ISO 27001
Information Security Management
DPDP Act 2023
India Data Protection Law
GDPR
EU Data Protection Regulation
IT Act 2000
India Information Technology Act
Anti-Bribery
Prevention of Corruption Act
SOC 2 Type II
Security & Availability Trust
1. Overview
Infrasys Limited ("Infrasys", "we", "us", or "our") is a public IT services and consulting company founded in 2016, headquartered at Spaze Itech Park, Sector 49, Gurgaon, Haryana 122018, India. We operate across 6+ countries, serving enterprises in energy, finance, manufacturing, healthcare, telecom, logistics, and government sectors.
This Compliance Statement outlines the regulatory frameworks, standards, and internal policies we adhere to in the conduct of our business. It applies to all Infrasys employees, contractors, consultants, and partners acting on our behalf.
Our compliance programme is not a checkbox exercise. It is embedded into how we hire, how we deliver, how we handle data, and how we engage with clients, vendors, and regulators. We believe that integrity and compliance are prerequisites for sustainable business growth.
Our compliance obligations are overseen by our internal Legal & Compliance function, with ultimate accountability resting with our Board of Directors and senior leadership team.
2. Regulatory Frameworks We Operate Under
As a global IT services company, Infrasys is subject to multiple regulatory frameworks depending on the country of operation, the nature of the service, and the type of data being handled.
| Framework / Law |
Jurisdiction |
Relevance |
Status |
| Digital Personal Data Protection Act 2023 (DPDP) |
India |
Governs all personal data processed in India or relating to Indian citizens |
Active |
| Information Technology Act 2000 (IT Act) |
India |
Covers electronic records, cybercrime, intermediary liability and data security |
Active |
| General Data Protection Regulation (GDPR) |
European Union |
Applies when processing personal data of EU residents in our UK / EU engagements |
Active |
| ISO/IEC 27001:2022 |
International |
Information Security Management System (ISMS) framework |
Active |
| SOC 2 Type II |
USA / International |
Security, availability, and confidentiality controls for cloud-hosted services |
In Progress |
| Prevention of Corruption Act 1988 |
India |
Anti-bribery and corruption compliance for all public and private sector dealings |
Active |
| UK Bribery Act 2010 |
United Kingdom |
Applies to our UK-based client engagements and UK-resident employees |
Active |
| Companies Act 2013 |
India |
Corporate governance, financial reporting, and director obligations |
Active |
| HIPAA (Health Insurance Portability and Accountability Act) |
USA |
Applies when handling Protected Health Information (PHI) for US healthcare clients |
Active |
3. Data Protection Principles
Infrasys processes personal data in accordance with the following core data protection principles, which apply across all our global operations regardless of local law:
- Lawfulness, Fairness & Transparency: We only process personal data with a valid legal basis and communicate clearly with individuals about how their data is used.
- Purpose Limitation: Personal data is collected for specified, explicit, and legitimate purposes and not processed in ways incompatible with those purposes.
- Data Minimisation: We collect only the personal data that is necessary for the stated purpose — no more.
- Accuracy: We maintain reasonable steps to ensure personal data is accurate and kept up to date.
- Storage Limitation: Personal data is retained only for as long as necessary, in line with our Data Retention Policy.
- Integrity & Confidentiality: We process personal data in a manner that ensures appropriate security, including protection against unauthorised access, accidental loss, destruction or damage.
- Accountability: We are responsible for compliance and can demonstrate it through documentation, training, and governance processes.
4. ISO & Security Standards
Infrasys aligns its internal security and operational processes with internationally recognised standards to provide clients with confidence in our delivery capabilities.
ISO/IEC 27001 — Information Security Management
Our Information Security Management System (ISMS) is designed in accordance with ISO/IEC 27001:2022. This includes:
- Risk assessment and treatment processes for all information assets
- Access control policies — role-based, least-privilege access across all systems
- Physical and environmental security controls for office and co-located infrastructure
- Supplier security assessments and contractual security obligations
- Regular internal audits and management reviews of security controls
- Incident management procedures including detection, containment, and root cause analysis
ISO/IEC 27701 — Privacy Information Management
As an extension of ISO 27001, we have implemented privacy controls aligned with ISO 27701 to govern the processing of Personally Identifiable Information (PII) across our systems and those we manage on behalf of clients.
Cloud Security (CSP Compliance)
When delivering cloud-based services on AWS, Azure, or Google Cloud, we operate within the Shared Responsibility Model. Our engineers are trained on each platform's compliance certifications including:
- AWS — ISO 27001, SOC 1/2/3, PCI DSS, HIPAA BAA eligible
- Microsoft Azure — ISO 27001, GDPR, SOC 2, FedRAMP (relevant to US clients)
- Google Cloud — ISO 27001, SOC 2/3, GDPR, HIPAA BAA eligible
5. GDPR Compliance
Where Infrasys processes personal data of individuals located in the European Union or United Kingdom, we comply fully with the General Data Protection Regulation (GDPR) and UK GDPR respectively.
Our GDPR Roles
- Data Controller: For personal data we collect directly (e.g. website visitors, newsletter subscribers, job applicants, client contact data)
- Data Processor: When processing personal data on behalf of our clients as part of a service engagement — governed by a Data Processing Agreement (DPA)
Legal Bases for Processing (GDPR Art. 6)
- Consent — for marketing communications and newsletter subscriptions
- Contract — for delivering agreed professional services
- Legitimate Interests — for client relationship management and fraud prevention
- Legal Obligation — for tax records, employment law, and regulatory reporting
Data Subject Rights Under GDPR
EU and UK data subjects have the right to: access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and objection to processing. Requests can be submitted to info@infrasys.tech and will be fulfilled within 30 days.
International Data Transfers
Where personal data of EU/UK data subjects is transferred outside the EEA, Infrasys ensures appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, and adequacy assessments where applicable.
6. India DPDP Act 2023
Infrasys is fully committed to compliance with India's Digital Personal Data Protection Act 2023 (DPDP Act), which governs the processing of digital personal data within India and personal data collected in India even if processed abroad.
Key Obligations We Fulfil
- Consent-Based Processing: We obtain free, specific, informed, and unambiguous consent before processing personal data, except where a legitimate use applies.
- Purpose Limitation: Data is processed only for the purpose for which consent was given.
- Data Minimisation: We collect only data that is necessary for the specified purpose.
- Accuracy: We maintain mechanisms to correct inaccurate personal data on request.
- Security Safeguards: We implement reasonable security measures to prevent personal data breach.
- Breach Notification: In the event of a personal data breach, we will notify the Data Protection Board of India and affected data principals as required by law.
- Grievance Redressal: Individuals can raise grievances through our designated Grievance Officer (contact details in Section 14).
- Data Fiduciary Obligations: As a Data Fiduciary, Infrasys takes full responsibility for decisions relating to the purpose and means of processing personal data.
Rights of Data Principals Under DPDP Act
- Right to access information about personal data being processed
- Right to correction and erasure of inaccurate or unnecessary data
- Right to grievance redressal through our Grievance Officer
- Right to nominate a person to exercise rights in the event of incapacity or death
7. Client Data Handling
When Infrasys processes data on behalf of a client in the course of a professional services engagement, we operate as a Data Processor. Our obligations include:
- Processing client data only on documented instructions from the client (Data Controller)
- Ensuring all persons authorised to process the data are bound by confidentiality obligations
- Implementing appropriate technical and organisational security measures
- Not engaging sub-processors without prior written authorisation from the client
- Assisting the client in fulfilling data subject rights requests and breach notification obligations
- Deleting or returning all personal data upon termination of the engagement, unless retention is required by law
- Providing all information necessary to demonstrate compliance and cooperating with audits
All client engagements involving personal data processing are governed by a formal Data Processing Agreement (DPA), which is available as a standard exhibit to our Master Service Agreement (MSA).
Data Classification
All data processed by Infrasys — whether internal or on behalf of clients — is classified into four tiers:
- Public: Information approved for public release (e.g. marketing content, published case studies)
- Internal: Non-sensitive business data accessible to employees on a need-to-know basis
- Confidential: Sensitive business data including client information, contracts, financial records, and personal data
- Restricted: Highly sensitive data including health records, financial credentials, and security configurations — access tightly controlled
8. Vendor & Supply Chain Compliance
Infrasys applies due diligence to all third-party vendors, sub-contractors, and technology partners to ensure that our supply chain meets our compliance standards.
- Vendor Assessment: All new vendors undergo a security and compliance assessment before onboarding, covering data handling practices, security certifications, and financial stability.
- Contractual Obligations: All vendors with access to Infrasys or client data must sign a Vendor Agreement that includes data protection, confidentiality, and security clauses aligned with our DPA standards.
- Ongoing Monitoring: Key vendors are reviewed annually for continued compliance with our standards and applicable regulations.
- Cloud Service Providers: Our primary CSPs (AWS, Azure, GCP) hold recognised certifications (ISO 27001, SOC 2) and have signed Data Processing Agreements with Infrasys.
- Sub-processing: Any sub-processing of client personal data requires prior written consent from the relevant client and is subject to the same data protection obligations as the primary engagement.
9. Employee Conduct & Training
Compliance begins with our people. All Infrasys employees, contractors, and interns are required to:
- Complete mandatory compliance and data protection training at onboarding and annually thereafter
- Adhere to our Code of Conduct, which sets out expected standards for professional behaviour, conflicts of interest, and confidentiality
- Report any suspected compliance violation, data breach, or unethical conduct through our Grievance Reporting channel
- Comply with our Information Security Policy including acceptable use of systems, password management, and device security
- Maintain confidentiality of client, employee, and business information at all times — including after leaving the organisation
Training Programme
- Data Protection & Privacy (DPDP Act / GDPR) — Annual mandatory
- Information Security Awareness — Annual mandatory
- Anti-Bribery & Corruption — Annual mandatory
- Code of Conduct — Onboarding + Annual refresh
- Role-specific compliance training (e.g. HIPAA for healthcare project teams)
10. Anti-Bribery, Anti-Corruption & Ethics
Infrasys has a zero-tolerance policy towards bribery and corruption in all forms. We comply with the Prevention of Corruption Act 1988 (India), the UK Bribery Act 2010, and all applicable anti-corruption legislation in the countries where we operate.
- Prohibited: Offering, giving, requesting, or receiving bribes — whether in cash, gifts, hospitality, or any other form — to influence business decisions
- Gifts & Hospitality: Employees may only give or receive gifts or hospitality within defined thresholds and must declare any gifts above INR 2,000 in value
- Political Contributions: Infrasys does not make political contributions on behalf of the company
- Third-Party Risk: All intermediaries, agents, and business partners are screened for bribery and corruption risk before engagement
- Facilitation Payments: We do not make or accept facilitation payments under any circumstances
Business Ethics
Beyond anti-bribery, our ethics commitments extend to:
- Fair competition — we comply with all applicable competition and antitrust laws
- Honest marketing — we do not make false or misleading claims about our services, certifications, or capabilities
- Conflicts of interest — employees must declare and manage conflicts through our formal process
- Modern slavery — we do not engage in or facilitate forced labour, human trafficking, or child labour in our operations or supply chain
11. Incident Response & Breach Notification
Infrasys operates a documented Incident Response Plan covering detection, containment, investigation, remediation, and post-incident review for security incidents and personal data breaches.
Breach Response Timeline
- 0–1 hours: Detection and initial triage — classify severity, activate response team
- 1–4 hours: Containment — isolate affected systems, preserve evidence
- 4–24 hours: Investigation — determine scope, affected data, and root cause
- 24–72 hours: Regulatory notification — notify relevant Data Protection Authorities as required by law (GDPR requires within 72 hours of becoming aware)
- 72 hours+: Individual notification — notify affected data principals where required
- Post-incident: Root cause analysis, remediation, and policy update
Client Notification
Where a security incident or data breach affects client data, we will notify the relevant client contact without undue delay and provide a written incident report within 5 business days of containment.
12. Audits & Compliance Reviews
Infrasys conducts regular internal and external reviews to verify the effectiveness of our compliance programme:
- Internal Compliance Audits: Conducted quarterly by our Legal & Compliance team covering data handling practices, access controls, and policy adherence
- Information Security Audits: Annual ISMS audit aligned with ISO 27001 requirements
- Vulnerability Assessments & Penetration Testing (VAPT): Conducted bi-annually on all production systems and client-facing infrastructure
- Third-Party Audits: Client-commissioned audits are accommodated under our standard MSA, subject to reasonable notice and scope agreement
- Regulatory Inspections: We cooperate fully with any inspection or investigation by a competent regulatory authority
- Annual Management Review: Our Compliance Status Report is reviewed by senior leadership annually and presented to the Board
13. Reporting Compliance Concerns
Infrasys takes all compliance concerns seriously. We operate a confidential reporting mechanism for employees, clients, and third parties to raise concerns about potential violations of law, regulation, or our internal policies.
Whistleblower Protection: Any individual who reports a genuine compliance concern in good faith will be protected from retaliation. Infrasys prohibits victimisation of whistleblowers and treats such reports with strict confidentiality to the extent permitted by law.
How to Report
- Email: Send concerns to info@infrasys.tech with subject line "Compliance Concern"
- Written Correspondence: Address to the Compliance Officer, Infrasys Limited, Spaze Itech Park, Sector 49, Gurgaon, Haryana 122018
- Regulatory Bodies: Data protection complaints can also be submitted to the Data Protection Board of India (DPDP Act) or the relevant supervisory authority in your country
All reports are triaged within 2 business days. Investigations are conducted confidentially and findings are reported back to the complainant where legally permissible.