Skip to main content
GullySystem

How to Secure Customer and Employee Data

By Ganesh HS, Strategy and Technology, GullySystem

Securing personal data starts with knowing what you actually hold and minimising what is unnecessary, then controlling who can access it and for how long, protecting it in transit and storage, reviewing vendors with access to it, and preparing for incidents and data-subject requests — with India's evolving DPDP framework reviewed by a qualified adviser for your specific obligations.

Inventory Personal Data and Minimise What You Collect

Most SMBs collect more personal data than they actively use — fields added to a form years ago "just in case," employee documents kept indefinitely after someone leaves, customer data retained long after the reason for collecting it has passed. The starting point is a straightforward inventory: what personal data exists, where it lives, and why it is actually needed.

Minimisation follows naturally from that inventory: if a field or a record is not genuinely needed for the business to operate, removing it removes the risk that comes with holding it. This is not only good security practice — it directly reduces exposure if a system is ever compromised, since data that was never collected cannot be exposed.

Define Access, Retention and Approved Sharing

Once the inventory exists, define who should actually have access to each category of personal data — customer contact details, payment information, employee records — and limit it to roles that genuinely need it, the same principle behind role-based access control applied specifically to personal data.

Retention should be a deliberate decision too: how long is a category of data actually needed before it can be safely deleted or archived, rather than kept indefinitely by default because nobody set a rule. Sharing personal data outside the business — with a vendor, a partner, a marketing tool — should go through an approved, reviewed process, not an ad hoc export whenever it seems convenient.

Protect Data in Transit, Storage, Exports and Backups

Personal data should be encrypted while it travels between systems and while it sits in storage, and access to backups deserves the same scrutiny as access to the live system — a backup is a full copy of the same sensitive data, and is sometimes protected less carefully simply because it is less visible day to day.

Exports are a particular risk point worth naming directly: a spreadsheet pulled out of the system for a one-off analysis, then emailed around or left on a personal laptop, can outlive every control that protects the original system. Imagine a mid-sized manufacturer's HR team exporting the full employee list to build a festival bonus spreadsheet — useful in the moment, but a copy that, once created, needs its own access and deletion plan or it simply becomes an unmanaged risk sitting outside the system that was actually secured.

Plan for Vendor Review, Incidents and User Requests

Any vendor or contractor with access to personal data — a payroll processor, a marketing platform, an outsourced support team — should be reviewed for how they handle it before access is granted, not assumed to be safe because the relationship is otherwise trusted. This review does not need to be elaborate for a small vendor relationship, but it should happen and be documented.

An incident response plan — what happens the moment a data exposure is suspected, who is told, how quickly — is worth preparing before it is needed, since decisions made calmly in advance are consistently better than ones made under pressure during an actual incident. The same applies to individual requests — a customer or employee asking what data is held about them, or asking for it to be corrected or deleted — which are becoming a more concrete operational expectation under India's evolving personal data protection framework and are easier to handle with a defined process than improvised each time.

Have Applicable Obligations Reviewed by Qualified Advisers

India's Digital Personal Data Protection Act, 2023 and its accompanying Rules were notified by the Ministry of Electronics and Information Technology in November 2025, with substantive compliance obligations for data fiduciaries phasing in over roughly eighteen months from that notification date — meaning the specific, binding requirements that apply to a given business depend on timing and on how that business actually processes personal data.

This article describes general, sensible practices, not a compliance verdict for any specific business — whether a particular SMB qualifies as a data fiduciary under the Act, what specific consent and notice obligations apply, and what the compliance timeline means for its own systems are questions that should be reviewed with a qualified legal adviser, not settled from a blog article.

Personal-data lifecycle controls

A lifecycle diagram — collect, store, use, share, retain, delete — with the relevant controls named at each stage: minimisation at collection, encryption and access limits at storage, approval at sharing, a defined retention period, and a documented deletion process, used as a working reference rather than a compliance certificate.

Frequently asked questions

Who should access employee records?

Only the roles that genuinely need them for their job — typically HR and direct management — rather than the broader access general administrators often accumulate by default. Sensitive fields like salary or medical information warrant even narrower access than the employee record as a whole.

How do we handle exported spreadsheets?

Treat an export as a new copy of sensitive data that needs its own access control and a deletion date, not as a disposable working file. Where practical, limit who can perform bulk exports in the first place, and require a stated business reason for any export that includes personal data.

Next step

Have a specific situation to work through?

This article covers the general case. Tell us what you're actually dealing with and we'll respond directly.

Discuss Your Requirement