- The DPDP Act, 2023 and the DPDP Rules, 2025 are both notified, but they commence in stages. The obligations that actually bind an employer take effect eighteen months from the November 2025 notification, which points to mid May 2027.
- Consent is usually the wrong basis for employee data. Section 7(i) of the Act treats processing for the purposes of employment as a legitimate use, so the consent and notice machinery most guides describe does not fit the employment relationship.
- Cross border transfer is permissive, not restrictive. India uses a negative list: personal data may leave India unless the Central Government notifies a country as restricted. This is close to the opposite of the GDPR position.
- You cannot contract out of it. Section 8(1) makes a Data Fiduciary responsible irrespective of any agreement to the contrary, so an EOR or vendor contract can allocate work but not liability.
- The three year deletion rule people worry about does not apply to employers. It is limited to large e-commerce, gaming and social media platforms named in the Third Schedule.
Need help with India employee data compliance? Talk to an expert!
Discover how Wisemonk creates impactful and reliable content.
If you employ people in India, you have probably been told that India now has a privacy law and that you need to do something about it. That is broadly right, but most of the guidance circulating is written for Indian consumer platforms, and it gives foreign employers three wrong impressions: that the obligations are already live, that you need employee consent, and that moving data out of India is now difficult.
None of those three is accurate for an employment relationship. The law is real and worth preparing for, but the timeline is longer than you have been told, consent is mostly beside the point, and cross border transfer is more permissive under India's framework than under Europe's.
This guide explains what the framework says, what it means when you employ people in India directly or through an Employer of Record, and what is genuinely worth doing now. Every legal point is sourced to the Act, the Rules, or a government publication, and we say clearly where the position is unsettled.
What is India's DPDP framework, in plain terms?
India's data protection regime has two parts. The Digital Personal Data Protection Act, 2023 is the statute, enacted on 11 August 2023. The Digital Personal Data Protection Rules, 2025 are the subordinate rules that make it operational, notified by the Ministry of Electronics and Information Technology in mid November 2025.
The vocabulary is different from the GDPR's, and getting it right matters because the duties attach to the labels.
| DPDP term | What it means | Nearest GDPR equivalent |
|---|---|---|
| Data Principal | The individual the personal data relates to, so your employee | Data subject |
| Data Fiduciary | Whoever determines the purpose and means of processing, alone or with others | Controller |
| Data Processor | Whoever processes personal data on behalf of a Data Fiduciary | Processor |
| Significant Data Fiduciary | A Data Fiduciary the Government notifies as significant, with extra duties | No direct equivalent |
| Consent Manager | A registered Indian company through which individuals manage consent | No equivalent |
| Data Protection Board of India | The adjudicating body that hears complaints and imposes penalties | Supervisory authority |
One structural point to hold on to. The Act covers only digital personal data, meaning data collected in digital form or digitised afterwards. A purely paper record that is never digitised sits outside it, though that is rare in practice for employment files.
Data protection is one strand of a wider India compliance picture, which we map in Payroll Compliance in India: A Guide for Foreign Companies.
Is the DPDP Act actually in force yet?
Partly. This is the single most misreported point about the framework, and it changes what you should be doing this quarter. The Act and the Rules are both notified, but neither commenced all at once. Both use a staged commencement, and the provisions that create employer duties are in the last stage.
The Act's commencement notification brought different sections into force on different dates:
- From 13 November 2025: the definitions in section 2, and the provisions establishing the Data Protection Board of India and related machinery.
- One year from 13 November 2025: a narrow set of provisions, including section 6(9).
- Eighteen months from 13 November 2025: sections 3 to 5, most of section 6, and sections 7 to 17, together with sections 28 to 34. This is the substantive regime: notice, consent, legitimate uses, the general obligations of a Data Fiduciary, breach reporting, data principal rights, cross border transfer, and the penalty provisions.
The Rules follow the same shape. Rules 1, 2 and 17 to 21 commenced on publication, Rule 4 on consent manager registration commences one year after publication, and Rules 3 and 5 to 16 commence eighteen months after publication. Those are the rules on notice, security safeguards, breach intimation, retention, the contact person, significant data fiduciary duties, data principal rights, and transfer outside India.
The practical reading: as of August 2026, the Board and the definitions are live, but the obligations that bind you as an employer, and the penalties attached to them, are not yet in effect. On the eighteen month timetable they arrive in mid May 2027.
Two cautions before you relax. First, eighteen months is a preparation window, not a holiday, and the government has described it as a phased compliance period for exactly that reason. Second, other Indian law already applies to employee data today, including confidentiality and contractual obligations and the reasonable security practices expected under the Information Technology Act, 2000 framework. The DPDP timeline does not suspend those.
This also answers a question we see asked constantly, including in Google's own results for these terms: there is no such instrument as the DPDP Act 2025. The statute is the DPDP Act, 2023. The 2025 instrument is the Rules.
Does the DPDP Act apply to a company outside India?
It depends on where the processing happens and what your business does, and the answer is narrower than most summaries suggest. Section 3 sets two hooks. The Act applies to processing of digital personal data within India, and it also applies to processing outside India where that processing is connected with offering goods or services to individuals in India.
Apply that to a foreign employer and three situations separate out:
- Your India entity or EOR processes the data in India: squarely covered, because the processing happens within India.
- You also sell to customers in India: covered by the extraterritorial limb, independently of employment.
- You only employ in India and sell nowhere near it: less clear. Employing someone is not obviously offering goods or services to them, so the extraterritorial hook may not reach your foreign parent directly.
We would not build a compliance position on the third reading, for three reasons. It is untested, no court or the Board has ruled on it. Your India side is covered regardless and will pass obligations to you contractually. And the cost of behaving as though you are covered is low compared with the cost of being wrong.
Treat this as a question for Indian counsel if it matters commercially to you, and treat the answer as unsettled rather than settled in either direction.
The broader question of which Indian laws reach a foreign company is covered in What US Software Agencies Need to Know About India Labor Law Before Hiring.
Founders working through the compliance list for the first time may find 8 India Compliance Concerns Wisemonk Solves for Startup Founders a useful orientation.
Do you need employee consent to process employee data?
Usually not, and this is where most published guidance actively misleads employers. The Act provides that a Data Fiduciary may process personal data for certain legitimate uses without consent, and one of those legitimate uses is employment. Section 7(i) covers processing:
for the purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee.
That is a wide clause. Running payroll, administering benefits, making statutory filings, managing performance, protecting confidential information and investigating misconduct all sit naturally inside it. So building an employee consent programme, complete with consent notices and withdrawal flows, is usually solving a problem you do not have.
Three qualifications keep this honest:
- It is a use based exemption, not a blanket one: processing that is not for employment purposes or for protecting the employer against loss or liability needs its own basis. Marketing to your employees, or using their data for an unrelated product, is not covered.
- It removes consent, not the other duties: the obligation to keep data secure, to report breaches, to publish a contact point, and to hold data no longer than needed does not depend on the legal basis.
- Consent still matters for some things: if you want to do something genuinely outside the employment purpose, consent becomes the route, and then the notice requirements in section 5 and Rule 3 apply.
The practical output is a short internal record of why you hold each category of employee data, rather than a consent form. That record is also what lets you answer an employee question sensibly.
Benefit administration is one of the clearest employment purposes, and what it covers in India is set out in Employee Benefits in India: Employer Guide 2026.
Unsure which DPDP duties reach your India team?
Wisemonk employs your India team as the legal employer and handles the payroll, filings and employee records that sit behind these obligations.
What rights will your India employees have over their data?
The Act gives individuals four rights: access to information about their data, correction and erasure, grievance redressal, and the ability to nominate someone to exercise their rights. But there is a drafting feature here that almost no guide mentions, and it matters specifically for employment.
The access right in section 11 and the correction and erasure right in section 12 are both expressed as rights of a Data Principal in respect of processing for which she has previously given consent, including consent as referred to in clause (a) of section 7. Clause (a) is the voluntary provision limb. It is not clause (i), the employment limb.
Read literally, that means access and erasure rights attach to consent based processing, and employee data processed under the employment legitimate use may sit outside them. Rule 14 repeats the same framing, directing a request to the Data Fiduciary to whom the individual has previously given consent.
We are flagging this as a genuine textual point, not advising you to rely on it. Our recommendation is the opposite:
- Honour access and correction requests anyway: the reading is untested, the Board may not adopt it, and refusing an employee's request to see or fix their own record is a poor position to defend in any forum.
- Treat grievance redressal as unconditional: the section 13 right is not limited to consent based processing, and Rule 14 requires a published grievance route with a response inside ninety days.
- Handle erasure on its merits: employment records usually have to be retained under other laws, and both the Act and the Rules preserve retention where law requires it.
So the useful conclusion is not that your employees have no rights. It is that a request to delete an employment record is normally answerable by pointing to a retention obligation, rather than by arguing about the legal basis.
Requests of this kind cluster around exits, which is one reason the Full and final settlement in India: 2026 compliance guide matters operationally as well as financially.
Can you still transfer employee data out of India?
Yes, and India's approach here is more permissive than the GDPR's, which surprises most people coming from a European compliance background. There is no adequacy assessment, no standard contractual clauses regime, and no transfer impact assessment in the DPDP framework.
Section 16 sets up a negative list. The Central Government may, by notification, restrict transfer of personal data to a country or territory it notifies. Rule 15 adds that personal data may be transferred outside India subject to any requirements the Government specifies about making that data available to a foreign State or its agencies.
The structure has three consequences worth being precise about:
- Transfer is permitted by default: the restriction operates only once a jurisdiction is actually notified, and a Minister confirmed the mechanism in Parliament in December 2025 as a power the Government may exercise.
- You should monitor for notifications: because the list can change without any change to the Act, and a notification would apply to you immediately once the provision is in force.
- Sector rules still bite: section 16(2) preserves any other Indian law that imposes a higher standard, so financial services, health and telecom localisation requirements continue to apply on their own terms.
One narrower localisation duty exists but probably does not reach you. Under Rule 13, a Significant Data Fiduciary must keep specified categories of personal data, and the traffic data about their flow, inside India. That applies only to entities the Government notifies as significant, and only to data categories a government committee specifies. It is not a general localisation rule for employee data.
If your concern is where your provider holds the data rather than the law, EOR Data Security: A Global Compliance & Protection Guide covers the controls to ask about.
What will you actually have to do once the obligations bite?
Six duties will matter to an employer. They come from section 8 of the Act and Rules 6 to 9, and none of them is exotic. Most well run companies already do a version of each.
Keep the data secure, to a specified minimum
Rule 6 is unusually concrete for Indian subordinate legislation. Reasonable security safeguards must include, at a minimum, measures such as encryption, obfuscation, masking or tokenisation; access controls on the systems used; logging and monitoring that lets unauthorised access be detected and investigated; backups for continued processing; retention of those logs for one year; a contractual security obligation on any processor; and appropriate technical and organisational measures overall.
The log retention point catches people out. One year of access logs is a design requirement, not a preference, and it is worth confirming that your HR and payroll systems actually meet it.
Report breaches, on three separate clocks
Rule 7 sets three obligations, not one. Affected individuals must be told without delay under Rule 7(1), in plain language, covering the nature and extent of the breach, the likely consequences for them, what you are doing about it, what they can do, and who to contact. The Board must be told without delay under Rule 7(2)(a), including the location of the occurrence and the likely impact. Then under Rule 7(2)(b) the Board must be given updated and detailed information within seventy two hours of you becoming aware, unless it allows longer on a written request.
So the common paraphrase, that a breach must be reported within seventy two hours, is wrong in both directions. The notification itself is due without delay, which is sooner than seventy two hours. And the seventy two hour deadline attaches only to the detailed follow up report to the Board, which is extendable on request.
If you are assessing providers partly on this, How to Choose an Employer of Record: A 2026 Buyer's Guide lists the security and process questions worth asking.
Publish a contact point
Rule 9 requires you to publish prominently the business contact information of the person who can answer questions about processing, and to include it in every response to a rights request. For most employers this is a named person and a monitored mailbox rather than a formal Data Protection Officer.
Keep data no longer than the purpose supports
Section 8(7) requires erasure once the purpose is no longer served, unless retention is necessary for compliance with a law. Employment records generally do carry retention requirements, so the practical exercise is mapping each category to the law that justifies keeping it, not deleting everything at exit.
Tax records are the clearest example, and the filing timetable behind them is in Payroll Tax in India: Employer Rates, TDS, and Deadlines.
Retain processing logs for a minimum period
Rule 8(3) requires a Data Fiduciary to retain personal data, associated traffic data and processing logs for at least one year from the date of processing, before erasing them, unless another law requires longer. This is a floor rather than a ceiling, and it sits oddly beside the erasure duty, so treat the two as needing a documented reconciliation.
Stay accountable for your processors
Section 8(1) is the sharpest sentence in the Act for anyone who outsources. A Data Fiduciary is responsible for complying with the Act in respect of any processing undertaken by it or on its behalf by a Data Processor, and it says so irrespective of any agreement to the contrary. Section 8(2) requires a valid contract with a processor. Together they mean a vendor contract allocates work and recourse, never your own responsibility.
Who is the Data Fiduciary when you use an EOR?
Probably both of you, for different purposes, and the answer is not a matter of preference. A Data Fiduciary is whoever determines the purpose and means of processing, and the definition expressly contemplates doing so alone or in conjunction with other persons.
Mapped onto an EOR arrangement, the split usually looks like this.
| Processing activity | Who decides purpose and means | Likely role |
|---|---|---|
| Payroll, tax and statutory filings | The EOR, as legal employer | EOR is Data Fiduciary |
| Statutory benefit enrolment | The EOR | EOR is Data Fiduciary |
| Employment records and retention | The EOR | EOR is Data Fiduciary |
| Work allocation and performance management | The client company | Client is Data Fiduciary |
| Access to client systems and tools | The client company | Client is Data Fiduciary |
| Recruitment and candidate assessment | Usually the client | Client is Data Fiduciary |
| Payroll software used by the EOR | The EOR instructs the vendor | Vendor is Data Processor |
This matters for a practical reason rather than a theoretical one. If your EOR is a Data Fiduciary in its own right for payroll, it carries its own statutory duties and cannot simply act on your instruction where the law says otherwise. And because you are a Data Fiduciary for what you decide, describing your provider as a processor for everything does not move your exposure.
The wider question of who the employer is, and what that changes, is covered in Employee Classification & EOR: A Global Guide (2026).
If you are weighing an EOR against incorporating locally, the trade-offs sit in Employer of Record vs Own Entity: Which Is Right for You?.
For how the arrangement works mechanically, see How Employer of Record Works: The Complete Guide 2026.
And if you are changing provider, the data transfer step is one of the harder parts, covered in How to Switch EOR Providers in India: A Migration Checklist.
How does employee data work at onboarding and offboarding?
These are the two moments when the most personal data moves, and where the framework has the most practical bite. Handle them well and the rest of the year is quiet.
At onboarding
Collect what the employment purpose and Indian statutory filings require, and record why. Identity and tax identifiers, bank details, provident fund nominations, qualifications and background checks each have a reason, and the reason is what you rely on later. Resist collecting extra data because a global template asks for it. Our guide to How to Hire Employees in India Without an Entity: A Guide covers what onboarding genuinely requires.
During employment
Keep the record accurate, because section 8(3) requires completeness, accuracy and consistency where the data will be used to make a decision affecting the person or will be disclosed to another Data Fiduciary. Performance data used for promotion decisions is squarely in that category.
Work product raises a separate ownership question that is worth settling at the same time, addressed in Does Your US Company Own the IP Your India EOR Developer Writes?.
At offboarding
Exit is not a signal to delete. Indian employment law requires records to be kept, wage and attendance registers for five years under the Code on Wages, 2019 for example, and tax and provident fund records on their own timetables. What should stop at exit is access, active use, and anything you were holding only because the person was employed.
The operational sequence for an India exit, including the statutory pay deadlines, is set out in EOR Employee Offboarding in India: What Employers Must Know.
What are the penalties, and who enforces them?
Penalties are set out in the Schedule to the Act and are imposed by the Data Protection Board of India after an inquiry. They are stated as maximums rather than fixed amounts, and the Board weighs the nature and gravity of the breach when deciding.
| Breach | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards, section 8(5) | Up to 250 crore rupees |
| Failure to notify a breach to the Board or affected individuals, section 8(6) | Up to 200 crore rupees |
| Breach of the additional obligations relating to children, section 9 | Up to 200 crore rupees |
| Breach of Significant Data Fiduciary obligations, section 10 | Up to 150 crore rupees |
| Breach of a Data Principal's own duties, section 15 | Up to 10,000 rupees |
| Breach of any other provision of the Act or Rules | Up to 50 crore rupees |
Two things are worth noticing in that table. The largest exposure attaches to security failures rather than to paperwork, which tells you where to spend first. And the penalty provisions sit in the eighteen month commencement bucket, so they arrive with the duties rather than before them.
On enforcement, the Board has been established and the Rules provide for it to function as a digital office with online complaint filing. Appeals go to the Telecom Disputes Settlement and Appellate Tribunal. As of August 2026 the Board's practice is untested, so nobody can tell you how it will exercise its discretion, and any guide that predicts penalty levels is guessing.
What should you do now, and what should you ask your EOR?
You have a preparation window rather than an emergency. Spend it on the things that take time to change, which are systems and habits rather than documents:
- Map your India employee data: what you hold, where it sits, who can see it, and which system it lives in. Nothing else is possible before this.
- Write down the purpose for each category: this is your substitute for a consent programme, and it is what section 7(i) reliance looks like in practice.
- Check your logging and retention against Rule 6: one year of access logs, real access controls, and encryption or masking on employee records.
- Build a breach runbook with three clocks: immediate intimation to affected people, immediate outline to the Board, and the detailed report inside seventy two hours.
- Name a contact person and publish the route: plus a grievance process that can answer inside ninety days.
- Map retention to legal bases: so you can answer an erasure request with a reason rather than a negotiation.
- Review your vendor contracts: for a security obligation, breach notification back to you, and clarity on who decides what.
- Set a calendar reminder for mid May 2027: and a watch on notifications under section 16 in the meantime.
Then put these questions to your EOR or India provider in writing, because the answers tell you whether they have read the Rules or only the headlines:
- Role allocation: which processing activities do you consider yourself a Data Fiduciary for, and which are ours?
- Location and sub processors: where is our employee data stored and processed, and who else touches it?
- Rule 6 safeguards: how do you meet the minimum safeguards, including one year log retention?
- Breach process: how quickly will you tell us, rather than only the Board?
- Retention: how long do you keep employee records after exit, and under which legal requirement?
- Contact and grievances: who is your published contact point, and what is your grievance turnaround?
- Readiness: what changes are you making before the eighteen month commencement date?
If a provider cannot answer the first question, treat that as the finding. Role allocation is the part that determines who carries what, and it cannot be resolved after an incident.
Smaller teams choosing a first provider may want to read this alongside Best EOR for Startups in 2026: Compare Providers, Pricing.
Where can you verify this for yourself?
Everything above is drawn from primary sources, and we would rather you read them than trust a summary. All of these are official and freely available:
- The Digital Personal Data Protection Act, 2023: Act No. 22 of 2023, available from India Code and from the Ministry of Electronics and Information Technology. The commencement footnote to section 1 is where the staged dates are recorded.
- The Digital Personal Data Protection Rules, 2025: notified as G.S.R. 846(E) and published in the Gazette of India, Extraordinary, Part II, Section 3(i). Rule 1 carries the commencement schedule and the Schedules carry the retention classes.
- The Ministry's press material on the Rules: which sets out the eighteen month phased compliance period and the ninety day response requirement.
- The Data Protection Board of India pages: for the Board's constitution and its digital office arrangements.
Two habits will keep you accurate. Check the commencement position before treating any section as live, because that is the mistake nearly every secondary source makes. And check for notifications under section 16 and section 17(3) before assuming either that transfers are unrestricted or that a startup exemption is available, since both depend on a notification that may or may not exist when you read this.
On that second point, the Act does allow the Government to exempt certain Data Fiduciaries, including startups, from some obligations such as the notice requirement and the access right. That is a power, and it takes effect only through a notification identifying who benefits. Do not plan around an exemption you cannot point to.
How does Wisemonk help with India employee data?
Wisemonk is an India native Employer of Record that helps global companies hire, pay, and manage employees in India without setting up a local entity. Because we act as the legal employer, we hold and process the employee data that Indian payroll and statutory filings require, and we treat that as our own compliance obligation rather than yours alone.
Here is how we support teams on the data side of employing people in India:
- Employment records: held and retained for the periods Indian law requires, with a documented basis for each category.
- Payroll and statutory filings: provident fund, insurance and tax filings run by us as the employer of record.
- Defined role split: we set out in writing which processing we determine and which you do, so the allocation is not discovered during an incident.
- Security and access controls: encryption, access control and logging over employee records, with named contacts for data questions.
- Onboarding and exit data handling: collecting only what the employment purpose and Indian filings require, and closing access cleanly at exit.
We work with 300+ global clients, support over 2,000 employees, and process more than $20M in annual payroll, with a 4.8/5 rating on G2. EOR pricing starts from $99 per employee per month.
Nothing in this article is legal advice, and the framework's staged commencement means the position will change before it fully takes effect. Where a decision carries real commercial weight, take Indian counsel on your specific facts.
Want your India employee data handled by the legal employer?
Talk to our India team about how we hold, process and retain employee records under Indian law.
Frequently asked questions
Is the DPDP Act applicable to foreign companies?
It applies to processing of digital personal data within India, and to processing outside India connected with offering goods or services to people in India. If your India entity or EOR processes employee data in India, that is covered. A foreign parent that only employs in India and sells elsewhere sits in a less certain position.
When do DPDP obligations actually take effect?
In stages. Definitions and the Data Protection Board commenced in November 2025. The substantive employer obligations, sections 3 to 17 and the penalty provisions, plus Rules 3 and 5 to 16, commence eighteen months from the November 2025 notification, which points to mid May 2027. Treat that window as preparation time.
Do we need consent from employees under the DPDP Act?
Usually not. Section 7(i) treats processing for the purposes of employment, and for protecting the employer against loss or liability, as a legitimate use that does not require consent. Payroll, benefits, filings and performance management generally fit. Processing outside the employment purpose needs its own basis.
Can employee data be transferred outside India under DPDP?
Yes. India uses a negative list: transfer is permitted unless the Central Government notifies a country as restricted. There is no adequacy or standard contractual clause regime. Sector specific localisation rules still apply, and notified Significant Data Fiduciaries may face limits on specified data categories.
What are the penalties under the DPDP Act?
The Schedule sets maximums. Up to 250 crore rupees for failing to take reasonable security safeguards, up to 200 crore for failing to report a breach, up to 150 crore for Significant Data Fiduciary breaches, and up to 50 crore for any other contravention. The Data Protection Board decides the amount.
How long must we keep employee data in India?
There is no single DPDP retention period for employers. You keep data while the purpose is served or a law requires it, and other Indian laws set the real periods, such as five years for wage and attendance records. Separately, processing logs must be kept for at least one year.
Does the three year data deletion rule apply to employee records?
No. That rule sits in the Third Schedule to the Rules and reaches only named classes: large e-commerce entities, online gaming intermediaries and social media intermediaries above user thresholds. Employers are not in that list, so it does not force deletion of employment records after three years.
Ready to build your India team?
Tell us who you're looking to hire. We'll walk you through exactly how the setup works for your company, your timeline, and your budget.