The Digital Personal Data Protection Act, 2023 (DPDP Act) marks a significant turning point for privacy regulation in India. For HR professionals, this legislation redefines how employee and candidate data must be handled, stored, and protected.
Whether you’re overseeing payroll, onboarding, background checks, or HRMS systems, the DPDP Act impacts your workflows. This guide walks you through everything HR needs to know to comply confidently and proactively.
The DPDP Act introduces a comprehensive legal framework for handling digital personal data in India. It harmonizes privacy rights with innovation, mirroring global best practices while remaining rooted in Indian regulatory realities.
Key Entities Defined:
The Act was:
The implementation will be phased based on future notifications by the Central Government.
The objectives of the Act include:
Applies To:
Exemptions:
| Section | Provision | HR Implication |
| Section 3 | Territorial Scope | Applies to employee data processed in India or outside, if related to Indian individuals. |
| Section 5 | Consent Requirements | HR must obtain informed, voluntary, purpose-specific consent—especially for background checks or optional benefits. |
| Section 8 | Notice Obligations | Employees must receive clear, pre-processing notices in simple language. |
| Section 11 | Data Principal Rights | Employees can request access, correction, or deletion of their personal data. HR must have a mechanism to respond. |
| Section 12 | Significant Data Fiduciaries (SDF) | If classified as SDF, HR must appoint a DPO, conduct DPIAs, and maintain an audit trail. |
| Section 16 | Minors’ Data | Verifiable parental consent is needed for interns or candidates under 18. |
| Section 25 | Data Breach Notification | Breaches must be reported to the Data Protection Board and affected individuals within 72 hours. |
| Sections 33–42 | Penalties | Financial penalties up to ₹250 Cr for security failures, improper consent, or non-notification. |
HR Implications
The DPDP Act reshapes HR compliance from passive paperwork to proactive privacy governance.
HR teams must:
- Obtain express consent for data beyond employment obligations
- Secure data relating to employees and their dependents
- Implement robust access and security controls
- Create policies for handling data subject rights
- Prepare breach response protocols
- Record all data processing activities in an auditable format
- Train staff regularly on privacy practices
The Draft Rules (released January 3, 2025) expand on the operational aspects:
| Aspect | Applicability | Notes |
| Legislation Scope | National | Central law overrides state laws |
| Variability by State | None | Uniform application |
| Enforcement Authority | Data Protection Board | Centralized enforcement |
| Appellate Forum | TDSAT | Pan-India jurisdiction |
| Form Name | Purpose | Frequency |
| Notice to Employees Form | Disclose data usage, storage, and retention policies | At onboarding & updates |
| Employee Consent Form | Obtain specific consent for optional processing | As needed |
| Children’s Data Consent Form | Get verifiable parental consent for minors | Onboarding |
| Third-Party Processor Agreement | Ensure vendors (e.g., HRMS, payroll) are compliant | On contract initiation |
| Data Breach Notification Form | Report incidents to DPB and data principals | Within 72 hours of breach |
| Data Protection Impact Assessment | Assess privacy risks before introducing new HR tech/tools | Before deployment |
| Employee Grievance Redressal Form | Enable rights request submission (correction/erasure) | As requested |
| Retention & Disposal Schedule | Define how long employee data is stored | Reviewed annually |
Each template includes fields, instructions, and usage examples tailored for HR.
| Violation Type | Max Penalty | Examples |
| Security Safeguard Failure | ₹250 Cr | Weak password/storage policies |
| Non-Notification of Breach | ₹200 Cr | Late or no reporting |
| Children’s Data Violations | ₹200 Cr | No verifiable consent |
| General Obligations Breach | ₹50 Cr | Consent errors, inaccurate data |
| False Complaints by Data Subject | ₹10,000 | Frivolous redressal requests |
Note: Penalties are adjudicated by DPB based on nature, gravity, and recurrence.
Avoid penalties and ensure compliance by following these core strategies:
The Ministry of Electronics and Information Technology (MeitY) issued Draft Rules detailing how organizations must implement the Act. While not yet in force, they offer critical guidance.
Highlights:
Stakeholders, including HR professionals, industry bodies, and legal experts, submitted feedback on:
The finalized rules and go-live dates are expected by September 2025. Sector-specific FAQs and toolkits for HR, finance, and IT are anticipated.
What HR Should Do Now
- Review draft rules with legal/compliance team
- Update internal privacy policies and employee handbooks
- Prepare consent and notice templates in simple language
- Set up a breach notification SOP aligned with the 72-hour rule
- Check if your company may be designated a Significant Data Fiduciary
Phase 1: Foundation (Days 1-30)
Week 1-2: Assessment and Documentation
Week 3-4: Policy Development
Phase 2: Implementation (Days 31-60)
Week 5-6: Team Training
Week 7-8: System Setup
Phase 3: Optimization (Days 61-90)
Week 9-10: Relationship Building
Week 11-12: Continuous Improvement
Monthly Ongoing Tasks
Yes, unless explicitly exempted, any business processing personal data falls under the Act.
Not for core functions. But yes, for any secondary purposes like analytics or marketing.
No. You must define and enforce a retention schedule.
Only entities designated as Significant Data Fiduciaries.
Yes, but ensure it meets encryption and access control standards as per the Act.