This policy document forms Tech Mahindra’s Personal Data Privacy and Protection Policy. Compliance with this policy will ensure compliance with applicable data privacy laws, implementation of best practices related to data privacy and minimize risks to Personal Data that is used for Tech Mahindra’s business operations. This policy endeavors to fulfil various requirements for Data Privacy specified in laws and regulations such as the Information Technology Act 2000, the UK Data Protection Act 2018, EU General Data Protection Regulation (“GDPR”), UK General Data Protection Regulation (“UK GDPR”), California Consumer Privacy Act “CCPA”, Brazilian General Data Protection Law “LGPD” among others and the ISO 27701 certification and SOC 2 assurance standard.
The purpose of this policy is to define the requirements to safeguard Personal Data which includes Personal Information (“PI”) also known as Personally Identifiable Information (“PII”) and Sensitive Personal Information (“SPI”), as defined below, related to Tech Mahindra or any third party including its clients, vendors, etc. That is controlled, processed, transferred, imported, or exported by or to Tech Mahindra, on any system, portable device, and portable electronic storage media/cloud on or off Tech Mahindra premises, and the procedures to be followed to achieve these objectives. In addition, the aim is to ensure that anyone handling the Personal Data is fully aware of the data privacy and protection requirements and handles it in accordance with this policy.
The policy is designed to ensure that Personal Data related to Tech Mahindra Business operations will be processed in accordance with the rights of data subjects.
The policy has one of the objectives to inform its data controllers whose data is being processed by Tech Mahindra (including its customers) that Tech Mahindra’s processing of their Personal Data is and will be in accordance with applicable data privacy laws and regulations.
This policy must be read in conjunction with all other relevant Information Security policies, Data Security policies, customer privacy requirements (as applicable) and HR policies. Nothing in this policy shall supersede the provisions regarding Personal Data protection and privacy contained in the contractual documents signed by Tech Mahindra with its customers, Supplier’s, or any other data controllers for the protection of such Personal Data.
2 Scope
This policy is applicable for Personal Data processed as a part of business operations by Tech Mahindra. It covers Tech Mahindra’s role as a data controller and/or processor for personal data of associates, customers, Suppliers, visitors, nominees, referrals, third party suppliers etc.
3 Applicability
This policy is applicable to all:
Tech Mahindra Limited, India (Tech Mahindra/TechM) and all Affiliates of Tech Mahindra worldwide (except Portfolio Companies), including without limitation all their Business Units and associates who collect, store, access, process or in any other manner handle any Personal Data.
Associates who handle Personal Data in client environment.
All systems/applications including without limitation, AI/ML where processing of Personal Data is automated.
3rd party suppliers as indicated in the “Information Security Policy for Supplier Relationships” which is published on BMS on their in-country specific regulations and compliance on data privacy and protection.
Portfolio Companies that are independently governed will have their own Data Protection and Privacy policies.
4 Definitions
The terminologies used in the policy are defined below-
Affiliate – means any corporation, company, or other entity, which: (i) is Controlled by a party hereto; or controls a party hereto; or is under common Control with a party hereto. For this purpose and only in connection with the definition of Affiliate, “Control” means that more than fifty percent (50%) of the controlled entity’s shares or ownership interest representing the right to make decisions for such entity are owned or controlled, directly or indirectly, by the controlling entity.
Portfolio Companies – are the companies acquired by Tech Mahindra or any of its Affiliate/s or where Tech Mahindra or any of its Affiliate/s have invested in order to acquire any equity stake, unless such Portfolio Company/ies legally merge with Tech Mahindra or specifically adopt this policy and includes the companies or firms that are or will be acquired or invested by any of the Portfolio Companies.
Personal Data – means any information relating to an identified or identifiable natural person (Data Subject) and includes both Personal Information as well as Sensitive Personal Information.
Sensitive Personal Information (SPI) – Any personal information consisting of physical or mental health or condition of a data subject, ethnic origin, age, color, sexual orientation, genetic, religious beliefs, philosophical or political affiliations, trade union etc.
Personal Information (PI) – any Personal Data other than SPI.
Processing – Any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, access, viewing, disclosure, transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, and destruction.
Processing personal data is generally prohibited, unless it is expressly allowed by law, or the data subject has consented to the processing. While being one of the more well-known legal bases for processing personal data, consent is only one of six bases mentioned in the General Data Protection Regulation (GDPR). The others are contract, legal obligations, vital interests of the data subject, public interest and legitimate interest as stated in Article 6(1) GDPR.
Consent – Consent must be freely given, specific, informed, and unambiguous. To obtain freely given consent, it must be given on a voluntary basis. The element “free” implies a real choice by the data subject. Any element of inappropriate pressure or influence which could affect the outcome of that choice renders the consent invalid. For example, in an employer-employee relationship: The employee may worry that his refusal to consent may have severe negative consequences on his employment relationship, thus consent can only be a lawful basis for processing in a few exceptional circumstances.
Data Subject – identified or identifiable natural person[s].” In other words, data subjects are just people—human beings from whom or about whom Personal Data is collected and/or processed in connection with Tech Mahindra’s business and operations.
Data Subject Rights – rights that are provided to Data Subjects whose Personal Data is being used, collected, processed, or transferred. Tech Mahindra recognizes following Data Subject Rights:
Right to be informed
Right of access
Right to rectification
Right to restriction of Processing
Right to object
Right to object to automated profiling, processing and decision making
Right to be forgotten (erasure)
Right to data portability
Other rights – e, g, communication about Personal Data breach, withdrawal of consent, compensation
Data Controller means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
Data Processor – Natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Data Controller.
Data Exporter – The Data Controller who transfers Personal Data to other countries.
Onward Transfer – When an initial recipient (a data importer) passes the data to some other vendor or supplier.
Privacy Incident – A privacy incident is any event that has resulted in (or could result in) unauthorized use or disclosure of Personal Data where persons other than authorized users have access (or potential access) to Persona Data or use it for an unauthorized purpose.
Personal Data Breach – Personal Data breach is “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored or otherwise processed”.
Data Protection Officer – An independent internal or external person designated based on professional qualities and expert knowledge of data protection law and practices to fulfil the DPO tasks as listed in the DPO Function Charter.
Data Processing Agreement (DPA) – A DPA is a contract agreed upon by a Data Controller and Data Processor or Data Controller to set out the provisions applicable for Processing the Personal Data, nature and category of Personal Data, various safeguards, and measures to be followed in transferring or Processing Personal Data and such other relevant provisions.
Data Transfer Agreement (DTA) – is an agreement between the providing and recipient organizations that governs the legal obligations and restrictions, as well as compliance with applicable laws and regulations related to the transfer of Personal Data between the parties.
Website Privacy Policy – A document published on the website for people accessing the sites to explain how the organization handles any customer or associate’s information gathered during its operations, including handling of cookies.
Supplier – Is an enterprise that provides goods or services to Tech Mahindra in any form. Suppliers include service providers, third party personnel working in Tech Mahindra or client premises on behalf of Tech Mahindra, working from Supplier premises on behalf of Tech Mahindra, contractors, vendors, white labelled platform service providers.
AI – Artificial intelligence is the science and engineering of making computers behave in ways that require human intelligence.
ML – Machine learning is the study of computer algorithms that allow computer programs to automatically improve through experience.
Platform – Any hardware or software used to host an application or a service.
Business Unit (BU) –is a core process or set of activities carried out within an organization or in department for its internal business operations. (E.g., Marketing, Human Resources (HR), Resource Management Group (RMG), Technical Infrastructure Management (TIM), Information Security Group (ISG), Corporate Services (CS), Project Management Operations (PMO), among others.
Device – includes Laptops, Desktops, portable storage media devices.
5 DPO Function
The DPO Function comprises of Data Protection Officers and ISG Data Privacy team.
DPOs are appointed by the Management and wherever required by applicable law, formally registered with the appropriate data protection authorities. The role the DPO is described in DPO Function Charter and in brief includes working towards the compliance with all relevant data protection laws as well as collaborating with the supervisory authorities.
The Global DPO is supported by DPOs within countries or geographic regions across the world.
The DPOs are supported by the ISG Data Privacy.
The ISG Data Privacy team implements, monitors, and improves privacy compliance within Tech Mahindra. Seeks advise from DPOs or acts on their recommendations to improve compliance. The privacy office will be supported by privacy officers in each function. These privacy officers will be part of their respective functions. DPO will work with the Privacy Office to ensure that their recommendations are considered and appropriately implemented.
In light with guidance and recommendations provided by ISG, Tech Mahindra Business Units will implement in letter and spirit the Eight Core Principles of Data Privacy listed below through this policy and related procedures.
Personal Data shall be processed fairly and lawfully.
The purpose of collection and Processing of Personal Data is transparent, clear, informed, easy to understand and concise, and so is communicated to Data Subjects.
Personal Data shall be obtained only for one or more specified and lawful purposes and shall not be further Processed in any manner incompatible with that or those purposes.
Personal Data shall be limited to what is necessary that is adequate and relevant in relation to the purpose or purposes for which it is Processed.
Personal Data shall be accurate and, where necessary, kept up to date.
Personal Data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes, and strictly in accordance with Data Retention Policy.
Personal Data shall be processed in accordance with the Data Subjects Rights under the relevant Act.
Appropriate technical and organizational measures shall be ensured to avoid unauthorized or unlawful processing of Personal Data and accidental loss or destruction of, or damage to Personal Data.
7 Salient features of the Policy
This Policy and its procedures will comply with specified in laws and regulations such as the IT Act 2000, the UK Data Protection Act 2018, EU GDPR, CCPA, LGPD among others and be customized to suit to the extent possible the Data Privacy laws and regulations of the individual countries in which Tech Mahindra processes Personal Data.
Tech Mahindra Business operations will implement in letter and spirit the Eight Core Principles of Data Privacy listed above through this policy and related procedures.
The policy will be updated to accommodate new amendments to applicable laws / acts / judgments.
The policy will be reviewed on an annual basis for improvement and enhancement.
Associate’s Responsibilities:
All associates handling Personal Data related to Tech Mahindra Business operations must ensure processing in adherence to the Data Protection and Privacy Policies.
Associates shall use only authorized devices such as desktops, laptops, and login credentials to access Tech Mahindra and customer data.
Associates shall not access/use/store Personal Data obtained from third party sources for Tech Mahindra Business Operations without the consent of the respective Business/Function Head and Information Security Group (ISG) Business/Function Head shall consult Information Security Group (“ISG”), before processing/accessing any Personal Data.
Assets provided by Tech Mahindra, or its customers, must not be used for personal use.
Associates shall not download / store any Personal Data including their own Personal Data not related to Tech Mahindra business operations on either a Customer or Tech Mahindra provided device.
No associate can collect or use Personal Data on cloud services without authorization from ISG.
No associate can make personal use of Personal Data for any unauthorized purpose including without limitation, marketing, or promotions of any kind.
Associates shall comply with the privacy policy of customers while working within customer environment.
Data Processing:
All Processing of Personal Data will follow Eight Core Principles of Data Privacy.
All the Business Units will undergo a Privacy Impact Assessment in accordance with ISG instructions before the commencement of their respective projects/processes.
Privacy Impact Assessment and Record of Processing Activities will be re-initiated by every change in project/process where additional Personal Data processing is undertaken or bi-annually.
Risks identified during the Privacy Impact Assessment shall be promptly mitigated by respective Business Units in accordance with instructions of ISG.
All Business Units having access to Personal Data must maintain Record of Processing Activities (RoPA) in accordance with instructions from ISG.
Privacy by design guidelines shall be followed during any Personal Data Processing. (Refer to Privacy Control Checklist published on BMS).
All business operations where Data Processing is carried out using automated tools including / without limitation of AI/ML based systems and applications shall also follow Privacy by Design guidelines.
No Personal Data should be disclosed to unauthorized users.
Wherever required under the law, Personal Data must be Processed lawfully, fairly, transparently. In absence of lawful basis for collection or Processing of Personal Data, Business Unit must obtain consent of Data Subjects. In all other cases, Business Units must provide Privacy Notice to Data Subjects and keep this Privacy notice updated to comply with global data privacy requirements.
Signing of the Data Processing Agreement and ensuring appropriate data protection controls between customer/supplier is mandatory.
Personal Data collected via CCTV recordings will be in accordance with applicable laws in addition to Privacy Laws.
All Business Units that are processing Personal Data are to be audited annually by ISG team.
Data Confidentiality:
Tech Mahindra shall enter into a Non-Disclosure Agreement (NDA) with all associates prior to commencement of their employment.
Associates must abide by the Non-Disclosure Agreement (NDA) entered during employment with Tech Mahindra and in specific cases, with customers, by ensuring compliance to the privacy policy and its processes while processing Personal Data. (Refer to Code of Ethical Business Conduct published on BMS).
Data Protection Officer & Privacy Office:
Tech Mahindra will nominate Data Protection Officer/who will serve as the privacy point of contact for Data Subjects, associates, customers, and Supervisory Authorities and to provide privacy governance over Tech Mahindra’s business operations (Refer the DPO Function Charter published on BMS).
Tech Mahindra shall have privacy office for process execution and compliance as per Data privacy regulations. (Refer the DPO Function Charter published on BMS).
Data Protection Training and Awareness :
All associates, contractors and Affiliate’s associates must undergo mandatory annual data privacy trainings. In addition, people processing Personal Data will undergo role /function specific training.
Data Subject Requests:
All Data Subjects will be provided an easy-to-use facility to exercise their Data Subject Rights pertaining to their Personal Data that is collected, stored, or processed by Tech Mahindra.
Children’s Privacy:
Tech Mahindra Websites, its associated products or services and hosted contents, are not intended for the use by children.
As such Tech Mahindra should not knowingly solicit or collect personally identifiable information online from children without prior verifiable parental consent. If Tech Mahindra learns that a child has submitted personally identifiable information online without parental consent, it will take all reasonable measures to delete such information from its databases and to not use such information for any purpose, (except where necessary to protect the safety of the child or others as required or allowed by law).
Data Protection and Monitoring:
Personal Data must be protected via various privacy controls, and Technical; Organizational & Contractual measures (such as data encryption, anonymization, pseudonymization).
Access to Personal Data shall be provided only to authorized associates, with appropriate limited access controls, based on their roles and responsibilities.
Within the permitted limits of applicable laws, Tech Mahindra shall monitor associate business communication (email, chat, IP use) and use of IT systems (USB, Internet, File, and collaboration platforms) for data leakage, using a data leakage prevention tool in accordance with country’s law.
Tech Mahindra ISG team shall perform risk assessment periodically to ensure that any cybersecurity risks that can lead to are identified and remediated.
Data Transfer:
No cross-border transfer shall take place without compliance to the Data Exporter country’s privacy regulations, data transfer risk assessment, signing of the Data transfer agreement and ensuring appropriate data protection safeguards & controls including without limited implementing requisite additional measures.
Incident Reporting and Management:
Tech Mahindra has set-up a process to report Data Privacy incidents. (Refer to Information Security Incident Management policy published on BMS).
Associates must immediately report security and privacy incidents such as unauthorized access to Personal Data to ISG/DPO preferably using the Incident Management System. (https://isg.techmahindra.com/IMS/)
Tech Mahindra as a Data Processor will ensure that any Data Privacy Incident shall be communicated to respective Data Controller at the earliest and in any event within not more than 72 Hrs., provided that in case a different period is required under the applicable law or as agreed by Tech Mahindra in the Contract, Tech Mahindra shall follow such period.
Tech Mahindra as a Data Controller will ensure that any Data Privacy Incident shall be communicated to respective supervisory authorities in accordance with the applicable law.
Tech Mahindra has mandatory data privacy training to create awareness on security along with incident raising in the system. (Refer to Information Security Training and Awareness Policy published on BMS)
Disciplinary Actions:
Any violation of the Data Privacy Policy shall be dealt with appropriate disciplinary action. (Refer to HR Disciplinary Policy published on BMS).
Suppliers/Third parties:
Business Units shall onboard third-party suppliers based on principle and guidelines defined as per Supplier Relationships policy. (Refer to Information Security Policy for Supplier Relationships published on BMS).
All suppliers shall be vetted using the Information Security Policy for Supplier Relationships which will include privacy checks. Refer to the above link for more details.
All functions with prior clearance from ISG, and subject to Data Protection Impact Assessment (“DPIA”) and maintaining Record of Processing (“RoP”) shall sign a Data Processing Agreement with the Suppliers who are processing the Personal Data.
All functions shall sign a Data Transfer Agreement in case of Cross Border transfer of Personal Data to Supplier/subsidiaries or/and within organization. Also, the functions shall monitor any onward transfer and check similar compliance with reference to such onward transfer.
All third-party agreements must include “right to audit” clauses, to mandate Supplier compliance as per country specific data protection laws and regulations along with this policy. Any exception from this must be documented and approved by customer or Tech Mahindra as the case may be. This should be subject to prior communication with respective Regional General Counsel, RMG Head and other relevant functions.
Supplier risk assessment shall be conducted for existing supplier in regular interval/minimum annually and new supplier shall be assessed during onboarding process Third as indicated in the ‘Information Security Policy for Supplier Relationships’
Handling of hardcopies:
Business Units must disable print access for the associates who handle Personal Data to restrict the creation of hardcopies.
Hardcopy Information must not be left unattended unless stored in a suitable locked container in a secure area.
Printouts containing Personal Data should be immediately removed from the printer.
Upon disposal, classified documents should be shredded in the official shredder bins. (Refer to Equipment and Media Handling Policy published on BMS).
8 Detailed Policy
The detailed policy related aspects of the high-level policy to specific implementation or policy actions under the three data processing scenarios in the ‘Scope’ section. The detailed policy is to be read in conjunction with the High-level policy.
Tech Mahindra as a Data controller and Processor for Personal Data of associates, Suppliers, visitors, nominees, referrals, third party suppliers:
Business Units processing Personal Data of associates and Customers, and Suppliers shall check and comply with all the statutory requirements such as contractual arrangement, privacy notice, consent requirement as the case may be in accordance with instructions and approval of ISG. For Personal Data Processing Requests Business Units shall take prior approval from ISG.
In consonance of data minimization principle, only such data will be collected and/or processed that is mandatory for the purpose for which it is collected and/or processed. There shall be reasonable endeavor to always keep the data up to date and accurate.
Where there is legal basis and lawful purpose for Processing Personal Data, Privacy notice in pre-approved appropriate standard format published on BMS shall be given (and amended from time to time in case of any changes required) to all the Data Subjects for whose Personal Data Tech Mahindra acts as Data Controller. For applications or processes not covered under the worker privacy notice, a specific privacy notice will need to be created and sent to all the respective or affected Data Subjects.
Personal Data access shall only be granted to the extent and only if required for performance of duties for the business operations of the Company. Where possible the system shall control rights (read/write/execute) and mask data elements not required for the role.
Personal Data shall be only stored on Tech Mahindra owned/leased/loaned Devices such as desktops, laptops and storage media which are encrypted. Use of portable storage media will only be allowed on an exception basis for a valid business requirement after approval by both the Business Unit Head and ISG. In case any such portable storage media is used, it shall not be used for copying Personal Data, unless there is no other alternative available. In such case, specific intimation must be given to ISG, and such portable storage media must be submitted to ISG first, which must be duly encrypted. Any such portable storage media must be kept in highly secure manner, accessible to only limited and defined senior associates of Tech Mahindra, location of such media must be documented and shall not be varied unless approved by ISG and any Personal Data on such media shall be immediately removed upon completion of the purpose, while ensuring that such Personal Data has been copied on other Tech Mahindra owned or leased Devices.
Personal Data shall be stored in designated and approved applications/databases/file folders. Applications/database/file server which store Personal Data shall be kept in approved and secured data centers. No Personal Data shall be stored, copied, transmitted, transferred, deleted, or migrated unless required for a valid Business purpose and authorized by the respective BU Head and ISG.
Personal Data collected shall not be retained for a period longer than required for its lawful use or otherwise required by any other law for the time being in force and shall be in line with the Data Retention policies published on BMS. Assets containing Personal Data shall be classified and protected as per Tech Mahindra's Information and Asset Classification Policy The associates shall be provided with a facility to raise requests to exercise their Data Subject Rights via helpdesk or any other equivalent system.
Refer to Data Subjects Rights Procedure – Associates in BMS Every Business Unit having access to Personal Data must document and maintain Record of Processing Activities (ROPA) in line with ISG instructions. They shall maintain an inventory and access control matrix specifying access policy based on roles, responsibilities, and business requirements.
In case of any Data Privacy Incident, the incident must be immediately reported to Tech Mahindra Incident Management System. (https://isg.techmahindra.com/IMS/).
Please refer to Data Privacy - Personal Incident Response Plan in BMS Business Units must ensure that all Suppliers which process associate Personal Data must comply with the policy requirements as specified under the section ‘Suppliers/Third Parties’ in this Policy.
Tech Mahindra as a Data Controller and Processor for its associates’ Personal Data on Tech Mahindra’s own platform and services:
Business Units collecting associates’ Personal Data shall ensure compliance with respective regulatory requirements in accordance with prior instructions and approvals from ISG.
The Personal Data collected shall be the minimum to suffice the business purpose for which it is processed. There shall be a process to ensure that data collected is accurate, and up to date.
Business Unit that Processes Personal Data of its associates shall do it fairly and transparently, it must be stored and saved with proper measures as suggested by ISG.
Personal Data access shall only be granted as required for performance of a defined role. Where possible the system shall control rights (read/write/execute) and mask data elements not required for the role.
Personal Data shall only be stored on Tech Mahindra owned/leased/loaned Devices such as desktops, laptops and storage media which are encrypted. Use of portable storage media will only be allowed on an exception basis for a valid business requirement after approval by both the Business Unit head and ISG. In case any such portable storage media is used, it shall not be used for copying Personal Data, unless there is no other alternative available. In such case, specific intimation must be given to ISG, and such portable storage media must be submitted to ISG first, which must be duly encrypted. Any such portable storage media must be kept in highly secure manner, accessible to only limited and defined senior associates of Tech Mahindra, location of such media must be documented and shall not be varied unless approved by ISG and any Personal Data on such media shall be immediately removed upon completion of the purpose, while ensuring that such Personal Data has been copied on other Tech Mahindra owned or leased Devices. (Refer to Work Instruction for Media Handling and Asset Disposal published on BMS).
Personal Data shall be stored in designated and approved applications/databases/file folders. Applications/database/file server which store Personal Data shall be kept in approved and secured data centers. No Personal Data shall be stored, copied, transmitted, transferred, deleted, or migrated unless required for a valid Business purpose and authorized by the respective Business Unit Head and ISG.
Personal Data shall be classified and protected as per Tech Mahindra’s Information and Asset Classification Policy.
Personal Data collected shall not be retained for a period longer than required for its lawful use or otherwise required by any other law applicable and shall be in line with the Data Retention Policy agreed with customer.
Business Units to ensure that the applications integrated with third parties, federated systems using APIs or Web Services shall use encrypted channels to process and transmit Personal Data.
Every Business Unit having access to Personal Data must document and maintain Record of Processing Activities (ROPA) in accordance with instructions from ISG. They shall maintain an inventory and access control matrix specifying access policy based on roles, responsibilities, and business requirements.
In case of any Privacy Incident, the incident must be immediately reported to Tech Mahindra Incident Management System. https://isg.techmahindra.com/IMS/
Business Units must ensure that all Suppliers that process Tech Mahindra associates Personal Data must comply with the policy requirements as specified under the section Suppliers/Third Parties in the High-Level policy.
Tech Mahindra as a Data Processor on behalf of Tech Mahindra’s customers:
Business Units shall ensure that Customer, as a Data Controller, wherever mandatory by law, are committed to follow requisite compliances including without limitation obtaining necessary consents from Data Subjects to enable Tech Mahindra to process Personal Data on their behalf.
The Personal Data collected shall be minimum and accurate, only to be used for the purpose for which it is authorized, and data must be kept up to date. Business units shall have a Data Processing Agreement in place with customers that defines the processing details of Personal Data.
Personal Data access shall only be granted as required for performance of a defined role. Where possible the system shall control rights (read/write/execute) and mask data elements not required for the role.
Personal Data shall only be stored on Tech Mahindra owned/leased/loaned devices such as desktops, laptops and storage media which are encrypted. Use of portable storage media will only be allowed on an exception basis for a valid business requirement after approval by both the Business Unit head and ISG. In case any such portable storage media is used, it shall not be used for copying Personal Data, unless there is no other alternative available. In such case, specific intimation must be given to ISG, and such portable storage media must be submitted to ISG first, which must be duly encrypted. Any such portable storage media must be kept in highly secure manner, accessible to only limited and defined senior associates of Tech Mahindra, location of such media must be documented and shall not be varied unless approved by ISG and any Personal Data on such media shall be immediately removed upon completion of the purpose, while ensuring that such Personal Data has been copied on other Tech Mahindra owned or leased Devices. (Refer to Work Instruction for Media Handling and Asset Disposal published on BMS).
Personal Data shall be stored in designated and approved applications/databases/file folders. Applications/database/file server which store Personal Data shall be kept in approved and secured data centers. No Personal Data shall be stored, copied, transmitted, transferred, deleted, or migrated unless required for a valid Business purpose and authorized by the respective Business Unit Head and ISG.
Personal Data shall be classified as per Tech Mahindra Information and asset classification policy or customer’s data classification policy, and all associates working with the project must be aware and follow the same. Refer to Information and Asset Classification Policy published on BMS.
Business Units shall ensure that the applications integrated with third parties shall use encrypted channels to process and transmit Personal Data.
Every Business Unit having access to Personal Data must document and maintain Record of Processing Activities (ROPA) in accordance with ISG instructions. They shall maintain an inventory and access control matrix specifying access policy based on roles, responsibilities, and business requirements.
In case of any Privacy Incident, without disclosing it to any third party, the incident must be immediately reported to Tech Mahindra Incident Management System. https://isg.techmahindra.com/IMS/
Business Units must ensure that all Tech Mahindra Suppliers that process customer Personal Data must comply with the policy requirements as specified under the section Suppliers/Third Parties in the High-Level policy.
Data Privacy Compliance for Internal and External applications:
S.No.
Internal Applications
External Applications
1
PIA and ROPA
Yes
Yes
2
Privacy Policy
NA
Yes
3
Terms and conditions
NA
Yes
4
Consent
NA
Yes
5
Cookie Policy
NA
Yes
Note:
For External Applications: PIA and ROPA, Privacy Policy, Consent and Cookie Policy are mandatory.
For Internal Applications: PIA and ROPA are essential, however Privacy Policy, consent and cookie policy are not required.
Internal applications may use cookies and similar technologies for:
Session management (e.g., authentication tokens), Usage analytics (to improve user experience and system performance) and security monitoring.
Types of cookies used:
Strictly Necessary Cookies: Required for operation (e.g., login) Performance Cookies: To track usage patterns internally (No marketing or third-party tracking cookies are used in internal applications)
9 References
#
Document ID
Owner (s)
Description of the Document
1
ISG-PO004
Information Security Group
Acceptable Usage Policy
2
ISG-PO000
Information Security Group
Information Security Policy
3
ISG-PO013
Information Security Group
Information and Asset Classification Policy
4
ISG-PO020
Information Security Group
Network Security Policy
5
ISG-PO007
Information Security Group
Compliance Policy
6
ISG-PO003
Information Security Group
Information Security Incident Management Policy
7
ISG-GL027
Information Security Group
Guidelines to Teleworking Document
8
HR-PO718
Human Resource
Whistleblower Policy
9
HR-PO860
Human Resource
Data Retention Policy Belgium
10
HR-PO861
Human Resource
Data Retention Policy Denmark
11
HR-PO865
Human Resource
Data Retention Policy France
12
HR-PO862
Human Resource
Data Retention Policy Hungary
13
HR-PO863
Human Resource
Data Retention Policy Netherlands
14
HR-PO864
Human Resource
Data Retention Policy Sweden
15
HR-PO866
Human Resource
Data Retention Policy Switzerland
16
HR-PO895
Human Resource
Data Retention Policy Germany-Bilingual
17
ISG-PR018
Information Security Group
Data Privacy and Protection Management Framework
18
ISG-FM001
Information Security Group
DPO Function Charter
19
ISG-CL016
Information Security Group
Privacy Control Checklist
20
ISG-PO032
Information Security Group
Information Security Policy for Supplier Relationships
21
HR-PO726
Human Resource
Disciplinary Policy
10 Glossary
#
Activity
PI
Personal Information
PII
Personally, Identifiable Information
SPI
Sensitive Personal Information
IPR
Intellectual Property Rights
ISG
Information Security Group
LSM
Location Security Manager
SAN
Storage Area Network
TUPE
Transfer of Undertakings (Protection of Employment) Regulations 2006 (UK Labor law)
DTA
Data Transfer Agreement
GDPR
General Data Protection Regulation
DPA
Data Processing Agreement
DPO
Data Privacy Officer (or Data Protection Officer or equivalent)
SCC
Standard Contractual Clauses
BCR
Binding Corporate Rules
ISO
International Organization for Standardization
APP
Australian Privacy Principles
11 Annexure C: Examples of PII / SPII
Personal Data - or Personal Information (PI) – (also known as Personally Identifiable Information - PII)
Any information that, when used alone or combined with other data, may be used to identify a living or deceased individual. This includes, but is not limited to:
An individual’s first and last name
An individual’s Internet ID (not necessary his/her name)
E-mail address
Mailing and/or residential addresses,
Telephone number
Title,
Birth date
Gender
Occupation
Contact information
Biographical information (Retina, Fingerprint, Face, Handwriting) where it is combined with information that identifies someone).
Personal Data (PII / SPI) stored through official email or messaging channel.
Employee ID
Password, (note even if applicable law may not categorize passwords as sensitive Tech Mahindra does and you shall treat them accordingly)
Sensitive Personal Information (SPI) - means any personal information like:
National insurance number
Social security numbers (Aadhar Card Number)
PAN Card Number
Race
Ethnic origin
Sexual orientation
Political opinions
Religious or philosophical beliefs
Trade union memberships that contain individual’s health-related records (e.g. patient records, medical photographs, diet information, hospital information records, biological traits, and genetic material)
Criminal records
Legal investigations and proceedings, etc.
Billing records and subscriber information
Financial information such as credit card or bank information
Health care and medical records
Biometric records
Passport Number
Driving license number
Visa Permit Number
Vehicle Registration Number.
Salary
Credit Score
Photo
Security Token
Cookies
Session Id i.e. JSESSIONID
IP Address
MSISDN Number
Hardware serial number
12 Annexure D: Few of the provisions of Data Protection laws from various geographies:
Without limitation salient points of GDPR (EEA):
Tech Mahindra and its Affiliates need to collect and use certain information about individuals to run their businesses effectively As per GDPR the Data Subject must be a natural person (living only).
The GDPR applies,
to companies which are Processing Personal Data or special categories of Personal Data of Data Subjects in European Economic Area (EEA)
to all companies in Europe where it is Processing Personal Data of Data Subjects (regardless of their nationality)
to all companies, worldwide, which are Processing Personal Data of Data Subjects who are covered under GDPR or to whom GDPR is applicable (regardless of whether the Processing takes place within EEA or not)
In the case of a Personal Data Incident, Tech Mahindra or its concerned Affiliate/s (in case of Data Controller) shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the Personal Data Incident to the supervisory authority competent in accordance with Article 55 in the GDPR, unless the Personal Data Incident is unlikely to result in a risk to the Data Subject Rights. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.
13 Annexure F: Without limitation, salient points of Australia (APP)
Definition of Personal Data: Information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether the information or opinion is recorded in a material form or not.
Tech Mahindra is exempt from the act while handling employee records in relation to current and former employment relationships.
If Tech Mahindra refuses to correct personal information requested by an individual and the individual requests to associate a statement with the information that the information is inaccurate, out-of-date, incomplete, irrelevant, or misleading, Tech Mahindra shall undertake necessary actions to do so.
Further, while informing the individual about refusal to correct the requested personal information, Tech Mahindra shall provide any other information prescribed by the regulations (Privacy Regulations issued under the Privacy Act by the Governor-General) along with reasons for refusal and complain mechanism.
Tech Mahindra shall make a written note of the use or disclosure if Tech Mahindra uses or discloses personal information because it reasonably believes that the use or disclosure of the information is reasonably necessary for one or more enforcement related activities conducted by, or on behalf of, an enforcement body,
Tech Mahindra shall perform cross-border transfer of personal information only in accordance with APP 8, such as ensuring that the overseas recipient does not breach the provisions of this Act, or if the disclosure is required or author
About Tech Mahindra
Tech Mahindra (NSE: TECHM) offers technology consulting and digital solutions to global enterprises across industries, enabling transformative scale at unparalleled speed. With 152,000+ professionals across 90+ countries helping 1100+ clients, Tech Mahindra provides a full spectrum of services including consulting, information technology, enterprise applications, business process services, engineering services, network services, customer experience & design, AI & analytics, and cloud & infrastructure services. It is the first Indian company in the world to have been awarded the Sustainable Markets Initiative’s Terra Carta Seal, which recognizes global companies that are actively leading the charge to create a climate and nature-positive future. Tech Mahindra is part of the Mahindra Group, founded in 1945, one of the largest and most admired multinational federation of companies.
Get in touch with us
Get in touch wth our dedicated team of experts today and experience the Altavec Advantage