Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection Act, 2023 (DPDP Act) marks a significant turning point for privacy regulation in India. For HR professionals, this legislation redefines how employee and candidate data must be handled, stored, and protected.
Whether you’re overseeing payroll, onboarding, background checks, or HRMS systems, the DPDP Act impacts your workflows. This guide walks you through everything HR needs to know to comply confidently and proactively.
Overview
The DPDP Act introduces a comprehensive legal framework for handling digital personal data in India. It harmonizes privacy rights with innovation, mirroring global best practices while remaining rooted in Indian regulatory realities.
Key Entities Defined:
- Data Principal: The individual whose data is being processed
- Data Fiduciary: The entity deciding how and why data is processed (e.g., your company)
- Data Processor: A third party that processes data on behalf of the fiduciary
- Data Protection Board (DPB): The enforcement and adjudication authority
Enactment Year
The Act was:
- Passed by Lok Sabha: August 7, 2023
- Passed by Rajya Sabha: August 9, 2023
- Received Presidential Assent: August 11, 2023
The implementation will be phased based on future notifications by the Central Government.
Purpose
The objectives of the Act include:
- Protecting digital privacy
- Establishing processing norms
- Encouraging digital trust
- Aligning with global laws like GDPR
- Providing individuals with clear rights and remedies
Applicability
Applies To:
- All digital personal data processed in India
- Data of individuals in India, even if processed overseas
Exemptions:
- Domestic/personal data use
- Publicly available data
- Certain government operations
- Legal/judicial functions
- Research and archiving under specific terms
Key Provisions
| Section | Provision | HR Implication |
| Section 3 | Territorial Scope | Applies to employee data processed in India or outside, if related to Indian individuals. |
| Section 5 | Consent Requirements | HR must obtain informed, voluntary, purpose-specific consent—especially for background checks or optional benefits. |
| Section 8 | Notice Obligations | Employees must receive clear, pre-processing notices in simple language. |
| Section 11 | Data Principal Rights | Employees can request access, correction, or deletion of their personal data. HR must have a mechanism to respond. |
| Section 12 | Significant Data Fiduciaries (SDF) | If classified as SDF, HR must appoint a DPO, conduct DPIAs, and maintain an audit trail. |
| Section 16 | Minors’ Data | Verifiable parental consent is needed for interns or candidates under 18. |
| Section 25 | Data Breach Notification | Breaches must be reported to the Data Protection Board and affected individuals within 72 hours. |
| Sections 33–42 | Penalties | Financial penalties up to ₹250 Cr for security failures, improper consent, or non-notification. |
HR Implications
The DPDP Act reshapes HR compliance from passive paperwork to proactive privacy governance.
HR teams must:
- Obtain express consent for data beyond employment obligations
- Secure data relating to employees and their dependents
- Implement robust access and security controls
- Create policies for handling data subject rights
- Prepare breach response protocols
- Record all data processing activities in an auditable format
- Train staff regularly on privacy practices
Rules of This Act
The Draft Rules (released January 3, 2025) expand on the operational aspects:
Notice & Consent
- Multi-language consent templates
- Child-specific mechanisms
- Consent withdrawal policies
Security
- Alignment with ISO/IEC 27001
- Audit trail requirements
- Encryption and data masking
Significant Data Fiduciaries (SDFs)
- Thresholds to be defined by Central Government
- DPO appointment requirements
- Annual DPIAs
Consent Managers
- Licensing and tech standards
Data Breaches
- Notify DPB and individuals within 72 hours
- Provide mitigation plans and risk assessments
State-Specific Applicability
| Aspect | Applicability | Notes |
| Legislation Scope | National | Central law overrides state laws |
| Variability by State | None | Uniform application |
| Enforcement Authority | Data Protection Board | Centralized enforcement |
| Appellate Forum | TDSAT | Pan-India jurisdiction |
Forms and Returns
| Form Name | Purpose | Frequency |
| Notice to Employees Form | Disclose data usage, storage, and retention policies | At onboarding & updates |
| Employee Consent Form | Obtain specific consent for optional processing | As needed |
| Children’s Data Consent Form | Get verifiable parental consent for minors | Onboarding |
| Third-Party Processor Agreement | Ensure vendors (e.g., HRMS, payroll) are compliant | On contract initiation |
| Data Breach Notification Form | Report incidents to DPB and data principals | Within 72 hours of breach |
| Data Protection Impact Assessment | Assess privacy risks before introducing new HR tech/tools | Before deployment |
| Employee Grievance Redressal Form | Enable rights request submission (correction/erasure) | As requested |
| Retention & Disposal Schedule | Define how long employee data is stored | Reviewed annually |
Each template includes fields, instructions, and usage examples tailored for HR.
Penalties for Non-Compliance
| Violation Type | Max Penalty | Examples |
| Security Safeguard Failure | ₹250 Cr | Weak password/storage policies |
| Non-Notification of Breach | ₹200 Cr | Late or no reporting |
| Children’s Data Violations | ₹200 Cr | No verifiable consent |
| General Obligations Breach | ₹50 Cr | Consent errors, inaccurate data |
| False Complaints by Data Subject | ₹10,000 | Frivolous redressal requests |
Note: Penalties are adjudicated by DPB based on nature, gravity, and recurrence.
Prevention Strategies
Avoid penalties and ensure compliance by following these core strategies:
- Consent-first HR: Collect clear, purpose-specific consent for data outside core employment (e.g., biometric, health, or analytics data).
- Standardized notices: Ensure all employee-facing communications explain how their data will be used.
- Secure storage practices: Use encrypted HRMS systems and restrict access based on roles.
- Set data retention limits: Define how long to store resumes, background checks, or exit records—and dispose securely.
- Appoint privacy champions: Assign HR PoCs or a DPO (if applicable) to monitor compliance and respond to data requests.
- Run breach drills: Establish and test your 72-hour response playbook in case of a data breach.
- Train HR & managers: Conduct quarterly privacy workshops to build awareness and preparedness.
- Vendor due diligence: Audit all third-party HR tech or payroll tools for DPDP compliance.
Recent Updates
January 3, 2025 – Draft Rules Released
The Ministry of Electronics and Information Technology (MeitY) issued Draft Rules detailing how organizations must implement the Act. While not yet in force, they offer critical guidance.
Highlights:
- Consent Language Standards
Templates must be simple, multilingual (at least English + one regional language), and explain the exact purpose of data collection (e.g., payroll, health insurance, attendance tracking).
- Consent Withdrawal Mechanism
Employees must be able to withdraw consent easily—through email, HRMS portal, or physical forms—without losing core employment benefits.
- Data Breach Reporting Protocol
Organizations must:- Notify the Data Protection Board (DPB) and impacted employees within 72 hours of discovering a breach.
- Provide a risk assessment, mitigation plan, and estimated impact report.
- Data Protection Officer (DPO) Requirements
Significant Data Fiduciaries must appoint a DPO who directly reports to the Board/CEO. HR teams may need to coordinate closely with this officer on audits, complaints, and DPIAs.
- Audit and Logging Mandates
All access to employee data must be logged with timestamps, user ID, and access purpose. HRMS systems must support audit trails.
February 2025 – Public Consultation Phase
Stakeholders, including HR professionals, industry bodies, and legal experts, submitted feedback on:
- Definition of Sensitive HR Data (e.g., health records, background checks)
- Cross-border data processing in global HR systems
- Clarity on retention timelines for ex-employee data
Q3 2025 – Final Notification Expected
The finalized rules and go-live dates are expected by September 2025. Sector-specific FAQs and toolkits for HR, finance, and IT are anticipated.
What HR Should Do Now
- Review draft rules with legal/compliance team
- Update internal privacy policies and employee handbooks
- Prepare consent and notice templates in simple language
- Set up a breach notification SOP aligned with the 72-hour rule
- Check if your company may be designated a Significant Data Fiduciary
90-Day Compliance Implementation Plan
Phase 1: Foundation (Days 1-30)
Week 1-2: Assessment and Documentation
- Verify registration with Kerala labor department
- Audit registers of employment, wages, leave, and working hours
- Check compliance with opening/closing hours and weekly holiday rules
- Review display of required notices in local language
Week 3-4: Policy Development
- Draft/review leave policy (sick leave, earned leave, casual leave)
- Create wage and overtime policies in line with state provisions
- Develop templates for required registers and employee communications
- Build compliance calendar for inspections and renewals
Phase 2: Implementation (Days 31-60)
Week 5-6: Team Training
- Train HR staff on state-specific leave and working hour provisions
- Educate payroll team on wage inclusions and statutory deductions
- Develop inspection-readiness manuals for managers
- Define compliance escalation protocols
Week 7-8: System Setup
- Digitize attendance, leave, and wage records
- Implement tracking system for holidays and weekly offs
- Schedule periodic audits to identify compliance gaps
- Create HR dashboard for compliance health
Phase 3: Optimization (Days 61-90)
Week 9-10: Relationship Building
- Conduct awareness programs for employees on leave entitlements
- Build transparent processes for overtime and holiday work
- Establish grievance channels for compliance-related concerns
- Engage external advisors for audit readiness
Week 11-12: Continuous Improvement
- Review statutory records and correct gaps
- Update HR training with new legal developments
- Evaluate employee satisfaction with leave and working hour practices
- Plan for annual compliance audits
Monthly Ongoing Tasks
- Track leave balances and overtime compliance
- Update statutory registers regularly
- Audit wage slips monthly for statutory compliance
- Conduct quarterly HR compliance reviews
Got questions?
Yes, unless explicitly exempted, any business processing personal data falls under the Act.
Not for core functions. But yes, for any secondary purposes like analytics or marketing.
No. You must define and enforce a retention schedule.
Only entities designated as Significant Data Fiduciaries.
Yes, but ensure it meets encryption and access control standards as per the Act.