CELEBRATING MORE THAN YEARS
AWARDS & RECOGNITION
PRACTICE AREAS
Dispute Resolution
Insolvency & Restructuring
General Corporate & Corporate Advisory
Real Estate & Property Laws
Employment & Labour Law
Regulatory Practice
Family Constitution, Succession, Estate Planning, Trust & Private Clients
Intellectual Property Rights
Mergers / Amalgamations / Business Transfer
Foreign Investments
Tax
Banking & Finance
Cyber Law, Privacy, Data Protection & Information Technology
Startups
PEOPLE

RA ShahManaging Partner

Niranjan parekhSenior Partner

Bhushan ShahPartner

Purvi AsherPartner

Meeta kadhiAssociate Partner

Akash JainAssociate Partner

Sanjana SaddyOf-Counsel

Bhavin shahOf-Counsel

Neha LakshmanAssociate partner
News and Articles
employee data privacy for employers,
Employee Data Privacy: Legal Responsibilities of Employers
Employee data privacy is no longer only an HR policy issue. Employers collect extensive personal information during recruitment, onboarding, payroll, performance management, benefits administration and exit formalities. As India moves towards full implementation of the Digital Personal Data Protection Act, 2023, businesses must understand how employee information is collected, used, stored, shared and deleted. For employers, employee data privacy for employers now requires coordination between HR, legal, IT, information security and senior management. India's privacy framework is also moving through a transition period. The Digital Personal Data Protection Act, 2023 was enacted on 11 August 2023. The Government notified the Digital Personal Data Protection Rules, 2025 on 13 November 2025. Several provisions are being introduced in phases, with the core processing provisions scheduled to commence 18 months after the November 2025 notification.
Why Employee Data Privacy Matters for Employers?
HR departments handle some of the most commercially and personally significant information within an organisation. Employee records may include names, addresses, contact details, identification documents, bank account information, salary records, tax information, health and insurance details, attendance records, photographs, performance reviews and background verification information. Modern workplaces also generate digital records through access control systems, CCTV, company email, endpoint security tools, attendance applications, collaboration platforms and employee monitoring software. Remote working and Bring Your Own Device arrangements can increase the volume and complexity of personal data processing. Recent legal commentary on workplace monitoring highlights the need to consider both the purpose and scope of such monitoring. The risk is not limited to external cyberattacks. Unauthorised internal access, excessive data collection, inappropriate sharing with vendors, poor retention practices and unsecured spreadsheets can also expose an organisation to legal and operational risk.
The Indian Legal Framework Governing Employee Data
The constitutional right to privacy forms an important background principle. The Supreme Court recognised privacy as a constitutionally protected right under Article 21 in Justice K.S. Puttaswamy v Union of India. For private employers, however, practical obligations also arise through legislation, contracts, confidentiality duties and data protection requirements. The Digital Personal Data Protection Act, 2023 is India's principal comprehensive framework for digital personal data. Under the Act, an employer generally acts as a Data Fiduciary because it determines the purpose and means of processing employee information. Employees are Data Principals in relation to their personal data. The DPDP Act creates two principal grounds for processing personal data: consent and certain legitimate uses. Importantly for HR departments, Section 7 recognises processing necessary for employment purposes and certain activities connected with safeguarding the employer from loss or liability as a legitimate use. This means employers should not assume consent is required for every HR activity.
At the same time, the employment related provision should not be treated as a blanket exemption. Processing must still be connected with the relevant legitimate purpose. Employers should distinguish between necessary employment processing and additional activities such as optional profiling, intrusive monitoring or unrelated secondary uses.The Information Technology Act, 2000 and the Information Technology Rules concerning reasonable security practices and sensitive personal data or information remain relevant during the transition. The existing SPDI framework covers categories such as financial information, health information, biometric information and certain other sensitive information. The legal position is therefore transitional rather than a simple switch from one regime to another. Businesses should monitor the commencement notifications carefully instead of assuming every provision of the DPDP Act became operational immediately upon enactment.
What Employee Data Can Employers Collect?
An employer may legitimately need considerable information to establish and manage an employment relationship. Recruitment data may include CV information, qualifications, professional history, references and verification details. Onboarding may require identification documents, tax information, bank details and emergency contact information. During employment, HR may process attendance information, leave records, payroll data, benefits information, insurance details, performance assessments and disciplinary records. Some organisations also process biometric information for attendance or access control. The key question is not simply whether the organisation can collect a particular category of information. The organisation should ask why the information is required, whether the purpose is legitimate, whether less intrusive information would be sufficient, who needs access and how long the information should remain available. Data minimisation should therefore become part of everyday HR decision making.
Notice and Transparency Obligations
Transparency is a central part of a mature privacy programme. Employees should understand what personal data an organisation processes, why it is required and how it is handled. The notified DPDP Rules, 2025 provide important detail on privacy notices. Rule 3 requires a notice to be presented independently and in clear and plain language. It must include an itemised description of personal data and the specified purpose or purposes of processing. It must also provide relevant means for exercising rights and withdrawing consent where consent is the applicable basis. Employers should therefore review onboarding documents, HR portals, recruitment forms and employee handbooks. A generic privacy statement copied from a consumer website may not adequately explain employment related processing. A practical employee privacy notice should explain the categories of information collected, purposes of processing, relevant disclosures, retention approach, rights, grievance channels and methods for contacting the organisation.
When Is Employee Consent Required?
Consent remains an important legal basis under the DPDP framework, but it is not the answer to every employment processing activity. Section 7(i) of the DPDP Act permits certain processing necessary for employment and for specified purposes connected with protecting an employer from loss or liability. This can cover activities linked with employment administration, protection of trade secrets, prevention of corporate espionage and provision of benefits or services to employees. Employers should avoid using consent as a substitute for proper legal analysis. For example, collecting bank information to process salary may have a clear employment related purpose. By contrast, using employee information for an unrelated marketing activity may require a different legal basis. The employment relationship also creates a practical power imbalance. A consent mechanism should therefore not be designed as a meaningless tick box. Organisations should document why processing is necessary and identify cases where separate consent is appropriate.
Employee Monitoring and Workplace Surveillance
Technology has made employee monitoring easier. Employers may use CCTV, access logs, email security tools, device management systems, location information, productivity tools and cybersecurity platforms. The existence of a legitimate business purpose does not automatically make every form of monitoring proportionate. Employers should define the purpose of monitoring, restrict access, establish appropriate safeguards and communicate relevant practices to employees. Monitoring company email for cybersecurity or preventing data leakage is different from accessing an employee's personal communications. Similarly, collecting location information during working hours may require a different assessment from continuous location tracking. A good governance approach asks four questions: what is being monitored, why it is being monitored, who can access the information and when the monitoring stops.
Security Responsibilities of Employers
Security is one of the most important responsibilities associated with employee data. HR information should not be accessible to every employee simply because it is stored on an internal system. Organisations should implement appropriate technical and organisational safeguards. These can include access controls, authentication, encryption where appropriate, secure backups, audit logs, vulnerability management and employee awareness programmes. Vendor access also requires careful control. Payroll providers, background verification agencies, HR technology platforms, insurers and cloud service providers may process employee information on behalf of an employer. Contracts should clearly address permitted processing, confidentiality, security measures, incident management, access controls and deletion or return of information. The notified DPDP Rules provide further security requirements as part of the emerging compliance framework.
Retention and Deletion of Employee Information
One common weakness in HR privacy programmes is indefinite retention. An organisation may retain an employee's information for years simply because nobody has decided when it should be deleted. This creates unnecessary exposure. Former employee information can remain in HR folders, email archives, cloud drives, payroll systems and vendor platforms long after the original purpose has ended. Employers should create retention schedules linked to specific categories of records. The schedule should consider employment requirements, tax obligations, labour requirements, litigation holds and other applicable legal duties. Deletion should also cover practical copies. Removing a document from the HR system is not enough if duplicate copies remain in shared drives, email accounts or third party systems.
Recruitment and Former Employee Data
Privacy compliance should begin before an individual becomes an employee. Recruitment teams often collect CVs, photographs, identification documents, references, assessment results and background verification information. Employers should explain why these details are being collected and avoid retaining unsuccessful candidates' information indefinitely. The same principle applies after employment ends. Exit formalities may require certain records to be retained for legitimate legal or business reasons. Other information may no longer have a continuing purpose. An effective HR privacy framework therefore covers the complete employee lifecycle, from candidate application to post employment retention.
Employee Rights and Grievance Handling
The DPDP Act provides rights for Data Principals, including mechanisms relating to access to information, correction and erasure, subject to the statutory framework and applicable exceptions. Employers should create an internal process for handling employee privacy requests. HR teams should know who receives a request, how identity is verified, which systems are searched, who approves the response and how the organisation records its decision. A grievance mechanism is equally important. Employees should have a clear route for raising concerns about inappropriate collection, access, disclosure or use of their information. Businesses should begin preparing these processes before the relevant provisions become fully operational rather than waiting until the statutory deadline.
How Employers Can Build Stronger Employee Privacy Governance?
A practical programme begins with a data inventory. HR should identify every major category of employee information and record where it comes from, where it is stored, who can access it and which vendors receive it. The next step is to map purposes. Each processing activity should have a defined business or legal purpose. Unnecessary information should be removed from forms and systems. Organisations should then review privacy notices, HR policies, vendor contracts, retention schedules and security controls. Employee monitoring practices deserve a separate review because they can create heightened privacy concerns. Training is also essential. A technically strong privacy framework can fail if HR personnel routinely send salary information to the wrong recipient or store identity documents in unsecured folders. For organisations with complex operations, employee data privacy should be integrated into wider governance rather than treated as a standalone HR document.
The Role of Legal and Compliance Teams
Privacy compliance is not solely an IT responsibility. Legal teams help determine the appropriate legal basis, review contracts, assess regulatory exposure and interpret changing requirements. HR teams understand the operational context. IT and security teams implement safeguards. Senior management provides oversight and resources. Organisations may also require specialist corporate legal responsibilities guidance where employee monitoring, cross border data flows, mergers, acquisitions, outsourcing or large scale HR technology deployments create additional legal questions. The strongest approach is collaborative. Privacy should become part of the organisation's standard decision making process.
Preparing for the DPDP Transition
The Government notified the DPDP Rules, 2025 on 13 November 2025 and established a phased commencement structure. Under the commencement notification, the core provisions covering processing of personal data, including Sections 3 to 17, are scheduled to take effect 18 months after publication of the notification. This transition period gives employers an important opportunity. They can audit HR databases, review employee notices, assess vendor arrangements, establish retention schedules, test breach response procedures and train HR personnel before the substantive provisions become fully applicable. The official Ministry of Electronics and Information Technology resources provide access to the notified Act, Rules and implementation information. Digital Personal Data Protection Act, 2023 on MeitY Digital Personal Data Protection Rules, 2025 on MeitY
Conclusion
Employee data is an essential part of modern business operations, but it should not be treated as an unrestricted corporate asset. Employers must understand why information is collected, establish appropriate legal grounds, provide meaningful transparency, protect records, control vendor access and delete information when continued retention is no longer justified. The transition to India's new data protection framework makes this an appropriate time to review existing HR practices. Businesses that build privacy into recruitment, onboarding, employment monitoring, payroll, vendor management and exit processes will be better positioned to meet their legal responsibilities and maintain employee trust. Where an organisation needs specialised support, data protection compliance can be incorporated into broader governance, HR policy and corporate risk management programmes.
Frequently Asked Questions (FAQs)
Q1. Does the DPDP Act apply to employee data?
Yes. Employee personal data can fall within the scope of the DPDP Act when it is digital personal data covered by the legislation. Employers generally act as Data Fiduciaries while employees are Data Principals.
Q2. Do employers always need employee consent to process personal data?
No. Section 7 of the DPDP Act recognises certain legitimate uses, including specified processing necessary for employment and for safeguarding an employer from certain losses or liabilities. Consent may still be relevant for processing outside those legitimate uses.
Q3. Is employee health information protected in India?
Yes. Health information can constitute personal information requiring appropriate protection. The existing SPDI framework also treats medical records and physical or mental health information as sensitive personal data or information. Employers should consider the applicable regime during the DPDP transition.
Q4. Can an employer monitor employee emails?
An employer may have legitimate reasons to monitor company systems for cybersecurity, compliance or protection of business information. However, monitoring should be connected to a legitimate purpose and implemented proportionately. Accessing personal communications raises different privacy considerations.
Q5. How long can an employer retain employee data?
There is no single retention period for every category of employee information. Retention should depend on the purpose of processing and applicable legal, regulatory, contractual and litigation requirements.
Q6. Do former employees have privacy rights?
Former employees may continue to have rights and protections concerning personal information held by an organisation, subject to the applicable legal framework and commencement of relevant provisions. Employers should therefore have a clear post employment retention and deletion policy.
Q7. What should an employee privacy notice contain?
It should explain the categories of personal data collected, purposes of processing, relevant disclosures, rights, grievance mechanisms and other information required under the applicable legal framework. The DPDP Rules, 2025 provide specific requirements concerning clear and plain language notices.
Q8. What is the biggest employee data privacy risk for employers?
One major risk is uncontrolled data accumulation. Organisations often collect information without clearly defining the purpose, retain it indefinitely and provide access to more people or vendors than necessary. Strong data mapping, access controls, retention rules and staff training can reduce this exposure.
Q9. Should employers review their HR technology vendors?
Yes. Payroll providers, HR management platforms, recruitment systems, background verification companies, insurers and cloud service providers may process employee information. Employers should assess their contractual and security arrangements before sharing personal data.
Q10. Is employee consent required for payroll processing?
Not necessarily under the future DPDP framework. Processing necessary for employment can fall within the legitimate use recognised under Section 7. Employers should still provide appropriate transparency and comply with applicable security, governance and other obligations.
data protection laws for HR departments
Data Protection Laws Every HR Department Should Understand
Human Resources departments handle some of the most extensive collections of personal information within an organisation. Recruitment records, identity documents, salary details, bank information, attendance records, health information, performance reviews and employee communications can all involve personal data. For this reason, data protection laws for HR departments are no longer simply an IT or legal concern. They directly affect recruitment, onboarding, payroll, employee monitoring, benefits administration, vendor management and employee exits. India's privacy framework has changed significantly with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. The framework is being introduced through a phased commencement structure. HR teams therefore need to understand both the substantive requirements and the dates on which different obligations become operational.
What Data Protection Laws for HR Departments Mean in India?
The central legislation is the Digital Personal Data Protection Act, 2023. It regulates the processing of digital personal data and places primary responsibility on the Data Fiduciary, meaning the organisation deciding why and how personal data is processed. India Code identifies the employer's processing activities within the wider framework of the Act rather than creating a general exemption for employee information. In an HR setting, a Data Principal may be an employee, job applicant, former employee, intern, consultant or other individual whose personal information is processed by the organisation. The employee relationship therefore creates a continuing flow of personal data across multiple systems. The important point for HR leaders is simple: employee information does not become outside the privacy framework merely because it is collected for employment purposes.
Which Employee Information Can Fall Within the Framework?
HR departments routinely process names, addresses, contact details, identity information, educational records, employment histories and financial information. They may also handle information relating to health, insurance, attendance, performance, disciplinary proceedings, workplace access and employee benefits. Modern HR systems make the data environment even broader. Applicant tracking systems, payroll platforms, biometric attendance systems, learning management tools, background verification providers, cloud storage platforms and employee engagement applications may all process information relating to individuals. A useful compliance exercise therefore begins with data mapping. HR should identify what information is collected, why it is required, where it is stored, who can access it, which vendors receive it and when it should be deleted. This approach is consistent with the practical compliance focus emerging around India's new privacy framework.
Does HR Always Need Employee Consent?
Consent is important under the DPDP Act, but HR departments should avoid assuming every employment related activity requires a separate consent form. Section 7 of the Act recognises certain legitimate uses. Section 7(i) specifically covers processing necessary for employment or purposes connected with safeguarding an employer from loss or liability. It also covers providing a service or benefit sought by an employee. This can be relevant to activities such as administering employment benefits, managing workforce responsibilities and protecting confidential information. Processing connected with preventing corporate espionage or protecting intellectual property may also fall within the statutory legitimate use framework. However, the existence of a legitimate use does not give HR unrestricted authority to collect or use personal information. The purpose still matters. Necessity still matters. Security still matters. An organisation should be able to explain why particular information is collected and how it relates to the relevant employment activity. For example, using employee information for payroll administration is materially different from using the same information for unrelated marketing. HR should therefore distinguish between necessary employment processing and secondary uses requiring separate legal assessment.
Privacy Notices and Transparency Are Important HR Controls
HR teams should ensure employees and candidates receive appropriate information about how their personal data is processed. A privacy notice should reflect actual processing activities. It should not simply reproduce a generic privacy statement prepared for customers Recruitment notices may need to address information obtained through applications and background checks. Employee notices may need to address payroll, benefits, attendance, workplace security, internal investigations and other employment related activities. The DPDP Rules, 2025 provide detailed requirements concerning notices, including clear information about personal data and processing purposes. The notified Rules are being implemented in stages, so organisations should distinguish between provisions already operational and provisions scheduled to commence later. A well drafted notice also helps HR answer a practical question employees increasingly ask: “Why does the organisation need this information?”
Employee Monitoring Requires Particular Care
Workplace monitoring can create significant privacy risks. Employers may use CCTV, access control systems, device monitoring, email systems, location tools and security software for legitimate organisational purposes. Yet HR and IT teams should avoid treating the ability to collect information as evidence of a legal entitlement to collect it. The purpose and scope of monitoring should be carefully assessed. Monitoring should have a genuine business or legal justification and should not become excessive simply because technology makes extensive surveillance possible. For example, security logging designed to investigate unauthorised access is different from continuously tracking an employee's personal device outside working hours. HR policies should explain relevant monitoring practices clearly. Access to monitoring information should also be restricted to personnel with a legitimate need to use it.
Background Verification and Recruitment Data
Recruitment creates another significant privacy risk. Candidates may provide CVs, addresses, identification documents, references, educational records and previous employment details. Employers may also appoint external background verification agencies. HR should understand the source of candidate information and the purpose for which it is being obtained. It should also review the contractual and operational controls governing external vendors. Candidate data should not remain indefinitely in recruitment systems merely because deletion was never considered. Retention should be linked to legitimate business, legal or regulatory requirements. The same principle applies to unsuccessful applicants. An organisation should establish a defined approach for deciding how long recruitment information remains accessible.
Health, Biometric and Financial Information Need Strong Controls
HR departments often handle information carrying a high degree of practical sensitivity, even though the DPDP Act does not reproduce the older SPDI classification as its central organising principle. Examples include medical information, biometric identifiers, salary information, bank details and identity documents. Such information should receive appropriate security protection. Access should be based on business need. Copies should not be created unnecessarily. Documents should not be circulated through informal channels merely because doing so is convenient. The earlier Information Technology Act framework and the SPDI Rules also remain relevant during the transition period in circumstances covered by their continuing operation. Current employment law commentary notes the continuing relevance of Section 43A and the SPDI Rules during the phased transition. HR should therefore avoid assuming the DPDP Act is the only legal instrument relevant to employee information.
HR Vendors and Data Processors
Most organisations do not manage employee information entirely within internal systems. Payroll providers, recruitment platforms, cloud providers, benefits administrators, background verification agencies and other technology vendors may process employee or candidate information. The employer remains responsible for understanding how such processing occurs. Contracts should therefore address permitted processing, confidentiality, security measures, incident reporting, assistance with legal requests and deletion or return of information where appropriate. Vendor due diligence should also be proportionate to risk. A provider handling payroll information deserves closer scrutiny than a supplier with no access to personal data. HR, procurement, information security and legal teams should work together rather than treating vendor privacy as a purely procurement issue. For organisations requiring specialist data protection compliance, a structured assessment can help identify gaps across HR systems, contracts, policies and operational processes.
Data Security Is an HR Responsibility Too
A data breach does not necessarily begin with sophisticated hacking. An unlocked computer, an incorrectly addressed email, excessive access permissions, an unsecured spreadsheet or an employee sharing payroll information through an informal channel can create serious risks. The DPDP Act requires Data Fiduciaries to implement reasonable security safeguards to prevent personal data breaches. The precise controls should reflect the nature and volume of processing and the associated risks. HR should therefore work with information security teams to establish access controls, authentication measures, secure storage, incident reporting procedures and employee awareness programmes. Training is especially important because HR personnel frequently handle information other employees cannot access.
Retention and Deletion Should Be Planned
One of the common weaknesses in HR data governance is indefinite retention. Employee information can remain scattered across email accounts, shared drives, HR software, archived recruitment folders and vendor systems long after the original purpose has ended. Retention should be linked to the purpose for which information is held and to applicable legal requirements. HR should also consider whether information exists in multiple systems and whether deletion from one platform leaves copies elsewhere. A practical retention schedule can identify categories such as recruitment records, payroll information, employee files, disciplinary records and benefits information, along with applicable retention requirements and responsible owners.
Employee Rights and Grievance Handling
The DPDP Act gives Data Principals rights including access to information about personal data, correction and erasure in applicable circumstances, and grievance redressal. HR departments will therefore need processes for handling employee requests. A request should not sit unanswered because HR does not know which system contains the relevant information. Organisations should establish an internal process for identifying the requester, locating relevant information, assessing the request and coordinating with legal, IT or other teams where required. A central point of contact can reduce confusion and improve consistency.
The Role of HR Policies and Employment Documentation
Privacy compliance should extend beyond the company's website privacy policy. Employee handbooks, onboarding documents, HR policies, monitoring policies, vendor contracts and internal procedures should reflect actual data practices. Where HR uses new technologies, privacy implications should be assessed before implementation. This is especially relevant to artificial intelligence tools, automated recruitment systems, employee analytics and workplace monitoring technologies. A written policy is useful only when operational teams follow it. HR should therefore periodically test whether its systems and processes match its stated commitments. Organisations can also review broader corporate legal compliance through an integrated governance exercise covering employment, technology, contractual and privacy obligations.
Current Implementation Position Under the DPDP Framework
Businesses should pay close attention to the commencement framework. The Digital Personal Data Protection Act received Presidential assent on 11 August 2023. The Government subsequently notified the Digital Personal Data Protection Rules, 2025 and an implementation timeline on 13 November 2025. Some provisions became operational on notification, while substantive provisions have later commencement dates. This means HR departments should not use the later commencement date for certain obligations as a reason to delay preparation. Changing HR platforms, contracts, retention processes and internal governance can take considerable time. Early preparation also helps organisations identify unnecessary data collection before it becomes embedded in systems. The official Digital Personal Data Protection Act, 2023 on India Code and Digital Personal Data Protection Rules, 2025 published by MeitY should be treated as primary reference sources for statutory requirements and implementation developments.
Why HR Teams Need a Practical Privacy Governance Model?
Effective employee data protection cannot sit entirely with the legal department. HR owns many of the processes through which employee information enters and moves across an organisation. IT controls systems. Cybersecurity manages technical safeguards. Procurement manages vendor relationships. Finance processes payroll. Legal interprets obligations and manages risk. A practical governance model connects these functions. HR should maintain visibility over its data flows, define ownership, review vendor access, establish retention practices, train personnel and coordinate with legal and security teams when new processing activities are introduced. This approach turns privacy from a document exercise into an operational control system.
Conclusion
The growing importance of data protection laws for HR departments reflects a simple reality: employee information is central to almost every stage of the employment lifecycle. The DPDP Act and Rules provide a new statutory framework, but compliance cannot be achieved by adding another clause to an employment contract. HR departments need to understand their data flows, distinguish consent from legitimate use, protect high risk information, control vendor access, establish retention practices and prepare for employee rights. The strongest approach is practical. Identify the information. Understand why it is processed. Limit access. Protect it properly. Retain it only as long as necessary. Review the process whenever the organisation, technology or law changes.
Frequently Asked Questions (FAQs)
Q1. Does the DPDP Act apply to employee data?
Yes. Employee personal data can fall within the DPDP framework when processed in digital form, subject to the Act's scope and applicable exemptions. Employment related processing may qualify as a legitimate use in specified circumstances.
Q2. Is employee consent required for payroll processing?
Not necessarily. Processing necessary for employment can fall within the legitimate use provision under Section 7(i). HR should still assess the purpose, necessity, transparency and security of the processing.
Q3. Does an employee have privacy rights under the DPDP Act?
Yes. The Act provides Data Principal rights including access to information, correction and erasure in applicable circumstances, grievance redressal and nomination.
Q4. Can employers monitor employees?
Monitoring may be possible for legitimate employment, security or compliance purposes, but organisations should assess the purpose, scope and necessity of the monitoring and implement appropriate safeguards.
Q5. How should HR manage employee data held by third party vendors?
HR should identify the information shared with each vendor and ensure appropriate contractual, security, confidentiality and incident management controls are in place. Vendor access should be limited to what is necessary.
Q6. How long can HR retain employee data?
There is no single universal retention period for every category of employee information. Retention should be assessed against the purpose of processing and applicable legal, regulatory and contractual requirements.
Q7. Is a privacy policy sufficient for HR compliance?
No. A privacy policy is only one component. Effective compliance also requires data mapping, appropriate processing grounds, notices, security measures, vendor governance, retention controls, rights handling and incident response.
Q8. What should HR do first when preparing for DPDP compliance?
HR should begin by mapping its personal data. Identify employee and candidate information, processing purposes, systems, vendors, access rights and retention practices. This provides the foundation for identifying legal and operational gaps.
consent management
Consent Management Under India's Data Protection Laws
Businesses collect personal data through websites, mobile applications, customer accounts, marketing forms, financial transactions and digital services. As data use becomes more complex, consent management is no longer simply a matter of adding an “I agree” button to a website. It involves obtaining valid consent, recording the decision, connecting it to a specific purpose, respecting withdrawal and ensuring the choice is reflected across relevant systems.
India's Digital Personal Data Protection Act, 2023 introduces a detailed statutory framework for consent. The Digital Personal Data Protection Rules, 2025 add operational requirements and establish a framework for registered Consent Managers. The provisions are being brought into force in phases, making it important for businesses to understand both the legal requirements and the implementation timeline.
What Is Consent Management?
Consent management is the process through which an organisation obtains, records, maintains and acts upon an individual's permission concerning the processing of personal data. A reliable system should answer several basic questions.
What did the individual agree to?
For what purpose?
When was consent given?
Which notice was presented?
What personal data was involved?
Can the individual withdraw consent?
Has the withdrawal reached the systems and service providers processing the information?
This makes consent management broader than consent collection. It is an ongoing governance process covering the entire consent lifecycle. A business may manage consent through internal processes, software, a consent management platform or, where relevant under the DPDP framework, through a registered statutory Consent Manager.
Consent Under India's DPDP Act
The DPDP Act establishes consent as one of the grounds for processing personal data. Section 4 permits processing for a lawful purpose based on consent or certain legitimate uses specified under the Act. Section 6 establishes the legal standard for valid consent. Consent must be free, specific, informed, unconditional and unambiguous. It must involve clear affirmative action and relate to the specified purpose. It must also be limited to personal data necessary for that purpose. This requirement has direct implications for how businesses design forms, applications and websites. A customer should not be asked to provide unnecessary information merely because it may be useful at some future point. Similarly, unrelated purposes should not be hidden inside a single blanket permission.
Consent Is Not the Same as a Privacy Notice
Privacy notices and consent serve different functions. A privacy notice provides information. It explains what personal data is being processed, why it is being processed and how relevant rights can be exercised. Consent is the individual's affirmative agreement where consent is the applicable legal basis. Section 5 of the DPDP Act requires notice to accompany or precede a request for consent. The 2025 Rules provide further requirements concerning the content and presentation of this notice. The official explanatory note states the notice should be clear, standalone and understandable, with an itemised description of personal data and the purpose for processing. Businesses should therefore avoid treating a long privacy policy as a substitute for a clear consent request.
What Makes Consent Legally Valid?
A valid consent process begins with meaningful information. The individual should understand what information is being requested and why. The purpose should be specific enough to understand the proposed processing. Consent should also involve a genuine choice. A business should not design its user journey in a manner which makes acceptance unavoidable where consent is not genuinely necessary for the service. The DPDP Act also prevents consent from being used to override statutory protections. Section 6 provides, among other things, that consent infringing the Act, Rules or another applicable law is invalid to the extent of the infringement. For businesses, this means consent is not a mechanism for contracting out of legal obligations.
Consent Withdrawal Is Part of Consent Management
Obtaining consent is only the beginning. Section 6 provides individuals with a right to withdraw consent at any time. The process for withdrawal must be as easy as the process for giving consent. Once consent is withdrawn, the Data Fiduciary must stop processing based on that consent and cause its Data Processors to stop, unless continued processing is otherwise authorised or required by law. This requirement creates a practical technology challenge. If a customer withdraws consent through a website, the preference should not remain active in a separate marketing database. Where relevant, the withdrawal should also reach connected processors and downstream systems. A withdrawal mechanism which changes only one database field may therefore be insufficient from an operational perspective.
Consent Management Must Be Purpose Based
Consent should be connected to a defined processing purpose. For example, a business may process customer information to provide a service, send promotional communications, personalise content or conduct analytics. These activities may involve different purposes and should not automatically be treated as one permission. Purpose based consent also improves internal accountability. When a processing activity is reviewed, the organisation can identify the consent supporting it rather than searching through a general customer preference record. This approach becomes particularly important for businesses using customer information for profiling, targeted advertising, artificial intelligence or data analytics.
How Should Businesses Record Consent?
A business should maintain sufficient evidence of consent. The record should ideally establish the identity or relevant identifier of the Data Principal, the date and time of the decision, the purpose involved, the personal data covered, the notice presented and the consent decision. Version control is also important. If a business changes its notice or consent language, it should be possible to identify which version an individual saw when consent was obtained. This creates a defensible audit trail and helps the organisation understand how its privacy practices changed over time. The DPDP Act places the burden of proving valid consent on the Data Fiduciary where consent is relied upon.
Consent Management Across Business Systems
Modern businesses rarely process customer information in a single system. A customer may provide information through a website, while the information is stored in a CRM, processed by a cloud provider, analysed by a data platform and used by a marketing system. Consent must therefore be connected to the wider data ecosystem. Suppose a customer withdraws consent for promotional communications. The withdrawal should be reflected not only in the main customer database but also in relevant email marketing, SMS, customer engagement and advertising systems. The objective is not simply to preserve evidence of the customer's decision. The organisation must also operationalise it.
Consent Management for Websites and Applications
Websites and applications are often the first point at which consent is requested. Consent interfaces should use clear language and should not obscure important information. Where multiple purposes are involved, users should be able to understand the choices being presented. Applications require additional consideration because they may process device identifiers, location information, photographs, contacts or other information depending on their functionality. The consent experience should correspond with the actual data practices of the application. A business should also review its cookies, tracking technologies, analytics tools and advertising integrations. A consent mechanism is ineffective if third party scripts continue processing information despite a user's choice.
What Is a Consent Management Platform?
A Consent Management Platform, commonly called a CMP, is a technology solution used by organisations to manage consent processes. A CMP can help display consent notices, record decisions, manage preferences and communicate choices to connected systems. However, using a CMP is not itself a statutory requirement under the DPDP Act. This distinction is important because the term “Consent Manager” has a specific meaning under Indian law.
Consent Manager Under the DPDP Act
The DPDP Act defines a Consent Manager as a person registered with the Data Protection Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. This is different from an ordinary consent management platform used by a company for its own website or applications. A statutory Consent Manager is an independent regulated intermediary. It is designed to allow an individual to manage consent across multiple Data Fiduciaries. The 2025 Rules establish registration conditions and operational duties for such Consent Managers. The official MeitY explanatory note states the Consent Manager must meet requirements concerning financial and operational capacity, an interoperable platform, security, records, transparency and conflicts of interest.
When Will Consent Managers Become Operational?
The implementation timeline is particularly important. The commencement notification issued in November 2025 provides different dates for different provisions. Section 6(9), which concerns accountability of Consent Managers, is subject to the one year commencement period. Most of Section 6 is subject to the eighteen month period. Based on the notification dated 13 November 2025, the one year milestone is 13 November 2026 and the eighteen month milestone is 13 May 2027. Rule 4 of the DPDP Rules, which deals with registration and obligations of Consent Managers, follows the one year commencement period. Therefore, businesses should distinguish between the concept and regulatory framework for Consent Managers and the later commencement of the provisions allowing Data Principals to use such services.
Is a Business Required to Use a Consent Manager?
No.
An ordinary Data Fiduciary does not become a statutory Consent Manager merely because it collects consent. The DPDP framework gives Data Principals the option to use a registered Consent Manager. A business can continue to collect and manage consent through its own compliant processes. The important requirement is to ensure the consent process itself satisfies the applicable legal standards.This distinction prevents a common misconception. Buying a consent management tool does not automatically make an organisation compliant, and operating an internal consent database does not make the organisation a statutory Consent Manager.
Consent Management and Children’s Data
Children's data requires additional safeguards. The DPDP Act defines a child as an individual who has not completed eighteen years of age. Section 9 requires verifiable parental or guardian consent before processing a child's personal data, subject to the statutory framework. It also restricts processing likely to cause a detrimental effect on a child's well being and addresses tracking, behavioural monitoring and targeted advertising directed at children, subject to specified exemptions. The Rules provide further requirements concerning verification of parental or guardian consent. Businesses serving children should therefore consider age assurance, guardian verification and consent records as part of their product architecture rather than adding them after launch.
Consent Management and Data Processors
Consent decisions must follow the data. If a Data Fiduciary appoints a Data Processor, the processor may handle personal data on behalf of the fiduciary. The Data Fiduciary must therefore ensure its contractual and technical arrangements allow consent related decisions to be implemented where required. For example, if a customer withdraws consent and the relevant processing must stop, the business should have a mechanism for communicating the change to the processor. Vendor contracts should address privacy responsibilities, security, incident reporting, deletion, subcontracting and assistance with Data Principal requests. This is especially important where the business uses numerous SaaS platforms.
Consent and Marketing Communications
Marketing consent should be handled carefully. Businesses often combine service communications with promotional communications. These activities may have different purposes and may be governed by different legal requirements. A customer may need transactional messages to receive a service while separately choosing whether to receive promotional email or SMS communications. Businesses should therefore avoid assuming one general customer acceptance covers every communication channel. The organisation should also consider applicable telecom and sector specific requirements governing commercial communications.
Consent and Artificial Intelligence
The growing use of artificial intelligence creates new consent questions. A business may collect customer conversations for support purposes and later want to use those records to train or improve an AI system. The organisation should assess whether the proposed use falls within the original purpose, whether another lawful basis applies and whether the customer was adequately informed. The same principle applies to profiling, behavioural analytics and personalisation. A consent record should not be treated as a permanent licence to use personal data for every future purpose.
Consent Management and International Privacy Laws
Indian businesses may also be subject to foreign privacy requirements. An organisation offering services to individuals in the European Economic Area, for example, may need to consider the GDPR. Other jurisdictions have their own rules governing consent, marketing, cookies and individual rights. A single consent architecture can support multiple legal regimes, but the underlying legal analysis must remain jurisdiction specific. Businesses should identify where customers are located, which data is processed, which systems receive it and which laws apply.
Consent Management and Information Security
Consent records themselves contain valuable information. A business should protect consent databases against unauthorised alteration, deletion and access. If an attacker can modify consent records, the organisation may lose the ability to demonstrate a customer's actual decision. Access controls, authentication, logging, backups and appropriate security measures should therefore apply to consent systems. The DPDP Act requires Data Fiduciaries to implement reasonable security safeguards to prevent personal data breaches. Businesses should also consider CERT In requirements. Its Cyber Security Directions require specified cyber incidents, including data breaches and data leaks, to be reported within six hours of noticing them.
Building a Practical Consent Management Framework
An effective programme should begin with a data and processing inventory. The organisation should identify each processing purpose for which consent may be required. It should then map the relevant notice, consent interface, data systems, processors and downstream recipients. The next step is to establish how consent is captured and recorded. The organisation should preserve sufficient evidence to demonstrate the decision. Withdrawal should then be tested across the technology environment. A business should verify whether the change reaches CRM systems, marketing platforms, analytics tools and relevant processors. Regular testing is important. A consent mechanism can become ineffective when a new vendor, tracking tool or product feature is introduced. Organisations requiring assistance with designing and implementing these processes may consider data protection compliance services as part of their broader privacy governance framework.
Common Consent Management Mistakes
One common mistake is treating consent as a single checkbox. Another is using vague purposes. A user should be able to understand what the consent actually permits. Businesses also sometimes make withdrawal difficult. A customer may be able to accept a permission in one click but need to contact customer support to withdraw it. This conflicts with the statutory principle requiring withdrawal to be as easy as giving consent. Other risks include missing consent records, outdated privacy notices, inconsistent records across systems and failure to communicate withdrawals to processors. A technically sophisticated platform cannot solve these issues if the underlying governance is weak.
Why Consent Management Matters for Business Governance?
Consent management sits at the intersection of privacy, technology, marketing, cybersecurity and corporate governance. A well designed system can help a business demonstrate accountability, respond to individual requests and maintain consistent data practices. It can also reduce operational confusion. Employees should not have to determine manually whether a customer has consented each time personal data is used. As organisations grow, business compliance legal services can help integrate privacy processes with contracts, vendor management, regulatory obligations and wider corporate governance.
Conclusion
Consent management under India's data protection framework is becoming an important operational discipline for businesses. It is no longer sufficient to collect an affirmative response and store a simple “yes” in a database. Businesses need to understand the purpose for which consent is sought, provide meaningful information, capture valid consent, preserve evidence, make withdrawal easy and ensure changes are reflected across relevant systems and processors.
The DPDP Act also introduces a distinct statutory concept of the Consent Manager. This should not be confused with ordinary consent management software. The 2025 Rules establish the framework for registration and operation of Consent Managers, with the relevant provisions coming into force in phases. Organisations should therefore use the transition period to review their consent journeys, privacy notices, customer databases, vendor contracts and technical controls. The objective should be a consent process which is legally defensible, technically enforceable and understandable to the individual.
Frequently Asked Questions (FAQs)
Q1. What is consent management under the DPDP Act?
Consent management refers to the processes used to obtain, record, manage and honour an individual's consent for processing personal data. It includes consent capture, evidence, withdrawal and implementation across relevant systems.
Q2. What are the requirements for valid consent in India?
Under Section 6 of the DPDP Act, consent must be free, specific, informed, unconditional and unambiguous, involve clear affirmative action and be limited to personal data necessary for the specified purpose.
Q3. Can consent be withdrawn under the DPDP Act?
Yes. A Data Principal may withdraw consent at any time. The withdrawal process must be as easy as the process used to give consent.
Q4. Is a Consent Management Platform mandatory in India?
No. The DPDP Act does not require every Data Fiduciary to use a particular consent management platform. Businesses must instead establish processes capable of meeting their applicable legal obligations.
Q5. Is a Consent Manager the same as a Consent Management Platform?
No. A statutory Consent Manager is a person registered with the Data Protection Board and provides an interoperable service through which Data Principals can manage consent. A Consent Management Platform is generally software used by an organisation to manage its own consent processes.
Q6. When will Consent Managers be registered in India?
The registration framework under Section 6(9) and Rule 4 is subject to the one year commencement period from 13 November 2025. The relevant milestone is 13 November 2026.
Q7. Does every business need to use a registered Consent Manager?
No. Businesses can manage consent directly. The statutory Consent Manager is an optional mechanism available to Data Principals under the DPDP framework.
Q8. Does consent apply to every type of personal data processing?
No. The DPDP Act recognises consent as one ground for processing and separately provides for certain legitimate uses. Businesses should identify the appropriate legal basis for each processing activity.
Q9. How should businesses prove consent?
Businesses should maintain reliable records showing the relevant consent decision, purpose, timing, notice version and other appropriate contextual information. The DPDP Act places the burden of proving valid consent on the Data Fiduciary where consent is relied upon.
Q10. What happens after a user withdraws consent?
Where consent is the applicable basis, the Data Fiduciary must stop processing based on the withdrawn consent and cause its Data Processors to stop, unless continued processing is otherwise authorised or required by law.
Q11. Do consent requirements apply to children's data?
Yes, with additional safeguards. The DPDP Act requires verifiable parental or guardian consent for processing a child's personal data, subject to the applicable statutory provisions and exemptions.
privacy policy requirements
Privacy Policies: Legal Requirements Every Business Should Know
A privacy policy is more than a page placed in the footer of a website. It explains how a business collects, uses, stores and shares personal information. For organisations operating in India, understanding the privacy policy requirements has become increasingly important following the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
The legal framework is moving towards a more structured approach to privacy notices, consent, security, retention and individual rights. At the same time, sector specific regulations and international privacy laws may apply to particular businesses. A well drafted privacy policy should therefore reflect actual business practices rather than rely on a generic template.
What Is a Privacy Policy?
A privacy policy is a document explaining an organisation's practices concerning personal data. It normally tells users what information is collected, why it is collected, how it is used, who may receive it, how long it may be retained and how individuals can exercise applicable rights. The document serves an important transparency function. It also helps businesses establish a consistent internal approach to handling personal information. For Indian businesses, the privacy notice framework is increasingly connected with the statutory obligations of a Data Fiduciary under the DPDP Act. A Data Fiduciary is an entity deciding the purpose and means of processing personal data. A privacy policy should therefore be consistent with the organisation's actual processing activities.
Privacy Policy Requirements Under Indian Law
India's privacy framework has developed through several legal instruments. The Information Technology Act, 2000 and the Information Technology Rules, including the Sensitive Personal Data or Information Rules, 2011, established earlier privacy and security requirements. The DPDP Act, 2023 now provides a broader statutory framework for digital personal data. Section 5 of the DPDP Act requires a notice to accompany or precede a request for consent. The notice must inform the Data Principal about the personal data proposed to be processed, the purpose of processing, how specified rights may be exercised and how a complaint may be made to the Board. The DPDP Rules, 2025 provide more detailed requirements for such notices. This means businesses should not view a privacy policy as a static legal document. It should form part of the organisation's wider privacy governance system.
What Should a Privacy Policy Contain?
A good privacy policy should clearly identify the organisation responsible for processing personal data. The legal name of the business and appropriate contact details should be easy to find. It should explain the categories of personal data collected. Depending on the business, this could include names, contact details, account information, location information, transaction records, device information or information generated through use of a service. The policy should then explain the purposes for which each category is processed. Specific explanations are preferable to broad statements such as “for business purposes”. The notice should also explain relevant rights, consent withdrawal procedures and grievance mechanisms. Rule 3 of the DPDP Rules requires the notice to provide an itemised description of the personal data and the specified purpose for processing. It also requires information concerning rights, the manner of exercising those rights and complaints to the Board. The notice must be presented in clear and plain language.
Identity and Contact Details of the Business
Users should know who is collecting their information. A privacy policy should identify the relevant legal entity and provide a reliable privacy contact mechanism. Where a Data Protection Officer is legally required, the relevant contact details should be provided. This becomes especially important for corporate groups. A website may display one brand while another legal entity actually processes customer information. The privacy documentation should make the relationship clear.
Explain What Personal Data Is Collected
Businesses should describe the information they collect in understandable terms. This can include information supplied directly by customers, information generated through transactions and information collected automatically through websites or applications. The description should be sufficiently specific for an individual to understand the nature of the information involved. A business should also review whether every data field it collects is necessary. Collecting information simply because the technology allows it can increase privacy and security risks.
Explain Why the Information Is Collected
Purpose is one of the most important elements of an effective privacy notice. A business should connect data collection with a defined purpose. For example, an e commerce business may process contact details to deliver an order, payment information to complete a transaction and account information to manage the customer relationship. Separate purposes should not be hidden behind vague language. This is particularly important when businesses later introduce analytics, profiling, personalised marketing or artificial intelligence tools. A new use should be assessed against the original purpose and the applicable legal basis.
Consent Must Be Meaningful
Where consent is used as the basis for processing, it must satisfy the requirements of the DPDP Act. Section 6 states consent must be free, specific, informed, unconditional and unambiguous, with clear affirmative action. It must relate to the specified purpose and be limited to personal data necessary for that purpose. The request for consent must also use clear and plain language. Businesses should avoid confusing consent interfaces, pre selected choices and bundled permissions for unrelated activities. A user should understand what they are agreeing to. Where consent is withdrawn, the business must follow the statutory requirements concerning cessation of processing, subject to circumstances where continued processing is authorised or required by law.
Privacy Policies Must Match Actual Business Practices
One of the biggest weaknesses in privacy documentation is inconsistency. A policy may state personal data is retained for a specific period while the company's systems retain it indefinitely. It may say information is shared only with selected providers while several additional analytics services receive data. Such inconsistencies can undermine the value of the policy. Businesses should therefore conduct a data mapping exercise before drafting or updating the document. The legal team should understand how the website, application, CRM, payment systems, cloud platforms and marketing tools actually process information. The policy should describe reality rather than an idealised version of the business.
Data Sharing With Third Parties
Many organisations share personal information with service providers. These may include payment gateways, cloud hosting providers, customer support platforms, analytics companies, marketing platforms and outsourced service providers. The privacy policy should explain relevant categories of recipients and the purpose for sharing information. The business should also examine its contracts with these providers. Under Section 8 of the DPDP Act, a Data Fiduciary remains responsible for compliance concerning processing carried out by it or on its behalf by a Data Processor. A Data Processor may be engaged for activities related to offering goods or services only under a valid contract. A privacy policy therefore cannot replace appropriate vendor agreements.
Data Retention and Deletion
A privacy policy should explain how long personal information is retained or the criteria used to determine retention. The retention approach should be linked to business purposes and legal requirements. Section 8 requires a Data Fiduciary, subject to legal retention requirements, to erase personal data when consent is withdrawn or when it is reasonable to assume the specified purpose is no longer being served. The Data Fiduciary must also cause its Data Processor to erase relevant information. Businesses should therefore maintain internal retention schedules alongside their public privacy notices.
Security Measures and Data Breaches
A privacy policy should provide an appropriate explanation of security practices without revealing information which could itself create security risks. The DPDP Act requires Data Fiduciaries to implement appropriate technical and organisational measures and reasonable security safeguards to prevent personal data breaches. The DPDP Rules 2025 further specify security safeguards. Rule 6 includes measures such as encryption, masking, access controls, logs, monitoring, backups and appropriate contractual provisions concerning Data Processors. Businesses should also establish an internal breach response procedure. A privacy policy can explain how affected individuals will be informed where notification is required, but the operational response must be supported by technical and organisational processes.
Cookies and Online Tracking
Websites often collect information automatically through cookies, pixels, analytics tools and similar technologies. A business should identify the technologies it uses and explain their purposes where applicable. It should also distinguish essential functionality from analytics, advertising and other tracking activities where the relevant legal framework requires separate choices or disclosures. Cookie practices should match the actual configuration of the website. A privacy policy should not state cookies are used only for basic functionality if advertising platforms or analytics providers are also receiving information.
Privacy Policies for Mobile Applications
Mobile applications create additional considerations. An application may access device identifiers, location information, camera functions, contacts, photographs or other information depending on its functionality. The privacy documentation should accurately describe such collection and use. Businesses must also consider platform specific requirements. Google Play, for example, requires apps to provide a clear and accessible privacy policy and to disclose relevant data collection, use, sharing, security and retention practices. The policy should therefore be reviewed alongside the application's actual permissions and platform disclosures.
Children's Personal Data
Businesses serving children require additional care. Under Section 9 of the DPDP Act, a child means an individual who has not completed eighteen years of age. Processing a child's personal data requires verifiable parental or guardian consent, subject to the statutory framework. The Act also addresses processing likely to cause detrimental effects on a child's well being and restricts tracking, behavioural monitoring and targeted advertising directed at children, subject to specified exemptions. Businesses offering gaming, education, social, healthcare or other services likely to be used by children should assess these obligations before collecting information. The privacy policy alone will not satisfy these requirements. Product design, age assurance and consent mechanisms may also need to be considered.
International Data Transfers
A business may store or process personal data outside India. The DPDP Act generally permits transfer of personal data outside India subject to restrictions which may be imposed by the Central Government. Other laws may impose additional requirements. Businesses should therefore disclose relevant international processing practices where appropriate and understand the countries in which information is stored or accessed. If an organisation serves individuals in other jurisdictions, foreign privacy laws may also apply. For example, the GDPR contains its own transparency and international transfer requirements. A privacy policy should not make broad claims about international transfers without first understanding the organisation's actual technology and vendor arrangements.
Sector Specific Privacy Requirements
Not every business operates under the same regulatory framework. Financial institutions, payment businesses, insurers, healthcare organisations, telecommunications companies and other regulated entities may face additional requirements. For example, the RBI's framework for payment system data includes specific storage requirements in India. A business operating in this sector therefore needs to consider RBI requirements alongside the general DPDP framework. This is one reason generic privacy templates can create risk. A document suitable for an ordinary online retailer may be inadequate for a regulated financial or healthcare business.
Privacy Policy Requirements During the DPDP Transition
Businesses should pay close attention to the DPDP implementation timeline. The DPDP Act was enacted on 11 August 2023. The Central Government issued the commencement notification in November 2025, establishing a phased implementation structure. Certain provisions commenced immediately, some after one year and the principal operational provisions after eighteen months. The DPDP Rules 2025 follow a similar phased structure. Rules 1, 2 and 17 to 21 commenced upon publication. Rule 4 is subject to a one year period, while Rules 3, 5 to 16, 22 and 23 are subject to the eighteen month period. The eighteen month period runs from 13 November 2025, making 13 May 2027 the commonly calculated date for the principal requirements. This distinction matters. Businesses should avoid saying the entire DPDP framework is already operational. At the same time, waiting until 2027 to begin preparation would be commercially unwise.
When Should a Business Update Its Privacy Policy?
A privacy policy should be reviewed whenever there is a material change in data processing. Examples include launching a new product, introducing a new analytics platform, appointing a new processor, changing data retention periods, introducing targeted advertising, expanding internationally or using customer information for artificial intelligence. The policy should also be reviewed when legislation, rules or sector specific regulatory requirements change. Businesses should maintain version control and record significant changes. Where appropriate, affected users should be informed about material changes.
Common Privacy Policy Mistakes
A common mistake is copying a policy from another business. A document may look professionally drafted but describe services, technologies or data practices the business does not actually use. Another problem is excessive legal language. Users should be able to understand how their information is handled without needing specialist legal knowledge. Businesses also sometimes list every possible type of data without explaining why it is collected. This weakens transparency. Other frequent issues include outdated vendor lists, missing retention information, broken privacy contact channels, inconsistent cookie disclosures and failure to update the policy after launching new features. A privacy policy should be treated as a living compliance document.
Why Legal Review Matters?
A privacy policy sits at the intersection of technology, contracts, consumer communication and regulatory compliance. Legal review can help determine whether the document accurately reflects the organisation's processing activities and whether additional requirements apply because of the business model or sector. Professional privacy policy legal services can be particularly useful when a business is preparing for DPDP compliance, entering regulated markets, launching an application or handling international customer data. The objective should not be to make the document unnecessarily long. It should be accurate, understandable and aligned with the organisation's actual practices.
Privacy Policy as Part of Corporate Governance
A privacy policy works best when supported by internal controls. The business should know who owns privacy compliance, how customer requests are handled, how vendors are assessed, how personal data is deleted and how incidents are escalated. For growing organisations, privacy governance should connect with contracts, cybersecurity, human resources, procurement and product development. Broader corporate legal support for businesses can help organisations integrate privacy requirements with wider contractual and regulatory obligations rather than treating the policy as an isolated website document.
Penalties and Business Risk
Privacy compliance has financial consequences as well as reputational implications. The DPDP Act's Schedule provides penalties of up to ₹250 crore for certain failures concerning security safeguards. Other breaches carry maximum penalties depending on the obligation involved. A defective privacy policy may also expose a business to customer complaints, contractual disputes, regulatory scrutiny and difficulties during investor or enterprise due diligence. The precise consequences depend on the nature of the contravention and the applicable legal framework.
How to Build an Effective Privacy Policy?
The process should begin with a data audit. The business should identify what information it collects, where it comes from, why it is processed, who receives it, where it is stored and how long it remains in the organisation's systems. The next stage is to identify the applicable legal requirements. This should include the DPDP Act and Rules, relevant sector specific regulations and foreign laws where applicable. The privacy notice can then be drafted around the organisation's real processing activities. Finally, the business should establish a review process. Privacy compliance is not completed when a document is uploaded to a website. It requires continuing governance.
Conclusion
A privacy policy should be treated as an important part of a business's data governance framework, not as standard website boilerplate. The document should accurately explain what information is collected, why it is used, who receives it, how it is protected, how long it is retained and how individuals can exercise applicable rights. For Indian businesses, the DPDP Act 2023 and DPDP Rules 2025 have made privacy governance increasingly important. The phased implementation timeline provides businesses with an opportunity to review their data practices, update notices, strengthen consent mechanisms and establish appropriate internal controls before the principal obligations become operational.
Businesses should also remember that privacy compliance extends beyond the DPDP framework. Sector specific regulations, cybersecurity requirements, contractual commitments and foreign privacy laws can create additional obligations. The most reliable approach is to begin with the business's actual data flows and build the privacy policy around them. A clear policy supported by sound operational controls can improve transparency, reduce legal risk and strengthen customer confidence. Businesses should monitor the official Digital Personal Data Protection Rules resources published by MeitY for future implementation notifications and regulatory developments. The India Code legal database is also a useful government source for checking current legislation.
Frequently Asked Questions (FAQs)
Q1. Is a privacy policy legally required for every business in India?
The answer depends on the nature of the business and the data processing involved. Businesses processing digital personal data should assess the applicable statutory notice and transparency requirements rather than assume a privacy policy is merely optional website content.
Q2. What should a privacy policy include in India?
It should explain relevant personal data collected, purposes of processing, consent mechanisms where applicable, rights, grievance procedures, data sharing, retention and other information required by the applicable legal framework. Section 5 and Rule 3 of the DPDP framework are particularly important for consent notices.
Q3. Does the DPDP Act require consent for all personal data processing?
No. The Act provides for processing based on consent as well as specified legitimate uses. The appropriate legal basis should be assessed according to the processing activity.
Q4. Can a business use a free privacy policy template?
A template can provide a starting point, but it may not accurately reflect the organisation's data practices or sector specific requirements. A policy should be customised and reviewed before publication.
Q5. How often should a privacy policy be updated?
There is no universal interval suitable for every business. It should be reviewed whenever material changes occur in data collection, processing, sharing, retention, technology or applicable law.
Q6. Does a privacy policy need to mention third party vendors?
The policy should provide appropriate information about relevant sharing and recipients. Businesses should also maintain appropriate contracts with Data Processors. Section 8 requires processing by a Data Processor on behalf of a Data Fiduciary to be supported by a valid contract.
Q7. Should a privacy policy mention cookies?
Yes, where the website or application uses cookies or similar technologies. The disclosure should accurately reflect the technologies actually deployed and their purposes.
Q8. Does the privacy policy need to mention data retention?
Retention practices should be explained where required by the applicable framework, and businesses should maintain internal retention controls. The DPDP Act also contains obligations concerning erasure when the relevant purpose is no longer being served or consent is withdrawn, subject to legal requirements.
Q9. Does the DPDP Act apply to employee information?
The Act covers digital personal data, subject to its scope and exemptions. Certain processing for employment related purposes is addressed within the Act's legitimate use framework. Businesses should assess employee data separately from customer data because employment laws and internal HR requirements may also apply.
Q10. What happens if a privacy policy is inaccurate?
An inaccurate policy can create transparency, contractual and regulatory risks. More importantly, it can demonstrate a gap between documented practices and actual processing. The business should investigate the underlying data flows and correct both the operational practice and the privacy documentation.
Q11. When do the main DPDP privacy notice requirements become operational?
The principal operational provisions of the DPDP Act and Rules are subject to an eighteen month commencement period from November 2025. The commonly calculated date for these provisions is 13 May 2027. Businesses should monitor official Government notifications for implementation developments.
MHCO Updates
SEBI Update
REGULATORY UPDATE | SEBI ORDERS VARANIUM CLOUD TO RESTORE & DISGORGE FUNDS OVER IPO & RIGHT ISSUE FRAUD
The Securities and Exchange Board of India (“SEBI”) on 25 August 2025 passed a Final Order against Varanium Cloud Limited (“VCL”) and its key management for alleged fraudulent and misleading activities in connection with its Initial Public Offer (IPO), Rights Issue and subsequent disclosures.
BACKGROUND
The proceedings stemmed from SEBI’s preliminary examination pursuant to media reports and complaints regarding VCL’s financial statements and corporate announcements, which led to an Interim Order dated 10 May 2024 against VCL and its MD/Chairman, Harshwardhan Hanmant Sabale (Mr Sabale).
VCL raised approximately Rs 40.39 crore through its IPO in September 2022 (primarily for Edge Data Centres and Edmission Digital Learning Centres) and proposed a further Rs. 48.45 crore through a Rights Issue in September 2023. SEBI examined the utilisation of issue proceeds, financial statements, Prospectus disclosures, corporate announcements, related-party transactions, and the role of directors, the CFO, the merchant banker and other intermediaries.
SEBI’S FINDINGS
SEBI found that VCL misrepresented its financial statements and prospectus by showing fictitious sales and purchases, and that its disclosures on utilisation of IPO proceeds (including the Statement of Deviation dated 17 November 2023) were incorrect and misleading.
SEBI found that IPO and Rights Issue proceeds of Rs. 62.51 crore were diverted to related parties and other entities, including Rs. 32.73 crore transferred directly to Mr Sabale’s personal account. BM Traders (operated by Mr Raj Jagtani) received Rs. 19.66 crore in aggregate from the issue proceeds, of which Rs. 15.60 crore was transferred onwards; and that no adequate evidence of genuine business purpose was produced.
SEBI found several business announcements by VCL to be false and unsubstantiated. SEBI also found that the Company also failed to support the substantial increase in reported revenues (including those of its US subsidiary) with invoices, contracts or employee details. Pending litigation was omitted from the Letter of Offer, and the Prospectus contained material omissions and misstatements. Liability was fastened on the Company, its MD, Executive Directors and CFO.
SEBI found that the lead manager, First Overseas Capital Limited (FOCL), failed to exercise independent due diligence and did not disclose pending litigation. SEBI rejected FOCL’s defence that it could rely on the Company’s representations and third-party reports. Athos Capital Advisors Private Limited (ACAPL) and Mr Jinesh Mehta were held to have aided and abetted the misrepresentations; ACAPL received approximately Rs. 2.50 crore from VCL, and Mr Mehta admitted drafting portions of the Prospectus and assisting with fundraising.
SEBI’S DIRECTIONS
VCL was directed to bring back Rs. 62.51 crore (with 12% p.a. interest) within three months. Mr Sabale was directed to disgorge unlawful gains of Rs. 128.77 crore (with 12% p.a. simple interest) to the Investor Protection and Education Fund. VCL and Mr Sabale were debarred from the securities market for 7 years.
ACAPL and Mr Jinesh Mehta were debarred for 2 years; Mr Raj Jagtani/BM Traders for 4 years; the Executive Directors and CFO (Mr Vinayak Jadhav, Mr Mukundan Raghavan and Mr Fahim Shaikh) for 1 year; and FOCL for 2 years (to run consecutively with an earlier debarment). Monetary penalties were also imposed, including Rs. 20.40 crore on Mr Sabale, Rs. 13 crore on VCL and Rs. 10.10 crore on Mr Raj Jagtani.
Proceedings against the Company Secretary (Ms Hetal Somani) and a Non-Executive Director (Mr Kalpesh Acharekar) were disposed of without directions or penalty, the allegations against them being found unsustainable.
MHCO COMMENT
The order is significant for its treatment of misrepresentation in financial statements and public-issue disclosures, diversion of IPO and Rights Issue proceeds, and the accountability of directors, KMPs and intermediaries. It reiterates that a lead manager must conduct independent due diligence and cannot merely rely on the issuer’s representations or third-party reports.
SEBI did not fasten liability on every director or officer; allegations against the Company Secretary and non-executive director were dropped for want of material. Overall, SEBI characterised the matter as a fraudulent scheme of raising public funds on misleading disclosures, followed by diversion of proceeds and creation of a false picture of the Company’s performance. The restoration, disgorgement, debarment and penalty directions reflect the seriousness with which the conduct was viewed.
By:
Mr. Bhushan Shah, Partner
Mr. Abhishek Nair, Associate
Ms. Sayali Kshirsagar, Associate
Rea Estate
BOMBAY HIGH COURT ALLOWS REFUND OF STAMP DUTY PAID ON CANCELLED DEVELOPMENT AGREEMENT
The Bombay High Court, vide judgment dated 20 August 2026 in Sai Innovation v. Joint District Registrar and Collector of Stamps, Pune City & Ors. (Writ Petition No. 7566 of 2016), has held that a Development Agreement which fails to achieve its intended purpose and is subsequently cancelled can qualify for refund of stamp duty under Section 47(c)(5) of the Maharashtra Stamp Act, 1958 (“the Stamp Act”), and that such an agreement can avail the extended limitation period under the proviso to Section 48(1) where stamp duty has been calculated with reference to Article 25 of Schedule I.
Background:
Sai Innovation had entered into a Development Agreement (“said Agreement”) dated 15 April 2013 with the owners of land at Village Mauje Balewadi, Pune, for development of approximately 8,000 sq. metres of land and paid stamp duty under Article 25 read with Article 5 of Schedule I to the Stamp Act. The owners were unable to obtain sanction of the building plans within a reasonable time, and disputes subsequently arose between the parties. The said Agreement was therefore cancelled by a registered Deed of Cancellation (“said Deed”) dated 18 February 2014, registered on 24 February 2014, and the consideration received was returned. Sai Innovation thereafter applied on 7 April 2014 for refund of the stamp duty. The Respondent Nos 1&2 vide their orders dated 11 August 2014 and 6 December 2014 (“Impugned Orders”) respectively, rejected the refund application of the Petitioner, principally on the ground that the said Agreement was not a “conveyance” and therefore did not fall within the proviso to Section 48(1) of the Stamp Act.
Issue:
The Court dealt with the following issues:
Whether the said Agreement had failed to achieve its intended purpose to attract Section 47(c)(5) of the Stamp Act;
Whether a Development Agreement could avail the benefit of the proviso to Section 48(1), particularly where stamp duty was calculated as per Article 25 of Schedule I;
Whether the reference to “actual, open possession” in Clause 13 of said Agreement be interpreted as transfer of possession to the developer, notwithstanding Clause 11 of the said Agreement which described the developer as a licensee; and
Whether the Respondents could subsequently rely upon the alleged transfer of possession as a ground for rejecting the refund claim, when the refund claim had initially been rejected by the Impugned Orders on other grounds, and the issue of possession did not form part of the reasons recorded in those orders.
Key Findings
The Court, while differentiating between Section 47 and Section 48 of the Stamp Act, held that while Section 47 is the main provision that gives the right to a refund of stamp duty, Section 48 only deals with the time limit. In the present case, the proposed development under the said Agreement was never acted upon, and the parties later cancelled the said Agreement by the said Deed. As a result, the transaction had clearly failed to achieve its intended purpose under Section 47(c)(5) of the Stamp Act. The Court therefore said the refund claim had to be examined first under Section 47 and could not be turned down simply by pointing to the limitation period.
On the question of possession, the Court held that Clause 13 of the said Agreement could not be read in isolation from Clause 11. Although Clause 13 referred to “actual, open possession”, Clause 11 expressly described the developer’s rights as those of “a licensee for development”. Reading the Agreement as a whole, the Court concluded that the developer was granted only a limited contractual licence to enter the property and undertake development activities, and that there was no transfer of legal or exclusive possession. The Court also noted that the absence of a separate possession receipt, by itself, did not establish that possession had been transferred.
Held
In light of the above reasoning, the Court allowed the writ petition and quashed the Impugned Orders passed by the Respondents. The Court held that the refund application was filed within the extended period prescribed under the proviso to Section 48(1) of the Stamp Act and, accordingly, rejected the Respondents’ objection that the claim was barred by the ordinary six-month limitation period.
MHCO Comment
Parties seeking refund of stamp duty on a cancelled Development Agreement should note that Section 47 governs the substantive entitlement to refund, while the proviso to Section 48(1) determines the applicable limitation period. Further, the legal character of a Development Agreement should be assessed by reading the same meaningfully and not in isolation from other clauses provided therein.
By:
Mr. Bhushan Shah, Partner
Ms. Meeta Kadhi, Associate Partner
Mr. Saptadip Nandi Chowdhury, Associate
SEBI Update
REGULATORY UPDATE | SEBI IMPOUNDS ₹ 3.67 CR FROM TWO ENTITIES FOR ALLEGED MANIPULATIVE TRADES DURING CLOSING AUCTION SESSION
BACKGROUND
The Securities and Exchange Board of India (“SEBI”) passed an Ex-Parte Interim Order dated 19 August 2026 against Copthall Mauritius Investment Limited (“Copthall”) and Mansi Share and Stock Broking Private Limited (“Mansi”) in relation to alleged manipulative trading during the Closing Auction Session (“CAS”) on the BSE SENSEX expiry day.
SEBI's CAS framework, introduced vide Circular dated 16 January 2026 and made effective from 3 August 2026, provides for determination of the closing price through a dedicated auction mechanism based on the interaction of buy and sell orders. The framework replaced the earlier methodology based on the volume-weighted average price (“VWAP”) for securities covered under the CAS framework, which determined the price of securities based on the closing price of the security or focused on the weight of trades executed in the last 30 minutes of the trading session. Now, under the CAS framework, the price of securities is determined based on buy and sell orders in a single pool, executed at a single equilibrium price in a dedicated 20-minute daily auction timeline.
SEBI’S FINDING
SEBI prima facie found that the trading activity of Copthall and Mansi was linked to their outstanding SENSEX option positions and was undertaken to influence the Indicative Equilibrium Price (“IEP”) and closing price of the SENSEX so as to obtain a favourable payoff from their expiry-day F&O positions.
On 13 August 2026, SEBI's surveillance observed three sharp movements in the SENSEX during the CAS. Upon examination of the trade and order logs, SEBI observed that these movements coincided with large and aggressive buy orders placed by Copthall and sell orders placed by Mansi in SENSEX constituent securities, which were subsequently cancelled. SEBI accordingly examined the trading activity of the two entities and its linkage with their outstanding SENSEX option positions. SEBI noted that the material on record did not prima facie indicate that the two Noticees acted in concert. Rather, each appeared to have adopted a separate strategy to move the SENSEX in a direction favourable to its respective F&O positions.
SEBI'S DIRECTIONS
SEBI directed that the bank accounts of Copthall and Mansi be impounded to the extent of ₹2,96,16,000 and ₹71,64,773 respectively, aggregating a total of ₹3,67,80,773. SEBI also debarred the noticees from accessing the securities markets and prohibited them from participating in the CAS, including placing, modifying or cancelling orders. Restrictions were also imposed on their bank and demat accounts, transfer/redemption of securities and disposal of assets without SEBI's permission. They were further directed to cooperate with SEBI's ongoing examination/investigation.
MHCO COMMENT
The order is significant in the context of the newly introduced CAS framework and SEBI's surveillance of potential attempts to influence the closing price through order placement and cancellation. The order demonstrates that SEBI is examining the nature, timing and price of orders, their impact on the IEP, subsequent cancellation of orders and the corresponding F&O positions of the concerned entities.
The directions are interim in nature and are based on prima facie findings pending further investigation. SEBI has expressly clarified that the detailed investigation is to proceed independently of the prima facie observations contained in the interim order. Notably, SEBI has not alleged that Copthall and Mansi acted in concert. The findings against the two entities are based on their respective trading patterns and F&O positions. Since the order is ex-parte and interim in nature, the findings remain subject to SEBI's further examination, as well as the Noticees' replies and opportunity of hearing.
By:
Mr. Bhushan Shah, Partner
Ms. Sayali Kshirsagar, Associate
IBC Update
IBC UPDATE - REMOVAL OF INTERIM MORATORIUM FOR PERSONAL GUARANTORS APPLIES TO PENDING PROCEEDINGS
Recently, the Bombay High Court in the case of Tata Capital Financial Services Limited v. Neel Motors LLP & Ors., held that the amendment introducing Section 96(4) of the Insolvency and Bankruptcy Code, 2016 (“IBC”) applies to insolvency applications filed before that date which remain pending. The Court consequently held that the interim moratorium under Section 96 ceased to operate against the personal guarantors from 26 May 2026, enabling Tata Capital to pursue limited interim relief under Section 9 of the Arbitration and Conciliation Act, 1996 (“Arbitration Act”).
FACTS:
The Petitioner, Tata Capital Financial Services Limited (“Tata Capital”) extended financial assistance to Respondent No. 1, Neel Motors LLP, under a Channel Finance Agreement. Respondent Nos. 2 to 4 were individual guarantors and partners of Neel Motors LLP, while Respondent No. 5 was a separate LLP acting as guarantor. The Letters of Guarantee contained arbitration clauses with Mumbai as the seat.
In 2021, Tata Capital filed a petition under Section 9 of the Arbitration Act seeking interim protection. Approximately one month prior to filing the Section 9 petition, Tata Capital had initiated Corporate Insolvency Resolution Process (“CIRP”) against Neel Motors under the IBC. The CIRP ultimately failed and Neel Motors was ordered to be liquidated by the NCLT, Mumbai, on 1 April 2022.
Thereafter, in June 2022, Tata Capital initiated insolvency proceedings under Section 95 of the IBC against Respondent Nos. 2, 3 and 4, who were the individual guarantors (“Guarantors”). The filing of the Section 95 applications triggered the interim moratorium under Section 96, stalling the Section 9 petition.
The legal position changed with the insertion of Section 96(4) into the IBC which came into force on 26 May 2026. The amendment provided that Section 96 would not apply where an application was filed for initiating an insolvency resolution process in respect of a personal guarantor to a corporate debtor.
Relying upon the amendment, Tata Capital sought consideration of its pending Section 9 petition. The principal issue before the Court was whether Section 96(4) could apply to Section 95 applications which had been filed before 26 May 2026 but continued to remain pending on the date of the amendment.
Tata Capital’s Case
Tata Capital contended that, in view of the newly inserted Section 96(4), the moratorium under Section 96 no longer operated against the individual guarantors and the expression “where an application is filed” was sufficiently broad to include pending applications. It further relied upon the legislative purpose behind the amendment, that it was intended to “remove any perverse incentives” associated with the initiation of individual insolvency proceedings. Considering the considerable delay since filing of the Section 9 petition, Tata Capital only sought disclosure of the guarantors’ assets and an injunction restraining them from selling, transferring, alienating, encumbering or otherwise dealing with such assets pending arbitration.
Guarantor’s Case
The guarantors opposed the application, contending that such an interpretation would give the amendment retrospective effect. They submitted that the expression “where an application is filed” covers only applications filed after 26 May 2026 and could not extend to applications which had already been filed. Any other interpretation, according to the guarantors, would retrospectively alter the legal consequences attached to the pending proceedings.
They further argued that although insolvency proceedings are not strictly recovery proceedings, both the insolvency and arbitration proceedings were directed towards recovery of the same debt and Tata Capital should therefore not be permitted to pursue both simultaneously
Court’s Finding
The Hon’ble Court held that the expression “where an application is filed” in Section 96(4) encompasses applications which had already been filed and continued to remain pending before the adjudicating authority. Had the legislature intended to restrict the provision only to applications filed after 26 May 2026, it could have expressly used language to that effect. The Court distinguished between retrospective and retroactive operation, relying upon the Supreme Court’s decision in Securities and Exchange Board of India v. Rajkumar Nagpal, the Court observed that a provision is retrospective when it operates backwards and impairs vested rights, whereas a retroactive provision operates prospectively on a character or status originating in the past. The existence of antecedent facts does not, by itself, make its application retrospective.
Accordingly, the moratorium under Section 96 operated against Respondent Nos. 2 to 4 until 25 May 2026 but ceased from 26 May 2026 when Section 96(4) came into force. The pending Section 9 petition was therefore no longer barred by the IBC moratorium. The Court further acknowledged the possibility of a conflict of interest where the creditor initiating insolvency proceedings may also be pursuing claims against the individual guarantor. However, it held that such considerations could not override the express statutory language, particularly when Section 96(4) was agnostic as to the identity of the person who initiated the Section 95 proceedings.
MHCO Comment
Pending proceedings can be affected by a new provision without the provision necessarily being retrospective. The decisive factor is whether the provision changes completed past rights or operates prospectively upon an existing/pending legal status. Section 96(4) therefore lifted the Section 96 moratorium prospectively from 26 May 2026 even in respect of Section 95 applications filed prior to the amendment coming into force.
By:
Mr. Bhushan Shah, Partner
Ms. Neha Lakshman, Associate Partner
2025 - MANSUKHLAL HIRALAL & CO.
Need Help? Chat with us







