DPDP Act 2023: What US Companies Must Do to Stay Compliant When Hiring in India
Hiring in India requires more than finding great talent. Learn what the DPDP Act 2023 means for US employers, including consent requirements, background verification, data handling, employee privacy, and the compliance steps needed to hire in India legally and confidently.
ByNilesh Parwani / July 15, 2026 / 11 min read

- What Is the DPDP Act and Why Does It Apply to US Companies?
- What Employee Data Is Covered Under India Data Privacy Law?
- The Three DPDP Compliance Deadlines Every US Employer Must Know
- DPDP Act Employer Obligations: The Complete List for US Companies Hiring in India
- Penalties for DPDP Act Non-Compliance
- The 8 Steps US Employers Should Take in 2026
- How an EOR Handles DPDP Compliance for US Companies
- Frequently Asked Questions
India's first comprehensive data privacy law is now operational. The Digital Personal Data Protection Act 2023, with its Rules notified on November 13, 2025, has changed how every company that processes personal data of Indian residents must operate, whether that company is in India or not.
For US companies hiring engineers, analysts, and technical staff in India, DPDP Act compliance is not optional and not limited to companies with an India entity. The law has extraterritorial reach. If you process personal data of individuals in India as part of offering goods or services, the DPDP Act applies to your operations regardless of where your company is headquartered.
The good news is that 2026 is a build year, not a penalty year. The full compliance deadline is May 13, 2027. But the Consent Manager Framework activates on November 13, 2026. And the Data Protection Board of India, which has the authority to investigate complaints and impose fines up to Rs 250 crore (approximately $30 million USD) per violation, is already constituted and operational.
This guide covers exactly what the DPDP Act means for US employers with India-based teams: who is covered, what employee data is affected, what the specific employer obligations are, the phased deadlines, the penalties, and how an EOR handles DPDP compliance on your behalf.
What Is the DPDP Act and Why Does It Apply to US Companies?
The Digital Personal Data Protection Act 2023 (DPDP Act) is India's first standalone data privacy law. It was enacted on August 11, 2023, and the DPDP Rules were notified on November 13, 2025, making the framework fully operational with a phased enforcement timeline.
The DPDP Act governs the collection, processing, storage, sharing, and deletion of digital personal data of Indian residents. Personal data means any data by which an individual can be identified: name, address, phone number, PAN, Aadhaar, bank account details, salary, health information, and employment records.
Who is a Data Fiduciary: Under the DPDP Act, any organization that determines the purpose and means of processing personal data is a Data Fiduciary. As a US employer hiring India-based staff, you are a Data Fiduciary. If something goes wrong, the Data Protection Board of India comes to you first.
Who is a Data Processor: Any third party that processes personal data on your behalf, including your EOR provider, payroll platform, background verification agency, or HR software vendor, is a Data Processor. You remain responsible for how your processors handle data.
The extraterritorial reach: The DPDP Act applies to processing digital personal data within India. It also applies to processing outside India if it relates to offering goods or services to individuals in India. This means US companies hiring India-based employees are covered, even without an India entity. Even US organisations without a physical presence in India must comply with the DPDP Act if they process personal data of Indian employees or users as part of their business operations (Association of Corporate Counsel, 2024).
What Employee Data Is Covered Under India Data Privacy Law?
Every piece of personal data in your India HR lifecycle is covered. The DPDP Act does not categorize data into sensitive and non-sensitive tiers the way GDPR does. All personal data is subject to the same framework.
For a US company with India-based employees, the data under DPDP coverage includes:
During hiring and pre-employment screening: Candidate name, contact details, PAN, Aadhaar, educational certificates, employment history, criminal record information, address, references, and any data collected via background verification. Consent is mandatory before any background check begins.
During employment: Payroll data (PAN, bank account details, salary, bonuses), attendance records, performance reviews, disciplinary records, health and insurance details, tax filing data (TDS and Form 130), EPFO and ESIC contribution data, and any data processed in HR management systems.
During exit: Separation documentation, full and final settlement records, relieving letters, data related to any exit interview, and data shared with third parties during the offboarding process.
The key distinction for employers: processing employee data for employment purposes is a "legitimate use" under the DPDP Act, which means you do not need separate consent to run payroll or process employment records. But the duties that come with legitimate use, including security safeguards, breach notification, and data principal rights handling, all apply fully.
The Three DPDP Compliance Deadlines Every US Employer Must Know
The DPDP Rules 2025 introduced a phased implementation timeline. Missing any deadline is not a soft compliance failure. Each unresolved obligation is a separate violation count under the Act.
Phase | Deadline | What activates |
Phase 1 | November 13, 2025 (already in force) | Data Protection Board of India constituted. Board has investigatory authority and penalty powers from this date. |
Phase 2 | November 13, 2026 | Consent Manager Framework becomes operational. Organizations relying on consent for data processing must integrate with registered Consent Managers under Rule 4 of the DPDP Rules. |
Phase 3 | May 13, 2027 (full compliance deadline) | All substantive obligations enforceable: consent and privacy notice operations, breach notification, data principal rights handling, vendor DPA requirements, and data deletion obligations. |
2026 is the year to build your compliance infrastructure. The Board is already operational. Complaints can be filed now. Full enforcement arrives in under 12 months from the time of writing. Companies that wait for May 2027 to start their compliance programs will be building under regulatory pressure rather than ahead of it.
DPDP Act Employer Obligations: The Complete List for US Companies Hiring in India
Here is every obligation that applies to US employers as Data Fiduciaries under India data privacy law.
1. Consent for Non-Employment Data Processing
Employment records processed for employment purposes (payroll, performance, statutory compliance) qualify as legitimate use. You do not need separate consent for these. But any processing outside the direct employment purpose, including marketing communications, sharing data with third-party analytics tools, or using employee data for internal research, requires explicit, specific, unambiguous consent.
Consent must be purpose-specific and collected separately from your Terms and Conditions or employment contract. Pre-ticked checkboxes are not compliant. Bundled consent in onboarding flows is not compliant. Each purpose needs a separate consent collection.
2. Privacy Notice Before or At Data Collection
At the point of collecting any personal data from a candidate or employee, you must provide a notice in clear, plain language explaining: what data is being collected, why it is being collected, how it will be used, how long it will be retained, and how the individual can withdraw consent or exercise their rights.
The notice must be available in English and Indian scheduled languages where applicable. Vague or generic privacy policies do not satisfy this requirement.
3. Purpose Limitation
Personal data collected for one purpose cannot be used for another. If you collect a candidate's Aadhaar for identity verification during background screening, you cannot retain it for payroll or use it for any other downstream purpose. If you collect salary data for payroll processing, you cannot reuse it to send promotional communications.
This is the DPDP Act obligation that most US companies violate in their HR systems without realizing it, because data collected at one stage of the hiring lifecycle routinely flows into systems designed for different purposes.
4. Data Accuracy and Completeness
If personal data is used to make a decision about a data principal (your employee or candidate) or is disclosed to a third party, you must take reasonable steps to ensure it is accurate, complete, and consistent.
Outdated employment records, stale performance data used in promotion decisions, and inaccurate tax information shared with the Income Tax Department all create liability under this provision.
5. Security Safeguards
You must implement reasonable technical and organizational security measures to protect personal data from breaches. The DPDP Act does not prescribe specific technical standards but references ISO 27001 as a recognized framework for secure data handling.
For HR data specifically, this means encrypted storage for payroll files, access controls limiting who can view personal data, secure channels for sharing data with processors, and documented security practices.
6. Data Breach Notification
If a breach occurs, you must notify the Data Protection Board of India and all affected data principals (your employees or candidates whose data was exposed) without delay. The DPDP Rules do not specify an exact breach notification timeline in hours, but the obligation is immediate and not subject to an internal investigation window before notification.
This is the obligation that creates the most operational pressure. You need a breach detection process, an internal escalation chain, pre-drafted notification templates for the DPBAI and individuals, and a tested response procedure, all before a breach occurs.
7. Data Principal Rights: Your Obligation to Respond
Every candidate and employee whose data you hold has four enforceable rights under the DPDP Act:
- Right to access: They can ask what personal data you hold and how you are using it.
- Right to correction: They can ask you to correct inaccurate or incomplete data.
- Right to erasure: They can ask you to delete their personal data when the purpose for which it was collected is complete.
- Right to grievance redressal: They must have access to a formal grievance mechanism through which they can raise data protection concerns.
You must have processes in place to respond to each of these rights requests within a reasonable timeframe. Ignoring a data principal rights request is itself a violation.
8. Data Processing Agreements with Vendors
Responsibility for data protection cannot be transferred to your processors. If your EOR provider, payroll platform, or background verification agency has a breach, you are still accountable as the Data Fiduciary. The DPDP Rules require appropriate security provisions in all Data Fiduciary to Data Processor agreements.
Every vendor that touches personal data of your India-based employees needs a signed Data Processing Agreement specifying their data protection obligations, breach notification timelines to you, data deletion requirements, and security standards.
9. Data Deletion When Purpose Is Served
You cannot retain personal data indefinitely. Once the purpose for which data was collected is complete, the data must be deleted. This applies to rejected candidate records (delete after the hiring process concludes), employee records after the legally required retention period, and any data collected for one-time purposes.
Indian employment law requires retaining certain payroll and employment records for specified periods. Your data retention policy needs to reconcile the DPDP deletion obligation with the statutory retention requirements under Indian labour law.
Penalties for DPDP Act Non-Compliance
The penalty structure under the DPDP Act is per violation, not an annual cap. Every unresolved obligation is a separate count.
Violation | Maximum penalty |
Failure to implement reasonable security safeguards leading to a breach | Rs 250 crore (approx. $30 million USD) |
Failure to notify DPBAI and data principals of a breach | Rs 200 crore (approx. $24 million USD) |
Violation of additional obligations for Significant Data Fiduciaries | Rs 150 crore (approx. $18 million USD) |
Violation of data principal rights obligations | Rs 50 crore (approx. $6 million USD) |
Non-compliance with other DPDP Act provisions | Rs 50 crore (approx. $6 million USD) |
Section 33 allows the DPBAI to impose twice the usual fine for serious or repeat offences, raising the maximum to Rs 500 crore per violation. A single data breach involving employee payroll data could simultaneously trigger three separate penalty rows: security safeguard failure, breach notification failure, and data principal rights violation.
The 8 Steps US Employers Should Take in 2026
The full enforcement deadline is May 2027. The Consent Manager Framework activates November 2026. Starting now gives you 13 months to build, not scramble.
Step 1: Conduct a data audit. Map every personal data flow in your India HR lifecycle: collection points, storage systems, processing purposes, sharing with third parties, and current retention periods. This is your Record of Processing Activities (RoPA).
Step 2: Identify your Data Fiduciary and Data Processor roles. For your India team, who determines the purpose of data processing? That is you. Who processes it on your behalf? That is your EOR, payroll vendor, background check agency, and HR software.
Step 3: Implement privacy notices. Write clear, plain-language notices for each data collection point: job applications, onboarding, payroll enrollment, performance reviews. Notices must be available in English and applicable Indian scheduled languages.
Step 4: Update consent collection. Audit any processing outside the legitimate employment use scope. Separate consent collection into purpose-specific buckets. Remove pre-ticked boxes and bundled consent flows.
Step 5: Sign Data Processing Agreements with all vendors. Every vendor touching India employee data needs a DPA with security provisions, breach notification timelines (to you), data deletion clauses, and audit rights.
Step 6: Build a breach response process. Designate a breach response owner. Draft DPBAI notification templates and employee notification templates. Establish internal escalation timelines. Test the process before November 2026.
Step 7: Create a data deletion schedule. Align your retention periods with both DPDP deletion obligations and Indian labour law statutory retention requirements. Build deletion into your HR system workflows so it happens automatically when retention periods expire.
Step 8: Train everyone who handles India employee data. DPDP compliance is not just a legal or IT function. HR staff, recruiters, payroll administrators, and managers who access India employee records all need to understand the obligations and their specific role in maintaining compliance.
How an EOR Handles DPDP Compliance for US Companies
When you hire in India through Kaamwork's EOR model, Kaamwork is the legal employer and the primary Data Fiduciary for your India-based employees under Indian law. This changes the DPDP compliance burden significantly.
Kaamwork processes all payroll data, statutory filing data, and employment records under its own India entity and DPDP compliance framework. Your US company is the operational employer directing the work. The employment data processing, security safeguards, and breach notification obligations for the employment record layer sit with Kaamwork, not directly with your US entity.
You still need to comply with DPDP obligations for any personal data you independently collect and process about your India team: performance data in your US-based HR systems, access logs in your engineering tools, Slack messages, email, and anything that does not flow through Kaamwork's payroll and employment infrastructure.
But the heaviest compliance layer, which is payroll data, statutory records, and employment contract data, is managed by Kaamwork as the legal employer under India's data protection framework.
See how Kaamwork's EOR model works in India, read the complete EOR India guide for US companies, understand how India payroll compliance works, and review background check compliance in India to understand the full data privacy and compliance picture before your first hire.
DPDP Act compliance for US companies hiring in India is not a 2027 problem. The Data Protection Board is operational. The Consent Manager Framework activates in November 2026. Full enforcement follows in May 2027. Companies that treat 2026 as a planning and build year will be compliant ahead of enforcement. Companies that wait will be building under regulatory pressure with an active Board already taking complaints.
The specific obligations that matter most for US employers with India-based teams are security safeguards, breach notification, data principal rights responses, vendor Data Processing Agreements, and data deletion schedules. An EOR handles the employment data layer. The tools, systems, and processes you use to manage India employees on a day-to-day basis are your own compliance responsibility.
If you want to understand what DPDP Act compliance looks like for your specific India team structure, Kaamwork can walk you through the data flows and obligations. Talk to Kaamwork today.
Frequently Asked Questions
Q: Does the DPDP Act apply to US companies hiring in India? Yes. The DPDP Act has extraterritorial reach. It applies to any organization that processes digital personal data of individuals in India, regardless of where the organization is located. US companies hiring India-based employees process personal data of Indian residents as part of the employment relationship. This makes DPDP Act compliance mandatory for US employers even without a registered India entity. The Association of Corporate Counsel confirmed in 2024 that US organizations without a physical presence in India must comply if they process personal data of Indian employees or users.
Q: What are the key DPDP Act employer obligations for companies hiring in India? The key employer obligations under India data privacy law include providing privacy notices at every data collection point, obtaining explicit consent for any processing outside the direct employment purpose, implementing security safeguards including encrypted storage and access controls, notifying the Data Protection Board of India and affected individuals immediately in the event of a breach, responding to data principal rights requests (access, correction, erasure, grievance), signing Data Processing Agreements with all vendors handling India employee data, and deleting personal data when the purpose for which it was collected is complete.
Q: What are the penalties for DPDP Act non-compliance? Penalties are per violation, not annual caps. Failure to implement security safeguards leading to a breach carries a maximum fine of Rs 250 crore (approximately $30 million USD). Failure to notify the DPBAI and data principals of a breach carries up to Rs 200 crore. Violation of data principal rights obligations carries up to Rs 50 crore per violation. Section 33 allows the DPBAI to double these fines for serious or repeat offences, raising the maximum to Rs 500 crore per violation. A single breach event can trigger multiple penalty rows simultaneously.
Q: What are the DPDP Act compliance deadlines in 2026? The phased compliance deadlines are: Phase 1, November 2025 (already in force): the Data Protection Board of India is constituted with active investigatory and penalty powers. Phase 2, November 13, 2026: the Consent Manager Framework becomes operational; organizations relying on consent for data processing must integrate with registered Consent Managers. Phase 3, May 13, 2027: full compliance deadline for all substantive obligations including consent operations, privacy notices, breach notification, data principal rights handling, and vendor DPA requirements.
Q: How does hiring through an EOR affect DPDP Act compliance? When you hire through an EOR like Kaamwork, Kaamwork is the legal employer and primary Data Fiduciary for employment records under Indian law. Payroll data, statutory filing data, and employment contract records are processed under Kaamwork's India entity and DPDP compliance framework. This removes the heaviest employment data compliance layer from your US entity's direct obligations. You remain responsible for DPDP compliance on any personal data you independently collect and process about your India team in your own US-based systems: performance data, tool access logs, communications, and similar operational data.
Share this article

Founder & CEO | Kaam.Work
Nilesh Parwani, a Kelley School BBA graduate, worked at UBS and Warburg Pincus before founding PrintBell (acquired by Cimpress). In 2020, he launched kaam.work, a remote work platform focused on flexible talent and distributed teams.