DPDP Act 2023 and Rented Laptops
A practical guide for companies in India that rent laptops: how the Digital Personal Data Protection Act, 2023 changes vendor due diligence, what your agreement should say, and how returned laptops should be wiped. This is general guidance, not legal advice.
What the DPDP Act 2023 does
The Digital Personal Data Protection Act, 2023 is India's first comprehensive personal data law. It applies to digital personal data processed in India, and to processing outside India connected with offering goods or services to people in India. It creates two main roles — the Data Fiduciary, which decides why and how personal data is processed, and the Data Processor, which processes it on the Fiduciary's behalf — and an oversight body, the Data Protection Board of India.
For a company that rents laptops, this means your company is the Data Fiduciary for the personal data those laptops hold: employee email, HR records, and customer data your teams work with. When a laptop comes back to the rental vendor with that data still on it, the vendor is handling it on your behalf until it is erased.
Where rented laptops meet the Act
- Handing a laptop to an employee. Your existing employment notice usually covers processing for employment purposes.
- Erasure when the purpose ends. Personal data should be erased once it is no longer needed and no law requires you to keep it. That applies to the laptop when an employee leaves or the rental ends.
- The vendor's handling at return. The vendor should handle the data only on your instructions and only to erase it. Your agreement is where you write that down.
- Evidence of erasure. A per-device wipe certificate is the record that shows erasure happened.
What your agreement with a rental vendor should say
- Purpose limitation. Data on returned devices is handled only to erase it — never copied, analysed or reused.
- Wiping standard. Name it — for example "NIST SP 800-88, Clear, Purge or Destroy as appropriate to the media" — and require a per-device certificate.
- Incident notice. How quickly the vendor must tell you about any incident affecting your data. Notifying the Board remains your duty as Data Fiduciary.
- Third parties. Whether couriers or recyclers handle your devices, and what they must do.
- Retention. How long wipe records are kept, and that no customer data is kept after wiping.
What Techvity does
Every returned or bought-back device is wiped to NIST SP 800-88 before it is reused or resold, and a per-device certificate is available on request. Tell us what your agreement needs to say about data handling and we will confirm in writing what we can commit to.
Penalties and why they matter for vendors
The Data Protection Board can impose penalties of up to ₹250 crore for certain failures, including failing to take reasonable security safeguards. For rented laptops the practical point is that you cannot point to the vendor and say "they had it": you remain the Data Fiduciary and need to show that you put reasonable contractual and technical controls in place. A clear agreement and per-device wipe certificates are that evidence.
Practical next steps
- Map your laptops: which roles, which kinds of personal data, which retention rules.
- Put the clauses above into your agreement before the next batch of laptops comes back.
- Include the vendor in your incident-response drill.
- File wipe certificates against your asset register.
- Review the arrangement each year as the Rules and the Board's practice develop.
Frequently asked questions
Does the DPDP Act 2023 apply to laptops rented from a vendor?
Yes, indirectly. The Act regulates personal data, not hardware. If a rented laptop holds personal data (of employees or customers), the company renting it is the Data Fiduciary, and a vendor that handles the returned laptop acts on the company's behalf. Both should treat the data carefully until it is erased.
What should an agreement with a laptop rental vendor say about data?
That the vendor handles personal data on returned devices only to erase it; the wiping standard, by name (for example NIST SP 800-88); a per-device certificate after wiping; how quickly the vendor tells you about an incident affecting your data; and that data is not transferred or reused. Your legal team decides the exact wording.
What does Techvity do with personal data on returned laptops?
Every returned or bought-back device is wiped to NIST SP 800-88 before it is reused or resold, and a per-device certificate is available on request. We handle the data on a returned device only to erase it.
Who notifies the Data Protection Board in case of a breach?
The Data Fiduciary — the company that decided why and how the personal data is processed. That is why your agreement with any vendor should say how quickly the vendor must tell you about an incident, so you can meet your own notification duties.
Are there special rules for children's or employees' data?
The Act gives children's personal data extra protection (verifiable parental consent and no behavioural tracking). Employee data can be processed for employment purposes as a legitimate use, but purpose limitation, accuracy and erasure obligations still apply, so laptops used for HR work need the same end-of-life care.
References
- Digital Personal Data Protection Act, 2023 — Government of India, Ministry of Electronics and Information Technology (MeitY).
- NIST Special Publication 800-88 — Guidelines for Media Sanitization.
Related: DPDP Act checklist for laptop fleets and what a wipe certificate contains.
