EnDetect
Back to Resources
Compliance

India's DPDP Act: What IT & HR Teams Need to Know

A plain-language guide to the Digital Personal Data Protection Act 2023 and what it means for workforce monitoring.

10 min readFeb 10, 2026
India's DPDP Act: What IT & HR Teams Need to Know

Why IT and HR must co-own monitoring

The Digital Personal Data Protection Act (DPDP Act) sets expectations for how organizations in India collect and process personal data, including employee and contractor information gathered through workforce monitoring tools.

IT deploys controls. HR owns notice, consent where required, and grievance handling. Neither team alone satisfies an auditor asking about screenshot retention on an NBFC PII desk.

Key Takeaway: Split ownership fails audits. Joint policy sign-off before deploy is the minimum bar.

Employee monitoring in the workplace

Monitoring employee activity on company systems is a common DPDP use case: security, productivity measurement, fraud prevention, or regulatory audit. Personal data includes activity logs, screenshots, and optional identity photos.

Document the purpose in your monitoring policy, limit collection to work devices, and define who may access reports. Avoid monitoring personal devices or off-duty activity unless law and contract clearly allow it.

Key Takeaway: Company devices, stated purpose, named accessors. Those three phrases belong in every monitoring policy.

Lawful purpose and notice

Processing employee activity data needs a clear purpose: security, productivity measurement, compliance, or fraud prevention. Employees should receive understandable notice describing what is collected, retention periods, and who can access reports.

EnDetect customers typically disclose attendance, idle time, and screenshots in onboarding packs. Live view and forensic capture get separate callouts because they collect richer data.

Key Takeaway: Tiered disclosure matches tiered collection. Do not bury live view in generic IT acceptable-use boilerplate.

Data minimization

Collect only what you need. Domain-level website tracking may suffice for productivity programs; full URL or keystroke logging should be reserved for investigations with stricter approval.

Across 10,000+ deployments, most seats run attendance, idle, and screenshots. Forensic depth on every user violates minimization and annoys engineers who never touch client data.

Key Takeaway: Minimization is a settings choice, not a legal footnote. Default to the lightest tier that meets your risk.

Retention and access rights

Define retention schedules and deletion after offboarding plus your legal hold window. Be prepared to respond to access requests about personal data your monitoring systems store.

Billions of logs require automated retention jobs. Manual spreadsheet tracking breaks at BPO scale within a single quarter.

Key Takeaway: Set retention in the product, not in a wiki page nobody updates.

Using EnDetect responsibly

Configure role-based access, document policies, export audit logs for regulators, and review settings when DPDP rules and guidance evolve.

NBFC and BPO auditors increasingly ask for tamper-proof exports. Plan export formats before the examination, not the week of.

Key Takeaway: Responsible use is provable access control plus exportable evidence, not a trust-us slide.

FAQ: quick answers for HR

Do we need consent for monitoring? Often notice and legitimate purpose suffice for employment contexts, but legal review is essential. Can employees see their data? Plan for access requests. Can we keep screenshots for a year? Match retention to policy and DPDP minimization principles.

Key Takeaway: HR FAQs should mirror your actual EnDetect settings, not generic legal language.

Your next step

Schedule a 90-minute working session with HR, IT, and legal. Bring your current monitoring settings: screenshot interval, retention days, live view roles, forensic users. Output a one-page DPDP appendix you attach to offer letters and contractor SOWs.

Key Takeaway: Settings review first, policy PDF second. Mismatch between them is what regulators notice.

Explore more on workforce security and productivity.Book a demo