The Practice |
A consulting or professional services firm completes a project for Client A. The engagement folder — containing employee interview transcripts, survey responses, and organisational charts with named individuals — remains accessible on a shared internal drive. A separate team, engaged months later by Client B in the same sector, accesses this folder for benchmarking and contextual research.
Questions Raised for Compliance Review |
- Is the use of personal data from one client engagement for the benefit of a separate client's engagement permissible under DPDP?
- What risks arise from the retention of personal data beyond the completion of the engagement for which it was collected?
- What governance controls should govern internal data access across project teams?
Is This Permitted Under DPDP? |
Not permissible. Personal data belonging to individuals associated with Client A — employees, interviewees, survey respondents — was collected under the terms of that specific engagement. Its use, even internally, for the benefit of a separate client constitutes unauthorised processing. The data principals were never informed that their information might be used to serve a third party's organisational interests.
Where the Breach Risks Sit |
- Unauthorised secondary processing — The individuals who participated in interviews or surveys for Client A's project consented, implicitly or explicitly, to that specific engagement's purpose. Their data being benchmarked against Client B's situation is a processing activity they had no knowledge of and did not consent to.
- Confidentiality and commercial exposure — Beyond DPDP, this practice likely breaches the confidentiality obligations in the Client A engagement contract. The organisation faces simultaneous regulatory and commercial liability.
- Uncontrolled data retention — Once a project concludes, personal data collected during it has no ongoing lawful basis unless explicitly defined. Retaining it on accessible shared drives without a retention policy and without deletion timelines is a standing compliance failure.
- Absence of access controls — If any team member in the organisation can access any project folder on the shared drive, the organisation has no meaningful data minimisation — a principle DPDP requires be embedded in the organisation's data handling practices.
The Ideal Compliant Approach |
- Implement project-level access controls. Shared drives must be structured so that each project folder is accessible only to the team members working on that engagement. Access should be revoked upon project closure.
- Define and enforce retention timelines. At project close, a standard process should archive or delete personal data collected during the engagement within a defined period — typically aligned with contractual obligations to the client. Retaining interview transcripts or named survey data indefinitely has no lawful basis under DPDP.
- Treat benchmarking data separately. Where the organisation wishes to build industry benchmarks, this must use anonymised or aggregated data only — no named individuals, no identifiable roles. The benchmark dataset must be created and maintained as a separate, purpose-declared resource.
DPDP Risk Summary |
| Element | Status | Recommended Action |
|---|---|---|
| Cross-project use of personal data | ✗ Unauthorised processing | Restrict project folder access; cease cross-project data use |
| Named personal data retained post-engagement | ✗ No lawful basis | Define retention policy; delete or archive within agreed timelines |
| Shared drive with open team access | ✗ No data minimisation | Implement role-based access controls on all project folders |
| Benchmarking using named client data | ✗ Purpose violation | Use anonymised aggregates only for any benchmarking activity |
| No data deletion process at project close | ⚠ Gap in data lifecycle governance | Build a standard project closure checklist including data review |