City · Gurugram

DPDPA Compliance in Gurugram

The Digital Personal Data Protection Act, 2023 applies to every business that processes personal digital data in India. Its rules were notified in November 2025, and the substantive obligations — notice, consent, security safeguards, breach reporting and grievance redressal — become enforceable on 13 May 2027. Gurugram employers have that window to map their data, fix consent flows and paper their processor contracts.

Last reviewed: 25 August 2026

Why DPDPA compliance matters in Gurugram specifically

Gurugram's data sits in HR systems, not warehouses. Cyber City and Udyog Vihar host global capability centres, captives, BFSI back offices, KPOs, staffing firms and startups serving Indian and offshore clients — and between them they hold enormous volumes of employee, contractor and candidate records in ATS and HRMS platforms. Many of these offices have no India-based privacy function because the parent sits abroad, yet the workforce data is processed here, which is what brings DPDPA into play.

What Gurugram businesses should prepare first

  • Separate India workforce data from any Section 17 offshore-client processing — HQ policy is not a substitute.
  • Put written Section 8(2) contracts on ATS, HRMS, staffing agencies and payroll vendors.
  • Set retention for rejected candidate CVs; a closed requisition is not a licence to keep the file forever.
  • Name owners for all four breach lanes: CERT-In within 6 hours; Rule 7(1) to affected people without delay; Rule 7(2)(a) initial Board intimation without delay; Rule 7(2)(b) detailed Board report within 72 hours.

Frequently asked questions

Our parent company is overseas and privacy is handled by HQ. Does DPDPA still apply to our Gurugram office?

Yes. DPDPA covers personal data processed within India regardless of where the group is headquartered — your employee, contractor and candidate records held in India are squarely in scope. It also reaches processing outside India where it relates to offering goods or services to people in India. There is a narrow carve-out under Section 17 for processing of foreign data principals' data pursuant to a contract with a person outside India, but that never covers your own India workforce data. Separately, being large doesn't make you a Significant Data Fiduciary — SDF status, and the Rule 13 annual audit, DPIA and India-resident DPO that come with it, applies only when the Central Government notifies you.

We receive candidate CVs from staffing agencies and store them in our ATS. Who is responsible for that data?

Once you decide why and how those CVs are used, you're the data fiduciary for them — the agency and the ATS vendor are processors acting on your instructions. That means a written contract with each, with security, breach-notification and deletion clauses. You also need a clear notice at the point of collection and a retention rule: rejected candidate records shouldn't sit in the ATS indefinitely once hiring for that role has closed.

If our HRMS or client environment is breached, what are the reporting timelines?

Four lanes run cumulatively, not as alternatives. CERT-In within 6 hours of noticing a reportable cyber incident; Rule 7(1) intimation to affected Data Principals without delay; Rule 7(2)(a) initial intimation to the Board without delay; Rule 7(2)(b) detailed report to the Board within 72 hours. A global incident-response playbook written for another jurisdiction usually misses the CERT-In and Rule 7(1) lanes, so map all four into it before 13 May 2027.

Official sources

Get a DPDPA readiness walkthrough for your Gurugram office

Book a 30-minute call to map workforce data, ATS vendors, and all four breach lanes against DPDPA — including where HQ policy does not cover India.

Book a demo Free Gap Analysis

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.