‹ All sectors

Sector reference

DPDP for Contract Labour and Manpower Contractors

What is processed
The worker file that sits with the contractor, and the second copy that sits with the principal employer: identity documents, bank details, attendance, gate passes and wage registers for people who are on one payroll and inside somebody else's premises.

Why it is allowed, and when

This is the arrangement the split between fiduciary and processor was written for. Whoever decides the purpose and the means is the fiduciary. Where the contractor merely runs payroll and attendance to the principal's specification it is a processor, and there has to be a valid contract. Where the contractor decides matters for itself, it is a fiduciary in its own right and answers directly.

Where the permission stops

The principal cannot contract the duty away. A fiduciary is responsible for processing done on its behalf irrespective of any agreement to the contrary, so a clause making the contractor solely liable moves the commercial loss and nothing else.

Questions people actually ask

The contractor employs them, so why do we hold any duty?

Because you hold their data. Once identity documents, attendance, bank details or gate records for those workers sit in your systems, you are processing personal data about identifiable individuals, and the Act attaches to whoever determines the purpose and means.

Who signs the wage slip is a labour law question. It does not decide this one.

Our contract says the contractor is responsible for data protection. Is that enough?

No. A fiduciary is responsible for complying with the Act in respect of processing undertaken by it or on its behalf by a processor, irrespective of any agreement to the contrary. That phrase is in the Act precisely to stop this arrangement working.

The clause is still worth having, because it decides who bears the commercial loss. It just does not move the duty.

What does the contract with a manpower contractor actually have to contain?

A processor may only be engaged under a valid contract, so a verbal arrangement fails at the first step. The Rules then require that contract to carry appropriate provisions for taking reasonable security safeguards.

In practice it should also fix what the contractor may do with the data, name what happens on exit, and require the contractor to tell you immediately if anything is lost, because your reporting clock starts when you become aware.

Workers send us their identity documents on a messaging group. Is that a problem?

It is the most common one there is. That data is sitting with no access control you own, no encryption you can evidence, no log anyone reviews, and no realistic way to erase it later. The Rules set each of those out as a minimum.

It also makes a breach almost impossible to scope, because you cannot say who still holds a copy. If it goes wrong you owe an intimation to every affected worker and a detailed report to the Board within seventy two hours, and you will not be able to produce either.

What people get wrong

The contractor is a separate employer, so their workers' data is nothing to do with us.

The moment you hold identity documents, attendance or gate records for those workers, you are processing their personal data and you answer for it. Who signs their wages is a labour law question, not the test here.

Our agreement says the contractor is responsible for data protection.

You remain responsible irrespective of any agreement to the contrary. The clause decides who ends up paying. It does not decide who owes the duty, and the Board will not read it as though it did.

A verbal understanding with the contractor is enough.

Engaging a processor for any activity related to offering goods or services requires a valid contract, and the Rules require that contract to carry security provisions. A handshake satisfies neither.

Worker identity documents in a supervisors' messaging group is just how it gets done.

That is personal data sitting outside every safeguard the Rules require: no access control, no encryption, no log to review, and no realistic ability to erase. It is the most common way a working habit turns into a reportable breach.

Related questions

This sector sits inside the full Sector Reference, which covers 26 sectors and 160 questions. To work through your own organisation rather than the general case, the Template Builder starts from your answers.