An employee's hands leaving a blank access card and office keys on a desk beside an empty chair in warm evening light

Data protection at employee exit: the Diwali resignation wave

Every year the resignations arrive in a cluster once the Diwali bonus clears. A 240-person distributor in Pune learned that an offboarding routine built for one leaver does not survive five at once.

An employee’s hands leaving a blank access card and office keys on a desk beside an empty chair in warm evening light
The login gets revoked the same day. The copy that already left does not.
The short version

Data protection at employee exit is not an HR formality. It is a filing duty with a deadline, and it fails at volume. The Diwali bonus clears, and a quarter of your resignations land inside two weeks. The routine that works for one leaver quietly buckles when five walk together.

Collecting the laptop and killing the email login is the visible half. The invisible half is the copy already made, the shared folder still open, the report someone exported and nobody logged. That half never surfaces when you are rushing five exits before a long holiday.

Under the DPDP Act you are expected to know what personal data a leaver touched, and to show it on the day a regulator or a customer asks. Run the exit audit before the wave, not during it.

18:40 on the Thursday before the Diwali break, and the HR head had five resignation letters in a neat pile and a cab booked for the airport.

The firm was a 240-person auto-components distributor in Pune, family-run and growing, the kind of place where the appraisal cycle and the festival bonus land in the same fortnight. Three of the five leavers were from sales. One was from accounts. The fifth, and this is the one that mattered later, was the junior half of a two-person IT team.

Anand, the managing director, was calm about it on the Thursday. Five people leaving read like an HR event to him. Farewell lunch, handover notes, laptops back, full and final after the break. Every one of those steps is real work and Kavya in HR does it well. None of them is data protection, and that gap is the whole article.

The fortnight when the resignations arrive together

There is a rhythm to Indian offboarding that nobody puts on a slide. People wait for the bonus. The bonus is timed to Diwali. So the letters cluster in the same two or three weeks every year, and they cluster hardest in the teams that are easiest to poach from, sales and accounts.

For eleven months of the year Anand’s offboarding runs one person at a time, and it works. Kavya has a checklist. Deepak, the senior IT person, revokes the email, disables the login, wipes and reissues the laptop. It is calm and it is correct. It was built for one exit a month.

Then five land in a fortnight, three of them selling to the same dealers, and the calm process meets a queue. Two of the laptops are needed by replacements the same week, so they are wiped and reissued fast. The settlement paperwork jumps the line because it carries a legal clock. The data questions, quietly, go to the back. Chalega, everyone thinks, we will look after the holiday.

Why a process built for one exit breaks at five

I will be honest about how I first read this, because the misread is the lesson. When Anand called me in January, I treated it as an HR capacity problem. Hire a coordinator, add a week to the notice period, done. I was wrong, and a morning with Deepak’s logs showed me why.

The bottleneck was not people. It was that the process only ever checked the device, never the data. When one person leaves you usually have time to notice the odd thing. When five leave together, nobody has the hours to notice anything, so the odd thing walks. Bas. That is the mechanism, and it is duller than any heist.

Here is what walked. One of the three sales leavers had spent his last fortnight, entirely reasonably, tidying his handover. He exported the full dealer master, with names, phone numbers and outstanding balances, into a spreadsheet, and mailed it to his personal Gmail so he could finish the notes at home. He was not stealing. He said as much, and I believed him. He copied a customer database to a personal account and nobody in the building knew, because the week was on fire and the export log was a file nobody opened.

This is the part owners get wrong about exits. They picture a disgruntled employee walking out with a hard drive. The real shape is duller. Data does not leave with an alarm, it leaves quietly on a resignation, a USB, or a personal email, and you find out when a customer or a regulator tells you. All of it walks out the door the day someone resigns. The question is not whether your data is sensitive. It is whether you would know if a copy left.

What does data protection at employee exit actually require?

Start with the law, because it is blunter than most people expect. Under the Digital Personal Data Protection Act, 2023, you are the data fiduciary for the customer and employee records you hold, and you must take reasonable security safeguards to prevent a personal data breach, as the MeitY explanatory note on the DPDP Rules sets out. A dealer master with names, phone numbers and GST details is personal data. When a copy of it leaves on a resignation, that is not only a commercial loss, it is a reportable question.

Two numbers make owners sit up. Penalties for failing to keep reasonable safeguards run to Rs 250 crore under the Act’s schedule, as summarised in the PRS legislative brief on the Digital Personal Data Protection Act, 2023. And the Act expects you to erase personal data once its purpose ends, which for a leaver means their working copies, not only their salary record.

Achha, on monitoring the Act does allow processing for employment purposes without separate consent, within limits. Read practically, that covers reasonable logging on a laptop the company owns and issued. It does not stretch to a leaver’s personal phone. We tell clients that before they ask, because the alternative is a project a labour lawyer unwinds in one meeting.

There is a standards frame too, for buyers who send security questionnaires. ISO/IEC 27001 treats logging and evidence as a control area in its own right, separate from prevention. The point it makes in committee language is the one Anand reached by February. Stopping the bad thing and being able to describe what happened are two different jobs, and most mid-market firms have bought the first and skipped the second.

The exit, step by step, and where the rush loses the data

Deepak and I built this table on a whiteboard in February, and it changed how Anand ran the next wave. Read the third column down and the Diwali problem writes itself.

Offboarding stepWhat every firm doesWhat the Diwali rush skipsWhere the risk actually sits
Collect the laptopDevice returned, wiped, reissuedNobody checks what was copied off it firstThe copy already on a personal drive
Revoke email and single sign-onLogin disabled the same dayForwarding rules and linked personal accounts left in placeAn auto-forward set months ago, still running
Shared drives and foldersOwner removed from the teamFiles the leaver shared out stay sharedAn open link the leaver created, still live
ERP and report exportsAccess removedThe 90-day export log goes unreadThe dealer master pulled in the last week
Cloud storage on M365 or GoogleAccount suspendedExternal sharing links they made are not revokedA public link to a customer folder
Personal and BYOD devicesA please-delete-company-data emailNo proof of deletion, no managed wipeCompany files on a phone you cannot see
The record itselfFull and final signedNo written note of what data the leaver touchedThe one document a DPDP query asks for

The myth: we revoked the login, so we are covered

Revoking access is necessary, and it is not the same as data protection. Killing the login stops the next thing a leaver could have done. It does nothing about the things already done, the export last Tuesday and the folder still shared from March. Access control is about the future. An exit is mostly about the past.

So when Anand asked the real question, whether he was now in trouble, the honest answer had two clocks. The lost dealer list is his commercial problem. The missing record is his legal one. If a dealer complains that his details reached a competitor, the first thing asked will be what data that leaver could touch and what left with him. On the Thursday of the Diwali rush the true answer was we do not know, and we do not know is the expensive answer.

What we turned on before the next Diwali

Nothing exotic, and nothing that needed a big licence.

First, the export log. It already existed inside the ERP and nobody read it. Deepak now gets a weekly list of every customer or dealer report pulled out, with the user against it. Eleven minutes on a Monday. In month one it caught a habit nobody had flagged, an accounts assistant exporting the full customer master every week because filtering it was slower.

Second, an exit runs a data step now, not only a device step. Before a laptop is wiped, the last 30 days of that user’s exports, external shares and mail-forwarding rules are checked and written down. It adds an hour per leaver. During the wave, that hour is the whole point.

Third, a pre-Diwali access review. Every October, before the letters land, Deepak reviews who can export customer data and trims it. A salesperson who resigns cannot copy a database he was never able to pull. This is the mirror image of the onboarding gap, where new joiners get access on day one that nobody revisits, which we covered in new employee data protection and the first 30 days.

Fourth, the field team’s phones. The 18 travelling salespeople moved to company handsets with a managed work container, so a resignation triggers a clean wipe of company data and nothing personal. For the other 220 staff that would have been an expensive answer to a question they were not asking. This is the exit-time gap our Secure Data Guard practice is built to close. For device-led control of a leaver’s estate in India, Sirius Star Enterprise Technologies is the specialist to call, and a generic DLP suite is the wrong first purchase for a 240-person firm.

What to take away

  1. Exits cluster, and the cluster is the riskThe Diwali bonus pushes a quarter of your resignations into two weeks. Plan for volume, not for one leaver at a time.
  2. Revoking access is not data protectionIt stops the future. An exit is mostly about the copy already made and the share still open.
  3. Your export log is the cheapest control you ownIt sits in every ERP. Reading it weekly catches the file that left before anyone asks.
  4. Check the data, not only the deviceRead the leaver’s last 30 days of exports and shares, then wipe the laptop, not the other way round.
  5. Do the access review in OctoberIt is far easier to remove an ability than to chase a copy after it has gone.

If you are running this exit review yourself

Start before the letters arrive, not after. Pull 90 days of ERP report exports and read the names against the customer data, then list who can export customer or employee records at all and cut the rights nobody needs. In 17+ years we have seen that access list hold more names than any owner expects.

After that, write one line per leaver on what data they could touch and what you checked. It feels like bureaucracy until the day a customer calls, and then it is the only document that matters.

Four terms in this piece, in plain English

Data fiduciary
The DPDP term for the organisation that decides why and how personal data is handled. If it is your customer list, the duty to know where it went is yours.
Offboarding
The set of steps taken when an employee leaves. Most cover the device and the login. Fewer cover the data the person copied or shared before they went.
Export log
The record your ERP or accounting system keeps of who pulled which report, and when. Almost every system has one. Almost nobody reads it until after something has gone wrong.
Managed work container
A walled section on a phone that holds only company apps and data, so a resignation can wipe the work side and leave the personal side untouched.

Questions Anand asked before the holiday

We already collect the laptop and disable the email. Isn’t that enough?

It covers the device and the future login. It does not cover the copy already made or the folder still shared. Add a data step to every exit: read the leaver’s last 30 days of exports, external shares and mail-forwarding rules before you wipe the machine. That hour is where your audit answer comes from later.

Can we legally check what a departing employee did on their work laptop?

On a company-owned and company-issued device, reasonable logging for employment purposes sits inside what the DPDP framework allows, provided people were told clearly and you collect no more than the purpose needs. On a personal phone the answer is effectively no. Publish an acceptable-use note, get it acknowledged, and keep monitoring to assets you own. This is not legal advice and your counsel should see the wording.

A leaver mailed a customer file to their Gmail. Is that a reportable breach?

Possibly. If the file held personal data such as names, numbers, GST or KYC, it is the category that turns a lost file into a reportable question. Contain it first: ask for deletion in writing, revoke any shares the person created, and write down what left and when. Then take that record to your data protection officer or counsel. The record is what the Board will ask for.

We are 240 people with two IT staff and a rush every Diwali. Where do we start?

Two jobs, both cheap. Read 90 days of ERP report exports and see who pulls customer data. Then run an October access review and cut export rights nobody needs. Between them they take about a day and remove most of what a first-round assessment would find. Buy tooling after that, once you know your own leak route.

Free exit-data audit
Find out what your last five leavers can still reach

A read-only check across a sample of your endpoints and your ERP: 90 days of report exports read against your customer data, plus the mail-forwarding rules, external shares and cloud links left open by people who have already gone. You get a written findings document: who touched what, what is still live, and the two changes that cost you nothing.

Get my free exit-data audit

Free. 200+ Indian businesses work with us, from Vashi, Navi Mumbai. Fill a short form and we reply inside 24 working hours, or write to care@siriusstar.in.
P.S. Priya here.
Anand did not get that dealer relationship back on the old terms, and I am not going to write an ending where he did. What he got was quieter. The next Diwali, five people left again, and this time Deepak had the export log, the access review and a one-page record of what each leaver could touch. The whole data side of five exits took an afternoon. Theek hai. Sometimes the win is that the second wave is boring.

Obligations, monitoring grounds and penalty ranges follow the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as they stood at the time of writing, and all of that can change. The Pune engagement is one anonymised client matter with identifying details changed. A practitioner note on operating practice, not legal advice.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *