DPDP Act India

The DPDP Act for US Employers

Quick answer: The DPDP Act India is India’s first comprehensive data privacy law, and its employer-facing obligations commence on 13 May 2027 they are not in force today. Employee data is fully in scope, with

Table of Contents

Quick answer: The DPDP Act India is India’s first comprehensive data privacy law, and its employer-facing obligations commence on 13 May 2027  they are not in force today. Employee data is fully in scope, with no employer carve-out. But two features work in a US company’s favour: processing “for the purposes of employment” is a legitimate use under Section 7(i), so consent is largely not required; and Section 16 operates as a negative list, so transfers to the United States are permitted with no adequacy finding, no Standard Contractual Clauses and no transfer impact assessment. The maximum penalty is ₹250 crore per breach event capped, not multiplied per record.

Most published guidance for US employers on this topic is out of date. The best-known piece predates the DPDP Rules 2025 entirely, and at least one major EOR’s India guide does not mention the Act at all. What follows is current as at September 2026 and says plainly which provisions are actually in force.

 

When Does the DPDP Act Start Binding Employers?

13 May 2027. The Act received assent in 2023, but commencement is staggered by Rule 1 of the Digital Personal Data Protection Rules, 2025 (notified 13 November 2025, G.S.R. 846(E)):

  • 13 November 2025 Phase I, live now. Rules 1, 2 and 17–21, plus Act sections 1(2), 2, 18–26, 35 and 38–43. This constitutes the Data Protection Board and the appeal framework. No employer obligations.
  • 13 November 2026 Phase II. Rule 4: Consent Manager registration opens. Two months away.
  • 13 May 2027 Phase III, full enforcement. Act Sections 3–17 and Rules 3, 5–16, 22 and 23: notice, consent, security safeguards, breach notification, children’s data, Significant Data Fiduciary obligations, retention, grievance redressal and cross-border transfer. This is the date that binds employers.

 

Get the framing right in your risk register. Sections 5, 7, 8 and 16  the provisions this page is mostly about are not operative today. Anything you read describing them as current law is wrong. What is true is that the work they require takes months, which is why 13 May 2027 is a 2026 project.

dpdp act india phased rollout penalties

Figure: Three phases and a penalty schedule. Only the third binds employers.

What Is the DPDP Act?

India’s first comprehensive data privacy law. It is narrower than GDPR it covers only digital personal data but it is national, it has a dedicated regulator in the Data Protection Board of India, and it reaches HR operations directly. Payroll records, biometric attendance, performance reviews and background-check data are all in scope the moment they are processed digitally.

The penalty schedule is where boards pay attention. Up to ₹250 crore (about $28 million) for failure to take reasonable security safeguards; ₹200 crore for breach-notification and children’s-data failures; ₹150 crore for Significant Data Fiduciary obligations; ₹50 crore residual.

India is not moving alone, and that is the useful framing for a US audience. GDPR landed in 2018, Brazil’s LGPD in 2020, China’s PIPL in 2021, and roughly twenty US states now have comprehensive consumer privacy laws, with Indiana, Kentucky and Rhode Island effective 1 January 2026. The direction of travel is one-way. A company that builds a DPDP-ready consent and vendor framework is largely building the framework it will need everywhere else.

Who Does the DPDP Act Apply To?

  • Any organisation processing digital personal data connected to India including a US company whose India-based employees’ HR data is processed digitally, regardless of where that processing physically happens.
  • Employers are “Data Fiduciaries.” Payroll vendors, HRIS platforms, background-check providers and EOR providers processing that data on your behalf are “Data Processors.” The fiduciary carries the obligation; the processor carries the contract. Section 8(1) makes you responsible for compliance regardless of what your contracts say.
  • Significant Data Fiduciaries face additional obligations a Data Protection Officer based in India, data protection impact assessments, independent audits, and algorithmic due diligence once notified by the government based on volume and sensitivity. No entities have been designated as SDFs to date.
  • Children and dependants. Anyone under 18 requires verifiable parental consent under Section 9 a stricter threshold than GDPR’s 13–16. A spouse or child enrolled in your group insurance is a Data Principal in their own right.

Do You Need Employee Consent Under the DPDP Act?

Largely no and the boilerplate consent clause sitting in your Indian appointment letter is doing no legal work.

Section 4(1) provides two routes to lawful processing: consent, or a “certain legitimate use”. Section 7(i) makes employment one of those legitimate uses, in terms:

“…for the purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee.”

Legitimate use is an alternative basis, not a fallback you reach for when consent fails. Payroll, benefits administration, attendance, performance management and loss-prevention all sit inside it.

Three qualifications, each of which matters in practice:

  • Notice is not legally required for legitimate-use processing. Section 5 ties the notice duty to a request for consent under Section 6. Where you are not seeking consent, there is no statutory notice obligation. We would still recommend a transparency notice — it is cheap, it is good practice, and it is required the moment any processing does rest on consent.
  • Pre-employment is a grey zone. It is not settled whether “the purposes of employment” covers shortlisting, interviews and background checks on candidates who are not yet employees. Do not assume it does.
  • Dependants are not covered by Section 7(i). The clause is drafted around “a Data Principal who is an employee.” A spouse or child enrolled in insurance needs its own basis in practice, consent, and verifiable parental consent for anyone under 18.

What Still Binds You Even Without Consent?

Choosing legitimate use removes the consent and notice machinery. It removes nothing else. All of the following apply regardless of your legal basis:

Obligation

Provision

What it means in practice

Overall compliance responsibility

s.8(1)

You are accountable even where a processor is at fault, and regardless of what the contract says

Processor only under a valid contract

s.8(2)

Every vendor touching India employee data needs a written data-processing contract

Accuracy and completeness

s.8(3)

Where data is used for a decision affecting the person, or disclosed onward

Reasonable security safeguards

s.8(5), Rule 6

The obligation carrying the ₹250 crore maximum penalty

Breach notification

s.8(6), Rule 7

Notify the Data Protection Board and every affected person

Erasure and retention

s.8(7), Rule 8

Erase once the purpose is exhausted — subject to statutory retention under PF, ESI, Shops & Establishments and income-tax law

Published contact point

s.8(9), Rule 9

A named contact for data protection queries

Grievance redressal

s.8(10)

A working mechanism, not a mailbox

Data Principal rights

ss.11–14, Rule 14

Access, correction, erasure, grievance and nomination

 

One precision point on retention. The fixed retention periods in Rule 8 and Schedule III attach only to specified classes large e-commerce, online gaming and social media intermediaries above user thresholds. They do not impose a generic deletion clock on ordinary employers’ HR records. Your retention driver remains the purpose test in Section 8(7), read with statutory retention requirements elsewhere.

dpdp act employee data when consent is needed

Figure: Where consent is needed, where it is not, and what binds you either way.

What Is the US Equivalent of the DPDP Act?

A single federal CCPA which the United States does not have. The comparison worth making runs three ways, because most US privacy teams think in GDPR terms as well.

The issue

United States

GDPR (for reference)

India — DPDP

Framework

No federal omnibus law. Sectoral (HIPAA, GLBA) plus roughly 20 state statutes, each with its own thresholds.

One regulation across the EEA.

One national law, covering digital personal data only.

Employee data

HIPAA expressly excludes employment records held by a covered entity as an employer. Under CCPA/CPRA, California’s employer exemption expired 1 January 2023.

Fully in scope.

Fully in scope. No employer carve-out.

Legal basis

Notice and opt-out, in most states.

Six lawful bases, including legitimate interests.

Consent, or one of the legitimate uses in s.7 — including employment.

Transfers to the US

n/a

Adequacy, SCCs, BCRs or a transfer impact assessment.

Permitted. s.16 is a negative list and no country has been restricted. No SCCs, BCRs or TIA required.

Penalty

California: $2,663 per violation, $7,988 if intentional  per violation.

Up to 4% of global turnover.

Up to ₹250 crore per breach event  capped, not per-record.

Regulator

State attorneys general; the CPPA in California.

National supervisory authorities.

Data Protection Board of India, with appeal to TDSAT.

 

Two of those rows are genuinely good news and worth taking to your privacy counsel. India needs no transfer machinery, and India’s penalties are capped per event rather than multiplied per affected individual which inverts the usual “US litigation risk versus India regulatory risk” intuition for a company with a large India headcount.

dpdp act vs gdpr ccpa us employer comparison

Figure: DPDP against GDPR and the US patchwork, from a US employer’s seat.

What Changed Compared With Before?

Aspect

Before

Now / from 13 May 2027

Legal framework

Thin coverage under the IT Act, 2000 and the 2011 SPDI Rules

Dedicated DPDP Act, 2023 plus DPDP Rules, 2025, phased to 13 May 2027

Consent standard

Implied consent widely accepted

Free, specific, informed, unconditional and unambiguous, with clear affirmative action — where consent is the basis at all

Employee data

Governed largely by contract and practice

Expressly in scope, with employment as a named legitimate use

Breach notification

No general obligation

Mandatory notification to the Board and to every affected person

Cross-border transfer

Sectoral restrictions only

Permissive by default under s.16; sectoral rules (for example the RBI payment-data directive) preserved by s.16(2)

Maximum penalty

₹5 crore under the IT Act

₹250 crore per breach event

Regulator

None dedicated

Data Protection Board of India, constituted from 13 November 2025

 

How Does the DPDP Act Affect US Companies in Practice?

The practical exposure is not the fine. It is that your India HR stack is a chain of data processors HRIS, payroll vendor, background-check provider, attendance and biometric system, and your EOR  and under Section 8(1) you are accountable for all of it, whatever the contracts say.

Most US companies discover at contract-review time that not one of their India vendor agreements contains a data-processing agreement addressing DPDP breach notification, retention or sub-processors. Renegotiating a handful of vendor contracts takes months, which is the real reason 13 May 2027 is not a 2027 problem.

dpdp act india hr data vendor chain

Figure: Your India HR data chain and what each contract needs to say.

Can You Transfer India Employee Data to the United States?

Yes, and you need no transfer machinery to do it. This is the single most useful thing on this page for a US privacy team, and it is under-reported.

Section 16(1) empowers the Central Government to restrict transfers to countries it notifies. That is a blacklist, not an adequacy regime and as of September 2026 no country has been notified. Transfers are therefore permitted by default. The Act does not require Standard Contractual Clauses, Binding Corporate Rules or a transfer impact assessment. Rule 15 of the DPDP Rules 2025 adds only that a Data Fiduciary must meet such requirements as the Government may specify in respect of making data available to a foreign State or its agencies and no such order has been issued.

Two caveats:

  • Sectoral localisation survives. Section 16(2) preserves any law imposing a higher standard. The RBI’s payment-system data directive, and SEBI and IRDAI record-keeping requirements, still apply where relevant.
  • A dormant localisation power exists. Rule 13(4) allows the Government to require that categories of data held by a Significant Data Fiduciary not leave India. No categories have been specified and no SDFs designated  but it is a switch that exists.

How Should You Prepare for the DPDP Act?

Treat 2026 as the build year. Six items, and the first is the input to the rest.

Do this

Why

Owner

Inventory every vendor that touches India employee data, including your EOR

You cannot paper a chain you have not mapped

Legal + IT

Put a DPDP-specific data-processing agreement into each contract breach timelines, retention, named sub-processors, auditable security

Required by s.8(2); the negotiation is what takes the months

Legal

Rewrite consent language in employment agreements and HR policies

Not because consent is required for employment processing, but because the boilerplate is misleading and the consent you do need dependants, optional programmes has to meet the standard

HR + legal

Build a data map and a retention schedule keyed to purpose, not to a fixed clock

s.8(7) is a purpose test, read with statutory retention under PF, ESI and tax law

IT

Write and rehearse a breach-notification runbook

s.8(6) and Rule 7 require notice to the Board and every affected person; you do not want to design that on the day

Security + legal

Decide your position on pre-employment screening

It sits in a grey zone under s.7(i). Pick a basis now and document the reasoning

Legal

 

Where Does DPDP Sit in Your India Expansion?

This is the one item on the hub you can safely sequence after your first hire but not much after.

If you expect to be above fifty India employees by mid-2027, start the vendor and consent work in 2026, while it is a project with a plan. In 2027 it becomes an incident response, and the difference between those two things is usually a quarter of legal time and a great deal of goodwill.

If you are hiring through an EOR, ask a single question at diligence: does the EOR agreement already carry DPDP data-processing terms, covering breach notification, retention and sub-processors? If it does, most of this work is already done for the employment data. If it does not, you have found your first action item.

Worth a second opinion on your data chain? Send us the list of vendors touching your India employee data and we will tell you which contracts need DPDP terms before May 2027 and which already have them. If your EOR agreement covers it, we will say so including when that EOR is not us. Talk to an India compliance specialist · or go back to the India Legislative Updates hub.

Frequently Asked Questions

Does the DPDP Act apply to employee data in India?

Yes, fully. There is no employer carve-out. Payroll, biometric attendance, performance and background-check data are all in scope once processed digitally. The employer-facing obligations commence on 13 May 2027.

Do employers need employee consent to process HR data under the DPDP Act?

Largely no. Section 7(i) makes processing “for the purposes of employment” a legitimate use, which is an alternative legal basis to consent under Section 4(1)(b) not a fallback from it. Consent is still needed for processing outside employment purposes and for dependants’ data.

Is a consent clause in the appointment letter valid?

It is generally unnecessary for employment processing, and where consent genuinely is the basis, boilerplate buried in a contract signed years ago is unlikely to meet the DPDP standard of free, specific, informed, unconditional and unambiguous consent given by clear affirmative action. Separate the two: rely on legitimate use for employment, and take real consent where you actually need it.

Does the DPDP Act cover employees’ family members?

Section 7(i) is drafted around “a Data Principal who is an employee”, so it does not obviously extend to a spouse or child enrolled in group insurance. The conservative position is that dependants need their own basis consent and that anyone under 18 requires verifiable parental consent under Section 9.

Can we transfer India employee data to the US?

Yes. Section 16 works as a negative list: the Government may restrict transfers to notified countries, and none has been notified. No adequacy finding, Standard Contractual Clauses, Binding Corporate Rules or transfer impact assessment is required. Sectoral rules such as the RBI’s payment-data directive still apply where relevant.

Is there data localisation in India under DPDP?

Not generally. Rule 13(4) gives the Government a dormant power to require that specified categories of data held by a Significant Data Fiduciary stay in India, but no categories have been specified and no SDFs designated. Sectoral localisation notably RBI payment-system data is separate and does apply.

How long can we keep ex-employee records?

The test is purpose-based: erase once the purpose is exhausted, under Section 8(7), unless retention is required by another law. In practice, provident fund, ESI, Shops & Establishments and income-tax retention requirements set the floor. The fixed periods in Rule 8 and Schedule III apply to specified classes of large platform, not to ordinary employers.

Can we monitor employee devices and productivity under the DPDP Act?

Monitoring for loss prevention and protection of trade secrets falls within the wording of Section 7(i). That does not make undisclosed monitoring wise: transparency, proportionality and a documented purpose remain the practical standard, and the security and grievance obligations apply regardless of your legal basis.

What are the penalties under the DPDP Act?

Up to ₹250 crore for failure to take reasonable security safeguards; ₹200 crore for breach-notification and children’s-data failures; ₹150 crore for Significant Data Fiduciary obligations; ₹50 crore residual. These are capped amounts per breach event, not per affected record.

When does DPDP enforcement actually start?

Phase I has been live since 13 November 2025 but constitutes only the Data Protection Board and the appeal framework. Consent Manager registration opens 13 November 2026. The substantive employer obligations notice, consent, security, breach notification, retention, cross-border transfer commence 13 May 2027.

Are we a Significant Data Fiduciary?

Probably not, and nobody is yet. The Government designates SDFs based on volume and sensitivity of data, risk to data principals, and effect on sovereignty and public order. No designations have been made. If designated, you would need an India-based Data Protection Officer, DPIAs, independent audits and algorithmic due diligence.

Does the DPDP Act apply if our EOR is the legal employer?

Both parties have roles. The EOR, as legal employer, will generally be a Data Fiduciary for the employment relationship, while you may be a fiduciary in your own right for data you process directly. In either case the practical step is the same: make sure the EOR agreement carries DPDP data-processing terms.

Where Can You Read the Official DPDP Notifications?

 

Sourcing standard. Every section and rule number above is cited to the Act or to the DPDP Rules, 2025 as notified not to the January 2025 draft, whose rule numbering differs and is still widely quoted. Cross-border transfer is Rule 15, not Rule 14; Significant Data Fiduciary obligations are Rule 13, not Rule 12. Where the position is genuinely unsettled pre-employment screening, dependants’ data we say so rather than pick a side. Interpretation is ours. This is not legal advice.

Let's Help You!

Please Share Your Details And Get Connected

Planning to Hire in India?

Don’t Leave Your India Expansion to Guesswork.

Hire in India without the entity hassle. As your Employer of Record (EOR), Husys handles employment, payroll, and compliance, freeing your team to focus entirely on growth.

Trusted by 5,000+ clients and managing 10,000+ employees.

Get your questions answered before making your next move.