Quick answer: The DPDP Act India is India’s first comprehensive data privacy law, and its employer-facing obligations commence on 13 May 2027 they are not in force today. Employee data is fully in scope, with no employer carve-out. But two features work in a US company’s favour: processing “for the purposes of employment” is a legitimate use under Section 7(i), so consent is largely not required; and Section 16 operates as a negative list, so transfers to the United States are permitted with no adequacy finding, no Standard Contractual Clauses and no transfer impact assessment. The maximum penalty is ₹250 crore per breach event capped, not multiplied per record.
Most published guidance for US employers on this topic is out of date. The best-known piece predates the DPDP Rules 2025 entirely, and at least one major EOR’s India guide does not mention the Act at all. What follows is current as at September 2026 and says plainly which provisions are actually in force.
When Does the DPDP Act Start Binding Employers?
13 May 2027. The Act received assent in 2023, but commencement is staggered by Rule 1 of the Digital Personal Data Protection Rules, 2025 (notified 13 November 2025, G.S.R. 846(E)):
- 13 November 2025 Phase I, live now. Rules 1, 2 and 17–21, plus Act sections 1(2), 2, 18–26, 35 and 38–43. This constitutes the Data Protection Board and the appeal framework. No employer obligations.
- 13 November 2026 Phase II. Rule 4: Consent Manager registration opens. Two months away.
- 13 May 2027 Phase III, full enforcement. Act Sections 3–17 and Rules 3, 5–16, 22 and 23: notice, consent, security safeguards, breach notification, children’s data, Significant Data Fiduciary obligations, retention, grievance redressal and cross-border transfer. This is the date that binds employers.
Get the framing right in your risk register. Sections 5, 7, 8 and 16 the provisions this page is mostly about are not operative today. Anything you read describing them as current law is wrong. What is true is that the work they require takes months, which is why 13 May 2027 is a 2026 project.

Figure: Three phases and a penalty schedule. Only the third binds employers.
What Is the DPDP Act?
India’s first comprehensive data privacy law. It is narrower than GDPR it covers only digital personal data but it is national, it has a dedicated regulator in the Data Protection Board of India, and it reaches HR operations directly. Payroll records, biometric attendance, performance reviews and background-check data are all in scope the moment they are processed digitally.
The penalty schedule is where boards pay attention. Up to ₹250 crore (about $28 million) for failure to take reasonable security safeguards; ₹200 crore for breach-notification and children’s-data failures; ₹150 crore for Significant Data Fiduciary obligations; ₹50 crore residual.
India is not moving alone, and that is the useful framing for a US audience. GDPR landed in 2018, Brazil’s LGPD in 2020, China’s PIPL in 2021, and roughly twenty US states now have comprehensive consumer privacy laws, with Indiana, Kentucky and Rhode Island effective 1 January 2026. The direction of travel is one-way. A company that builds a DPDP-ready consent and vendor framework is largely building the framework it will need everywhere else.
Who Does the DPDP Act Apply To?
- Any organisation processing digital personal data connected to India including a US company whose India-based employees’ HR data is processed digitally, regardless of where that processing physically happens.
- Employers are “Data Fiduciaries.” Payroll vendors, HRIS platforms, background-check providers and EOR providers processing that data on your behalf are “Data Processors.” The fiduciary carries the obligation; the processor carries the contract. Section 8(1) makes you responsible for compliance regardless of what your contracts say.
- Significant Data Fiduciaries face additional obligations a Data Protection Officer based in India, data protection impact assessments, independent audits, and algorithmic due diligence once notified by the government based on volume and sensitivity. No entities have been designated as SDFs to date.
- Children and dependants. Anyone under 18 requires verifiable parental consent under Section 9 a stricter threshold than GDPR’s 13–16. A spouse or child enrolled in your group insurance is a Data Principal in their own right.
Do You Need Employee Consent Under the DPDP Act?
Largely no and the boilerplate consent clause sitting in your Indian appointment letter is doing no legal work.
Section 4(1) provides two routes to lawful processing: consent, or a “certain legitimate use”. Section 7(i) makes employment one of those legitimate uses, in terms:
“…for the purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee.”
Legitimate use is an alternative basis, not a fallback you reach for when consent fails. Payroll, benefits administration, attendance, performance management and loss-prevention all sit inside it.
Three qualifications, each of which matters in practice:
- Notice is not legally required for legitimate-use processing. Section 5 ties the notice duty to a request for consent under Section 6. Where you are not seeking consent, there is no statutory notice obligation. We would still recommend a transparency notice — it is cheap, it is good practice, and it is required the moment any processing does rest on consent.
- Pre-employment is a grey zone. It is not settled whether “the purposes of employment” covers shortlisting, interviews and background checks on candidates who are not yet employees. Do not assume it does.
- Dependants are not covered by Section 7(i). The clause is drafted around “a Data Principal who is an employee.” A spouse or child enrolled in insurance needs its own basis in practice, consent, and verifiable parental consent for anyone under 18.
What Still Binds You Even Without Consent?
Choosing legitimate use removes the consent and notice machinery. It removes nothing else. All of the following apply regardless of your legal basis:
Obligation | Provision | What it means in practice |
|---|---|---|
Overall compliance responsibility | s.8(1) | You are accountable even where a processor is at fault, and regardless of what the contract says |
Processor only under a valid contract | s.8(2) | Every vendor touching India employee data needs a written data-processing contract |
Accuracy and completeness | s.8(3) | Where data is used for a decision affecting the person, or disclosed onward |
Reasonable security safeguards | s.8(5), Rule 6 | The obligation carrying the ₹250 crore maximum penalty |
Breach notification | s.8(6), Rule 7 | Notify the Data Protection Board and every affected person |
Erasure and retention | s.8(7), Rule 8 | Erase once the purpose is exhausted — subject to statutory retention under PF, ESI, Shops & Establishments and income-tax law |
Published contact point | s.8(9), Rule 9 | A named contact for data protection queries |
Grievance redressal | s.8(10) | A working mechanism, not a mailbox |
Data Principal rights | ss.11–14, Rule 14 | Access, correction, erasure, grievance and nomination |
One precision point on retention. The fixed retention periods in Rule 8 and Schedule III attach only to specified classes large e-commerce, online gaming and social media intermediaries above user thresholds. They do not impose a generic deletion clock on ordinary employers’ HR records. Your retention driver remains the purpose test in Section 8(7), read with statutory retention requirements elsewhere.

Figure: Where consent is needed, where it is not, and what binds you either way.
What Is the US Equivalent of the DPDP Act?
A single federal CCPA which the United States does not have. The comparison worth making runs three ways, because most US privacy teams think in GDPR terms as well.
The issue | United States | GDPR (for reference) | India — DPDP |
|---|---|---|---|
Framework | No federal omnibus law. Sectoral (HIPAA, GLBA) plus roughly 20 state statutes, each with its own thresholds. | One regulation across the EEA. | One national law, covering digital personal data only. |
Employee data | HIPAA expressly excludes employment records held by a covered entity as an employer. Under CCPA/CPRA, California’s employer exemption expired 1 January 2023. | Fully in scope. | Fully in scope. No employer carve-out. |
Legal basis | Notice and opt-out, in most states. | Six lawful bases, including legitimate interests. | Consent, or one of the legitimate uses in s.7 — including employment. |
Transfers to the US | n/a | Adequacy, SCCs, BCRs or a transfer impact assessment. | Permitted. s.16 is a negative list and no country has been restricted. No SCCs, BCRs or TIA required. |
Penalty | California: $2,663 per violation, $7,988 if intentional per violation. | Up to 4% of global turnover. | Up to ₹250 crore per breach event capped, not per-record. |
Regulator | State attorneys general; the CPPA in California. | National supervisory authorities. | Data Protection Board of India, with appeal to TDSAT. |
Two of those rows are genuinely good news and worth taking to your privacy counsel. India needs no transfer machinery, and India’s penalties are capped per event rather than multiplied per affected individual which inverts the usual “US litigation risk versus India regulatory risk” intuition for a company with a large India headcount.

Figure: DPDP against GDPR and the US patchwork, from a US employer’s seat.
What Changed Compared With Before?
Aspect | Before | Now / from 13 May 2027 |
|---|---|---|
Legal framework | Thin coverage under the IT Act, 2000 and the 2011 SPDI Rules | Dedicated DPDP Act, 2023 plus DPDP Rules, 2025, phased to 13 May 2027 |
Consent standard | Implied consent widely accepted | Free, specific, informed, unconditional and unambiguous, with clear affirmative action — where consent is the basis at all |
Employee data | Governed largely by contract and practice | Expressly in scope, with employment as a named legitimate use |
Breach notification | No general obligation | Mandatory notification to the Board and to every affected person |
Cross-border transfer | Sectoral restrictions only | Permissive by default under s.16; sectoral rules (for example the RBI payment-data directive) preserved by s.16(2) |
Maximum penalty | ₹5 crore under the IT Act | ₹250 crore per breach event |
Regulator | None dedicated | Data Protection Board of India, constituted from 13 November 2025 |
How Does the DPDP Act Affect US Companies in Practice?
The practical exposure is not the fine. It is that your India HR stack is a chain of data processors HRIS, payroll vendor, background-check provider, attendance and biometric system, and your EOR and under Section 8(1) you are accountable for all of it, whatever the contracts say.
Most US companies discover at contract-review time that not one of their India vendor agreements contains a data-processing agreement addressing DPDP breach notification, retention or sub-processors. Renegotiating a handful of vendor contracts takes months, which is the real reason 13 May 2027 is not a 2027 problem.

Figure: Your India HR data chain and what each contract needs to say.
Can You Transfer India Employee Data to the United States?
Yes, and you need no transfer machinery to do it. This is the single most useful thing on this page for a US privacy team, and it is under-reported.
Section 16(1) empowers the Central Government to restrict transfers to countries it notifies. That is a blacklist, not an adequacy regime and as of September 2026 no country has been notified. Transfers are therefore permitted by default. The Act does not require Standard Contractual Clauses, Binding Corporate Rules or a transfer impact assessment. Rule 15 of the DPDP Rules 2025 adds only that a Data Fiduciary must meet such requirements as the Government may specify in respect of making data available to a foreign State or its agencies and no such order has been issued.
Two caveats:
- Sectoral localisation survives. Section 16(2) preserves any law imposing a higher standard. The RBI’s payment-system data directive, and SEBI and IRDAI record-keeping requirements, still apply where relevant.
- A dormant localisation power exists. Rule 13(4) allows the Government to require that categories of data held by a Significant Data Fiduciary not leave India. No categories have been specified and no SDFs designated but it is a switch that exists.
How Should You Prepare for the DPDP Act?
Treat 2026 as the build year. Six items, and the first is the input to the rest.
Do this | Why | Owner |
|---|---|---|
Inventory every vendor that touches India employee data, including your EOR | You cannot paper a chain you have not mapped | Legal + IT |
Put a DPDP-specific data-processing agreement into each contract breach timelines, retention, named sub-processors, auditable security | Required by s.8(2); the negotiation is what takes the months | Legal |
Rewrite consent language in employment agreements and HR policies | Not because consent is required for employment processing, but because the boilerplate is misleading and the consent you do need dependants, optional programmes has to meet the standard | HR + legal |
Build a data map and a retention schedule keyed to purpose, not to a fixed clock | s.8(7) is a purpose test, read with statutory retention under PF, ESI and tax law | IT |
Write and rehearse a breach-notification runbook | s.8(6) and Rule 7 require notice to the Board and every affected person; you do not want to design that on the day | Security + legal |
Decide your position on pre-employment screening | It sits in a grey zone under s.7(i). Pick a basis now and document the reasoning | Legal |
Where Does DPDP Sit in Your India Expansion?
This is the one item on the hub you can safely sequence after your first hire but not much after.
If you expect to be above fifty India employees by mid-2027, start the vendor and consent work in 2026, while it is a project with a plan. In 2027 it becomes an incident response, and the difference between those two things is usually a quarter of legal time and a great deal of goodwill.
If you are hiring through an EOR, ask a single question at diligence: does the EOR agreement already carry DPDP data-processing terms, covering breach notification, retention and sub-processors? If it does, most of this work is already done for the employment data. If it does not, you have found your first action item.
Worth a second opinion on your data chain? Send us the list of vendors touching your India employee data and we will tell you which contracts need DPDP terms before May 2027 and which already have them. If your EOR agreement covers it, we will say so including when that EOR is not us. Talk to an India compliance specialist · or go back to the India Legislative Updates hub.
Frequently Asked Questions
Does the DPDP Act apply to employee data in India?
Yes, fully. There is no employer carve-out. Payroll, biometric attendance, performance and background-check data are all in scope once processed digitally. The employer-facing obligations commence on 13 May 2027.
Do employers need employee consent to process HR data under the DPDP Act?
Largely no. Section 7(i) makes processing “for the purposes of employment” a legitimate use, which is an alternative legal basis to consent under Section 4(1)(b) not a fallback from it. Consent is still needed for processing outside employment purposes and for dependants’ data.
Is a consent clause in the appointment letter valid?
It is generally unnecessary for employment processing, and where consent genuinely is the basis, boilerplate buried in a contract signed years ago is unlikely to meet the DPDP standard of free, specific, informed, unconditional and unambiguous consent given by clear affirmative action. Separate the two: rely on legitimate use for employment, and take real consent where you actually need it.
Does the DPDP Act cover employees’ family members?
Section 7(i) is drafted around “a Data Principal who is an employee”, so it does not obviously extend to a spouse or child enrolled in group insurance. The conservative position is that dependants need their own basis consent and that anyone under 18 requires verifiable parental consent under Section 9.
Can we transfer India employee data to the US?
Yes. Section 16 works as a negative list: the Government may restrict transfers to notified countries, and none has been notified. No adequacy finding, Standard Contractual Clauses, Binding Corporate Rules or transfer impact assessment is required. Sectoral rules such as the RBI’s payment-data directive still apply where relevant.
Is there data localisation in India under DPDP?
Not generally. Rule 13(4) gives the Government a dormant power to require that specified categories of data held by a Significant Data Fiduciary stay in India, but no categories have been specified and no SDFs designated. Sectoral localisation notably RBI payment-system data is separate and does apply.
How long can we keep ex-employee records?
The test is purpose-based: erase once the purpose is exhausted, under Section 8(7), unless retention is required by another law. In practice, provident fund, ESI, Shops & Establishments and income-tax retention requirements set the floor. The fixed periods in Rule 8 and Schedule III apply to specified classes of large platform, not to ordinary employers.
Can we monitor employee devices and productivity under the DPDP Act?
Monitoring for loss prevention and protection of trade secrets falls within the wording of Section 7(i). That does not make undisclosed monitoring wise: transparency, proportionality and a documented purpose remain the practical standard, and the security and grievance obligations apply regardless of your legal basis.
What are the penalties under the DPDP Act?
Up to ₹250 crore for failure to take reasonable security safeguards; ₹200 crore for breach-notification and children’s-data failures; ₹150 crore for Significant Data Fiduciary obligations; ₹50 crore residual. These are capped amounts per breach event, not per affected record.
When does DPDP enforcement actually start?
Phase I has been live since 13 November 2025 but constitutes only the Data Protection Board and the appeal framework. Consent Manager registration opens 13 November 2026. The substantive employer obligations notice, consent, security, breach notification, retention, cross-border transfer commence 13 May 2027.
Are we a Significant Data Fiduciary?
Probably not, and nobody is yet. The Government designates SDFs based on volume and sensitivity of data, risk to data principals, and effect on sovereignty and public order. No designations have been made. If designated, you would need an India-based Data Protection Officer, DPIAs, independent audits and algorithmic due diligence.
Does the DPDP Act apply if our EOR is the legal employer?
Both parties have roles. The EOR, as legal employer, will generally be a Data Fiduciary for the employment relationship, while you may be a fiduciary in your own right for data you process directly. In either case the practical step is the same: make sure the EOR agreement carries DPDP data-processing terms.
Where Can You Read the Official DPDP Notifications?
- Digital Personal Data Protection Rules, 2025 notified Press Information Bureau, 14 November 2025
- The Digital Personal Data Protection Act, 2023 MeitY official text (PDF)
- Digital Personal Data Protection Act, 2023 India Code
- DPDP Rules, 2025 PIB explainer (PDF)
- US comparison: California Attorney General CCPA · HHS HIPAA laws and regulations · FTC Gramm-Leach-Bliley Act
Sourcing standard. Every section and rule number above is cited to the Act or to the DPDP Rules, 2025 as notified not to the January 2025 draft, whose rule numbering differs and is still widely quoted. Cross-border transfer is Rule 15, not Rule 14; Significant Data Fiduciary obligations are Rule 13, not Rule 12. Where the position is genuinely unsettled pre-employment screening, dependants’ data we say so rather than pick a side. Interpretation is ours. This is not legal advice.
