What HRs Should Know About the Digital Personal Data Protection Act, 2023

Personal Data Protection Bill 2023
Reading Time: 10 minutes

The term data protection refers to the protection of user data safely and securely. It is a protocol that defines the numerous policies on how to restrict the user’s personal data usage and protect it from data breaches.

 

The Digital Personal Data Protection Act of 2023 defines the compliance regulations for companies taking responsibility for using users’ personal data.

 

Personal data protection is built based on technologies like Data Loss Prevention (DLP), which ensures end-to-end encryption, built-in data protection, firewalls, and more. It is essential in business operations such as research and development, finance, etc.

 

In this blog, we are sharing the details of the Digital Personal Data Protection (DPDP) Act, the DPDP Rules, 2025 that operationalise it, and how HRMS data management will change based on the personal data management policies defined in the Act.

 

What is the Digital Personal Data Protection (DPDP) Act, 2023?

The Digital Personal Data Protection (DPDP) Act, 2023 is a law passed by the Indian Government to regulate the use of personal data of Indian citizens. It is designed to regulate the collection, processing, and storage of personal data of individuals by organizations.

 

The Lok Sabha cleared the 9-chapter Digital Personal Data Protection Act in August of 2023. The key elements included in the DPDP Act are:

  • To protect the rights of individuals to protect their personal data.
  • To outline the obligations of law to protect the personal data of individuals.
  • Procedures for protecting personal data lawfully.
  • Rights of citizens to file a complaint with the Data Protection Board if the personal data protection law is breached.
  • Duties of citizens to safeguard personal data.

 

The DPDP Act ensures the safety of personal data of citizens while supporting India’s digital mission to reach every nook and corner of the nation. To regulate the growing use of personal data by businesses and government to ensure accountability of citizens, this Act plays a pivotal role in safeguarding data while ensuring access to fiduciaries.

 

If any violation takes place, the penalty will be borne by the individuals or companies using the personal data. Under the Act, organizations failing to take reasonable security safeguards resulting in a data breach can be fined up to ₹250 crores. Some of the other penalties include:

 

Offense Whom it applies to Maximum Penalty
Failure to take reasonable security safeguards to prevent a personal data breach Data Fiduciary ₹250 crore
Failure to notify the Board and affected Data Principals of a personal data breach Data Fiduciary ₹200 crore
Breach of obligations relating to children’s personal data (e.g. no parental consent, profiling/targeted ads at kids) Data Fiduciary ₹200 crore
Breach of additional obligations of a Significant Data Fiduciary (DPIAs, audits, appointing a DPO, etc.) Significant Data Fiduciary ₹150 crore
Breach of any other provision of the Act or Rules not separately specified Data Fiduciary ₹50 crore
Breach of a voluntary undertaking accepted by the Board Any person, including Data Principal Up to the amount applicable to the original breach
Non-compliance with duties (e.g. filing false/frivolous complaints) Data Principal ₹10,000

 

Key Aspects of the Digital Personal Data Protection Act, 2023

Let us discuss the key parameters of the DPDP Act:

 

➔ Applicability

The DPDP Act applies to Government and private entities involved in the processing and securing of personal data in India. The Act has provisions for protecting the personal data of Indian citizens processed outside of India as well, where the processing relates to offering goods or services to individuals in India.

 

➔ Data Protection Authority

The DPDP Act ensures the protection of user data under the Data Protection Board of India. This is an independent regulatory body responsible for the enforcement and implementation of the provisions of the Act.

 

➔ Rights of Individuals

The DPDP Act grants individuals certain rights over their data, such as the ability to correct data inaccuracies or delete unwanted data. By empowering individuals with these rights, the Act gives them greater control over their personal information.

 

➔ Sensitive Personal Data

The DPDP Act classified the user’s personal data into various categories, such as financial data, health data, biometric data, etc. Any data protection violation results in hefty fines and penalties.

 

➔ Data Localization

While the DPDP Bill had provisions related to data localization, requiring personal data to be stored and processed within India, the final Act changed it. Under the Act, a data fiduciary can transfer or store personal data to any country except those restricted by the Central Government.

 

➔ Consent Managers

The DPDP framework introduces the concept of a Consent Manager, a registered intermediary that lets individuals give, manage, review, and withdraw their consent to data processing through a single interface, instead of chasing each organization separately. For HR, this matters as employees increasingly expect the same consent transparency from their employer’s HRMS that they get from consumer apps.

 

How DPDP Relates to the Older SPDI Rules

Before the DPDP Act, sensitive personal data (like health records, biometrics, and financial information) was governed by the SPDI Rules under the Information Technology Act, 2000. Indian employers are currently expected to continue complying with the SPDI regime while the DPDP framework is phased in, since the two overlap for now rather than the DPDP Act cleanly replacing the older rules overnight.

 

 

DPDP Rules, 2025 and the Compliance Timeline

The DPDP Act sat largely dormant for two years after it was passed, because the operational detail, consent notice formats, breach timelines, retention schedules, and the Data Protection Board’s own procedures were left to subordinate rules. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 and finally operationalise the Act.

 

The Rules are not fully in force all at once. They commence in a staggered manner over roughly 18 months: definitional and Board-related provisions took effect immediately on notification, the bulk of the compliance obligations (consent, security safeguards, breach notification, children’s data, retention and erasure) are being phased in through November 2026, and the remaining provisions are set to come into force by 13 May 2027. As of today, HR teams should treat DPDP compliance as a live, in-progress rollout rather than a fully settled regime.

 

A few operational specifics HR and HRMS teams should have on their radar:

  • Breach notification: the Board must be notified without delay, and affected Data Principals (including employees) must be notified within 72 hours of the Board being informed.
  • Erasure notice: where personal data is due for erasure because an employee hasn’t engaged with the organization for a specified period, the Data Fiduciary must give at least 48 hours’ notice before deleting it.
  • Rights requests: correction and erasure requests from employees must generally be addressed within 90 days.
  • Log retention: processing and traffic logs must be retained for a minimum of one year for security investigation purposes.
  • Sector-specific retention: a fixed 3-year retention window (from last user interaction) applies to large e-commerce, social media, and online gaming platforms under the Rules’ Third Schedule — this doesn’t directly apply to typical employee HR data, but it’s a useful reference point when vendors in your HR tech stack straddle both categories.
  • Children’s and dependents’ data: verifiable parental or guardian consent is required, with DigiLocker-based verification as one accepted method.

 

Impact of DPDP Act on HRMS Data Management

Digital Personal Data Protection Bill ensures data protection in various ways by introducing people with clear rules and guidelines for handling personal information in the digital realm.

 

Let us discuss how deploying a robust HRMS will help automate personal data management with the help of the PDP Bill.

 

1. Data Processing Rules

The PDP bill sets forth rules and regulations for adequately processing employee data. It defines the lawful grounds for data processing, such as obtaining explicit consent from individuals, fulfilling contractual obligations, or complying with legal requirements.

 

By establishing these rules, the bill ensures that HR processes analyze and maintain personal data fairly and lawfully.

 

2. Individual Rights

The PDP bill grants individuals certain rights over their data. After getting special permission from management, employees can correct data inaccuracies or delete unwanted data.

 

By empowering individuals with these rights, the bill gives them greater control over their personal information.

 

3. Data Security Measures

The PDP bill changes the security process for employee data. Organizations need a bill to improve their security measures and protect personal data from unauthorized access, disclosure, alteration, or destruction.

 

It may set specific standards for data security and require organizations to report any data breaches promptly.

 

4. Data Localization

HRs are often required to store and process certain kinds of employee data on company premises. The personal data protection bill helps HR handle data without fear of data breaches.

 

The law ensures that data is subject to local laws or company policy and protections, reducing the risk of data exposure to foreign jurisdictions with potentially weaker data protection laws.

 

5. Regulatory Authority

The bill may establish a regulatory authority responsible for overseeing and enforcing employee data protection laws.

 

This law can investigate complaints, conduct audits, issue fines or penalties for non-compliance, and provide proper guidance to organizations on data protection best practices.

 

6. Cross-Border Data Transfers

Companies are often required to transfer personal data outside the country. The bill ensures that organizations follow adequate safeguards to protect company data during this transfer.

 

It may involve standard contractual clauses or other legally recognized mechanisms for cross-border data transfers.

 

7. Accountability and Compliance

The bill ensures the accuracy and accountability of data processing activities. Organizations may be required to maintain records of their processing activities and demonstrate compliance with the relevant data protection laws.

 

Overall, a well-designed Data Protection Bill can provide a comprehensive framework for safeguarding employee personal data, protecting individual privacy rights, and fostering a culture of responsible data handling in the digital age.

 

By adhering to the provisions of the Bill, organizations can build trust with their customers and stakeholders while ensuring that personal data remains secure and confidential.

 

How will DPDP change HRMS Data Management?

By deploying HRMS software, organizations can store their employees’ personal data safely and securely. A robust HRMS software encrypts sensitive and confidential employee information so that any random entity cannot access it.

 

Usually, organizations hire cybersecurity experts and consultants who can provide further insights and guidance on strengthening data security in their companies.

 

However, with an HRMS at your disposal, the provisions of the DPDP Act will be automatically followed since it will be updated by the software vendor for maintaining compliance. It will also automate the entire data security process.

 

Let us discuss how deploying a robust HRMS will help automate personal data management as required by the DPDP Act:

 

1. Data Processing Rules

The DPDP Act sets forth rules and regulations for adequately processing employee data. It defines the lawful grounds for data processing, such as obtaining explicit consent from individuals, fulfilling contractual obligations, or complying with legal requirements. By establishing these rules, the Act ensures that HR processes analyze and maintain personal data fairly and lawfully.

 

2. Access Controls

HRMS software provides robust access controls for the private and public sectors by implementing user authentication mechanisms such as strong passwords, multi-factor authentication, role-based access controls (RBAC), etc.

 

As defined by the provisions of the DPDP Act, an employee can process their personal data and analyze whether there are errors in the data or missing information.

 

3. Data Encryption

HRMS software plays a crucial role in employing encryption. HRMS software also ensures the personal data protection protocol by securely transmitting data over networks and encrypting sensitive data stored in databases to prevent unauthorized access.

 

4. Data Backup and Recovery

Regular data backups are essential to ensure data availability and provide protection against data loss or system failures. HRMS software has mechanisms for performing automated and secure backups of employee data and establishing procedures for timely data recovery in emergencies. Hence, it helps comply with the data backup provisions of the DPDP Act automatically.

 

5. Audit Trails and Logs

Maintaining comprehensive audit trails and logs helps monitor and track user activities within the HRMS software. Additionally, HRMS detects any unauthorized access or suspicious behaviour and provides an accountability mechanism for data handling. With the DPDP Rules requiring organizations to maintain audit trails and logs for at least one year, personal data transactions can be accounted for with the help of HRMS.

 

6. Compliance with Data Protection Laws

HRMS software will help in staying compliant with the DPDP Act to ensure data protection and security of the employee data. Since HRMS deals with the employee management process, the data related to onboarding, offboarding, attendance, payroll, etc. should be stored securely.

 

The Act will also ensure the accuracy and accountability of data processing activities. Organizations may be required to maintain records of their processing activities and demonstrate compliance with the relevant data protection laws.

 

The HRMS will ensure that the data is stored as well as accessed securely since it will be compliant with the provisions of the DPDP Act.

 

Key Compliance Imperatives for Users of HRMS and Payroll Systems

To ensure complete compliance with DPDP, organizations must overhaul these systems:

 

Compliance Area Requirements for HRMS/Payroll Potential Challenges
Consent Management
  • Obtain granular, verifiable consent for data collection (e.g., via onboarding).
  • Present notices independently, in clear language, in English, and, per the DPDP Rules, a regional Indian language where applicable—no bundling consent inside a lengthy policy document.
  • For pre-Act data, issue notices detailing usage and rights.
  • Allow easy withdrawal.
Legacy data in old HRMS may lack consent trails; retroactive notices could overwhelm systems.
Data Mapping & Minimization
  • Inventory all personal data flows (e.g., from applicant tracking to payroll APIs).
  • Retain only as long as needed for the stated purpose (e.g., 7 years for tax records), or as required by other law.
  • Where inactivity-based erasure applies, issue a 48-hour advance notice to the employee before deleting data, and complete correction/erasure requests within the 90-day window set by the DPDP Rules.
HRMS often hoards data indefinitely; it requires automated purging tools and a workflow to track the 48-hour and 90-day clocks.
Security Safeguards
  • Implement encryption, access controls, and audits.
  • Conduct a Data Protection Impact Assessment (DPIA) for high-risk activities like biometric payroll.
  • Retain processing logs and traffic data for a minimum of one year, as required under the DPDP Rules.
Integrating with legacy payroll software; SDFs must appoint India-based Data Protection Officers (DPOs).
Vendor & Third-Party Oversight
  • Contracts must mandate DPDP compliance (e.g., with payroll processors).
  • Perform due diligence and indemnify against breaches.
Outsourcing is common in India; misaligned vendors could expose employers to fines.
Breach Response & Rights Fulfilment
  • Notify the Data Protection Board without delay, and notify affected employees within 72 hours of the Board notification.
  • Honor rights requests (e.g., data erasure post-resignation, correction requests) within the timelines set by the DPDP Rules.
Payroll breaches could affect thousands; HRMS must enable self-service portals for rights exercises.

 

How does Pocket HRMS ensure compliance with DPDP?

The HRMS software is directly responsible for ensuring compliance with the DPDP Act in handling employee data.

 

HRMS software developers like Pocket HRMS have already implemented employee data protection policies in their systems and are striving towards providing enhanced data protection to secure employees’ personal data and company databases.

 

Pocket HRMS employs Microsoft Azure cloud infrastructure, which provides advanced military-grade 256-bit encryption for saving company and employee data securely. This system prevents the database from unauthorized access and data breaches.

By complying with the DPDP Act rules and regulations, Pocket HRMS can store Sensitive Personal Identifying Information (SPII) data securely with a multi-layered encryption system.

 

Features of Pocket HRMS Data Protection:

  • A centralized data maintenance service that encrypts, decrypts, and maintains employee personal data.
  • Enterprise-grade 256-bit encryption with Microsoft Azure cloud infrastructure.
  • User access control to ensure effective data abstraction.
  • Well-scrutinized database for convenient application maintenance and compliant MIS reporting.
  • Bulk data processing for simplified data imports and report generation.

 

End Note

Personal data protection is an essential aspect of safeguarding every individual’s privacy. Hence, every organization should have the right HRMS software that is compliant with personal data protection policies and practices.

 

Data protection laws and regulations, like the DPDP Act of 2023 and the DPDP Rules of 2025, are established to enforce and regulate personal data protection at the country level. These laws set out obligations for individuals, organizations, and governments regarding the collection, use, storing, and sharing of personal data.

 

FAQs

 

1. Is the DPDP Act fully enforced yet?

Not entirely. The DPDP Act was passed in 2023, but the DPDP Rules, 2025 that operationalise it were only notified on 13 November 2025, and they commence in phases over roughly 18 months, with full compliance expected by 13 May 2027. HR teams should treat this as an active, in-progress rollout rather than a fully settled law.

 

2. What is the full form of DPDP Act?

The full form of DPDP Act is the Digital Personal Data Protection Act.

 

3. What is the DPDP Act for HR professionals?

The DPDP Act, 2023 mandates HR professionals to ensure lawful data handling, obtain informed consent, protect employee rights, secure data, ensure vendor compliance, and adopt transparent retention and deletion practices in line with the DPDP Rules, 2025.

Contact Us

Contact Us