Privacy Notice For Employees
Effective Date: August 10, 2026
Ness Digital Engineering, its subsidiaries and affiliates and any other directly controlled entities as may exist from time to time (“Ness” or “We” or “Our”), is committed to protect the privacy and security of your personal data. It is important that you read this Privacy Notice (“Notice”), together with our website Privacy Policy (“Policy”) available at https://www.ness.com/privacy-policy/, so that you are aware of how and why we are using such personal data.
Please note: All information in this privacy notice is applicable to you unless otherwise indicated based on your residency status. For the additional terms which may be applicable to you based on your residency status, please refer to your country-specific terms at the end of this notice.
1. Purpose
This Notice highlights our privacy practices regarding Personal Information that we collect and process depending on your association with us and nature of processing activity in compliance with applicable data privacy laws.
2. Applicability
This Notice applies to all employees, contractors, consultants and temporary workers at Ness. It applies to personal data that we collect and process during your employment or engagement with us, whether that is in a full-time, part-time, permanent, or temporary capacity. The notice is applicable to all personal data processed through various means, including in-person, by email, via our internal systems, or through other communication channels used by Ness. This notice also extends to all employees of Ness who have ceased to be an employee for any reason whatsoever (Alumni), where applicable, in relation to the retention and processing of personal data after the termination of employment, as required for legal, administrative, or contractual purposes. We may update this Notice at any time, subsequent to which, a copy of the updated Notice will be published on Ness Intranet.
3. Relationship
We are the “Data Controller/Data Fiduciary” as specified under applicable data privacy laws, and herein we refer to ourselves as the Data Controller in this notice. This means that we are responsible for deciding how and why we process your personal data. Processing will include collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure (including transmission), erasure, or destruction of your personal data. We will keep and use it to enable us to run the business and manage our relationship with you effectively, lawfully, and appropriately, whilst you apply for a job opportunity with us, are working for us, at the time when your employment ends and thereafter. This includes using information to enable us to comply with the employment contract, to comply with any legal requirements, pursue our legitimate interest and protect our legal position in the event of legal proceedings. This processing is necessary for the normal operation of our business and to ensure that we
can manage your employment relationship lawfully, appropriately, and effectively.
4. Your Personal Data That We Will Process
We may collect, store, and process the following categories of personal information about you:
- “Personal Details,” including name (including maiden names and parents’ names), known by any other name, title, addresses, telephone numbers, mobile number, personal email addresses, citizenship, nationality, Higher education details, facial recognition readers details, family details including details of the spouse, children, parents along with their insurance and nomination details, date and place of birth, gender, marital status, dependent’s details, emergency contact information, next of kin, nominee details, biometric information(if applicable), photographs, and signatures.
- “National ID Details,” including Nationality/National identity number/passport number/tax identification number/ social security linkages/ driving license number/ identity Cards/family certificates (if applicable)
- “Employment Details,” including start date and, if different, the date of your continuous employment, employment location, salary, salary history, billability status, leave details, pension details, benefits-related information, job title, work history, performance information and feedback, disciplinary and grievance information, employee identity number that is assigned to you (including SAP personnel ID numbers), attendance history, details of expenses claimed, training records, food preferences and dress size, termination date and your reason for termination, background check reports, information about your use of our information and communications systems and military service status.
- “Employment records,” including job titles, grade/level, technical or service skills, work history, projects/departments, working hours, holidays, training records and professional memberships.
- “Recruitment information,” including copies of to-work documentation, references and other information included in a CV or cover letter or as part of the application process.
- “Financial Details,” including bank details, bank account number, payroll records, tax status information, etc.
- “Surveillance Details,” including CCTV footage and other information obtained through electronic means such as swipe card records, information security measures protecting our data on information assets used for business purposes.
- “Travel details,” including passport, visa, citizenship and immigration status details
- We may also process the following ” Sensitive Personal Data ” of Personal Information based on specific business and regulatory requirements. This may include one or any of the following:
- Information about your health, including blood group, disability details, any medical condition, health and sickness records/certificated, HMO’s memberships, etc. (if applicable)
- Information required for pensions and permanent health insurance purposes (if you leave employment for health reasons)
- Biometric data (if applicable)
- Trade union membership (if applicable)
- Information about criminal convictions and offences (if applicable)
* Please note that the categories of personal (or sensitive personal) details processed may differ based on the business requirement of the entity and legal requirement of a country.
5. How we collect your Personal Information:
We collect your personal data through the job application, interviews, recruitment, and onboarding process, either directly from you, or sometimes indirectly through third party service providers or employee referrals. We may collect additional personal data during job-related activities throughout the period of your working for us. All data collected during the recruitment process or additional data collected during your employment will be used and stored for the performance of an employment agreement as well as for complying with other contractual and legal obligations.
Your Personal Data and/or Sensitive Personal Data may be obtained by us from various sources, including but not limited to information provided by you (whether in oral or written form) and from third party information sources during reference, verification, credit, or background checks.
To the extent that you disclose to us any Personal Data and/or Sensitive Personal Data (whether or not coming within the definition of Personal Data and Sensitive Personal Data above) of another individual, We shall assume, without independent verification, that you have obtained such individual’s consent for the disclosure of such information and/or personal data and/or Sensitive Personal Data as well as the processing of the same in accordance with the terms of this Privacy Notice.
We collect your personal data/information with your explicit consent as required under the applicable laws.
6. Changes to your personal data:
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
7. What we use your personal information for:
We may use your personal information for the following purposes:
If you are employed by Ness
- Payroll, Pension, Tax and Accounts: To calculate and pay your salary, tax and pension contributions and to update our business accounts.
- Benefits: To calculate, pay and provide benefits to you such as statutory benefits, life assurance, private medical cover, profit shares and childcare vouchers and other benefits.
- Employee Administration: To administer your employment with us such as to administer your employment contract, carry out background checks based on client requirements, meet our other contractual and legal obligations, enforce our policies, administer medical and sickness records, calculate pay, trach and calculate leaves, track holidays and other absences, conduct appraisals and promotions, plan events, administer disciplinary and grievance matters, review applications/interview records, working time records and conduct immigration checks. We may process your dependent’s data to provide them with necessary benefits such as nominee benefits, different internal events, annual health check-ups (if applicable).
- Administration of Membership Records: To administer your membership with professional associations/bodies and other organizations for business and/or professional purposes (if applicable).
- Training and Career Development: To administer and supervise your training and career development. For example, conducting performance reviews.
- Trade Unions: To facilitate trade union memberships and relationships. This might include the processing Sensitive Personal Data of personal information
If you are not employed by Ness
- Remuneration and Accounts: To calculate and/or pay your fees/expenses/allowances and to maintain business accounts
- Personnel Administration: To administer your work with us. For example, this will include complying with contracts for services, legal obligations and, where relevant, our policies
- Training: To provide you with training relevant to your role
All staff members
- Access to systems: To provide you with access to IT systems and applications used by Ness and/or its clients and to monitor usage of such systems
- Security: To keep your personal data and that of other staff members secure and to prevent unauthorized access, loss, damage, destruction, or corruption of data. This may include monitoring communications and use of Ness IT systems
- Business Development: To develop our business generally including through bidding for new projects (i.e. we may provide your name, work contact details, salary range and/or experience to potential and existing clients/suppliers)
- Business Travel: To administer any travel and/or accommodation arrangements where you are required to travel for work within or outside of the country that you operate in.
- Company and Group Company Administration: To carry out administration tasks within each Ness Group company and across the whole Ness Group
- Equal Opportunities: To promote and monitor equal opportunities and diversity within Ness. This might include the processing of special category personal information including religious or similar beliefs, and ethnic origin (if applicable).
- Restructuring, Mergers and Acquisitions: To carry out group company restructuring, to sell any of the Ness companies or acquire or merge with other businesses, or to undergo any other corporate action.
- Regulatory Requirements: To comply with applicable laws and regulations which Ness is subject to.
- Tax: To administer our revenue and tax obligations
- As part of its business activities, Ness may capture and use photographs and videos during internal or external events and campaigns for communication, branding, marketing and promotional purposes, with your consent where required by applicable laws.
8. Data sharing & Transfer:
Your personal information will be shared with other entities in the Ness Group during our normal business operations. In addition, certain IT systems used by Ness are supported or hosted by third parties. Your personal information will be shared with these third parties for the purpose of supporting these systems.
We may also disclose your personal information to:
- Third parties that we engage to provide services related to your employment such as payroll providers, pension administrators, occupational health professionals, Emergency notification service (Crisis Management) vendor, training providers, benefits providers, marketing/events agencies, recruitment agencies, immigration/visa/permit providers, travel companies and educational/academic establishments.
- Professional advisers (including lawyers, auditors and accountants), banks, professional bodies, tax authorities, courts, the police and other governmental authorities where we are required to do so by law, or to protect or defend our rights and interests.
- Clients (where applicable) based on contractual obligation.
- Internal departments, including with your line manager, managers in the business areas, IT team, Travels team or any other team if access to the data is necessary for the performance of their roles.
9. International transfer of your personal information:
As Ness operates across multiple jurisdictions, your personal information may be transferred to countries outside of your local jurisdiction. We will ensure that appropriate safeguards are in place, in accordance with applicable Data Protection Laws, to protect the transfer of your personal data.
Additionally, we may engage service providers located outside your geographical region. However, we will ensure that these service providers adhere to strict confidentiality and security requirements to protect your data.
10. Your rights in relation to your personal information:
You may have certain rights under applicable data protection laws in relation to personal information that We hold about you. Under certain circumstances, by law, you have the:
- Right of Access to your personal data (commonly known as “data subject access request”). This enables you to manage and review your personal data on record with us and to receive a copy of the personal data we hold about you. This also includes access to personal data given, processing activities and identities of data processors/other data fiduciaries with whom the data has been shared. The information specified herein can be accessed by addressing an email at [email protected]
- Right to Rectification of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected.
- Right to be Informed about the collection and use of personal data and about any data breach which shall be duly intimated to you along with the details, consequences relevant to you, measures implemented by us to mitigate the risk, safety measures that you may take to protect interests and business contact information of a person who is able to respond to related queries on Our behalf.
- Right to Object to Processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your situation which makes you want to object to processing on this ground.
- Right to Request the Restriction of Processing of your personal data. This enables you to ask us to suspend the processing of personal data about you
- Right of Data Portability/ Transfer to another party.
- Right to Withdraw Consent for processing of personal data where explicit consent has been sought. In the limited circumstances where you may have provided your consent to the collection, processing, and transfer of your personal data for a specific purpose, you have the right to withdraw your consent for that specific processing at any time.
- Right to be Forgotten your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data. And upon receiving such a request, We shall delete your personal data or cause it to be deleted by the data processor with whom the data has been shared for aforesaid purposes.
- Right in relation to automated decision-taking. We do not engage in automated decision-making processes or profiling activities that significantly affect individuals based on their personal data without obtaining your explicit consent or unless permitted by applicable laws.
- Right to raise queries. This enables you to raise queries regarding the processing of your data and the same shall be responded to within a reasonable time by our duly appointed Data Protection Officer on our behalf.
- Right to grievance redressal. In certain jurisdictions, we have established a grievance redressal mechanism for addressing your grievances in relation to your personal data obtained and processed by us. You have the right to grievance redressal in respect of any act or omission regarding the performance of obligations in relation to your personal data. You can register your grievance by following the process provided under Clause 15 herein. You shall not register a false or frivolous grievance with us.
- Right to lodge a complaint. You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the applicable Data Protection Laws. However, in certain jurisdictions, you would be required under the applicable data protection law to first approach the designated grievance redressal system established by Ness within the relevant jurisdiction before seeking recourse to the supervisory authority. Further, you shall not register a false or frivolous complaint with such authority.
- Right to nominate: You have right to nominate, any individual who shall, in the event of death or incapacity, exercise the rights on your behalf.
All the above-mentioned rights can be exercised by contacting the Ness appointed Data Protection Officer ([email protected]) and all such requests will be evaluated based on the legal requirements, as applicable on the date of receipt of request from you.
In some jurisdictions, after exhausting the right to grievance redressal as explained above, you may exercise the right to complain about the use of your personal information to a public authority with responsibility for overseeing the compliance with the Data Protection Laws.
11. If You Refuse to Provide Consent for Collection and Processing of Personal Data
If you do not provide your consent for collection and processing of your information when requested, we may not be able to comply with our contractual and/or legal obligations including but not limited to the execution of the labor contract, payment of salary, administration of social security benefits, insurance, and holiday entitlements, etc. Similarly, we would not be able to pursue our legitimate interest such as carrying out administrative activities including but not limited to employee id creation, access creation, conducting background check, issuing of laptop, CCTV monitoring, etc.
12. Change of Purpose
We will only use your personal data for the purposes for which we collected it. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so without undue delay. Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by applicable law.
13. Data Security
We have implemented appropriate technical and organizational measures to ensure the security of your personal information. These measures are designed to prevent unauthorized access, disclosure, alteration, or destruction of your data.
Where third parties process your personal data on our behalf, they will only do so in accordance with our instructions. We enter into specific agreements with such third parties to ensure they comply with applicable data protection laws and maintain the confidentiality and security of your data.
In the event of a suspected data security breach, we have established procedures to assess and address the situation. If a breach occurs that affects your personal data and where legally required, we will promptly notify you and applicable relevant regulatory authority.
14. Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any contractual, legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements. In some circumstances, we may anonymize your personal data so that it can no longer be associated with you, in which case we may use such information without further notice to you.
15. How to contact the Data Protection Officer
If you have any concerns or complaints as to how your data is processed, you can contact our Data Protection Officer by writing to [email protected]
16. Privacy Statements for Specific Geos
Detailed privacy notice for our employees shall be provided at the time of onboarding to maintain compliance to the local laws of the land as prevalent in our global locations.
Please refer to some of the region-specific applicable regulations below:
16.1. EU/EEA
- When processing your Personal Information within the EU/EEA Regions, we adhere to the Data Privacy Principles and regulations set forth in the General Data Protection Regulation (GDPR).
- The following applies only where the data controller processing your Personal Information is domiciled in the European Economic Area (“EEA”):
- We transfer Personal Information to countries outside the EEA to third parties, including to countries which have different data protection standards to those which apply in the EEA. The locations of our subsidiaries and affiliates are set out here.
- Our service providers are primarily located in Europe, India and USA. Where service providers process your Personal Information in countries deemed adequate by the European Commission, we rely on the European Commission’s decision to protect your Personal Information.
- For transfers to subsidiaries, affiliates, and service providers outside the EEA, we use standard contractual clauses or rely on a service provider’s corporate rules that are in place to protect your Personal Information. When required, we disclose Personal Information to external law enforcement bodies or regulatory authorities, in order to comply with legal obligations.
- We may also Transfer personal information to a Third Party located outside the EEA without having to implement the above measures where one of the following conditions is met:
- You have given your consent for the Transfer your Personal Information.
- We need to carry out the transfer of personal information to perform or conclude a contract with you; the transfer of personal information is necessary (i) to protect your vital interests (i.e. in case of a life-or-death situation), or (ii) to allow us to establish, exercise or defend a legal claim, or (iii) for reasons of public interest.
16.2. California
- When processing Personal Information in California, we adhere to the Data Privacy Principles and Regulations outlined in the California Consumer Privacy Act of 2018 (CCPA) as amended by the California Privacy Rights Act (“CPRA”). We may be responsible as a “business” for such Personal Information.
- We do not share the personal information of employees who are California residents with third parties for any direct marketing purposes
16.3. India
- We adhere to requirements as laid down by Information Technology Act, 2000 and Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 while processing your information.
- We adhere to requirements as laid down by the Digital Personal Data Protection Act 2023 and the Rules framed thereunder (which regulates the processing that balances the rights of individuals to protect their personal data with the necessity of processing such data for lawful purposes) while processing your information.
- Employees have the right to seek access to information regarding the processing of their personal data, correction and updating of personal data, erasure of personal data, grievance redressal, withdrawal of consent (where consent forms the basis of processing), and nomination of an individual to exercise such rights in accordance with applicable provisions of the DPDPA.
- Where processing is based on consent, Employees may withdraw such consent at any time through the channels specified in this Notice. Withdrawal of consent shall not affect the lawfulness of processing undertaken prior to such withdrawal.
- If employee is not satisfied with the resolution provided through Ness’s grievance redressal mechanism, the employee may lodge a complaint with the Data Protection Board of India, subject to applicable legal requirements. Information regarding the Data Protection Board of India may be accessed through the official Government website or any successor website notified by the Government of India.
- This Privacy Notice is primarily made available in English. Where required, localized versions may also be made available in applicable regional languages of India. You may request access to the applicable local language version by contacting the Data Protection Officer at [email protected]. We will make reasonable efforts to provide the requested version within a reasonable period, not exceeding 30 days from the date of your request. In the event of any inconsistency between language versions, the English version shall prevail to the extent permitted by applicable law.
16.4. Canada
- For the purpose of processing your Personal Information in Canada (applicable to data subjects residing in Canada), we will follow the Data Privacy Principles and regulations of the Personal Information Protection and Electronic Documents Act, 2000 (commonly known as PIPEDA). Under PIPEDA, there is no distinction between domestic and international transfers of data. Ness as the transferring organization will remain accountable for the protection of that Personal Information and ensuring compliance with the applicable legislation, using contractual or other means to provide a comparable level of protection while the information is being processed by the third party.
16.5. Singapore
- For the purpose of processing your Personal Information in Singapore we will follow the Data Privacy Principles and Regulations of the Personal Data Protection Act, 2012 (commonly known as ‘PDPA’) and the Personal Data Protection Amendment Act, 2020 (‘the Amendment Act’).
16.6. UK
- For the purposes of processing your Personal Information in UK, we will follow all the applicable Data Privacy Regulations, including UK General Data Protection Regulation.
16.7. Mexico
- For the purpose of processing your Personal Information in Mexico we will follow the Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP), 2025 and its regulations (the “Personal Data Protection Law”).