For Technology Companies And Global Capability Centers
Let distributed teams work on sensitive data without multiplying uncontrolled copies
Global delivery spreads documents across employees, contractors, clients, suppliers, and collaboration tools. Client extracts, source and design assets, delivery packs, and audit responses leave the provider as a matter of routine, and a download or an email attachment can become a copy that outlives the statement of work it was created for.
Vaultize applies persistent rights to the document itself, with source-side encryption and customer-controlled keys, so a client or delivery file can move while custody stays with the organisation.
Client dataSource and designDelivery networkShared services
Exposure signal
Where IT, ITeS, And GCC Risk Concentrates
Document exposure changes as client records, source and design assets, delivery files, shared-services data, and assurance evidence move between onshore teams, offshore pods, capability centres, subcontractors, and client reviewers. Select a column to inspect the handoff risk it represents.
Illustrative exposure pattern, not live security telemetry
Selected threat
Client Data
Customer records held on a client's behalf are extracted for support, testing, and reporting work and can outlive the ticket that justified them.
Protected and controlledElevated or exposed risk
The delivery network is part of the data boundary
A Signed Contract Is Not The Same Thing As A Controlled Copy
Client contracts, processing agreements, repository permissions, and certification scopes govern the relationship and the systems around the work. The exposure changes when a client extract, a design document, a delivery pack, or an audit response is downloaded, forwarded, or retained outside those systems.
This is a practical risk view. It is not a determination of regulatory, contractual, or certification applicability or compliance, and it is not legal advice.
View the risk routeExpand full screen
India Operating Environment
Scope depends on the entity, the contract, the data, and the current instrument
Section 2(k) of the Digital Personal Data Protection Act, 2023 defines a Data Processor as any person who processes personal data on behalf of a Data Fiduciary, and Section 8(2) provides that a Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract. Section 8(1) makes the Data Fiduciary responsible for compliance in respect of any processing undertaken by it or on its behalf by a Data Processor. Indian service providers and capability centres routinely sit on the processor side of that arrangement.
Section 8(5) of the same Act requires a Data Fiduciary to protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach. Section 8(7)(b) requires the fiduciary to cause its Data Processor to erase any personal data that was made available for processing. Entry 1 of the Schedule provides a penalty that may extend to two hundred and fifty crore rupees for breach of the Section 8(5) obligation. Copies retained after an engagement ends sit directly against both duties.
The CERT-In Directions of 28 April 2022 apply to service providers, intermediaries, data centres, body corporate, and Government organisations. Direction (ii) requires the cyber incidents listed in Annexure I, which expressly include unauthorised access of IT systems or data, data breach, and data leak, to be reported to CERT-In within 6 hours of noticing them or being brought to notice about them. Direction (iv) requires logs of all ICT systems to be enabled and maintained securely for a rolling period of 180 days, and provides that the same shall be maintained within the Indian jurisdiction.
Section 43A of the Information Technology Act, 2000, as amended, provides that where a body corporate possessing, dealing or handling any sensitive personal data or information in a computer resource which it owns, controls or operates is negligent in implementing and maintaining reasonable security practices and procedures and thereby causes wrongful loss or wrongful gain to any person, it shall be liable to pay damages by way of compensation. The Explanation defines reasonable security practices and procedures as those designed to protect such information from unauthorised access, damage, use, modification, disclosure or impairment, as may be specified in an agreement between the parties. For an outsourced provider, the client's security schedule is part of the legal test.
A press note issued through the Press Information Bureau by the Ministry of Communications and Information Technology on 24 August 2011 clarifies the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, notified on 11.4.2011 vide notification no. G.S.R. 313(E). It records that any body corporate providing services relating to collection, storage, dealing or handling of sensitive personal data or information under contractual obligation with any legal entity located within or outside India is not subject to the requirement of Rules 5 and 6, while a body corporate providing services to the provider of information under a contractual obligation directly with them is subject to those rules. The carve-out is about consent and disclosure, not about security.
The SEBI (Listing Obligations and Disclosure Requirements) (Second Amendment) Regulations, 2023 inserted Regulation 27(2)(ba), under which details of cyber security incidents or breaches or loss of data or documents are to be disclosed along with the quarterly corporate governance report, as may be specified. Listed Indian IT services, engineering services, and business process companies sit inside that reporting obligation alongside their client contractual duties.
Client Contracts And Cross-Border Data
Scope depends on the client, the market, the contract, and the data
Article 28(3) of Regulation (EU) 2016/679 requires processing by a processor to be governed by a contract that stipulates, in particular, that the processor processes the personal data only on documented instructions from the controller, ensures that persons authorised to process the personal data have committed themselves to confidentiality, takes all measures required pursuant to Article 32, and respects the conditions for engaging another processor. Article 28(3)(g) requires that, at the choice of the controller, the processor deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies.
Article 32 of the same Regulation requires the controller and the processor to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, and names pseudonymisation and encryption of personal data among them. Article 83(4) places infringements of the obligations of the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43 in the tier of administrative fines up to 10 million euro, or up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher. The processor carries that exposure in its own name.
Commission Implementing Decision (EU) 2021/914 of 4 June 2021 sets out standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679. Recital 9 records that where the processing involves data transfers from controllers subject to the Regulation to processors outside its territorial scope, or from processors subject to the Regulation to sub-processors outside its territorial scope, the clauses should also allow the requirements of Article 28(3) and (4) to be fulfilled. Recital 10 explains the modular approach that lets the parties select the module matching their role. Offshore delivery and sub-processing chains are the situation these modules describe.
The Information Commissioner's Office publishes guidance on international transfers of personal information under the UK GDPR, covering when a transfer is a restricted transfer, adequacy regulations, the appropriate safeguards permitted including the UK IDTA, the Addendum and UK Binding Corporate Rules, and how to complete a transfer risk assessment, which UK legislation now refers to as a data protection test. A UK client's data reaching an Indian delivery centre is the transfer this guidance addresses.
Where a provider handles protected health information for a United States healthcare client, Section 164.504(e)(2) of Title 45 of the Code of Federal Regulations requires the business associate contract to establish the permitted and required uses and disclosures, and to provide that the business associate will not use or further disclose the information other than as permitted by the contract, use appropriate safeguards, report any use or disclosure not provided for by its contract including breaches of unsecured protected health information, and ensure that any subcontractors that create, receive, maintain, or transmit protected health information on its behalf agree to the same restrictions. Section 164.504(e)(1)(iii) makes a business associate non-compliant if it knew of a pattern of activity by a subcontractor amounting to a material breach and did not act.
The Federal Trade Commission's guidance on the Safeguards Rule sets out the elements of the required information security program, including encrypting customer information on the system and in transit, or securing it with effective alternative controls approved by the Qualified Individual where encryption is not feasible. Under the element on monitoring service providers, it states that contracts must spell out security expectations, build in ways to monitor the service provider's work, and provide for periodic reassessments of their suitability for the job. A vendor to a covered financial institution is on the receiving end of that clause.
Assurance And Certification Expectations
Scope depends on the scheme, the scope statement, the assessor, and the report
ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection, Information security management systems, Requirements, is published by ISO and IEC as Edition 3, dated 2022-10. ISO describes it as the world's best-known standard for information security management systems and states that conformity means an organization has put in place a system to manage risks related to the security of data owned or handled by the company. Certification is against the management system within a defined scope; it is not a statement about any individual file.
ISO/IEC 27701:2025, Information security, cybersecurity and privacy protection, Privacy information management systems, Requirements and guidance, is published as Edition 2, dated 2025-10. ISO describes it as an international standard that sets out requirements for establishing, implementing, maintaining, and continually improving a Privacy Information Management System. Clients that place personal data with a provider increasingly ask for this alongside the information security certificate.
The AICPA describes System and Organization Controls, or SOC, as a suite of service offerings CPAs may provide in connection with system-level controls of a service organization or entity-level controls of other organizations, and states that CPAs can use these offerings to provide assurance reports that give users information needed to assess and address the risks associated with outsourcing services. The AICPA promulgates the professional standards for SOC engagements. A report describes controls over a defined system for a defined period; it does not travel with a document that has left that system.
Where a business process or managed-service engagement touches cardholder data, the PCI Security Standards Council states that the PCI Data Security Standard provides a baseline of technical and operational requirements designed to protect payment account data, and identifies the intended audience as entities that store, process, or transmit cardholder data or sensitive authentication data, or could impact the security of the cardholder data environment, including all entities involved in payment card processing and expressly including service providers. Applicability depends on the engagement and the data actually handled.
Ranked by business exposure
Priority IT, ITeS, And GCC Records
Swipe the wheel or tap a record class.Drag, scroll, click, or use the arrow keys to move between record classes without changing the layout.
Swipe or tapDrag or scroll01 / 05
Client
Source
Delivery
Shared
Assurance
Client And Customer Records
01
Processor duty · purpose limitation · deletion at the end of service
Client And Customer Records
01
Leak scenario
Production extracts, support tickets, and test data sets containing a client's customer records are pulled into a delivery environment for a defect, a migration, or a report, and the extract stays on a laptop or a shared drive long after the ticket is closed.
02
Common stopping point
Client systems, VDI sessions, and processing agreements protect the platform and the relationship. None of them necessarily governs the exported spreadsheet once it is on a delivery engineer's device, nor produces evidence that copies were deleted at the end of the engagement.
03
Stronger practice
Treat every client extract as its own release decision: name the recipient, bound the permitted use and the period to the ticket or the release, keep forwarding visible and revocable, and retain an attributable record of who opened which extract.
04
Cost of inaction
Section 8(5) of the DPDP Act, 2023 requires reasonable security safeguards including for processing carried out on the fiduciary's behalf by a processor, with a Schedule penalty that may extend to two hundred and fifty crore rupees. Article 28(3)(g) of Regulation (EU) 2016/679 requires the processor, at the choice of the controller, to delete or return all the personal data after the end of the provision of services relating to processing, and to delete existing copies.
Operational risk map only, and not legal advice. Regulatory, contractual, and certification scope depends on the entity, the client, the data, and the current instrument. Linked official sources are authoritative. File controls support confidentiality and security obligations as part of a wider network, identity, personnel, governance, and incident-response program; they do not satisfy a client contract, a certification, or an assurance report, and they do not establish compliance by themselves.
Operational risk map only, and not legal advice. Regulatory, contractual, and certification scope depends on the entity, the client, the data, and the current instrument. Linked official sources are authoritative. File controls support confidentiality and security obligations as part of a wider network, identity, personnel, governance, and incident-response program; they do not satisfy a client contract, a certification, or an assurance report, and they do not establish compliance by themselves.
Documented industry incidents
The Cost Is Real
Exposure inside technology and services companies has already reached exchange intimations, quarterly filings, and a federal sentencing. In each case the organisation or a court put the facts on the record.
Client delivery
was the first thing the filing addressed
Case 01
The Intimation Went To Both Exchanges That Night
Case date
Intimation dated January 31, 2025; filed to BSE in the early hours of 31 January 2025
Case location
India; the affected IT assets are not identified in the intimation
Tata Technologies Limited filed an intimation under Regulation 30 of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015, addressed to BSE Limited and the National Stock Exchange of India Limited under reference TTL/COSEC/SE/2024-25/91. The letter states that the Company has become aware of a ransomware incident that has affected a few of our IT assets, and that as a precautionary measure, some of the IT services were suspended temporarily and have now been restored.
What The Company Disclosed
The intimation records that Our Client delivery services have remained fully functional and unaffected throughout, and that further detailed investigation is underway in consultation with experts to assess the root cause and to take remedial action as necessary. For an engineering and IT services company the disclosure is written around the client relationship first, which is the exposure a delivery organisation carries in addition to its own systems.
Publicly documented incidents. The organizations named are not represented as Vaultize customers, and no claim is made that Vaultize would have prevented these events. Dates, locations, roles, figures, and consequences follow the linked primary sources; undisclosed parties and systems are identified as redacted or not disclosed. Individuals are named only where the linked official document names them and the matter is concluded; the individuals named here are the company secretary who signed the exchange intimation, the officer who signed the Form 8-K, the United States Attorney whose office issued the release, and the defendant the court sentenced. The first case is an Indian exchange filing; the second and third are United States records.
A deliberate control trail
Make The Release Decision Reviewable
Use the file-level route as part of a broader client-assurance, third-party-risk, privacy, and security program. The objective is a clear answer to what was released, to whom, under what conditions, and what activity followed.
Controlled document route
A concise record around a delivery exchange
ClientPartyUseExpiryEventsPreservation
01
Classify The Record
Identify the client, engineering, delivery, shared-services, and assurance files that carry personal data or client intellectual property before external access. Discover & Classify can apply content and context rules across endpoints and repositories, including detection of PII, so the classification reflects the client, the engagement, and the sensitivity rather than a generic file type.
02
Define Permitted Use
Decide who can view, edit, print, copy, forward, or download each document before it leaves, and apply the organization's approved identity and approval process for client teams, offshore delivery pods, capability centres, subcontractors, and contract staff.
03
Open A Bounded Exchange
Release the file or the workspace to named users and groups under expiry, watermarking, and access conditions bound to the statement of work or the release, subject to the organization's policy and technical environment. Governed sharing can replace ad hoc FTP, SFTP, and MFT routes where the delivered payload otherwise arrives uncontrolled, and browser-based co-editing keeps a single governed copy instead of one per reviewer.
04
Protect The Message, Not Only The Attachment
Where a client extract or a design note travels by email, protect the body alongside the attachment, keep each recipient's access verifiable, and retain the ability to revoke downstream forwards after the message has been sent.
05
Preserve, Trace, And Withdraw
Keep release, access, policy-change, and revocation evidence available to security, client-assurance, privacy, and audit teams, retain immutable versions of assurance and incident evidence, and require multi-stakeholder approval before any permanent deletion.
Common delivery routes
Start Where Delivery Files Change Hands
Information moves from pursuit through transition, engineering, managed services, shared services, and audit. The map shows where file-level control must remain connected as documents cross each handoff.
Delivery and shared-services lifecycleFour priority control points
01
Client Data Release
Release production extracts, support data, and reporting packs to named delivery teams under expiry and usage conditions bound to the ticket or the release. Where the record travels by email, protect the body alongside the attachment and keep the ability to expire or revoke a forwarded message.
Purpose-bound client data
02
Source And Design Exchange
Apply persistent rights, watermarking, and per-recipient activity records to source, architecture, and design documents so a legitimate download stays governed, and revoke after the assignment ends rather than at laptop return.
Control after the download
03
Subcontractor And Contract Staff
Send statements of work, transition documents, and runbooks to staffing partners and subcontractors through governed links with MFA and watermarking, without file-size or file-type friction, and end access at rotation or offboarding.
Access ends when the assignment does
04
Assurance And Incident Evidence
Maintain immutable versions of client questionnaire responses, certification evidence, incident timelines, and log extracts under the organisation's own custody, and require multi-stakeholder approval before any permanent purge.
Evidence stays recoverable
Bring one delivery route
Make One Client Release Reviewable
Walk through the records, recipients, permitted use, and evidence a responsible security, client-assurance, and privacy team can verify.