The DPDP Act, explained for firms that hold client data
If your firm keeps candidate CVs, client KYC or signed documents, India’s new data-protection law now speaks to you — with no small-business exemption. Here is what it asks, and when.
Recruitment consultancies, CA practices, law firms and agencies all sit on the same thing: other people’s personal data — candidate CVs, client KYC, PAN and Aadhaar copies, signed agreements. India’s Digital Personal Data Protection Act, 2023, with its final Rules notified in November 2025, turns holding that data into a set of legal duties. And crucially, there is no size threshold.
You are a "Data Fiduciary" — yes, even at two people
The Act calls the individual whose data you hold the Data Principal, and the business that decides why and how to process it the Data Fiduciary. That definition is purely functional: there is no turnover, headcount or data-volume floor. A two-person recruitment desk deciding what to do with candidate data is a Data Fiduciary, with the same core obligations as a large company. A narrow exemption for notified startups exists on paper but has not been activated — do not plan around it.
What the Act actually asks of you
- Notice and consent — a standalone, plain-language notice at collection, itemising the data you take and why, offered in English and the Constitution’s scheduled languages. Consent must be specific to that purpose.
- Reasonable security safeguards — the Rules set a floor: encryption or masking, access control, logs kept for a year, backups, and security clauses in your vendor contracts.
- Breach reporting — notify affected individuals without delay and file a detailed report to the Data Protection Board within 72 hours. There is no materiality threshold; any breach triggers it.
- Erasure and a contact — delete data when the purpose is served or consent is withdrawn (unless a law requires you to keep it), publish a named contact, and run a grievance mechanism that answers within 90 days.
The penalties are large — but not the myth
The Schedule allows penalties up to Rs 250 crore for failing to take reasonable security safeguards and up to Rs 200 crore for failing to report a breach. Two things temper the headline: these are ceilings ("may extend to"), set with regard to proportionality and the likely impact on the person, and — contrary to widely repeated 2023 coverage — they are not a per-breach multiplier. A small firm acting in good faith is not the target; a firm with no notice, no access control and no breach process is.
What to do now
The core obligations become enforceable around mid-May 2027, so you have runway — but the burden of proving you gave notice and obtained consent falls on you, so build it into your intake flow from the day it goes live. Practically: put a real privacy notice on every candidate and client form, lock access so a consultant sees only their own files, encrypt stored documents, write a breach runbook, and map which documents you must keep by law versus erase when done.
General awareness only, accurate to the best of our research as of August 2026 — not legal advice. The Act and Rules are notified but the core obligations are not yet enforceable (a phased timeline runs to roughly mid-May 2027), the Data Protection Board was still being constituted at the time of writing, and the government had floated shortening the timeline. Confirm the current position before acting.
One login for your team and your clients.
Attendance, tasks, a client portal and your own page — free while we onboard.