/ Compliance Policies
Data Privacy Policy Template (DPDP Compliant)
Free data privacy policy template compliant with Digital Personal Data Protection Act, 2023. Covers consent, data principal rights, retention, and breach notification.
Version 1.0Effective 2026-01-01Updated 2026-01-01
data privacydpdpdpdp actdata protectionprivacy policyconsent managementgdpr india
/ Complete Template
16 sections
# Data Privacy Policy
[Company Name] ("we," "us," "our") is committed to protecting the personal data of our employees, candidates, customers, and business partners. This policy is formulated in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act).
• Personal Data: Any data about an individual who is identifiable by or in relation to such data
• Data Principal: Individual whose personal data is processed
• Data Fiduciary: Entity that determines purpose and means of processing
• Consent Manager: Person registered with Data Protection Board to enable consent management
• Data Protection Officer (DPO): Person responsible for data protection compliance
• Name: [Company Name]
• Address: [Registered Office Address]
• DPO: [Name, Email, Phone]
• Grievance Officer: [Name, Email, Phone]
4.1 Employee Data
• Identity: Name, date of birth, gender, photograph
• Contact: Address, phone, email, emergency contacts
• Professional: Resume, qualifications, experience, references
• Financial: Bank details, PAN, salary, tax declarations
• Health: Medical records, disability information, insurance nominees
• Biometric: Fingerprint, facial recognition (where applicable)
4.2 Candidate Data
• Resume, cover letter, application details
• Interview recordings and assessment results
• Background verification reports
• Reference check information
4.3 Customer/Client Data
• Contact information, business details
• Transaction records, payment information
• Communication history
• Recruitment and hiring decisions
• Employment administration (payroll, benefits, attendance)
• Performance evaluation and career development
• Compliance with legal obligations (tax, labour laws)
• Internal investigations and disciplinary proceedings
• Business operations and client services
• Security and access control
• Consent: Explicit consent obtained for specific purposes
• Legitimate Use: Processing necessary for employment relationship
• Legal Obligation: Compliance with applicable laws
• Employment: Processing necessary for employment purposes
• Consent obtained in clear, plain language
• Specific purpose stated
• Right to withdraw consent anytime
• No denial of service for refusal (where not mandated by law)
• Consent records maintained with timestamps
8.1 Right to Access
• Request information about personal data processed
• Obtain summary of processing activities
• Free of charge for first request; nominal fee for subsequent
8.2 Right to Correction and Erasure
• Request correction of inaccurate data
• Request completion of incomplete data
• Request updating of outdated data
• Request erasure of data no longer necessary
8.3 Right to Grievance Redressal
• Register complaint with DPO
• Appeal to Data Protection Board
• Seek compensation for harm suffered
8.4 Right to Nominate
• Nominate another individual to exercise rights in case of death/incapacity
• Employee data: 7 years post-employment (statutory requirement)
• Candidate data: 1 year post-rejection (unless consent for longer)
• Financial data: 8 years (Income Tax Act)
• Biometric data: Deleted upon termination
• Reviewed annually; automated deletion where applicable
• Encryption at rest and in transit
• Access controls and role-based permissions
• Regular security audits and penetration testing
• Incident response plan
• Employee training on data handling
• Secure disposal procedures
• Report to Data Protection Board within 72 hours
• Notify affected data principals
• Maintain breach register
• Root cause analysis and remediation
• Board may direct publication of breach details
• Transfer to countries with adequate data protection (as notified by Government)
• Standard contractual clauses for other transfers
• Data principal consent for specific transfers
• Impact assessment before transfer
• Not applicable for employment context
• For apprenticeship/internship: Verifiable parental consent required
• Up to ₹250 crore for non-compliance with provisions
• Up to ₹200 crore for failure to implement security safeguards
• Up to ₹50 crore for failure to notify breach
• Up to ₹10,000 for minor violations
• Personal liability for officers in charge
This policy is reviewed annually and updated as per regulatory changes.
Last Updated: [Date]
Next Review: [Date + 1 year]
Building your HR foundation? workro helps you hire faster with AI resume scoring, proctored interviews, and compliant offer letters — all in one place.
Learn more →