The Digital Personal Data Protection Act, 2023 (“DPDP Act”) introduces a comprehensive legal framework for managing digital personal data in India. For employers, the Act imposes significant obligations regarding the collection, processing, and safeguarding of employee data. These new provisions complement and, to an extent, overlap with existing requirements under the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (commonly referred to as the “SPDI Rules”).
Key Employer Obligations Under the DPDP Act
1. Data Fiduciary Responsibilities
Employers are classified as “Data Fiduciaries” because they determine the purpose and means of processing employee data. Accordingly, they must adhere to several core requirements:
Lawful Processing
Personal data must be processed only for lawful purposes. In an employment context, this includes functions such...