International standards are making credible labour practices a necessity
As multinationals scale operations across India, their primary operational risk is no longer mere labour compliance, it is the direct intersection of employment law and digital data governance. For foreign advisories and group counsel, the focus has shifted towards the ease of doing business (EoDB) agenda, which the government has established as a pillar of growth through digitisation and trust-based governance.
Multinational firms are increasingly choosing partners who demonstrate operational excellence through workplace formalisation and ethical compliance. In an era defined by rigorous supply chain audits, simple adherence to domestic law is merely the floor. Buyers now benchmark Indian operations against international standards for timely wage payments and statutory accuracy.
DPDPA reshapes HR data compliance

Managing Partner
Singhania & Partners
Tel: +91 11 4430 5000
Email: ravi@singhania.in
The Digital Personal Data Protection Act, 2023 (DPDPA), which became India’s principal data law in November 2025, represents a major shift for HR operations. Under this framework, companies act as “data fiduciaries” while employees are recognised as “data principals” with enforceable rights over their information.
Section 7(i) specifies that personal data may be processed for employment-related purposes without explicit consent under the “certain legitimate uses” exemption. However, there is significant ambiguity.
While the provision covers core needs like payroll and statutory filings, it is not a blanket authorisation. Any activity falling outside these core functions, such as commercial profiling or non-essential surveillance, still requires granular, withdrawable consent. Arguably, background verification (BGV) could be exempt because an active employment relationship does not yet exist, but typically documented candidate consent is a legal necessity. Indian employers, being the data fiduciaries of employees’ digital personal data, have significant responsibilities and obligations, such as sharing data with a data processor and recognising the rights of the employee (as data principal) to correction and accuracy while transferring to the data processor information on what is shared, and grievance redressal, related to digital personal data.
Similarly sharing worker data with overseas headquarters and data processors is subject to the negative list (yet to be notified) of countries to which such data is not to be shared. Failing to do so triggers fines up to INR2.5 billion (USD26.2 million).
Privacy meets labour code reform

Partner
Singhania & Partners
Tel: +91 80 4113 1900
Email: mdamodaran@singhania.in
This privacy overhaul coincided with the activation of the four new labour codes in November 2025, which consolidated 29 outdated statutes into a modern framework. Through portals like Shram Suvidha, the government has streamlined registrations and reporting to reduce the compliance burden, turning every labour law artifact from wage registers to disciplinary files into a regulated data asset. When data and labour laws overlap, a payroll mistake is not just a worker dispute, it is a data breach. With new mandates like the 50% wage rule and the 48-hour settlement of wages requirement, the need for automated, real-time data accuracy is paramount.
EOR models create layered liability
Many firms use employer of record (EOR) or staffing models to enter India quickly. However, these arrangements often create a “layered liability trap” because DPDPA liability hinges on who determines the purpose and means of processing.
To reduce risk, group counsel must sign data processing agreements (DPAs) that explicitly define whether the staffing partner is a data processor or a co-fiduciary. These contracts must mandate indemnification clauses and real-time audit rights for third-party compliance platforms to verify statutory deposits and data security protocols.
Four DPDPA priorities for HR
Legal leadership should focus on four immediate priorities:
-
- Unbundle candidate consent. Secure standalone DPDPA consent for pre-hire BGV. Section 7(1)(i) applies only after employment starts;
- Map HQ data transfers. Audit cross-border employee data flows to global systems to limit parent-entity fiduciary liability;
- Formalise EOR role clarity. Execute DPAs with staffing partners that specify clear indemnities and fiduciary versus processor roles; and
- Align IT and payroll exits. Integrate IT access revocation with mandatory 48-hour wage settlement to prevent statutory data breaches.
- The window for full DPDPA operationalisation closes in May 2027. Build a strong compliance setup today.

B-14/A 4th Floor,
Qutub Institutional Area
Katwaria Sarai,
New Delhi – 110016, Indiagranular






















