Kolkata combines long-established engineering and trading houses with a growing BFSI back-office and healthcare sector. Its distinguishing feature is age: many organisations here run systems that have accumulated personal data for decades, in formats and stores that predate anyone currently employed.
Legacy accumulation is the defining problem. Retention is the obligation these organisations most often fail, not because they decided to keep data forever but because nobody ever decided to delete it.
Back-office operations serving clients elsewhere are typically processing rather than determining purposes, which changes what they owe and to whom.
ProtectComply is built by Exuverse, whose team sits in Noida. We work with organisations across India — remotely for most of a programme, in person when discovery or a workshop genuinely needs it.
Retention. Data accumulated over decades with no current purpose and no legal duty to keep it is a liability with no offsetting benefit, and it enlarges the impact of any breach.
Usually processors, acting on a client's documented instructions for the client's data — while remaining fiduciaries for their own employee and vendor data.
Jupinder Bedi — Jupinder writes on data protection practice at ProtectComply, with a focus on how obligations translate into system behaviour.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →