India's Largest HR Virtual Summit
23rd July, 2026 Register for FREE
Acts /
Digital Personal Data Protection Act 2023

Digital Personal Data Protection Act, 2023

The Digital Personal Data Protection Act, 2023 (DPDP Act) marks a significant turning point for privacy regulation in India. For HR professionals, this legislation redefines how employee and candidate data must be handled, stored, and protected.

Whether you’re overseeing payroll, onboarding, background checks, or HRMS systems, the DPDP Act impacts your workflows. This guide walks you through everything HR needs to know to comply confidently and proactively.

Overview 

The DPDP Act introduces a comprehensive legal framework for handling digital personal data in India. It harmonizes privacy rights with innovation, mirroring global best practices while remaining rooted in Indian regulatory realities.

Key Entities Defined:

  • Data Principal: The individual whose data is being processed
  • Data Fiduciary: The entity deciding how and why data is processed (e.g., your company)
  • Data Processor: A third party that processes data on behalf of the fiduciary
  • Data Protection Board (DPB): The enforcement and adjudication authority

Enactment Year

The Act was:

  • Passed by Lok Sabha: August 7, 2023
  • Passed by Rajya Sabha: August 9, 2023
  • Received Presidential Assent: August 11, 2023

The implementation will be phased based on future notifications by the Central Government.

Purpose

The objectives of the Act include:

  • Protecting digital privacy
  • Establishing processing norms
  • Encouraging digital trust
  • Aligning with global laws like GDPR
  • Providing individuals with clear rights and remedies

Applicability

Applies To:

  • All digital personal data processed in India
  • Data of individuals in India, even if processed overseas

Exemptions:

  • Domestic/personal data use
  • Publicly available data
  • Certain government operations
  • Legal/judicial functions
  • Research and archiving under specific terms

Key Provisions

Section Provision HR Implication
Section 3 Territorial Scope Applies to employee data processed in India or outside, if related to Indian individuals.
Section 5 Consent Requirements HR must obtain informed, voluntary, purpose-specific consent—especially for background checks or optional benefits.
Section 8 Notice Obligations Employees must receive clear, pre-processing notices in simple language.
Section 11 Data Principal Rights Employees can request access, correction, or deletion of their personal data. HR must have a mechanism to respond.
Section 12 Significant Data Fiduciaries (SDF) If classified as SDF, HR must appoint a DPO, conduct DPIAs, and maintain an audit trail.
Section 16 Minors’ Data Verifiable parental consent is needed for interns or candidates under 18.
Section 25 Data Breach Notification Breaches must be reported to the Data Protection Board and affected individuals within 72 hours.
Sections 33–42 Penalties Financial penalties up to ₹250 Cr for security failures, improper consent, or non-notification.

HR Implications

The DPDP Act reshapes HR compliance from passive paperwork to proactive privacy governance.

HR teams must:

  • Obtain express consent for data beyond employment obligations
  • Secure data relating to employees and their dependents
  • Implement robust access and security controls
  • Create policies for handling data subject rights
  • Prepare breach response protocols
  • Record all data processing activities in an auditable format
  • Train staff regularly on privacy practices

Rules of This Act

The Draft Rules (released January 3, 2025) expand on the operational aspects:

Notice & Consent

  • Multi-language consent templates
  • Child-specific mechanisms
  • Consent withdrawal policies

Security

  • Alignment with ISO/IEC 27001
  • Audit trail requirements
  • Encryption and data masking

Significant Data Fiduciaries (SDFs)

  • Thresholds to be defined by Central Government
  • DPO appointment requirements
  • Annual DPIAs

Consent Managers

  • Licensing and tech standards

Data Breaches

  • Notify DPB and individuals within 72 hours
  • Provide mitigation plans and risk assessments

State-Specific Applicability

Aspect Applicability Notes
Legislation Scope National Central law overrides state laws
Variability by State None Uniform application
Enforcement Authority Data Protection Board Centralized enforcement
Appellate Forum TDSAT Pan-India jurisdiction

Forms and Returns

Form Name Purpose Frequency
Notice to Employees Form Disclose data usage, storage, and retention policies At onboarding & updates
Employee Consent Form Obtain specific consent for optional processing As needed
Children’s Data Consent Form Get verifiable parental consent for minors Onboarding
Third-Party Processor Agreement Ensure vendors (e.g., HRMS, payroll) are compliant On contract initiation
Data Breach Notification Form Report incidents to DPB and data principals Within 72 hours of breach
Data Protection Impact Assessment Assess privacy risks before introducing new HR tech/tools Before deployment
Employee Grievance Redressal Form Enable rights request submission (correction/erasure) As requested
Retention & Disposal Schedule Define how long employee data is stored Reviewed annually

Each template includes fields, instructions, and usage examples tailored for HR.

Penalties for Non-Compliance

Violation Type Max Penalty Examples
Security Safeguard Failure ₹250 Cr Weak password/storage policies
Non-Notification of Breach ₹200 Cr Late or no reporting
Children’s Data Violations ₹200 Cr No verifiable consent
General Obligations Breach ₹50 Cr Consent errors, inaccurate data
False Complaints by Data Subject ₹10,000 Frivolous redressal requests

Note: Penalties are adjudicated by DPB based on nature, gravity, and recurrence.

Prevention Strategies

Avoid penalties and ensure compliance by following these core strategies:

  • Consent-first HR: Collect clear, purpose-specific consent for data outside core employment (e.g., biometric, health, or analytics data).
  • Standardized notices: Ensure all employee-facing communications explain how their data will be used.
  • Secure storage practices: Use encrypted HRMS systems and restrict access based on roles.
  • Set data retention limits: Define how long to store resumes, background checks, or exit records—and dispose securely.
  • Appoint privacy champions: Assign HR PoCs or a DPO (if applicable) to monitor compliance and respond to data requests.
  • Run breach drills: Establish and test your 72-hour response playbook in case of a data breach.
  • Train HR & managers: Conduct quarterly privacy workshops to build awareness and preparedness.
  • Vendor due diligence: Audit all third-party HR tech or payroll tools for DPDP compliance.

Recent Updates

January 3, 2025 – Draft Rules Released

The Ministry of Electronics and Information Technology (MeitY) issued Draft Rules detailing how organizations must implement the Act. While not yet in force, they offer critical guidance.

Highlights:

  • Consent Language Standards
    Templates must be simple, multilingual (at least English + one regional language), and explain the exact purpose of data collection (e.g., payroll, health insurance, attendance tracking).
  • Consent Withdrawal Mechanism
    Employees must be able to withdraw consent easily—through email, HRMS portal, or physical forms—without losing core employment benefits.
  • Data Breach Reporting Protocol
    Organizations must:

    • Notify the Data Protection Board (DPB) and impacted employees within 72 hours of discovering a breach.
    • Provide a risk assessment, mitigation plan, and estimated impact report.
  • Data Protection Officer (DPO) Requirements
    Significant Data Fiduciaries must appoint a DPO who directly reports to the Board/CEO. HR teams may need to coordinate closely with this officer on audits, complaints, and DPIAs.
  • Audit and Logging Mandates
    All access to employee data must be logged with timestamps, user ID, and access purpose. HRMS systems must support audit trails.

February 2025 – Public Consultation Phase

Stakeholders, including HR professionals, industry bodies, and legal experts, submitted feedback on:

  • Definition of Sensitive HR Data (e.g., health records, background checks)
  • Cross-border data processing in global HR systems
  • Clarity on retention timelines for ex-employee data

Q3 2025 – Final Notification Expected

The finalized rules and go-live dates are expected by September 2025. Sector-specific FAQs and toolkits for HR, finance, and IT are anticipated.

What HR Should Do Now

  • Review draft rules with legal/compliance team
  • Update internal privacy policies and employee handbooks
  • Prepare consent and notice templates in simple language
  • Set up a breach notification SOP aligned with the 72-hour rule
  • Check if your company may be designated a Significant Data Fiduciary

90-Day Compliance Implementation Plan

Phase 1: Foundation (Days 1-30)

Week 1-2: Assessment and Documentation

  • Verify registration with Kerala labor department
  • Audit registers of employment, wages, leave, and working hours
  • Check compliance with opening/closing hours and weekly holiday rules
  • Review display of required notices in local language

Week 3-4: Policy Development

  • Draft/review leave policy (sick leave, earned leave, casual leave)
  • Create wage and overtime policies in line with state provisions
  • Develop templates for required registers and employee communications
  • Build compliance calendar for inspections and renewals

Phase 2: Implementation (Days 31-60)

Week 5-6: Team Training

  • Train HR staff on state-specific leave and working hour provisions
  • Educate payroll team on wage inclusions and statutory deductions
  • Develop inspection-readiness manuals for managers
  • Define compliance escalation protocols

Week 7-8: System Setup

  • Digitize attendance, leave, and wage records
  • Implement tracking system for holidays and weekly offs
  • Schedule periodic audits to identify compliance gaps
  • Create HR dashboard for compliance health

Phase 3: Optimization (Days 61-90)

Week 9-10: Relationship Building

  • Conduct awareness programs for employees on leave entitlements
  • Build transparent processes for overtime and holiday work
  • Establish grievance channels for compliance-related concerns
  • Engage external advisors for audit readiness

Week 11-12: Continuous Improvement

  • Review statutory records and correct gaps
  • Update HR training with new legal developments
  • Evaluate employee satisfaction with leave and working hour practices
  • Plan for annual compliance audits

Monthly Ongoing Tasks

  • Track leave balances and overtime compliance
  • Update statutory registers regularly
  • Audit wage slips monthly for statutory compliance
  • Conduct quarterly HR compliance reviews

Got questions?

Does this apply to small businesses?

Yes, unless explicitly exempted, any business processing personal data falls under the Act.

Do I need explicit consent for payroll data?

Not for core functions. But yes, for any secondary purposes like analytics or marketing.

Can I keep background checks indefinitely?

No. You must define and enforce a retention schedule.

Who must appoint a DPO?

Only entities designated as Significant Data Fiduciaries.

Can I use Google Drive to store employee data?

Yes, but ensure it meets encryption and access control standards as per the Act.

We use cookies to ensure you get the best experience. Check our "cookie policy