DPDP Act 2023: Employee Data Privacy Guide for Employers

Published: September 14, 2026 Last modified: October 01, 2026 15 min read
DPDP Act 2023

The DPDP Act 2023 is India’s law on digital personal data. Parliament passed it in August 2023. It has not yet come fully into force. Rules under the Act were notified in November 2025. The core obligations, notice, consent, and breach reporting commence only in May 2027. This guide covers what the Act requires, what is currently in effect, and what it means, specifically for employee data privacy.

Key Takeaways

  • Understand what the DPDP Act 2023 covers and why most of it isn’t enforceable yet.
  • See the phased timeline: what commenced in November 2025 and what starts in November 2026 and May 2027.
  • Learn why your company is a “data fiduciary” and every employee is a “data principal” under the law.
  • Discover Section 7’s exemption, the provision that lets HR process employee data without fresh consent for routine work.
  • Understand Significant Data Fiduciary (SDF) obligations and whether your organization could fall under them.
  • Familiarize yourself with the penalty structure, which allows fines up to ₹250 crore per instance, and the actionable steps to take before enforcement begins.

What is the DPDP Act 2023?

The Digital Personal Data Protection (DPDP) Act, 2023, is India’s principal legislation. It is an Indian law that regulates the processing of digital personal data and protects individuals’ privacy while allowing organizations to process data for lawful purposes. The Act aims to:

  • Protect an individual’s digital personal data.
  • Establish rules for organizations that collect and process personal data.
  • Give individuals certain rights regarding their personal data.
  • Create obligations for organizations that determine the purpose and means of processing data.
  • Provide penalties for certain breaches of the Act.

The DPDP Act, 2023, seeks to balance individual privacy and data protection with the legitimate use of data by businesses and other organizations. The Act is supported by detailed rules, and its provisions have been brought into force in stages, so the exact compliance requirements depend on the provision and applicable commencement date.

Is the DPDP Act 2023 in Force? The Phased Rollout

The government notified the Act in stages rather than all at once. The Digital Personal Data Protection Rules, 2025, were finalized on 13 November 2025, after a draft version circulated for comment from January 2025. Only a limited set of provisions took effect that day.

The rollout follows three phases:

  1. Phase 1, 13 November 2025: Definitions, establishment of the Data Protection Board, and related amendments to the RTI Act.
  2. Phase 2, 13 November 2026: Consent Manager registration opens.
  3. Phase 3, 13 May 2027: Notice, consent, security safeguards, breach reporting, children’s data rules, and data principal rights all commence.

The Data Protection Board of India was formally established under Phase 1 and is headquartered in the National Capital Region. As of publication, the government has not yet appointed a Chairperson or Members to staff it. This distinction is critical because the Board’s adjudicatory powers begin taking effect around the same time as Phase 3.

Key Definitions: Data Fiduciary, Data Principal, and Processing

Three core terms define the scope of the Act; mapping them to organizational roles clarifies compliance requirements.

Your organization acts as the Data Fiduciary when it determines the purposes and means of processing personal data, such as employee bank details for payroll, candidate résumés, or biometric attendance records.

Every employee, candidate, and dependent whose data you hold is a data principal. Processing covers almost anything done with that data: collection, storage, use, sharing, or deletion, whether manual or automated.

A personal data breach is the unauthorized processing or the accidental disclosure, loss, or alteration of personal data that compromises the confidentiality, integrity, or availability of that data. Given how much employee data now resides in HRMS platforms, the risks extend beyond high-profile cyberattacks to include internal oversights, such as misdirected payroll emails or unsecured shared drives. Together, these three terms form the backbone of employee data privacy compliance for any HR function.

Data Fiduciary Obligations under the Act

Once Phase 3 takes effect, every data fiduciary carries three core duties under Section 8 of the Act.

First, Data Fiduciaries must provide clear notice. Before processing personal data, or as soon as practicable after, a fiduciary must clearly describe what data it collects and why. Second, processing requires valid consent that is freely given, specific, informed, and obtained through a clear affirmative action. It cannot be assumed through silence or a pre-ticked box, and it must be as easy to withdraw as it was to give.

Third, organizations must maintain reasonable security safeguards. A data fiduciary must implement technical and organizational safeguards to prevent a personal data breach. It must also erase personal data once its purpose has been fulfilled, unless another law requires its retention. For payroll security and HR records, this means access controls and a documented retention schedule, not indefinite storage by default.

Employee Data and the Section 7 Exemption

HR leaders should pay particular attention to Section 7 of the Act. It lists situations in which a data fiduciary may process personal data without obtaining fresh consent each time. It is written specifically for the employment relationship.

The clause permits processing for employment purposes or for safeguarding the employer from loss or liability, such as preventing corporate espionage, maintaining the confidentiality of trade secrets, intellectual property, or classified information, or providing any service or benefit sought by a data principal who is an employee.

In practice, this exemption encompasses most standard HR operations. Maintaining personnel files, processing payroll, administering leave and attendance, and providing requested benefits all fall under it. None of these operations require standalone consent forms.

However, this statutory exemption has distinct boundaries. It covers processing genuinely tied to the employment relationship, not every conceivable use of employee data. Marketing an unrelated product to staff or sharing data with third parties outside a legitimate business purpose falls outside it. Treat Section 7(i) as a foundation for everyday employee data privacy work, not a blanket exemption. Notice and security obligations remain in effect once Phase 3 commences.

Children’s Data and Verifiable Parental Consent

Section 9 sets tighter rules for anyone under 18. A data fiduciary needs verifiable consent from a parent or guardian before processing a child’s personal data. It also cannot track or monitor behavior or target advertising at children.

This matters to employers mainly through apprenticeship and internship programs that involve minors, and through benefit schemes that collect data about employees’ dependent children. Where a program knowingly processes a minor’s data, build verifiable parental consent into onboarding rather than treating it as a secondary consideration.

Significant Data Fiduciary Obligations

The government can notify certain data fiduciaries as “significant.” The criteria include the volume and sensitivity of the personal data processed, as well as the risk of harm involved. Large HR and payroll processors, sizable staffing firms, and organizations that hold sensitive data categories are likely candidates once notification begins.

A significant data fiduciary carries extra duties under Section 10. It must appoint a Data Protection Officer based in India, who reports to its board. An independent data auditor and periodic audits are also required. Additionally, it must conduct a Data Protection Impact Assessment, a documented review of the risk that a processing activity poses to data subjects.

Personal Data Breach Notification Requirements

Under Section 8(6), a data fiduciary that suffers a personal data breach must notify both the Data Protection Board and each affected data principal. The DPDP Rules, 2025 set the format and timeline: an initial notice without delay, followed by a more detailed report to the Board.

For HR teams, this makes breach response a shared exercise rather than something IT handles alone. Payroll data, online attendance management, and background-verification files are under HR’s purview. Any incident-response plan needs HR represented from the first hour, not integrated later.

Penalties for Non-Compliance

The Schedule to the Act sets a penalty ceiling for each kind of default. The Data Protection Board decides the actual amount based on the nature, duration, and impact of the breach.

Default Maximum penalty
Failure to take reasonable security safeguards (Sec. 8(5)) ₹250 crore
Failure to notify a personal data breach (Sec. 8(6)) ₹200 crore
Breach of children’s data obligations (Sec. 9) ₹200 crore
Breach of significant data fiduciary obligations (Sec. 10) ₹150 crore
Breach of a data principal’s own duties (Sec. 15) ₹10,000
Any other breach of the Act or Rules ₹50 crore

These are ceilings, not fixed fines, and they apply once Phase 3 and the Board’s adjudicatory process are both operating. The scale still matters for planning. A ₹250 crore maximum for weak security safeguards treats data protection as a major financial non-compliance, not a minor paperwork lapse.

What HR and Payroll Teams Should do Now

Waiting until May 2027 is the costliest option. Notice templates, consent workflows, and retention policies all take time to build and test.

Start by mapping what employee data you hold, where it lives, and who can access it. Most HR teams are surprised by how many systems, HRMS, payroll, attendance, and verification vendors, each hold overlapping copies of the same records.

Next, review retention. Data kept “just in case” past its real business purpose is exactly what Section 8 targets. Tie retention periods to a genuine reason, and put an actual deletion process behind the policy.

Finally, draft your notice-and-consent language now. A cyber security policy that already reflects DPDP principles gives your organization a head start on employee data privacy. This is far more effective than attempting to adapt under pressure when Phase 3 arrives.

Compliance Checklist for HR and Business Teams

  1. Map every system that stores employee personal data, from your HRMS to background verification vendors.
  2. Classify which processing relies on the Section 7(i) exemption and which would need explicit consent.
  3. Review data retention periods against real business or legal need, not habit.
  4. Confirm access controls around payroll, biometric, and attendance data specifically.
  5. Build an incident-response plan for a personal data breach that includes HR from the outset, not just IT and legal.
  6. Assess whether your data volumes could bring you within the significant data fiduciary criteria once notified.
  7. Track the Data Protection Board’s staffing and any further notifications as signals of enforcement readiness.

Conclusion

The DPDP Act 2023 is not yet the law employers will live with day-to-day, but May 2027 is closer than the phased timeline makes it feel. Section 7(i) gives HR significant flexibility for routine employee data processing, and that’s worth understanding precisely rather than assuming the Act doesn’t apply yet.

Notice templates, retention schedules, and access controls built now turn Phase 3 into a milestone rather than a crisis. Strengthening employee data privacy ahead of the deadline is far more cost-effective than retrofitting systems under pressure. factoHR’s HR and payroll platform treats data security and access control as core infrastructure, so the systems that hold your employee data are ready before the law formally requires them.

Frequently Asked Questions

Is the DPDP Act 2023 Currently in Force?

Partially. Provisions on definitions and the establishment of the Data Protection Board took effect on 13 November 2025. Consent Manager registration begins in November 2026. Core obligations around notice, consent, and breach reporting commence on 13 May 2027.

Does HR Need Employee Consent to Process Payroll and Personnel Data?

Not usually. Section 7(i) permits processing for employment purposes and related employer interests without separate consent each time. Processing unrelated to the employment relationship still needs its own legal basis.

What Counts as a Significant Data Fiduciary?

An organization the government formally notifies, based on the volume and sensitivity of personal data it processes and the risk of harm involved. No notifications have been issued yet, since this falls under Phase 3.

What is the Maximum Penalty under the DPDP Act 2023?

Up to ₹250 crore for a single failure to implement reasonable security safeguards. Other defaults carry lower ceilings, from ₹10,000 for a breach of duties by a data principal up to ₹200 crore for breach-notification or children’s-data failures.

Who Enforces the DPDP Act 2023?

The Data Protection Board of India was established in November 2025. As of publication, the government had not appointed its Chairperson or Members, which affects how quickly it can adjudicate cases once Phase 3 obligations commence.

Meet the author
Chief Technology Officer (CTO)

Niraj Karelia, Co-founder and CTO at factoHR, brings 22 years of experience across technology, digital transformation, security, and system operations. With a Bachelor’s degree in Computer Engineering, he ensures content is technically accurate, practical, and aligned with how real HR and payroll systems function. Niraj’s deep expertise in product architecture and security helps translate complex technical concepts into clear, reliable insights for readers.

Grow your business with factoHR today

Focus on the significant decision-making tasks, transfer all your common repetitive HR tasks to factoHR and see the things falling into their place.

Get a Free Trial