Compliance & labour law · Updated September 2026
The Digital Personal Data Protection Act, 2023 governs how employers can collect and use employee personal data, but as of late 2026 its core substantive duties are still phasing in rather than fully binding today.
The DPDP Rules, 2025 were notified on 13 November 2025, and as of that point only the provisions establishing the Data Protection Board and rule-making machinery were actually in force. Consent Manager registration is scheduled to begin 13 November 2026, and the substantive business obligations, the actual consent, notice, data-principal-rights and breach-notification mechanics, are scheduled to take effect 13 May 2027. In practical terms, 2026 is a preparation year, not a year of binding day-to-day compliance duties. Once fully operative, processing employee data will generally need either informed, specific consent, or a “legitimate use” ground covering what’s genuinely necessary for the employment relationship, payroll, benefits, statutory compliance, recruitment, not a blanket license to use employee data however an employer likes. Until then, the older IT Act’s SPDI Rules continue governing sensitive categories like biometric data in the interim.
Not yet, its core substantive duties are scheduled for May 2027, 2026 is best treated as a preparation window, not a compliance deadline already passed.
Map what employee data is collected and why, prepare consent and notice mechanisms, and review background-verification clauses ahead of the 2027 deadline.
No, it’s narrower than that, it covers what’s strictly necessary for the employment relationship, not open-ended use.
See biometric attendance for one specific data category with its own consent requirements.