New employee data protection: what the first 30 days must cover
A 240-person engineering services firm in Coimbatore hired nineteen people last April. The data problem started on their first morning. Nobody looked at it again until day forty-one.

New employee data protection in the first thirty days comes down to three habits, and none of them is a training slide. Scope the access you grant on day one instead of cloning it from whoever sits nearest. Name the person who reviews that access on day thirty. Point your data-movement monitoring at the folders that would actually hurt you.
The law is already on your side for the third one. Section 7(i) of the Digital Personal Data Protection Act, 2023 lets an employer process employee data without consent for the purposes of employment, and it names prevention of corporate espionage and confidentiality of trade secrets as examples of what that covers. It does not authorise watching everybody all day.
Substantive obligations commence on 13 May 2027 under the phased notification of 13 November 2025. An onboarding habit takes about a quarter to bed in, so an April intake is the cheapest place to start one.
09:52 AM on a Wednesday in June, and the finance controller had a question about a spreadsheet.
It was not his spreadsheet. A client of theirs, a mid-size auto component maker, had received a rate comparison from a competing vendor, and three of the line items matched their own internal costing sheet down to the paise. Not similar. Matching. He forwarded it to the IT lead with one line above it. Is this ours.
It was theirs. What took the next four days was working out how it left, and the answer sat in a set of decisions made on a Monday in April that nobody in the building thought of as security decisions at all.
The first thirty days, reconstructed
Nineteen people joined that month. New financial year, budget released, hiring plan finally signed. Two in finance, four in design, the rest across project delivery and site.
The onboarding ticket for one of the design hires said four words in the access field. Same as Rahul, it said.
Rahul had been with the company six years. He had started in site coordination, moved to design support, then to a project management role that touched client costing. Nobody had ever taken away the access from the first two jobs. So Rahul’s account, by June, was a sedimentary rock of six years of permissions, and every layer of it got handed to a designer in his third week of employment.
By the time we finished the reconstruction, eleven people in the company were running on some version of same as Rahul. Rahul himself had resigned in February.
The designer did nothing dramatic. He had a deadline, he wanted to work from home on a Saturday, and he zipped a project folder and dropped it on a personal cloud drive. The folder he zipped was one level too high. It carried the costing sheet for a different client, from a project he had never been staffed on, because a folder is a folder and nothing on his screen said otherwise.
He left in May for a competitor. The drive went with him. Nothing he did required a password he was not given.
The monitoring was on. It told us nothing.
Here is the part that stung, because they had spent money on this.
They had an endpoint agent running on every laptop. It had been installed eighteen months earlier by a reseller who configured it the way agents get configured when nobody has decided what matters. Log everything. Alert on nothing. The console was recording somewhere north of four lakh events a month, and the number of humans reading them was zero.
The upload was in there. We found it on day three of the review, timestamped, sized, with the destination domain written out in full. Thirteen weeks it had been sitting in a log that a licence was being paid for.
This is the sentence we say to clients who tell us they will handle it themselves, and I will repeat it here because it earned the right. A DLP that nobody monitors is just a false sense of safety. Installing it is the smallest part of the job. It is a policy you write, tune and watch, and the day it fires an alert is the day it matters who is actually reading the console. If the honest position in your company is that nobody owns that inbox every morning, that is worth admitting out loud before you renew. We have written up the less dramatic versions of this in the five exit routes most Indian companies cannot detect.
Section 7(i) treats employment as a legitimate use, so you do not need an employee’s consent to process their data for employment purposes, including safeguarding the employer from loss or liability. The Act’s own examples are prevention of corporate espionage, maintenance of confidentiality of trade secrets and intellectual property, and classified information. Every example is defensive and narrow. Section 7 is a closed list, so blanket keystroke capture across a whole workforce is not sitting inside it, and a clause in the appointment letter does not widen it.
The thirty-day map we wrote afterwards
We built this for them in a meeting room with a whiteboard, and I have used it eleven times since with almost no changes. It is deliberately boring. The point of it is that every row has a name against it, not a department.
| When | What happens | Who owns it | What breaks if you skip it |
|---|---|---|---|
| Day minus 3 | Manager writes the access list from the role, not from a person. Named systems, named folders | Hiring manager | You get same as Rahul, and inherit six years of somebody else’s permissions |
| Day 1 | Account created with that list only. Device issued and recorded against the person by serial number | IT | No asset trail, so nothing to recover or wipe when they leave |
| Day 1 | Acceptable use explained in four sentences, in the language the person actually speaks | HR | A twelve-page policy signed unread proves nothing to anyone |
| Day 7 | Monitoring scoped to the folders that would hurt you. Costing, customer master, source code, HR files | IT or partner | Four lakh events a month and no signal in any of them |
| Day 15 | First alert review with the manager, even if there are no alerts. Fifteen minutes | IT and hiring manager | Nobody learns to read the console, so nobody reads it in month nine |
| Day 30 | Access review against the day-minus-3 list. Remove what got added ad hoc during the month | Hiring manager | Everything granted in a hurry becomes permanent |
| Day 30 | Confirm the device is enrolled, encrypted and reachable for a remote wipe | IT | The laptop leaves with the person, and the data leaves with the laptop |
The day-30 review is the row people delete first and regret most. Microsoft describes the same discipline as least privilege in its Entra ID Governance guidance, and the joiner and leaver automation sits in access reviews. If you already pay for Microsoft 365, some of this is licensing you own and have not switched on.
The bit I got wrong
I want to be honest about a mistake, because the mistake is the lesson.
I wrote that company’s onboarding checklist. Not this year, in 2024, as part of a small engagement that lasted three weeks and that everyone including me considered a success. Eleven steps, laminated, stuck on the wall of the IT room. I have seen it.
Every one of those eleven steps was a day-one step. Create the account. Issue the laptop. Enrol the device. Add to the groups. Hand over the sim. Not one line about day thirty. I had built them a grant and called it a process.
Arre, that is the specific shape of the error, and I think it is common. Onboarding gets designed by people whose job is to make a new person productive by lunch. Nobody in that room is measured on what gets taken back. The review step has no owner because it has no urgency, and access that nobody revisits is just a slow leak with a start date. Bas, I now refuse to write an onboarding SOP that does not end with a calendar entry.
New employee data protection without buying anything
Most of what went wrong in Coimbatore cost nothing to fix. I want to separate that clearly from the part where we sell something, because the two get blurred by people in my line of work.
Write access lists against roles. A designer, a site engineer, a finance executive. Three or four templates cover a 200-person company, and the templates take an afternoon. Once they exist, nobody types a colleague’s name into an access field again.
Put the day-30 review in a calendar with the manager’s name on it. Not IT’s calendar. The manager knows what the person is actually working on, and IT does not.
Delete leavers’ accounts the same week, not the same quarter. The Coimbatore trail ran through a resigned employee’s permission set. That is not an unusual detail, it is the usual one.
Say the monitoring out loud. If you are watching data movement on company devices, tell people at induction in plain words: what is watched, what is not, and why. Section 7(i) gives you the legal room. Telling them gives you the room to actually use it without a fight later, and it changes behaviour more than any alert does.
Now the part where we sell something. Scoping the monitoring, tuning it so the console has ten meaningful events a week instead of four lakh meaningless ones, and having someone read it every morning, that is work and it does not do itself. That is what Secure Data Guard is. The other half is the hardware. A laptop that leaves the company unwiped carries whatever was on it, which makes it a device lifecycle management problem rather than a software one. If you are buying fifty or more machines for this year’s intake, ask us about DaaS in the same conversation, because a certified wipe on return costs less as a line item than as a project.
Where we lose, and I would rather write it here than argue it in a proposal. If your company is under twenty-five people, holds no customer PII beyond an invoice address and has nothing a competitor would want, you do not need us for this. Do the access templates yourself and spend the money on something that grows revenue. Forcing DLP onto a business that does not need it makes us the vendor we claim to hate.
The Schedule to the Act prices a failure to take reasonable security safeguards at up to ₹250 crore, and the operating detail for those safeguards sits in the Digital Personal Data Protection Rules, 2025. Quoting that ceiling at a 240-person engineering firm would be fear-selling. What it actually cost them was a client relationship in its fourth year and a rate card their competitor now knows.
What to take away
- Cloned access is the root cause, not carelessness. Same as Rahul hands a three-week employee six years of accumulated permissions, and nobody involved thinks they made a security decision.
- Day 30 is the missing step in almost every onboarding SOP. The grant has an owner and a deadline. The review usually has neither.
- Logging is not monitoring. An agent recording four lakh events a month that nobody reads is a licence fee, not a control.
- The law permits scoped watching. Section 7(i) covers employment purposes including protecting trade secrets and preventing espionage. It is a closed list, so scope it and say it out loud.
- Leavers and joiners are the same problem. The Coimbatore leak ran through a resigned employee’s permission set that had never been closed.
Four terms in this piece, in plain English
- DLP, or data loss prevention
- Software on company laptops that watches where files go. Email attachments, USB copies, uploads to personal cloud drives, files pasted into chat apps. It writes down the who, the what and the when, and it can block the ones you tell it to block.
- Least privilege
- Giving a person access to exactly what their job needs and nothing beyond it. The opposite of copying a colleague’s permissions. It sounds strict on day one and saves you the argument on day forty-one.
- Access review
- A short scheduled check where a manager looks at what one person can open and confirms they still need it. Fifteen minutes per new joiner at day thirty catches most of what an audit would find a year later.
- DaaS, or Device-as-a-Service
- Renting laptops instead of buying them. One monthly cost per device covers supply, support, replacement and a certified wipe when the machine comes back. It matters here because an unwiped returned laptop leaves the building with whatever the last user put on it, and nobody notices for months.
Questions the IT lead asked me that week
Can we monitor a new employee’s laptop without their consent under DPDP?
For employment purposes, yes, within limits. Section 7(i) of the DPDP Act 2023 treats employment as a legitimate use, which means consent is not the basis you rely on. The Act’s examples of what that covers are defensive and specific: safeguarding the employer from loss or liability, prevention of corporate espionage, maintenance of confidentiality of trade secrets and intellectual property, and classified information. Section 7 is a closed list, so the further your monitoring drifts from those purposes, the weaker your position gets. Scope it to company-owned devices and to the data categories that would actually cause loss, write down that scope, and tell employees about it at induction. A clause buried in an appointment letter does not widen the legal ground, and it makes the conversation worse if something ever goes wrong.
What access should a new joiner actually get on day one?
The access their role needs to do week one of the job, defined before they arrive and written against the role rather than against a colleague. In practice that means email, the collaboration suite, the one or two business systems their function uses, and the specific project folders they have been staffed on. It does not mean the department shared drive at its top level. The failure mode we see most often in Indian mid-market companies is an onboarding ticket that says same access as a named employee, which inherits every permission that person accumulated across previous roles. Build three or four role templates once, then use them. The afternoon it takes is the cheapest security work available to you.
We are 60 people with no IT team. What is the minimum here?
Four things, none of which needs a product. Keep a list of who has which device, by serial number. Write access lists per role instead of per person. Put a fifteen-minute day-30 access review in the hiring manager’s calendar as a recurring task. Close leaver accounts within the same week they leave, including any shared mailboxes or forwarding rules they set up. If you do only those four, you will be ahead of most companies twice your size. Buy monitoring when you have something a competitor would pay for, such as customer pricing, source code, formulations or a customer master, and not before.
Does a signed NDA cover us if a new hire takes data?
It gives you a contractual remedy after the fact. It does not stop the file moving, and under DPDP it does not discharge your own duty to have taken reasonable security safeguards over personal data you hold. Those are separate obligations with separate consequences. An NDA is what you take to a lawyer once the damage is known. Access scoping and data-movement monitoring are what mean you know about it in week one rather than in month four, when a client forwards you your own costing sheet. Most companies have the first and not the second, which is why the discovery almost always comes from outside the building.
Still deciding? These are the pages we send next.
The Coimbatore firm hired again in July. Sixteen people. The IT lead sent me a photo of the new checklist on his wall, and somebody had written the day-30 row in a different pen, larger than the rest, with a box drawn around it by hand. Theek hai. That box is worth more than the laminating.
Send us your last two quarters of joiners. We map what each one can open against what their role needs, and hand back the list of permissions nobody would grant on purpose.
Section numbering, the scope of legitimate uses and commencement dates above follow the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as they stood at the time of writing. Both can change, and the application of Section 7(i) to a specific monitoring programme depends on its scope. Confirm before relying on this. The Coimbatore engagement is one anonymised client matter and identifying details have been changed. This is a practitioner note on operating practice, not legal advice.






