This article is general information about the DPDP Act, 2023 as of 10 August 2026. It is not legal advice — consult qualified counsel before making compliance decisions.

India's DPDP Act creates no special category for employee wellbeing data. It is ordinary personal data, and most obligations are not yet in force.

That sentence is worth sitting with, because most vendor pitches imply the opposite. The Digital Personal Data Protection Act, 2023 has no sensitive-data tier and does not name wellbeing. It regulates personal data as one class and attaches its heavier duties to who you are and whose data it is, not to how private the data feels. What follows is what the statute and the notified Rules actually say, what commences when, and the five questions worth putting to any wellbeing vendor before you sign.

Wellbeing data is not a special category under the Act

The DPDP Act, 2023 is Act No. 22 of 2023 and received Presidential assent on 11 August 2023. Read it end to end and the phrases "sensitive personal data" and "special categories of personal data" do not appear. This is a deliberate departure from the European posture, and it is the single most misunderstood feature of the Indian regime.

Where the Act does escalate, it escalates on the actor or the subject rather than the data type. Section 10 creates the Significant Data Fiduciary, a class the Central Government may notify based on such factors as the volume and sensitivity of personal data processed and risk to the rights of Data Principals, among others, carrying extra duties. Section 9 escalates for children and for persons with disabilities. Neither hook is "this data concerns wellbeing".

One caveat, because the opposite claim is also wrong. The notified Rules do reference mental health in more than one place. The Fourth Schedule references "a Data Fiduciary who is a clinical establishment, mental health establishment or healthcare professional" in connection with a defined children's-consent carve-out under section 9, itself defined by reference to the Mental Health Care Act, 2017. It is not a sensitive-data classification, and it does not apply to an employer running a workforce wellbeing programme.

What the Act calls you, and what it calls your employee

Two definitions carry the whole framework, and both are shorter than the commentary around them.

Section 2(i) defines a Data Fiduciary as "any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data". If you decide that your workforce will have access to a wellbeing programme and you decide what the programme reports back to you, you are a Data Fiduciary. Section 2(j) defines a Data Principal as "the individual to whom the personal data relates" — your employee.

The practical consequence is that the obligation does not transfer to the vendor because the vendor holds the servers. You determined the purpose. A processing agreement allocates work and liability between you and the vendor; it does not move your status under the Act.

What is actually in force today, and what is not

This is where most published commentary is simply wrong, and being wrong in the direction of urgency.

The Rules were notified as G.S.R. 846(E), dated 13 November 2025. They do not all commence at once. Rules 1, 2 and 17 to 21 came into force on publication. Rule 4, covering Consent Manager registration and obligations, commences one year after publication. Rules 3, 5 to 16, 22 and 23 commence eighteen months after publication. The parallel commencement notification for the Act itself, G.S.R. 843(E), brings sections 1(2), 2, 18 to 26, 35, 38 to 43 and 44(1) and (3) into force immediately, sections 6(9) and 27(1)(d) at one year, and sections 3 to 5, 6(1) to (8) and (10), 7 to 17, 27 apart from (1)(d), 28 to 34, 36 to 37 and 44(2) at eighteen months.

Work in months rather than dates. A corrigendum, G.S.R. 892(E) of 10 December 2025, amended the commencement wording, the gazette masthead and the e-Gazette identifier differ by a day, and practitioner notes currently compute the twelve-month milestone as 12, 13 or 14 November 2026 with a matching split in May 2027. Anyone quoting you a precise deadline day is quoting one reading of a genuinely contested point. Plan to mid-November 2026 and mid-May 2027.

The consequence for a CHRO is worth stating plainly. Sections 7, 8 and 12, and the Schedule of penalties, all sit in the eighteen-month tranche. The obligations described in this article are not enforceable against you today. They become enforceable in mid-2027. That is not a reason to defer — an eighteen-month runway is roughly one procurement cycle plus one renewal [Estimate], and the contracts you sign this year will still be running — but it does mean a vendor invoking imminent penalty exposure is either uninformed or selling to a deadline that does not exist yet.

The penalties, quoted rather than paraphrased

When the Schedule commences, two entries matter most for a wellbeing programme.

Serial number 1 of the Schedule addresses a "Breach in observing the obligation of Data Fiduciary to take reasonable security safeguards to prevent personal data breach under sub-section (5) of section 8", with a penalty that "may extend to two hundred and fifty crore rupees". Section 8(5) itself requires a Data Fiduciary to protect personal data in its possession or under its control, "including in respect of any processing undertaken by it or on its behalf by a Data Processor". The words "on its behalf" are the ones to notice: your vendor's security failure is assessed against your obligation.

Serial number 2 addresses a "Breach in observing the obligation to give the Board or affected Data Principal notice of a personal data breach under sub-section (6) of section 8", with a penalty that "may extend to two hundred crore rupees".

Both figures are statutory maxima quoted verbatim from the Schedule to the Act, not estimates of likely exposure, and neither is enforceable until the eighteen-month tranche commences.

How this differs from the GDPR and HIPAA posture a vendor may be selling

A wellbeing vendor selling into India will often lead with a European or American certification. Compare the three frameworks criterion by criterion and the gap becomes obvious.

On whether wellbeing data is a special category: the EU's General Data Protection Regulation does carve out special categories of personal data, including data concerning health, and attaches a distinct lawful-basis test to them; HIPAA regulates protected health information but only in the hands of covered entities and their business associates within the United States health system; the DPDP Act creates no such category at all and applies one standard to all personal data. On who is covered: GDPR reaches processing tied to the EU regardless of sector; HIPAA reaches a defined set of American healthcare actors, which an Indian employer's wellbeing vendor generally is not; DPDP reaches processing of digital personal data within India, and processing outside India connected with offering goods or services to Data Principals in India. On what an Indian regulator will ask you for: GDPR alignment is evidence of maturity but is not the test; HIPAA alignment is largely beside the point; the DPDP Act and its Rules are the test, and nothing else discharges it.

The honest reading is that a GDPR-aligned vendor is probably running good practice, and that this is not the same as being aligned to the instrument that will actually be applied to you. Ask for the second thing specifically.

What aggregate-only should mean in the contract

"Aggregate-only" is the most-used and least-defined phrase in this category. Three things make it real rather than decorative, and all three belong in the contract rather than the pitch.

The first is a stated cohort floor: a minimum group size below which no report is generated at all, written as a number, with the behaviour on falling below it specified. Without a floor, "aggregate" over a team of four is individual data with extra steps. The second is a prohibition on re-identification that survives the commercial relationship, binding the vendor not to combine reported aggregates with any other dataset that would name an individual. The third is a plain statement that no individual entry, transcript, session record or score is available to the employer through any interface, export, support request or escalation path. Support-channel access is the usual leak, and it is usually unaddressed.

Five questions to run before you sign

You can do this without buying anything, and it takes about an hour with a vendor on a call [Estimate]. There are five questions.

Ask, first, which lawful basis under section 4(1) the vendor asserts for individual wellbeing records, and require the answer to name either consent or a specific clause of section 7. An answer that cannot name one is an answer that has not been thought about. Ask, second, what the cohort floor is as an integer and what happens to a report when a team falls below it. Ask, third, how an employee exercises erasure, and whether the route is published in the manner Rule 14 requires. Ask, fourth, what the breach notification chain looks like in practice — who tells whom, in what window, and whether you as Data Fiduciary are told in time to meet your own section 8(6) obligation once it commences. Ask, fifth, whether the vendor is aligned to the DPDP Act and its Rules specifically, and count a GDPR or HIPAA answer as a non-answer to that question.

Where ManoYatra sits

ManoYatra is built privacy-by-design and DPDP-aligned. We will not claim a certification against the Act, because none exists to be held.

If you are assembling a workforce wellbeing programme against a 2027 commencement, the ManoYatra for business page sets out our approach, and you can bring a shortlist to us through contact. Related reading on this blog: the hidden cost of absenteeism on what workforce data is actually worth to a finance function, and POSH Act compliance and director liability on the adjacent statute where individual-level confidentiality is also load-bearing.

Sources

the Ministry of Electronics and Information Technology's text of The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023, assented 11 August 2023), read 10 August 2026, cross-checked against the Ministry of Law and Justice text on India Code, read 10 August 2026; the Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) dated 13 November 2025 (Ministry of Electronics and Information Technology), read 10 August 2026; the commencement notification G.S.R. 843(E) of 13 November 2025 (Ministry of Electronics and Information Technology), read 10 August 2026; the corrigendum G.S.R. 892(E) of 10 December 2025 (Ministry of Electronics and Information Technology), read 10 August 2026; and the Press Information Bureau's release on the notification of the DPDP Rules, 2025 (Government of India), read 10 August 2026.