Nobody is checking those old folders — and that is a big problem.

You finished a project six months ago. The client's data is still sitting in a folder. Nobody deleted it. Nobody even checked it. This happens in almost every consultancy and BPO in India. Old resumes, support chat logs, salary slips, candidate phone numbers — all stored, all forgotten. Under the new DPDPA law, keeping people's information longer than needed is a serious mistake. Fines can go up to ₹250 crore.
Say your BPO handled calls for a bank last year. You still have customer phone numbers and account details in a shared folder. That is a risk today. Or your consultancy interviewed 200 candidates. Their resumes with Aadhaar copies are still in your HR inbox. Nobody deleted them. If there is a data leak, you must report it quickly — the law expects fast action. If nobody in your team knows what to do during a breach, you will miss the deadline and face heavy fines.
List all old project folders and decide which ones to delete now.
Name one person in ops and one in leadership to handle any data breach.
Check if your business is ready. Takes 3 minutes. Visit saralprivacy.com/assessment
“Service archives become silent risk when nobody owns review.”
Free — takes 3 minutes
Answer a few simple questions. Get your free Readiness Score — sent to your email or WhatsApp.
Check My Readiness →Take our free 3–5 minute industry assessment to find out your compliance risk level.
Take Free Assessment →Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Download the Guide →5 Ready-to-Use Templates
Start complying — not just reading
Privacy Notice, Consent Language, Data Inventory, DSR SOP, Vendor Register. Delivered free to your email.
2-min reads, plain English, every morning. Free forever.