.
- Everybody can see everything. If every agent can open every HR ticket, you have widened access rather than controlled it. Restrict by role, then check by signing in as a requester.
- Uncontrolled attachments. Agents paste identity documents into ticket bodies because it is convenient. Train them not to, and give them a field that is meant for it when they genuinely need one.
Where it genuinely helps
- Access and correction requests become a single screen instead of an afternoon of searching a mailbox.
- Erasure can be performed and evidenced, rather than hoped for.
- An audit log answers the first question anybody asks after an incident: who accessed this, and when.
- Retention rules can actually run, instead of being a paragraph in a policy document.
The consent question, answered plainly
The most common misreading of the Act inside IT teams is that everything now needs consent. For the employment relationship it largely does not — the Act makes room for processing that is necessary for employment purposes, which is what a service desk record mostly is. What it does require is that people are told, in language they can read, what is held and why, and that somebody is accountable for it.
Where consent does become the right basis is for the things that sit outside the employment relationship: monitoring that goes beyond what is needed to run the systems, using employee data for something unrelated to their work, or sharing it with a third party that is not a processor acting for you. If you cannot explain to the person why a piece of data is necessary for their employment, treat that as the signal to stop and ask rather than to write a longer notice.
A starting checklist
- Write down what personal data your desk holds and why.
- Publish an employee-facing notice, separate from your customer privacy policy.
- Appoint and publish a Grievance Officer with an inbox somebody reads.
- Set retention periods per record type, and turn them on.
- Restrict who can see employee records, then verify it as a requester.
- Get a signed DPA from every vendor that touches the data.
- Run a breach drill once: who is called, who decides, who notifies, and by when.
None of that requires a consultant. All of it is the sort of thing that is much cheaper to do in an afternoon now than to explain the absence of later.
Data in India, a signed DPA, role-based access and retention you can actually configure. How we handle DPDP
Tagged: Dpdp