Skip to content
RegulensR

Industry solution

DPDP, CERT-In and state labour law for a distributed workforce

Technology services firms and global capability centres assumed compliance meant client contracts and SEZ conditions. DPDP, CERT-In directions and state-level labour obligations across every delivery centre have made it a much broader problem, and one that engineering has to participate in.
2,600+
obligations for a multi-centre IT firm
6 hours
CERT-In clock with escalation tracking
Jira-native
delivery of obligations to engineering

Sector pressures

What makes it & gcc compliance hard

01

Delivery centres in multiple states

Each centre carries its own shops and establishments registration, professional tax, labour welfare fund and, where applicable, SEZ or STPI conditions.

02

DPDP as processor and as fiduciary

You process client personal data as a Data Processor while remaining a Data Fiduciary for your own employees and users. The two roles carry different obligations and most programmes only address one.

03

Six-hour CERT-In reporting

The window is shorter than most incident triage cycles, and applies across twenty incident categories including ones that are routine in a large estate.

04

Client and regulator obligations flow through

Serving RBI or SEBI regulated clients brings their outsourcing obligations onto you contractually, including audit and inspection rights for the regulator.

Coverage

Key instruments we track in depth for this sector

A representative sample, not the full list. Depth varies by jurisdiction and we will tell you exactly where it sits for your markets before you buy.

InstrumentJurisdictionWhat it drives
DPDP Act, 2023 and RulesCentralFiduciary and processor duties, breach intimation, SDF obligations
CERT-In Directions, 2022CentralSix-hour reporting, 180-day log retention in India
Shops & Establishments ActsStatePer-centre registration, working hours, women’s night shift conditions
SEZ Act, 2005 / STPICentralNet foreign exchange, unit approval conditions, annual performance reports
RBI Outsourcing DirectionsCentralFlow-down obligations when serving regulated entities
POSH Act, 2013Central + StateInternal Committee per location, annual District Officer report
E-Waste Rules, 2022CentralEPR obligations on IT asset disposal

Use cases

How teams in this sector use Regulens

Per-centre labour registers

Scope shops and establishments, professional tax and welfare fund obligations to each delivery centre and its state.

Dual-role DPDP mapping

Separate the obligations you carry as processor for client data from those you carry as fiduciary for your own, with different controls for each.

Engineering-ready obligations

Deliver DPDP and CERT-In requirements into Jira as stories with acceptance criteria and the rule citation attached.

Client flow-down tracking

Maintain the regulatory obligations inherited through client contracts alongside the ones that apply directly.

“Our engineers were never going to read the DPDP Rules. Getting the obligation as a story with acceptance criteria, cited back to the rule, is the only version of this that works.”
Director, Privacy & Compliance · a global capability centre

See it scoped to a it & gcc footprint

We configure your legal entities, licences and jurisdictions and run live intelligence for two weeks. You compare it against what your team actually caught in the same period.